WO2011091728A1 - 授权管理物联网终端的方法和系统 - Google Patents

授权管理物联网终端的方法和系统 Download PDF

Info

Publication number
WO2011091728A1
WO2011091728A1 PCT/CN2011/070269 CN2011070269W WO2011091728A1 WO 2011091728 A1 WO2011091728 A1 WO 2011091728A1 CN 2011070269 W CN2011070269 W CN 2011070269W WO 2011091728 A1 WO2011091728 A1 WO 2011091728A1
Authority
WO
WIPO (PCT)
Prior art keywords
internet
things
terminal
things terminal
iot
Prior art date
Application number
PCT/CN2011/070269
Other languages
English (en)
French (fr)
Inventor
邢晓江
Original Assignee
中兴通讯股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中兴通讯股份有限公司 filed Critical 中兴通讯股份有限公司
Priority to EP20110736610 priority Critical patent/EP2482488A4/en
Publication of WO2011091728A1 publication Critical patent/WO2011091728A1/zh

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L41/00Arrangements for maintenance, administration or management of data switching networks, e.g. of packet switching networks
    • H04L41/28Restricting access to network management systems or functions, e.g. using authorisation function to access network configuration
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/305Authentication, i.e. establishing the identity or authorisation of security principals by remotely controlling device operation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0884Network architectures or network communication protocols for network security for authentication of entities by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/70Services for machine-to-machine communication [M2M] or machine type communication [MTC]

Definitions

  • the present invention relates to the field of telecommunications and information technology, and more particularly to a method and system for authorizing management of an Internet of Things terminal.
  • the Internet of Things includes IoT terminals, IoT platforms and objects.
  • the IoT platform collects data through IoT terminals and provides acquired data to objects such as vehicle management, elevator management, retail management, logistics management, and automation. Waiting for services to humans; At the same time, the IoT platform also manages the IoT terminals for billing and security.
  • the transport bearer channel for data in the Internet of Things can be either a wireless network or a wired network.
  • the IoT platform forwards commands to realize the management of the Internet of Things terminals, which increases the load on the IoT platform, increases the processing of the entire system, increases the system delay, and reduces the system. Reliability.
  • the present invention provides a method and system for authorizing management of an Internet of Things terminal, and reducing the management load of the Internet of Things platform on the Internet of Things terminal under the condition of ensuring data security of the Internet of Things terminal.
  • a method for authorizing management of an Internet of Things terminal comprising: an IoT platform authorizing an object to be managed by an IoT terminal, and obtaining an authorized object to manage the IoT terminal .
  • the step of obtaining the authorized object to manage the Internet of Things terminal comprises: acquiring, by the object from the Internet of Things platform, authorization information for managing the Internet of Things terminal, wherein the object uses the authorization for managing the Internet of Things terminal Information and authentication and session with the IoT terminal
  • the key agreement is to manage the IoT terminal by using the negotiated session key.
  • the method further includes: the object canceling management of the Internet of Things terminal by deleting the authorization information for managing the Internet of Things terminal.
  • the step of the IoT platform authorizing the management of the IoT terminal to the object includes: the object transmitting the identity information of the IoT terminal to the Internet of Things platform; the IoT platform according to the identity information of the IoT terminal, Negotiating authorization information for managing the IoT terminal with the corresponding IoT terminal;
  • the Internet of Things platform transmits the authorization information for managing the Internet of Things terminal to the object.
  • the authorization information for managing the Internet of Things terminal includes at least one of an authorization key, an encryption mode, and an authorization object.
  • the step of performing communication authentication between the object and the Internet of Things terminal includes: encrypting an authentication request by using the authorization key and the encryption method, where the authentication request includes the authorized object; And the IoT terminal sends the encrypted authentication request; and receives an authentication result of the IoT terminal to the authorized object.
  • the step of authenticating the object with the Internet of Things terminal further includes: when the authentication result is passed, the Internet of Things terminal sends the session key to the object by using the authentication result.
  • An Internet of Things system comprising: an object, an Internet of Things platform, and an Internet of Things terminal, wherein the Internet of Things platform is configured to: authorize an object to be managed by the object network terminal; and the object is set to: after being authorized, managing the object Networked terminal.
  • the object is configured to manage the Internet of Things terminal in the following manner: obtaining authorization information for managing the Internet of Things terminal from the Internet of Things platform, and using the authorization information and the management information for managing the Internet of Things terminal Description of Internet of Things terminals for communication authentication and session key association And managing the IoT terminal with the negotiated session key.
  • the IoT platform is further configured to: notify the object to cancel management of the Internet of Things terminal; and the object is further configured to: after receiving the management information for canceling the Internet of Things terminal, by deleting the The 4 authorized information for managing the Internet of Things terminal cancels the management of the Internet of Things terminal.
  • the IoT platform includes: a first receiving module, configured to: receive identity information of the Internet of Things terminal from the object; and a negotiation module, configured to: according to the identity information of the Internet of Things terminal, The corresponding IoT terminal negotiates authorization information for managing the IoT terminal; and the first sending module is configured to: send the authorization information for managing the IoT terminal to the object.
  • the authorization information for managing the Internet of Things terminal includes at least one of an authorization key, an encryption mode, and an authorization object.
  • the object includes: an encryption module, configured to: encrypt the authentication request including the authorization object by using the authorization key and the encryption manner; and the second sending module is configured to: The IoT terminal sends the encrypted authentication request to carry the authorized object; the second receiving module is configured to: receive the authentication result of the IoT terminal to the authorized object. The IoT terminal sends the session key to the object by using the authentication result when the authentication result is passed.
  • the technical solution provided by the invention authorizes the management of the Internet of Things terminal to the object through the Internet of Things platform, reduces the management load of the Internet of Things platform, and reduces the processing link of the Internet of Things system, and shortens the system under the condition of ensuring data security of the Internet of Things terminal. The processing delay increases the reliability of the system.
  • FIG. 1 is a schematic structural diagram of an Internet of Things system provided by the present invention
  • FIG. 2 is a timing diagram of a method for managing an Internet of Things terminal of an object in the present invention
  • FIG. 3 is a timing chart of a method for communication negotiation between an Internet of Things terminal and an object according to the present invention
  • FIG. 4 is a schematic structural diagram of an Internet of Things platform in an Internet of Things system provided by the present invention
  • FIG. 5 is a schematic structural diagram of an object in an Internet of Things system provided by the present invention.
  • the Internet of Things system provided by the present invention includes an object, an Internet of Things platform, and an Internet of Things terminal.
  • the Internet of Things platform is set up to: control and manage the IoT terminal, receive data reported by the IoT terminal, process the data, provide the processed data to the object, and also have security, billing, network management, etc.
  • the object of the Internet of Things platform authorization object directly manages the Internet of Things terminal; the object is the specific application and service of the Internet of Things, and the Internet of Things terminal is managed through the Internet of Things platform.
  • the object requests the Internet of Things platform to directly manage part of the Internet of Things terminal, and realizes direct management of the Internet of Things terminal after the authorization is passed, without forwarding the management command of the Internet of Things terminal through the Internet of Things platform;
  • the Internet of Things terminal also accepts direct management of objects.
  • the following describes the method for directly managing the Internet of Things terminal in the object of the Internet of Things, as shown in Figure 2: Step 201:
  • the Internet of Things platform provides the information of the managed IoT terminal to the object; the specific provision may be provided by the Internet of Things platform. It is also possible that the object actively requests the information of the Internet of Things terminal.
  • Step 202 The object requests authorization from the Internet of Things platform to directly manage the target Internet of Things terminal, including identity information of the target Internet of Things terminal.
  • Step 203 The Internet of Things platform negotiates an authorization key, an authorization object, and an encryption mode with the corresponding IoT terminal according to the identity information of the target Internet of Things terminal.
  • the authorization key is generated by the target Internet of Things terminal and the Internet of Things platform.
  • the method for generating the authorization key in the prior art is applicable to the present invention, which is not limited herein; wherein the authorization object is to allow the object to directly manage the target Internet of Things terminal.
  • the project information may be all items of the target Internet of Things terminal, or may be part of the project.
  • Step 204 The Internet of Things platform provides an authorization key, an encryption method, an authorization object, and address information of the authorization object to the object.
  • the address information of the authorized object is information pre-stored by the Internet of Things platform.
  • Step 205 The object obtains a session key by using an authorization key and an authorization object to perform communication authentication, and the specific process is as shown in FIG. 3 .
  • Step 206 The object and the target Internet of Things terminal enable the session key to implement secure communication. The following describes the process of authenticating the object with the target Internet of Things terminal, as shown in FIG.
  • Step 301 The object actively initiates an authentication request according to the address information of the authorized object, carries the identifier of the authorized object, and the authentication request is Encryption is performed using the authorization key and encryption method sent by the IoT platform.
  • Step 302 After receiving the request, the Internet of Things terminal decrypts the corresponding decryption method and the authorization key, obtains the authorization object from the decrypted authentication request, and authenticates the obtained authorized object, and determines whether to negotiate with the Internet of Things platform.
  • the authorization objects are the same. If they are consistent, the authentication is passed, the session key is generated, and the session key is encrypted by the authorization key and the encryption method. Then, step 303 is performed; if not, the authentication fails, and the process ends.
  • Step 303 The Internet of Things terminal transmits the authentication confirmation information, the authorization object, and the encrypted session key to the object.
  • the cancellation method is that the IoT platform sends the authorization information to the terminal and the object, and after receiving the cancellation authorization message,
  • the target IoT terminal deletes the authorization key, encryption method, and authorization object of the object, and rejects the management request sent by the object; and the object also deletes the authorization key, the encryption method, the authorization object, and the address of the authorized object after receiving the deauthorization.
  • Information and other related information The method provided by the invention authorizes the management of the Internet of Things terminal to the object through the Internet of Things platform, reduces the management load of the Internet of Things platform while reducing the data security of the Internet of Things terminal, reduces the processing link of the Internet of Things system, and shortens the system. Handling delays and improving system reliability.
  • the present invention further provides an Internet of Things system using the above method, the system comprising an object, an Internet of Things platform, and an Internet of Things terminal, wherein the Internet of Things platform is configured to: authorize an object to be managed by the object network terminal; Set to: Manage the IoT terminal after authorization.
  • the object is configured to manage the Internet of Things terminal as follows: obtaining authorization information for managing an Internet of Things terminal from an Internet of Things platform, using the authorization information for managing the Internet of Things terminal, and the The Internet of Things terminal performs communication authentication and session key negotiation, and manages the IoT terminal by using the negotiated session key.
  • the Internet of Things platform is further configured to: notify the object to cancel management of the Internet of Things terminal; and the object is further configured to: After the management information of the Internet of Things terminal, the management of the Internet of Things terminal is cancelled by deleting the authorization information for managing the Internet of Things terminal.
  • the Internet of Things platform sends the authorization for managing the Internet of Things terminal to the object through the first receiving module 401, the negotiating module 402, and the first sending module 403.
  • the information includes: the first receiving module 401 is configured to: receive the identity information of the Internet of Things terminal from the object, and according to the identity information of the Internet of Things terminal, the negotiation module 402 is configured to: The networked terminal negotiates the authorization information for managing the Internet of Things terminal. After the negotiation succeeds, the first sending module 403 sends the authorization information for managing the Internet of Things terminal to the object.
  • the authorization information for managing the Internet of Things terminal includes at least one of an authorization key, an encryption method, and an authorization object. As shown in FIG.
  • the object is authenticated by the encryption module 501, the second sending module 502, and the second receiving module 503, and the encryption module 501 is configured to: Encrypting the authentication request including the authorization object by using the authorization key and the encryption method
  • the second sending module 502 is configured to: send the encryption to the Internet of Things terminal
  • the subsequent authentication request carries the authorized object.
  • the second receiving module 503 is configured to: receive an authentication result of the authorized object by the Internet of Things terminal.
  • the IoT terminal sends the session key to the object by using the authentication result.
  • the system provided by the invention authorizes the management of the Internet of Things terminal to the object through the Internet of Things platform, reduces the management load of the Internet of Things platform while reducing the data security of the Internet of Things terminal, reduces the processing link of the Internet of Things system, and shortens the system. Handling delays and improving system reliability.
  • a person skilled in the art can understand that all or part of the steps of implementing the above embodiments can be completed by a program to instruct related hardware, and the program can be stored in a computer readable storage medium, when executed, including One or a combination of the steps of the method embodiments.
  • each functional unit in each embodiment of the present invention may be implemented in the form of hardware, or may be implemented in the form of a software functional module.
  • the integrated modules if implemented in the form of software functional modules and sold or used as separate products, may also be stored in a computer readable storage medium.
  • the above-mentioned storage medium may be a read only memory, a magnetic disk or an optical disk or the like.
  • the above is only the specific embodiment of the present invention, but the scope of the present invention is not limited thereto, and any person skilled in the art can easily think of changes or substitutions within the technical scope of the present invention. It should be covered by the scope of the present invention. Therefore, the scope of the invention should be determined by the scope of the claims.
  • the technical solution provided by the present invention authorizes and manages an Internet of Things terminal to an object through an Internet of Things platform, and reduces the management load of the Internet of Things platform while reducing the processing link of the Internet of Things system while ensuring data security of the Internet of Things terminal. , shorten the processing delay of the system and improve the reliability of the system.

Description

授权管理物联网终端的方法和系统
技术领域 本发明涉及电信和信息技术领域, 尤其涉及一种授权管理物联网终端的 方法和系统。
背景技术
物联网包括物联网终端、 物联网平台和对象, 物联网平台通过物联网终 端进行数据釆集, 并将获取的数据提供给对象, 例如提供车辆管理、 电梯管 理、 零售管理、 物流管理、 以及自动化等服务给人类; 同时, 物联网平台还 对物联网终端进行计费、 以及安全等管理。 其中物联网中数据的传送承载通 道可以是无线网络, 也可以是有线网络。 随着物联网中对象的逐渐增多, 通过物联网平台转发命令实现对物联网 终端的管理,加重了物联网平台的负荷, 同时也增加了整个系统的处理环节, 增大了系统时延, 降低系统的可靠性。
发明内容 本发明提供一种授权管理物联网终端的方法和系统, 在保证物联网终端 数据安全的条件下, 降低物联网平台对物联网终端的管理负荷。 为达到上述发明目的, 本发明提供了如下技术方案: 一种授权管理物联网终端的方法, 该方法包括: 物联网平台向对象授权管理物联网终端 , 得到授权后的对象管理所述物 联网终端。 其中, 得到授权后的对象管理所述物联网终端的步骤包括: 对象从物联网平台获取用于管理物联网终端的授权信息, 所述对象釆用 所述用于管理所述物联网终端的授权信息与所述物联网终端进行认证和会话 密钥协商, 釆用协商得到的会话密钥管理所述物联网终端。 所述方法还包括: 所述对象通过删除所述用于管理物联网终端的授权信息取消对所述物联 网终端的管理。 其中, 物联网平台向对象授权管理物联网终端的步骤包括: 所述对象向所述物联网平台发送所述物联网终端的身份信息; 所述物联网平台根据所述物联网终端的身份信息, 与对应的物联网终端 协商用于管理物联网终端的授权信息; 以及
所述物联网平台将所述用于管理物联网终端的授权信息发送给所述对 象。
其中, 所述用于管理物联网终端的授权信息包括授权密钥、 加密方式和 授权对象中的至少一个。 其中, 所述对象与所述物联网终端进行通信认证的步骤包括: 釆用所述授权密钥和所述加密方式对认证请求进行加密, 所述认证请求 包括所述授权的对象; 向所述物联网终端发送所述加密后的认证请求; 以及 接收所述物联网终端对所述授权对象的认证结果。 其中, 所述对象与所述物联网终端进行认证的步骤还包括: 在认证结果 为通过时,所述物联网终端通过所述认证结果向所述对象发送所述会话密钥。 一种物联网系统, 其包括对象、 物联网平台、 以及物联网终端, 所述物联网平台设置为: 向对象授权管理物联网终端; 所述对象设置为: 在得到授权后, 管理所述物联网终端。 其中, 所述对象是设置为按如下方式管理所述物联网终端: 从物联网平台获取用于管理物联网终端的授权信息, 釆用所述用于管理 所述物联网终端的授权信息与所述物联网终端进行通信认证和会话密钥协 商, 并釆用协商得到的会话密钥管理所述物联网终端。 其中, 所述物联网平台还设置为: 通知所述对象取消对所述物联网终端 的管理; 所述对象还设置为: 在接收到取消对所述物联网终端的管理信息后, 通 过删除所述用于管理物联网终端的 4受权信息取消对所述物联网终端的管理。 其中, 所述物联网平台包括: 第一接收模块,其设置为:从所述对象接收所述物联网终端的身份信息; 协商模块, 其设置为: 根据所述物联网终端的身份信息, 与对应的物联 网终端协商用于管理物联网终端的授权信息; 以及 第一发送模块, 其设置为: 将所述用于管理物联网终端的授权信息发送 给所述对象。 其中, 所述用于管理物联网终端的授权信息包括授权密钥、 加密方式和 授权对象中的至少一个。 其中, 所述对象包括: 加密模块, 其设置为: 釆用所述授权密钥和所述加密方式对包括所述授 权对象的认证请求进行加密; 第二发送模块, 其设置为: 向所述物联网终端发送所述加密后的认证请 求, 携带所述授权对象; 第二接收模块, 其设置为: 接收所述物联网终端对所述授权对象的认证 结果。 其中, 在认证结果为通过时, 所述物联网终端通过所述认证结果向所述 对象发送所述会话密钥。 本发明提供的技术方案, 通过物联网平台向对象授权管理物联网终端, 在保证物联网终端数据安全的条件下, 减轻了物联网平台的管理负荷, 同时 减少物联网系统的处理环节, 缩短系统的处理时延, 提高系统的可靠性。 附图概述 图 1为本发明提供的物联网系统的结构示意图; 图 2为本发明中对象管理物联网终端的方法时序图; 图 3为本发明中物联网终端和对象进行通信协商的方法时序图; 图 4为本发明提供的物联网系统中物联网平台的结构示意图; 图 5为本发明提供的物联网系统中对象的结构示意图。
本发明的较佳实施方式
下面结合附图对本发明提供的技术方案进行详细介绍。 需要说明的是, 在不冲突的情况下,本申请中的实施例及实施例中的特征可以相互任意组合。 如图 1所示, 本发明提供的物联网系统包括对象、 物联网平台和物联网 终端,
物联网平台设置为: 对物联网终端进行控制和管理, 接收物联网终端上 报的数据, 并对数据进行处理, 将处理后的数据提供给对象, 同时也具备安 全、 计费、 以及网络管理等功能。 在本发明中, 物联网平台授权对象直接管 理物联网终端, ; 对象为物联网的具体应用和服务, 通过物联网平台对物联网终端进行管 理。 在本发明中, 对象请求物联网平台授权直接管理部分物联网终端, 在授 权通过后, 实现对物联网终端的直接管理, 无需通过物联网平台转发对物联 网终端的管理命令; 物联网终端设置为: 釆集和上报数据, 并接受物联网平台的管理, 在本 发明中, 物联网终端还接受对象的直接管理。 下面说明物联网中对象实现直接管理物联网终端的方法, 如图 2所示: 步骤 201、 物联网平台将所管理的物联网终端的信息提供给对象; 具体提供方式可以是物联网平台主动提供, 也可以是由对象主动请求物 联网终端信息。 步骤 202、 对象向物联网平台请求授权直接管理目标物联网终端, 包括 该目标物联网终端的身份信息。 步骤 203、 物联网平台根据目标物联网终端的身份信息, 与对应的物联 网终端协商授权密钥、 授权对象和加密方式。 其中授权密钥是目标物联网终端和物联网平台产生的, 现有技术中生成 授权密钥的方法均适用于本发明, 此处不作限定; 其中授权对象是允许对象直接管理目标物联网终端的项目信息, 可以为 该目标物联网终端的全部项目, 也可以是部分项目, 当为部分项目时, 需列 举允许访问的项目; 其中加密方式是用于对象与目标物联网终端通信时釆用的加密信息。 步骤 204、 物联网平台将授权密钥、 加密方式、 授权对象以及该授权对 象的地址信息提供给该对象。 其中授权对象的地址信息为物联网平台预先保存的信息。 步骤 205、 对象通过授权密钥、 授权对象进行通信认证, 获取会话密钥, 具体过程如图 3所示。 步骤 206、 对象和目标物联网终端启用会话密钥, 实现安全通讯。 下面对该对象与该目标物联网终端进行认证的过程进行说明, 如图 3所 示: 步骤 301、 对象根据授权对象的地址信息主动发起认证请求, 携带授权 对象的标识, 且该认证请求釆用物联网平台发送的授权密钥和加密方式进行 加密。 步骤 302、 物联网终端接收到请求后釆用对应的解密方式和授权密钥进 行解密,从解密后的认证请求中获取授权对象,对得到的授权对象进行认证, 判断是否与物联网平台协商后的授权对象一致, 如果一致, 则认证通过, 生 成会话密钥, 并用授权密钥和加密方法对会话密钥进行加密, 然后执行步骤 303; 如果不一致, 认证不通过, 流程结束。 步骤 303、 物联网终端将认证确认信息、 授权对象以及加密后的会话密 钥传送给对象。 步骤 304、 对象釆用授权密钥和对应的解密方法解密后, 确定认证通过, 得到会话密钥。 本实施例中会话密钥与认证同时进行, 也可以在认证通过之后双方再对 会话密钥进行协商。 在对象直接管理物联网终端过程中, 物联网平台可以随时取消该目标物 联网终端和对象之间的授权, 取消方法是物联网平台向终端和对象发取消授 权信息, 接收到取消授权消息后, 目标物联网终端删除对象的授权密钥、 加 密方式以及授权对象, 拒绝该对象发送的管理请求; 而对象也在接到取消授 权后, 删除授权密钥、 加密方式、 授权对象以及授权对象的地址信息等相关 信息。 本发明提供的方法, 通过物联网平台向对象授权管理物联网终端, 在保 证物联网终端数据安全的条件下, 减轻了物联网平台的管理负荷, 同时减少 物联网系统的处理环节, 缩短系统的处理时延, 提高系统的可靠性。 对应的, 本发明还提供一种釆用上述方法的物联网系统, 该系统包括对 象、 物联网平台、 物联网终端, 所述物联网平台设置为: 向对象授权管理物联网终端; 所述对象设置为: 在得到授权后, 管理所述物联网终端。 其中所述对象是设置为按如下方式管理所述物联网终端: 从物联网平台获取用于管理物联网终端的授权信息, 釆用所述用于管理 所述物联网终端的授权信息与所述物联网终端进行通信认证和会话密钥协 商, 并釆用协商得到的会话密钥管理所述物联网终端。 当所述对象实现对所述物联网终端的管理后,所述物联网平台还设置为: 通知所述对象取消对所述物联网终端的管理; 所述对象还设置为: 在接收到 取消对所述物联网终端的管理信息后, 通过删除所述用于管理物联网终端的 授权信息取消对所述物联网终端的管理。 如图 4所示, 在所述系统中, 所述物联网平台通过第一接收模块 401、 协商模块 402和第一发送模块 403 , 实现向所述对象发送所述用于管理物联 网终端的授权信息, 包括: 所述第一接收模块 401设置为: 从所述对象接收所述物联网终端的身份 信息, 根据所述物联网终端的身份信息, 所述协商模块 402设置为: 与对应 的物联网终端协商用于管理物联网终端的授权信息, 在协商成功后, 所述第 一发送模块 403将所述用于管理物联网终端的授权信息发送给所述对象。 其中所述用于管理物联网终端的授权信息包括授权密钥、 加密方式和授 权对象中的至少一个。 如图 5所示, 在所述系统中, 所述对象通过加密模块 501、 第二发送模 块 502和第二接收模块 503实现与所述物联网终端的认证, 包括: 所述加密模块 501设置为: 釆用所述授权密钥和所述加密方式对包括所 述授权对象的认证请求进行加密, 在加密完成后, 所述第二发送模块 502设 置为: 向所述物联网终端发送所述加密后的认证请求, 携带所述授权对象, 在所述物联网终端认证完成后, 所述第二接收模块 503设置为: 接收所述物 联网终端对所述授权对象的认证结果。 可选的, 在认证结果为通过时, 所述物联网终端通过所述认证结果向所 述对象发送所述会话密钥。 本发明提供的系统, 通过物联网平台向对象授权管理物联网终端, 在保 证物联网终端数据安全的条件下, 减轻了物联网平台的管理负荷, 同时减少 物联网系统的处理环节, 缩短系统的处理时延, 提高系统的可靠性。 本领域普通技术人员可以理解实现上述实施例的全部或部分步骤是可以 通过程序来指令相关的硬件完成, 所述的程序可以存储于一种计算机可读存 储介质中, 该程序在执行时, 包括方法实施例的步骤之一或其组合。 另外, 在本发明各个实施例中的各功能单元可以釆用硬件的形式实现, 也可以釆用软件功能模块的形式实现。 所述集成的模块如果以软件功能模块 的形式实现并作为独立的产品销售或使用时, 也可以存储在一个计算机可读 取存储介质中。 上述提到的存储介质可以是只读存储器, 磁盘或光盘等。 以上所述, 仅为本发明的具体实施方式, 但本发明的保护范围并不局限 于此, 任何熟悉本技术领域的技术人员在本发明揭露的技术范围内, 可轻易 想到变化或替换, 都应涵盖在本发明的保护范围之内。 因此, 本发明的保护 范围应以权利要求所述的保护范围为准。
工业实用性 本发明提供的技术方案, 通过物联网平台向对象授权管理物联网终端, 在保证物联网终端数据安全的条件下, 减轻了物联网平台的管理负荷, 同时 减少物联网系统的处理环节, 缩短系统的处理时延, 提高系统的可靠性。

Claims

权 利 要 求 书
1、 一种授权管理物联网终端的方法, 该方法包括: 物联网平台向对象授权管理物联网终端 , 得到授权后的对象管理所述物 联网终端。
2、根据权利要求 1所述的方法, 其中, 得到授权后的对象管理所述物联 网终端的步骤包括: 对象从物联网平台获取用于管理物联网终端的授权信息, 所述对象釆用 所述用于管理所述物联网终端的授权信息与所述物联网终端进行认证和会话 密钥协商, 釆用协商得到的会话密钥管理所述物联网终端。
3、 根据权利要求 2所述的方法, 所述方法还包括: 所述对象通过删除所述用于管理物联网终端的授权信息取消对所述物联 网终端的管理。
4、根据权利要求 2或 3所述的方法, 其中, 物联网平台向对象授权管理 物联网终端的步骤包括: 所述对象向所述物联网平台发送所述物联网终端的身份信息; 所述物联网平台根据所述物联网终端的身份信息, 与对应的物联网终端 协商用于管理物联网终端的授权信息; 以及
所述物联网平台将所述用于管理物联网终端的授权信息发送给所述对 象。
5、根据权利要求 4所述的方法, 其中, 所述用于管理物联网终端的授权 信息包括授权密钥、 加密方式和授权对象中的至少一个。
6、根据权利要求 5所述的方法, 其中, 所述对象与所述物联网终端进行 通信认证的步骤包括: 釆用所述授权密钥和所述加密方式对认证请求进行加密, 所述认证请求 包括所述授权的对象; 向所述物联网终端发送所述加密后的认证请求; 以及 接收所述物联网终端对所述授权对象的认证结果。
7、根据权利要求 6所述的方法, 其中, 所述对象与所述物联网终端进行 认证的步骤还包括: 在认证结果为通过时, 所述物联网终端通过所述认证结 果向所述对象发送所述会话密钥。
8、 一种物联网系统, 其包括对象、 物联网平台、 以及物联网终端, 所述物联网平台设置为: 向对象授权管理物联网终端; 所述对象设置为: 在得到授权后, 管理所述物联网终端。
9、根据权利要求 8所述的系统, 其中, 所述对象是设置为按如下方式管 理所述物联网终端: 从物联网平台获取用于管理物联网终端的授权信息, 釆用所述用于管理 所述物联网终端的授权信息与所述物联网终端进行通信认证和会话密钥协 商, 并釆用协商得到的会话密钥管理所述物联网终端。
10、 根据权利要求 8所述的系统, 其中, 所述物联网平台还设置为:通知所述对象取消对所述物联网终端的管理; 所述对象还设置为: 在接收到取消对所述物联网终端的管理信息后, 通 过删除所述用于管理物联网终端的 4受权信息取消对所述物联网终端的管理。
11、 根据权利要求 8或 9所述的系统, 其中, 所述物联网平台包括: 第一接收模块,其设置为:从所述对象接收所述物联网终端的身份信息; 协商模块, 其设置为: 根据所述物联网终端的身份信息, 与对应的物联 网终端协商用于管理物联网终端的授权信息; 以及 第一发送模块, 其设置为: 将所述用于管理物联网终端的授权信息发送 给所述对象。
12、根据权利要求 11所述的系统, 其中, 所述用于管理物联网终端的授 权信息包括授权密钥、 加密方式和授权对象中的至少一个。
13、 根据权利要求 12所述的系统, 其中, 所述对象包括: 加密模块, 其设置为: 釆用所述授权密钥和所述加密方式对包括所述授 权对象的认证请求进行加密; 第二发送模块, 其设置为: 向所述物联网终端发送所述加密后的认证请 求, 携带所述授权对象;
第二接收模块, 其设置为: 接收所述物联网终端对所述授权对象的认证 结果。
14、 根据权利要求 13所述的系统, 其中, 在认证结果为通过时, 所述物 联网终端通过所述认证结果向所述对象发送所述会话密钥。
PCT/CN2011/070269 2010-01-28 2011-01-14 授权管理物联网终端的方法和系统 WO2011091728A1 (zh)

Priority Applications (1)

Application Number Priority Date Filing Date Title
EP20110736610 EP2482488A4 (en) 2010-01-28 2011-01-14 METHOD AND SYSTEM FOR AUTHORIZING THE MANAGEMENT OF INTERNET TERMINALS

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201010106593.1 2010-01-28
CN201010106593.1A CN102142974B (zh) 2010-01-28 2010-01-28 授权管理物联网终端的方法和系统

Publications (1)

Publication Number Publication Date
WO2011091728A1 true WO2011091728A1 (zh) 2011-08-04

Family

ID=44318666

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2011/070269 WO2011091728A1 (zh) 2010-01-28 2011-01-14 授权管理物联网终端的方法和系统

Country Status (3)

Country Link
EP (1) EP2482488A4 (zh)
CN (1) CN102142974B (zh)
WO (1) WO2011091728A1 (zh)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102497677A (zh) * 2011-11-29 2012-06-13 山东中创软件工程股份有限公司 一种物联网业务处理系统及方法
WO2018196758A1 (en) * 2017-04-25 2018-11-01 SKY1 Technology Limited Establishing secure communication over an internet of things (iot) network
CN111031120A (zh) * 2019-12-03 2020-04-17 国家电网有限公司 基于泛在电力物联网现场安全管控的系统及方法
US11017375B2 (en) 2015-07-30 2021-05-25 Mastercard International Incorporated Systems and methods for using an internet of things device presence to authenticate a cardholder for a financial transaction

Families Citing this family (16)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102790721A (zh) * 2012-08-09 2012-11-21 福建物联天下信息科技有限公司 物联网路由方法及系统、路由器
CN103676803B (zh) * 2012-09-14 2016-02-10 中兴通讯股份有限公司 工业控制系统
US20140244997A1 (en) * 2013-02-25 2014-08-28 Qualcomm Incorporated Emergency mode for iot devices
CN103309315B (zh) * 2013-05-24 2015-09-02 成都秦川科技发展有限公司 物联网汽车智能控制仪表及物联网汽车智能管理系统
US10075500B2 (en) 2013-08-22 2018-09-11 Korea Advanced Institute Of Science And Technology Service method and system using instance interface of virtualization object in internet of things environment
WO2015056952A1 (ko) * 2013-10-14 2015-04-23 전자부품연구원 리소스 접근 방법 및 이를 적용한 시스템
CN105827573B (zh) * 2015-01-07 2019-03-05 中国移动通信集团山东有限公司 物联网设备强认证的系统、方法及相关装置
US9830603B2 (en) 2015-03-20 2017-11-28 Microsoft Technology Licensing, Llc Digital identity and authorization for machines with replaceable parts
US9876823B2 (en) 2015-06-09 2018-01-23 Intel Corporation System, apparatus and method for privacy preserving distributed attestation for devices
WO2017007497A1 (en) * 2015-07-08 2017-01-12 Hewlett Packard Enterprise Development Lp Location of object within network of objects
CN105007164B (zh) * 2015-07-30 2021-07-06 青岛海尔智能家电科技有限公司 一种集中式安全控制方法及装置
CN112822108A (zh) * 2015-12-30 2021-05-18 华为技术有限公司 建立lsp的方法、服务器及路由器
CN107528733B (zh) * 2017-08-30 2021-10-12 京东方科技集团股份有限公司 一种物联网的管理方法和物联网系统
CN110677410A (zh) * 2019-09-27 2020-01-10 四川长虹电器股份有限公司 物联网设备控制权限的授权方法
CN112087417B (zh) * 2020-07-22 2022-10-21 深圳奇迹智慧网络有限公司 终端权限控制方法、装置、计算机设备和存储介质
CN114598501A (zh) * 2022-02-11 2022-06-07 阿里云计算有限公司 一种基于物联网的数据处理方法和装置

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1719768A (zh) * 2004-07-09 2006-01-11 千乡万才科技(中国)有限公司 电子签核安全保护系统及其方法
US7584510B2 (en) * 2004-12-10 2009-09-01 Fujitsu Limited Network service processing method and system

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1183841A (zh) * 1995-02-13 1998-06-03 英特特拉斯特技术公司 用于安全交易管理和电子权利保护的系统和方法
CA2279468A1 (en) * 1998-10-13 2000-04-13 Joseph Thomas O'neil Method and apparatus to provide a secure multicast transmission
US6418472B1 (en) * 1999-01-19 2002-07-09 Intel Corporation System and method for using internet based caller ID for controlling access to an object stored in a computer
US7162649B1 (en) * 2000-06-30 2007-01-09 Internet Security Systems, Inc. Method and apparatus for network assessment and authentication

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1719768A (zh) * 2004-07-09 2006-01-11 千乡万才科技(中国)有限公司 电子签核安全保护系统及其方法
US7584510B2 (en) * 2004-12-10 2009-09-01 Fujitsu Limited Network service processing method and system

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP2482488A4 *

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102497677A (zh) * 2011-11-29 2012-06-13 山东中创软件工程股份有限公司 一种物联网业务处理系统及方法
US11017375B2 (en) 2015-07-30 2021-05-25 Mastercard International Incorporated Systems and methods for using an internet of things device presence to authenticate a cardholder for a financial transaction
WO2018196758A1 (en) * 2017-04-25 2018-11-01 SKY1 Technology Limited Establishing secure communication over an internet of things (iot) network
CN111031120A (zh) * 2019-12-03 2020-04-17 国家电网有限公司 基于泛在电力物联网现场安全管控的系统及方法

Also Published As

Publication number Publication date
CN102142974A (zh) 2011-08-03
EP2482488A1 (en) 2012-08-01
EP2482488A4 (en) 2014-08-27
CN102142974B (zh) 2015-05-13

Similar Documents

Publication Publication Date Title
WO2011091728A1 (zh) 授权管理物联网终端的方法和系统
JP6888673B2 (ja) デバイスを認証および認可するためのシステムおよび方法
CN103517273B (zh) 认证方法、管理平台和物联网设备
US8543814B2 (en) Method and apparatus for using generic authentication architecture procedures in personal computers
EP2790370B1 (en) Authentication method and system oriented to heterogeneous network
US20160105410A1 (en) OMA DM Based Terminal Authentication Method, Terminal and Server
CN101156352B (zh) 基于移动网络端到端通信的认证方法、系统及认证中心
JP4670598B2 (ja) ネットワークシステム、プロキシサーバ、セッション管理方法、及びプログラム
JP2014523579A (ja) 安全なクライアント認証およびネットワークサービス許可
CN101523801A (zh) UPnP认证和授权
WO2014173361A1 (zh) 一种对智能家居终端进行鉴权的方法及相应装置
JP2008005434A (ja) 通信制御装置、通信制御方法および通信制御プログラム
US11721148B2 (en) Authorization system, management server and authorization method
CN111080858A (zh) 一种蓝牙钥匙注销方法及其装置
CN109314693A (zh) 验证密钥请求方的方法和设备
KR20100101887A (ko) 통신시스템에서 인증 방법 및 시스템
EP3095266B1 (en) Access control for a wireless network
CN105591748B (zh) 一种认证方法和装置
JP6155237B2 (ja) ネットワークシステムとその端末登録方法
US8516555B2 (en) Method and system for authenticating pay-per-use service using EAP
KR100589677B1 (ko) 휴대 인터넷 시스템 및 이의 인증 방법
CN114095919A (zh) 一种基于车联网的证书授权处理方法及相关设备
KR102416562B1 (ko) 블록체인을 기반으로 한 IoT 디바이스의 인증 및 해지 방법
CN102231736B (zh) 一种网络访问控制方法及系统
KR102557051B1 (ko) 사물 인터넷 개방형 플랫폼에서의 디바이스 인증 방법 및 장치

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 11736610

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2011736610

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE