WO2016023367A1 - 访问认证方法、装置及系统 - Google Patents

访问认证方法、装置及系统 Download PDF

Info

Publication number
WO2016023367A1
WO2016023367A1 PCT/CN2015/074876 CN2015074876W WO2016023367A1 WO 2016023367 A1 WO2016023367 A1 WO 2016023367A1 CN 2015074876 W CN2015074876 W CN 2015074876W WO 2016023367 A1 WO2016023367 A1 WO 2016023367A1
Authority
WO
WIPO (PCT)
Prior art keywords
access
user account
accessed
password
bound
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2015/074876
Other languages
English (en)
French (fr)
Inventor
李飞云
高自光
任桥
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Xiaomi Inc
Original Assignee
Xiaomi Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Xiaomi Inc filed Critical Xiaomi Inc
Priority to JP2016541817A priority Critical patent/JP6105173B2/ja
Priority to MX2015009993A priority patent/MX359497B/es
Priority to KR1020157013718A priority patent/KR20160030470A/ko
Priority to BR112015024562A priority patent/BR112015024562A2/pt
Priority to RU2015140671A priority patent/RU2611968C1/ru
Publication of WO2016023367A1 publication Critical patent/WO2016023367A1/zh
Priority to US15/233,212 priority patent/US10498723B2/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/34User authentication involving the use of external additional devices, e.g. dongles or smart cards
    • G06F21/35User authentication involving the use of external additional devices, e.g. dongles or smart cards communicating wirelessly
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0853Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication

Definitions

  • the present disclosure relates to the field of computer technologies, and in particular, to an access authentication method, apparatus, and system.
  • Wi-Fi Wireless-Fidelity
  • Wi-Fi smart device After the Wi-Fi smart device is connected to the network, it needs to cooperate with the mobile app (Application). To use, the mobile app can view the status and results of the smart device and can send commands to control the smart device. It is especially important for smart devices to authenticate mobile apps and let mobile apps securely access and control smart devices.
  • An access authentication method provided in the related art is: when a user accesses a Wi-Fi smart device through a mobile phone App, the user needs to manually input an access password on the mobile phone App, and the mobile phone App sends the access password input by the user to the Wi- The Fi smart device, the Wi-Fi smart device allows the mobile phone App to access after matching the access password successfully.
  • the related art has at least the following drawbacks: since the user is required to manually input the access password on the mobile phone App, the illegal user can easily obtain the access password and use the access password to the Wi- Fi smart devices are accessed with poor security.
  • the present disclosure provides an access authentication method, apparatus, and system.
  • the technical solution is as follows:
  • an access authentication method is provided, which is applied to an access device, the method comprising:
  • the access password is that the third-party device receives the device identifier sent by the access device and a user account of the access device, where When the device identifier is bound to the user account, and the user account of the access device is different from the user account bound to the device identifier, the authentication request is sent to the login end of the user account bound to the device identifier, After receiving the allowed access response fed back by the login terminal according to the authentication request, the access corresponding to the device identifier sent to the access device And a password request, the authentication request is used to request the access device to access the accessed device, and the permission access response is used to indicate that the access device is allowed to access the accessed device.
  • the obtaining the device identifier of the accessed device includes:
  • an access authentication method is provided, which is applied to a visited device, and the method includes:
  • the access password is a device identifier sent by the third-party device and the user account of the access device, where the device identifier is bound with a user account and the
  • the authentication request is sent to the login end of the user account bound to the device identifier, and the authentication end is received according to the authentication.
  • An access password corresponding to the device identifier sent to the access device after requesting the feedback request the authentication request is used to request the access device to access the accessed device, and the access request is allowed Used to indicate that the access device is allowed to access the accessed device;
  • the access device is allowed to access the accessed device.
  • the method further includes:
  • the method further includes:
  • an access authentication method is provided, which is applied to a third-party device, and the method includes:
  • the device When it is detected that the device identifier is bound to the user account, and the user account of the access device is different from the user account bound to the device identifier, the device sends a certificate to the login end of the user account bound to the device identifier. a request for permission to request the access device to access the accessed device;
  • the allowed access response After receiving the allowed access response fed back by the login terminal according to the authentication request, sending an access password corresponding to the device identifier to the access device, where the access device is configured to access the access password according to the access password
  • the allowed access response is used to indicate that the access device is allowed to access the accessed device.
  • the method further includes:
  • the device identifier is bound to the user account of the access device, and the access device is determined to be the login terminal.
  • the user that is bound to the device identifier is The login end of the account sends an authentication request, including:
  • the step of sending an authentication request to the login end of the user account bound to the device identifier is performed.
  • the sending the access password corresponding to the device identifier to the access device includes:
  • the step of sending the access password corresponding to the device identifier to the access device is performed.
  • the method further includes:
  • the access password and the device identifier of the accessed device are bound and saved.
  • the method further includes:
  • the device identifier of the accessed device When the device identifier of the accessed device has a bound access password, it is detected whether the received access password is the same as the bound access password;
  • the access password update bound by the device identifier is bound to the received access password.
  • an access authentication apparatus which is applied to an access device, the apparatus comprising:
  • An obtaining module configured to obtain a device identifier of the accessed device
  • a first sending module configured to send the device identifier and a user account of the access device to a third-party device
  • the access module is configured to receive the access password, and access the accessed device according to the access password, where the access password is the device identifier sent by the third-party device and the access device
  • the user account is logged in to the user account bound to the device identifier when the device identifier is bound to the user account and the user account of the access device is different from the user account bound to the device identifier.
  • the acquiring module includes:
  • a first obtaining sub-module configured to receive a broadcast message that is sent by the visited device and that carries the device identifier of the visited device, and obtain a device identifier of the accessed device from the broadcast message;
  • a second obtaining submodule configured to obtain a device identifier of the accessed device by scanning a graphic code on the accessed device.
  • an access authentication apparatus for use in a visited device, the apparatus comprising:
  • the first receiving module is configured to receive an access password sent by the access device, where the access password is a device identifier sent by the third-party device and the user account of the access device, where the device identifier has been
  • an authentication request is sent to the login end of the user account bound to the device identifier, and the receiving request is received.
  • An access password corresponding to the device identifier sent by the login device to the access device after the access request is returned according to the authentication request, where the authentication request is used to request the access device to access the And accessing the device, the permission access response is used to indicate that the access device is allowed to access the accessed device;
  • a first detecting module configured to detect whether the access password is the same as the access password generated by the accessed device
  • the enabling module is configured to allow the access device to access the accessed device when the first detecting module detects that the access password is the same as the access password generated by the accessed device.
  • the device further includes:
  • a second sending module configured to send the access password and a device identifier of the accessed device to the third-party device, where the third-party device is configured to bind the access password and the device identifier save.
  • the device further includes:
  • a change module configured to periodically change the access password to obtain a changed access password
  • a third sending module configured to send the changed access password and the device identifier of the accessed device to a third-party device, where the third-party device binds the pre-stored access password binding bound to the device identifier The password for the changed access.
  • an access authentication apparatus which is applied to a third party device, the apparatus comprising:
  • a second receiving module configured to receive a device identifier of the accessed device sent by the access device and a user account of the accessed device;
  • the fourth sending module is configured to bind to the device identifier when detecting that the device identifier is bound to the user account and the user account of the access device is different from the user account bound to the device identifier
  • the login end of the user account sends an authentication request, where the authentication request is used to request the access device to access the accessed device;
  • a fifth sending module configured to receive an allowed access response fed back according to the authentication request by the login end And sending, to the access device, an access password corresponding to the device identifier, where the access device is configured to access the accessed device according to the access password, where the allow access response is used to indicate that the access device is allowed to access The device under investigation.
  • the device further includes:
  • the second detecting module is configured to detect whether the device identifier is bound to a user account
  • the first binding module is configured to bind the device identifier and the user account of the access device when the second detection module detects that the device identifier is not bound with a user account, and the The access device is determined to be the login terminal.
  • the fourth sending module includes:
  • the detecting sub-module is configured to detect, when the second detecting module detects that the device identifier is bound to the user account, whether the user account of the access device is the same as the user account bound to the device identifier;
  • a sending sub-module configured to: when the detecting sub-module detects that the user account of the access device is different from the user account bound to the device identifier, the login end of the user account bound to the device identifier Send an authentication request.
  • the fifth sending module is further configured to send, when the detecting submodule detects that the user account of the access device is the same as the user account bound to the device identifier, to the access device.
  • the device further includes:
  • a third receiving module configured to receive the access password sent by the accessed device and a device identifier of the accessed device
  • the second binding module is configured to bind and save the access password and the device identifier of the accessed device when the device identifier of the accessed device does not have a binding access password.
  • the device further includes:
  • the third detecting module is configured to detect, when the device identifier of the accessed device has a bound access password, whether the received access password is the same as the bound access password;
  • the third binding module is configured to: when the received access password is different from the bound access password, the access password update bound by the device identifier is bound to the received access password.
  • an access authentication system including an access device, a visited device, and a third-party device;
  • the access device includes the access authentication device according to any of the above fourth aspect or the fourth aspect of the fourth aspect;
  • the device for accessing includes the access authentication device according to any one of the foregoing fifth aspect or the fifth aspect;
  • the third party device includes the access authentication device as described in any of the above sixth aspect or the sixth aspect.
  • an access authentication apparatus which is applied to an access device, the apparatus comprising:
  • a memory for storing the processor executable instructions
  • processor is configured to:
  • the access password is that the third-party device receives the device identifier sent by the access device and a user account of the access device, where When the device identifier is bound to the user account, and the user account of the access device is different from the user account bound to the device identifier, the authentication request is sent to the login end of the user account bound to the device identifier, After receiving the allowed access response fed back by the login terminal according to the authentication request, the access password corresponding to the device identifier sent to the access device, the authentication request is used to request permission to the access device Accessing the visited device, the allow access response is used to indicate that the access device is allowed to access the accessed device.
  • an access authentication apparatus for use in a visited device, the apparatus comprising:
  • a memory for storing the processor executable instructions
  • processor is configured to:
  • the access password is a device identifier sent by the third-party device and the user account of the access device, where the device identifier is bound with a user account and the
  • the authentication request is sent to the login end of the user account bound to the device identifier, and the authentication end is received according to the authentication.
  • An access password corresponding to the device identifier sent to the access device after requesting the feedback request the authentication request is used to request the access device to access the accessed device, and the access request is allowed Used to indicate that the access device is allowed to access the accessed device;
  • the access device is allowed to access the accessed device.
  • an access authentication apparatus for use in a third-party device, the apparatus comprising:
  • a memory for storing the processor executable instructions
  • processor is configured to:
  • the device When it is detected that the device identifier is bound to the user account, and the user account of the access device is different from the user account bound to the device identifier, the device sends a certificate to the login end of the user account bound to the device identifier. a request for permission to request the access device to access the accessed device;
  • the allowed access response After receiving the allowed access response fed back by the login terminal according to the authentication request, sending an access password corresponding to the device identifier to the access device, where the access device is configured to access the access password according to the access password
  • the allowed access response is used to indicate that the access device is allowed to access the accessed device.
  • the device identifier of the accessed device is obtained by using the access device, and the device identifier and the user account of the access device are sent to the third-party device.
  • the third-party device asks the login terminal to determine that the access device is allowed to access the accessed device, the third-party device sends the device identifier.
  • Accessing the password and accessing the accessed device according to the access password since the access device needs to be allowed through the login terminal when accessing the accessed device, the problem is that the illegal user can easily obtain the access password because the user needs to manually input the access password on the mobile phone App.
  • the password and the access password are used to access the Wi-Fi smart device, and the security is relatively poor; the effect of improving the security of the accessed device is achieved.
  • FIG. 1 is a schematic diagram of an implementation environment involved in an access authentication method, according to some exemplary embodiments
  • FIG. 2 is a flowchart of an access authentication method according to an exemplary embodiment
  • FIG. 3 is a flowchart of an access authentication method according to another exemplary embodiment
  • FIG. 4 is a flowchart of an access authentication method according to still another exemplary embodiment
  • FIG. 5A is a flowchart of an access authentication method according to still another exemplary embodiment
  • FIG. 5B is a schematic diagram of a third party device sending a binding request to an access device according to an exemplary embodiment
  • FIG. 6A is a flowchart of an access authentication method according to still another exemplary embodiment
  • FIG. 6B is a schematic diagram of acquiring a device identifier of a visited device through a local area network broadcast according to an exemplary embodiment
  • FIG. 6C is a schematic diagram of acquiring a device identifier of a visited device by scanning a graphic code on the accessed device according to an exemplary embodiment
  • 6D is a schematic diagram of a third party device sending an authentication request to a login end according to an exemplary embodiment
  • FIG. 7 is a block diagram of an access authentication apparatus according to an exemplary embodiment
  • FIG. 8 is a block diagram showing an access authentication apparatus according to another exemplary embodiment
  • FIG. 9 is a block diagram of an access authentication apparatus according to still another exemplary embodiment.
  • FIG. 10 is a block diagram of an access authentication apparatus according to still another exemplary embodiment.
  • FIG. 11 is a block diagram of an access authentication apparatus according to still another exemplary embodiment.
  • FIG. 12 is a block diagram showing an access authentication apparatus according to still another exemplary embodiment
  • FIG. 13 is a block diagram showing an access authentication system according to an exemplary embodiment
  • FIG. 14 is a block diagram of an apparatus for accessing a visited device, according to an exemplary embodiment
  • FIG. 15 is a block diagram of an apparatus for verifying an access device, according to an exemplary embodiment.
  • the implementation environment may include a visited device 120, an access device 140, a third-party device 160, and a login. End 180.
  • the visited device 120 may be a smart device with Wi-Fi, which may be a camera, a router, a smart TV, or the like.
  • the accessed device 120 has a factory reset function and can release the user account bound to the accessed device 120.
  • the visited device 120 can be connected to the Internet through a router.
  • the access device 140 may be an electronic device capable of installing an App, which may be a smart phone, a tablet computer, a smart TV, an e-book reader, and an MP4 (Moving Picture Experts Group Audio Layer IV). Players, laptops and desktop computers, etc.
  • an App which may be a smart phone, a tablet computer, a smart TV, an e-book reader, and an MP4 (Moving Picture Experts Group Audio Layer IV). Players, laptops and desktop computers, etc.
  • the third party device 160 may be a server, a router, or the like having functions of binding, authentication, and the like.
  • the third-party device 160 may be a server, or a server cluster composed of several servers, or a cloud computing service center.
  • the login terminal 180 can be an electronic device capable of installing an App, and the electronic device can be a smart phone, a tablet computer, a smart TV, an e-book reader, and an MP4 (Moving Picture Experts Group Audio Layer IV). Players, laptops and desktop computers, etc.
  • the user account logged in at the login end 180 has owner rights to the accessed device 120.
  • the accessed device 120, the access device 140, the third party device 160, and the login terminal 180 may be connected by a wireless network, and the wireless network may be Wi-Fi, Bluetooth, infrared, or the like.
  • FIG. 2 is a flowchart of an access authentication method according to an exemplary embodiment. As shown in FIG. 2, the access authentication method is applied to the access device 140 in the implementation environment shown in FIG. 1, and includes the following steps.
  • step 201 the device identifier of the accessed device is obtained.
  • step 202 the device identifier and the user account of the access device are sent to the third party device.
  • the access password is received, and the accessed device is accessed according to the access password.
  • the access password is a device identifier that the third-party device receives from the access device and a user account that accesses the device.
  • the device identifier is bound to the user account and accessed.
  • the user sends an authentication request to the login end of the user account bound to the device ID.
  • the device After receiving the access request response based on the authentication request, the device sends an authentication request to the login end. Access the access password corresponding to the device ID sent by the device.
  • the authentication request here is for requesting the access device to access the accessed device
  • the access response is for indicating that the access device is allowed to access the accessed device.
  • the access authentication method obtains the device identifier of the accessed device by using the access device, sends the device identifier and the user account of the accessed device to the third-party device, and queries the third-party device to the login terminal.
  • the access device is allowed to access the accessed device
  • the access password sent by the third-party device is received, and the accessed device is accessed according to the access password; since the access device needs to be allowed through the login terminal when accessing the accessed device, the user is required to be in the mobile phone.
  • Manually input the access password on the App It is easy for an illegal user to obtain the access password and use the access password to access the Wi-Fi smart device.
  • the security is relatively poor; the effect of improving the security of the accessed device is achieved. .
  • FIG. 3 is a flowchart of an access authentication method according to another exemplary embodiment. As shown in FIG. 3, the access authentication method is applied to the accessed device 120 in the implementation environment shown in FIG. 1, including the following. step.
  • the access password sent by the access device is received.
  • the access password is the device identifier sent by the third-party device and the user account of the access device, and the user identifier of the device is bound to the device identifier.
  • the authentication request is sent to the login end of the user account that is bound to the device identifier, and is sent to the access device after receiving the allowable access response fed back by the login terminal according to the authentication request.
  • the access password corresponding to the device ID.
  • the authentication request here is for requesting the access device to access the accessed device
  • the access response is for indicating that the access device is allowed to access the accessed device.
  • step 302 it is detected whether the access password is the same as the access password generated by the accessed device.
  • step 303 when it is detected that the access password is the same as the access password generated by the accessed device, the access device is allowed to access the accessed device.
  • the access authentication method after receiving the access password sent by the access device, allows the access device to access the accessed device after detecting that the access password is the same as the access password generated by the accessed device. Since the accessed device needs to access the device after verifying the access password after receiving the access password, it solves the problem that if the access password is not verified, the accessed device can still access the interview after changing the access password. Equipment, low security; achieved the effect of improving the security of the equipment being interviewed.
  • FIG. 4 is a flowchart of an access authentication method according to still another exemplary embodiment. As shown in FIG. 4, the interview is performed. The authentication method is applied to the third party device 160 in the implementation environment shown in FIG. 1, and includes the following steps.
  • step 401 the device identifier sent by the access device and the user account of the access device are received.
  • step 402 when it is detected that the device identifier is bound to the user account and the user account of the access device is different from the user account bound to the device identifier, the authentication request is sent to the login end of the user account bound to the device identifier.
  • the authentication request here is used to request access to the device to be accessed by the access device.
  • step 403 after receiving the allowed access response fed back by the login terminal according to the authentication request, the access password corresponding to the device identifier is sent to the access device, and the access device is configured to access the accessed device according to the access password.
  • the allow access response here is used to indicate that the access device is allowed to access the visited device.
  • the access authentication method receives the device identifier sent by the access device and the user account of the access device, and sends an authentication request to the login terminal after detecting that the device identifier is bound, and receives the authentication request.
  • the access password corresponding to the device identifier is sent to the access device after the access request is sent back to the access device.
  • the third-party device can send the access password to the access device after the permission of the login terminal is allowed. Therefore, the illegal user obtains the access password.
  • the access password can be used to access the Wi-Fi smart device, and the security is relatively poor; the effect of improving the security of the accessed device is achieved.
  • the accessed device Before the access device accesses the accessed device, the accessed device needs to access the password, and sends the generated access password and the device identifier of the accessed device to the third-party device for binding.
  • the third-party device binds the user account of the accessed device to the device identifier of the accessed device, so that the user account obtains the owner rights of the accessed device. See Figure 5A for specific implementation steps.
  • FIG. 5A is a flowchart of an access authentication method according to still another exemplary embodiment. As shown in FIG. 5A, the access authentication method is applied to the implementation environment shown in FIG. 1, and includes the following steps.
  • step 501 the accessed device generates an access password.
  • the accessed device can randomly generate an access password.
  • the accessed device may periodically change the access password; or change the access password of the accessed device after receiving the change access password command sent by the login end corresponding to the accessed device.
  • the accessed device sends the access password and the device identifier of the accessed device to the third party device.
  • the device identification here may be that the accessed device is assigned when it is produced, and the device identification uniquely identifies the accessed device.
  • the device identifier may be a string, and the string may be combined by at least one of a number, a letter, or other types of characters.
  • the accessed device may send the generated access password and device identifier to the third-party device through the encrypted channel, where the encrypted channel may reduce the possibility of accessing the password leak.
  • the third-party device receives the access password sent by the accessed device and the device identifier of the accessed device.
  • step 504 when the device identifier of the accessed device does not have a bound access password, the third-party device binds and saves the access password and the device identifier of the accessed device.
  • the third-party device After receiving the access password sent by the accessed device and the device identifier of the accessed device, the third-party device first detects the Whether the device identifier is bound with an access password. If it is detected that the received device identifier does not have an access password, the received access password is bound to the device identifier and saved.
  • the accessed device can change the bound access password at any time in order to ensure security.
  • the access password is changed periodically, the changed access password is obtained, and the changed access password and the accessed device are
  • the device ID is sent to the third-party device.
  • the third-party device detects that the received device ID has a bound access password, it detects whether the received access password is the same as the bound access password. The third-party device does not operate. If the received access password is different from the bound access password, the third-party device unbinds the bound access password from the device ID and receives the access password.
  • the access password is bound to the device ID and saved.
  • the third-party device receives the access password and the device identifier sent by the accessed device, if the access password is detected and the access password that is bound to the device identifier is different, the pre-stored device identifier is tied.
  • the specified access password update is bound to the changed access password.
  • the third-party device is bound to the device identifier of the accessed device and the access password generated by the accessed device.
  • step 505 the access device obtains the device identification of the accessed device.
  • the access device may receive a broadcast message that is sent by the visited device and that carries the device identifier of the accessed device, obtain the device identifier of the accessed device from the broadcast message, or may be interviewed by scanning.
  • the graphics code on the device gets the device ID of the device being accessed.
  • the specific manner in which the access device obtains the device identifier of the accessed device is not limited in this embodiment.
  • step 506 the access device sends the device identifier and the user account of the access device to the third party device.
  • the user account here is registered by the user on the third-party device, and the user can log in to the user account on different access devices.
  • the access device After obtaining the device identifier of the accessed device, the access device sends the device identifier and the user account that the access device logs in to the third-party device.
  • the third-party device receives the device identifier sent by the access device and the user account of the accessed device.
  • the third-party device binds the received user account of the access device to the device identifier when it detects that the received device identifier is not bound to the user account.
  • the third-party device After receiving the device identifier sent by the access device and the user account of the access device, the third-party device detects whether the device identifier is bound to the user account.
  • the binding request may be sent to the access device, where the binding request is used to query the access device whether to bind the device identifier of the accessed device and the user account of the accessed device.
  • FIG. 5B is a schematic diagram of a third-party device sending a binding request to an access device according to an exemplary embodiment.
  • the access device displays a request “Do you want to bind to the device: 9527?” on the screen, and the user can click the “Yes” option. , agree to bind with the device: 9527, you can also click the "No” option, give up and tie with the device: 9527 set.
  • the third-party device binds the user account of the accessed device to the device identifier of the accessed device, and the user account of the accessed device obtains the owner rights of the accessed device.
  • the access device having the owner rights of the accessed device is determined as the login end.
  • the login terminal is an access device having the owner rights of the accessed device, and the naming of the login terminal is not used to limit the scope of protection of the present invention. In actual applications, the login terminal may have other name.
  • step 509 the third party device sends an access password corresponding to the device identifier to the access device.
  • the access password corresponding to the device identifier can be directly sent to the access device, so that the The access device directly accesses the accessed device according to the access password.
  • step 510 the access device receives the access password.
  • the access device (that is, the login terminal) can receive the access password through a wireless network or a short message.
  • step 511 the access device sends an access password to the accessed device.
  • the access device After receiving the access password, the access device accesses the accessed device according to the access password.
  • the access device (that is, the login terminal) accesses the accessed device according to the access password, and may send an access password to the accessed device. At this time, the access device may directly send the access password obtained through the wireless network. For the accessed device, in this scenario, the access device may not display the received access password, thereby enhancing the security of the access password of the accessed device.
  • the access device when the access device sends an access password to the accessed device, the access device displays the received access password to the user, and pops up a password input box, and the user inputs the received access password into the password input box, where After receiving the password entered by the user, the access device sends the password to the accessed device.
  • step 512 the accessed device receives the access password.
  • step 513 the accessed device detects whether the access password is the same as the access password generated by the accessed device.
  • the accessed device Since the accessed device changes the access password, it is necessary to detect whether the received access password is the same as the access password generated by the accessed device.
  • step 514 if the access password is detected to be the same as the access password generated by the accessed device, the accessed device allows the access device to access the accessed device.
  • the third-party device detects that the user account of the accessed device is bound to the device identifier of the accessed device, and then directly The access device sends an access password of the accessed device, and the access device receives and accesses the accessed device according to the access password.
  • the access authentication method when the third-party device detects that the device identifier is not bound, binds the received user account to the device identifier, and determines the user account pair.
  • the equipment interviewed Ownership is privileged; because the owner privilege is determined by binding the user account to the device ID of the device being accessed, the access device needs to be allowed by the logged-in terminal to access the accessed device, which solves the problem of manually inputting the user on the mobile app.
  • the illegal user can easily obtain the access password and use the access password to access the Wi-Fi smart device, which has a relatively poor security problem; and the effect of improving the security of the accessed device is achieved.
  • the ordinary access device After the first user accessing the access device of the accessed device obtains the owner's right of the accessed device, the ordinary access device needs to obtain the user account corresponding to the owner's account when accessing the accessed device. Access to the device is allowed to access the device. See Figure 6A for specific implementation steps.
  • FIG. 6A is a flowchart of an access authentication method according to still another exemplary embodiment. As shown in FIG. 6A, the access authentication method is applied to the implementation environment shown in FIG. 1, and includes the following steps.
  • step 601 the access device acquires the device identifier of the accessed device.
  • the access device may receive a broadcast message that is sent by the visited device and that carries the device identifier of the accessed device, obtain the device identifier of the accessed device from the broadcast message, or may be interviewed by scanning.
  • the graphics code on the device gets the device ID of the device being accessed.
  • FIG. 6B is a schematic diagram of acquiring a device identifier of a visited device by using a local area network broadcast according to an exemplary embodiment.
  • the access device searches for the nearby visited device through the local area network broadcast, the search result is displayed on the screen, and the user can click the device identifier of the accessed device that wants to connect to connect, and the user clicks the device. ID: After 9527, the access device pops up "Do you want to establish a connection with the device: 9527?"
  • FIG. 6C is a schematic diagram of acquiring a device identifier of a visited device by scanning a graphic code on the accessed device according to an exemplary embodiment.
  • the inquiry “Do you want to establish a connection with the device: 9527?” is directly popped up.
  • step 602 the access device sends the device identifier and the user account of the access device to the third party device.
  • the user account here is registered by the user on the third-party device, and the user can log in to the user account on different access devices.
  • the access device After obtaining the device identifier of the accessed device, the access device sends the device identifier and the user account that the access device logs in to the third-party device.
  • the access device sends the device ID of the accessed device: 9527 and the user account that the access device logs in to the third-party device.
  • step 603 the third-party device receives the device identifier sent by the access device and the user account of the accessed device.
  • step 604 when the third-party device detects that the device identifier is bound to the user account and the received user account is different from the bound user account, the third-party device sends an authentication request to the login end of the user account bound to the device identifier.
  • the third-party device After receiving the device identifier sent by the access device and the user account of the access device, the third-party device detects whether the device identifier is bound to the user account. When detecting that the device identifier is bound to the user account, detecting whether the user account of the accessed device is When the user account bound to the device identifier is different from the user account bound to the device identifier, the authentication is sent to the login end of the user account bound to the device identifier. request.
  • the access device that sends the user account does not have the owner rights of the accessed device. That is, the access device is a normal access device, and the owner of the accessed device needs to be authenticated, that is, the login end of the accessed device is authenticated.
  • the login terminal here has a binding relationship between the user account that is logged in to the login device and the device ID. That is, the login terminal has the owner rights of the accessed device.
  • the authentication request here is used to request that the access device be allowed to access the accessed device.
  • the authentication request may carry a user account sent on the access device.
  • the third-party device When the third-party device detects that the device ID is bound to the user account and the received user account is the same as the bound user account, the device indicates that the access device has the owner rights of the accessed device.
  • the access device sends an access password corresponding to the device identifier.
  • step 605 the login terminal receives the authentication request.
  • the login terminal may prompt the user of the login terminal according to the authentication request, for example, the authentication request may be displayed on the screen of the login end.
  • FIG. 6D is a schematic diagram of a third-party device sending an authentication request to a login end according to an exemplary embodiment.
  • the login terminal displays an inquiry on the screen, “Do you agree that the device: visitor accesses the device: 9527?”.
  • step 606 the login terminal sends an allow access response to the third party device.
  • the allow access response here is used to indicate that the access device is allowed to access the visited device.
  • the user on the login side allows the access device to access the accessed device, the user is allowed to send an access response.
  • the user on the login side allows access to the device: visitor accesses the accessed device: 9527
  • the user can click the “Yes” option
  • the login terminal sends an allow access response to the third party device.
  • the user on the login side prohibits access to the device: the visitor accesses the accessed device: 9527
  • the user can click the "No" option
  • the login terminal sends a forbidden access response to the third-party device, optionally, a third-party device.
  • the access device: visitor can send an error code to indicate that the access device: the visitor cannot access the accessed device.
  • step 607 the third party device receives the allowed access response.
  • step 608 the third party device sends an access password corresponding to the device identifier to the access device.
  • step 609 the access device receives the access password.
  • the access device can receive the access password through a wireless network or a short message.
  • step 610 the access device sends the access password to the accessed device.
  • the access device After receiving the access password, the access device accesses the accessed device according to the access password.
  • the access device accesses the accessed device according to the access password, and may send an access password to the accessed device.
  • the access device may directly send the access password obtained through the wireless network to the access device.
  • the accessed device in this scenario, the access device may not display the received access password, thereby enhancing the security of the access password of the accessed device.
  • the access device when the access device sends the access password to the accessed device, the access device displays the received access password to the user, and pops up a password input box, and the user inputs the received access password into the password input box, and the access device is in the After receiving the password entered by the user, the password is sent to the accessed device.
  • step 611 the accessed device receives the access password.
  • step 612 the accessed device detects whether the access password is the same as the access password generated by the accessed device.
  • the accessed device Since the accessed device changes the access password, it is necessary to detect whether the received access password is the same as the access password generated by the accessed device. For example, if the accessed device does not continue to access the accessed access device, the accessed device can modify the original access password to the existing access password. If the device accesses the accessed device again by using the original access password, the accessed device can match the received original access password with the updated existing access password. If the matching is unsuccessful, the device is prohibited. Access the device for access so that the latest permissions required for the accessed device to be accessed are guaranteed.
  • step 613 if the access password is detected to be the same as the access password generated by the accessed device, the accessed device allows the access device to access the accessed device.
  • the accessed device prohibits the access device from accessing the accessed device, and the accessed device may send an error code to the access device.
  • the access device cannot access the accessed device.
  • the access permission of the access device to access the accessed device is only reserved for a period of time, and the accessed device can cancel the access permission of the accessed device by changing the access password.
  • the access authentication method obtains the device identifier of the accessed device by using the access device, sends the device identifier and the user account of the accessed device to the third-party device, and queries the third-party device to the login terminal.
  • the access password sent by the third-party device to the access device is received, and the accessed device is accessed according to the access password; since the access device needs to be allowed through the login terminal when accessing the accessed device, the solution is solved due to the need
  • Sexual effect is possible to be performed by the third-party device to the access device is received, and the accessed device is accessed according to the access password; since the access device needs to be allowed through the login terminal when accessing the accessed device, the solution is solved due to the need
  • the access authentication method after receiving the access password sent by the access device, allows the access device to access the accessed device after detecting that the access password is the same as the access password generated by the accessed device; After accessing the password, it is necessary to verify access to the generated access password before allowing access to the device, thus solving the problem. If the access password is not verified, the accessed device can still access the accessed device after changing the access password, and the security is low; the effect of improving the security of the accessed device is achieved.
  • the access authentication method after receiving the device identifier sent by the access device and the user account of the access device, sends an authentication request to the login terminal after detecting that the device identifier is bound, and receiving the feedback from the login terminal. After the access request is enabled, the access password corresponding to the device identifier is sent to the access device.
  • the third-party device can send the access password to the access device after the login terminal is allowed. Therefore, the illegal user can obtain the access password.
  • the access password accesses the Wi-Fi smart device, and the security is relatively poor; the effect of improving the security of the accessed device is achieved.
  • FIG. 7 is a block diagram of an access authentication apparatus, as shown in FIG. 7, which is applied to an access device 140 in the implementation environment shown in FIG. 1, according to an exemplary embodiment.
  • the access authentication device includes, but is not limited to, an acquisition module 702, a first transmission module 704, and an access module 706.
  • the obtaining module 702 is configured to acquire a device identifier of the accessed device.
  • the first sending module 704 is configured to send the device identifier and the user account of the access device to the third-party device.
  • the access module 706 is configured to receive an access password, and access the accessed device according to the access password.
  • the access password is a device identifier that the third-party device receives from the access device and a user account that accesses the device, and the device identifier is bound to the user. If the user account of the accessing device is different from the user account to which the device ID is bound, the authentication request is sent to the login end of the user account bound to the device ID, and the access request is received by the login terminal according to the authentication request. Then, an access password corresponding to the device identifier sent to the access device, the authentication request is used to request the access device to access the accessed device, and the access response is used to indicate that the access device is allowed to access the accessed device.
  • the access authentication device acquires the device identifier of the accessed device by using the access device, and sends the device identifier and the user account of the accessed device to the third-party device, and the third-party device queries the login terminal to determine After the access device is allowed to access the accessed device, the third-party device sends the access password to the access device.
  • the access device accesses the accessed device according to the access password.
  • the access device needs to be enabled by the login terminal when accessing the accessed device. Manually inputting the access password on the mobile phone app, the illegal user can easily obtain the access password, and use the access password to access the Wi-Fi smart device, and the security is relatively poor; and the security of the accessed device is improved. effect.
  • FIG. 8 is a block diagram of an access authentication apparatus, as shown in FIG. 8, which is applied to an access device 140 in the implementation environment shown in FIG. 1, according to another exemplary embodiment.
  • the access authentication device includes, but is not limited to, an acquisition module 802, a first transmission module 804, and an access module 806.
  • the obtaining module 802 is configured to acquire a device identifier of the accessed device.
  • the first sending module 804 is configured to send the device identifier and the user account of the access device to the third-party device.
  • the access module 806 is configured to receive an access password, and access the accessed device according to the access password.
  • the access password is a device identifier that the third-party device receives from the access device and a user account that accesses the device, and the device identifier is bound to the user. If the user account of the accessing device is different from the user account to which the device ID is bound, the authentication request is sent to the login end of the user account bound to the device ID, and the access request is received by the login terminal according to the authentication request. Then, an access password corresponding to the device identifier sent to the access device, the authentication request is used to request the access device to access the accessed device, and the access response is used to indicate that the access device is allowed to access the accessed device.
  • the obtaining module 802 may include: a first obtaining submodule 802a or a second obtaining submodule 802b.
  • the first obtaining sub-module 802a is configured to receive a broadcast message that is sent by the visited device and that carries the device identifier of the accessed device, and obtain the device identifier of the accessed device from the broadcast message. or,
  • the second obtaining submodule 802b is configured to obtain a device identifier of the accessed device by scanning a graphic code on the accessed device.
  • the access authentication device acquires the device identifier of the accessed device by using the access device, and sends the device identifier and the user account of the accessed device to the third-party device, and the third-party device queries the login terminal to determine After the access device is allowed to access the accessed device, the third-party device sends the access password to the access device.
  • the access device accesses the accessed device according to the access password.
  • the access device needs to be enabled by the login terminal when accessing the accessed device. Manually inputting the access password on the mobile phone app, the illegal user can easily obtain the access password, and use the access password to access the Wi-Fi smart device, and the security is relatively poor; and the security of the accessed device is improved. effect.
  • FIG. 9 is a block diagram of an access authentication apparatus, as shown in FIG. 9, which is applied to the accessed device 120 in the implementation environment shown in FIG. 1, according to still another exemplary embodiment.
  • the access authentication device includes, but is not limited to, a first receiving module 902, a first detecting module 904, and an enabling module 906.
  • the first receiving module 902 is configured to receive an access password sent by the access device, where the access password is a device identifier sent by the third-party device and the user account of the access device, and the user identifier is bound to the device identifier.
  • the authentication request is sent to the login end of the user account bound to the device identifier, and after receiving the allowable access response fed back by the login terminal according to the authentication request, An access password corresponding to the device identifier sent to the access device, the authentication request is used to request the access device to access the accessed device, and the access response is used to indicate that the access device is allowed to access the accessed device.
  • the first detecting module 904 is configured to detect whether the access password is the same as the access password generated by the accessed device.
  • the permission module 906 is configured to allow the access device to access the accessed device when the first detection module 904 detects that the access password is the same as the access password generated by the accessed device.
  • the access authentication device allows the access device to access the accessed device after receiving the access password sent by the access device and detecting that the access password is the same as the access password generated by the accessed device; After receiving the access password, the accessed device needs to be authenticated and the generated access password is the same to allow access to the device. Therefore, if the access password is not verified, the accessed device can still access the accessed device after changing the access password, and the security is low; the effect of improving the security of the accessed device is achieved.
  • FIG. 10 is a block diagram of an access authentication apparatus shown in FIG. 10, which is applied to the accessed device 120 in the implementation environment shown in FIG. 1, according to still another exemplary embodiment.
  • the access authentication device includes but is not limited to: a first receiving module 1002, a first detecting module 1004, and an enabling module 1006.
  • the first receiving module 1002 is configured to receive an access password sent by the access device, where the access password is a device identifier sent by the third-party device and the user account of the access device, and the user identifier is bound to the device identifier.
  • the authentication request is sent to the login end of the user account bound to the device identifier, and after receiving the allowable access response fed back by the login terminal according to the authentication request, An access password corresponding to the device identifier sent to the access device, the authentication request is used to request the access device to access the accessed device, and the access response is used to indicate that the access device is allowed to access the accessed device.
  • the first detecting module 1004 is configured to detect whether the access password is the same as the access password generated by the accessed device.
  • the permission module 1006 is configured to allow the access device to access the accessed device when the first detection module 1004 detects that the access password is the same as the access password generated by the accessed device.
  • the apparatus further includes: a generating module 1008 and a second sending module 1010.
  • the generating module 1008 is configured to generate an access password.
  • the second sending module 1010 is configured to send an access password and a device identifier of the accessed device to the third-party device, where the third-party device is configured to bind and save the access password and the device identifier.
  • the apparatus further includes: a modification module 1012 and a third transmission module 1014.
  • the change module 1012 is configured to periodically change the access password to obtain the changed access password.
  • the third sending module 1014 is configured to send the changed access password and the device identifier of the accessed device to the third-party device, and the third-party device binds the updated access password bound to the pre-stored device identifier to the changed one. Access password.
  • the access authentication device allows the access device to access the accessed device after receiving the access password sent by the access device and detecting that the access password is the same as the access password generated by the accessed device; After receiving the access password, the accessed device needs to be authenticated and the generated access password is the same to allow access to the device. Therefore, if the access password is not verified, the accessed device can still access the accessed device after changing the access password. , the problem of low security; achieved the effect of improving the security of the equipment being interviewed.
  • FIG. 11 is a block diagram of an access authentication apparatus, as shown in FIG. 11, which is applied to a third party device 160 in the implementation environment shown in FIG. 1, according to still another exemplary embodiment.
  • the access authentication device includes but is not limited to: a second receiving module 1102, a fourth transmitting module 1104, and a fifth transmitting module 1106.
  • the second receiving module 1102 is configured to receive a device identifier of the accessed device sent by the access device and a user account of the accessed device.
  • the fourth sending module 1104 is configured to: when detecting that the device identifier is bound to the user account, and the user account of the access device is different from the user account bound to the device identifier, the login end of the user account bound to the device identifier An authentication request is sent, and the authentication request is used to request permission to access the device to access the accessed device.
  • the fifth sending module 1106 is configured to: after receiving the allowed access response fed back by the login terminal according to the authentication request, send an access password corresponding to the device identifier to the access device, where the access device is configured to access the accessed device according to the access password,
  • the Allow Access Answer is used to indicate that the access device is allowed to access the visited device.
  • the access authentication apparatus receives the device identifier sent by the access device and the user account of the access device, and after detecting that the device identifier is bound, sends an authentication request to the login end, and receives the authentication request.
  • the access password corresponding to the device identifier is sent to the access device after the access request is sent back to the access device.
  • the third-party device can send the access password to the access device after the permission of the login terminal is allowed. Therefore, the illegal user obtains the access password.
  • the access password can be used to access the Wi-Fi smart device, and the security is relatively poor; the effect of improving the security of the accessed device is achieved.
  • FIG. 12 is a block diagram of an access authentication apparatus, as shown in FIG. 12, applied to a third party device 160 in the implementation environment shown in FIG. 1, according to still another exemplary embodiment.
  • the access authentication device includes but is not limited to: a second receiving module 1202, a fourth transmitting module 1204, and a fifth transmitting module 1206.
  • the second receiving module 1202 is configured to receive the device identifier sent by the access device and the user account of the access device.
  • the fourth sending module 1204 is configured to: when detecting that the device identifier is bound to the user account, and the user account of the access device is different from the user account bound to the device identifier, the login end of the user account bound to the device identifier An authentication request is sent, and the authentication request is used to request permission to access the device to access the accessed device.
  • the fifth sending module 1206 is configured to: after receiving the allowed access response fed back by the login terminal according to the authentication request, send an access password corresponding to the device identifier to the access device, where the access device is configured to access the accessed device according to the access password,
  • the Allow Access Answer is used to indicate that the access device is allowed to access the visited device.
  • the apparatus further includes: a second detecting module 1208 and a first binding module 1210.
  • the second detecting module 1208 is configured to detect whether the device identifier is bound to a user account.
  • the first binding module 1210 is configured to bind the device identifier to the user account of the access device when the second detection module 1208 detects that the device identifier is not bound to the user account, and determine the access device as the login terminal.
  • the fourth sending module 1204 can include: a detecting submodule 1204a and a sending submodule 1204b.
  • the detecting sub-module 1204a is configured to detect, when the second detecting module 1208 detects that the device identifier is bound to the user account, whether the user account of the access device is the same as the user account bound to the device identifier.
  • the sending sub-module 1204b is configured to send an authentication request to the login end of the user account bound to the device identifier when the detecting sub-module 1204a detects that the user account of the access device is different from the user account bound to the device identifier.
  • the fifth sending module 1206 is further configured to detect at the detecting submodule 1204a.
  • the access password corresponding to the device identifier is sent to the access device.
  • the apparatus further includes: a third receiving module 1212 and a second binding module 1214.
  • the third receiving module 1212 is configured to receive an access password sent by the accessed device and a device identifier of the accessed device.
  • the second binding module 1214 is configured to bind and save the access password and the device identifier of the accessed device when the device identifier of the accessed device does not have a bound access password.
  • the apparatus further includes: a third detecting module 1216 and a third binding module 1218.
  • the third detecting module 1216 is configured to detect whether the received access password is the same as the bound access password when the device identifier of the accessed device has a bound access password.
  • the third binding module 1218 is configured to bind the access password update bound to the device identifier to the received access password when the received access password is different from the bound access password.
  • the access authentication apparatus receives the device identifier sent by the access device and the user account of the access device, and after detecting that the device identifier is bound, sends an authentication request to the login end, and receives the authentication request.
  • the access password corresponding to the device identifier is sent to the access device after the access request is sent back to the access device.
  • the third-party device can send the access password to the access device after the permission of the login terminal is allowed. Therefore, the illegal user obtains the access password.
  • the access password can be used to access the Wi-Fi smart device, and the security is relatively poor; the effect of improving the security of the accessed device is achieved.
  • FIG. 13 is a block diagram of an access authentication system, as shown in FIG. 13, which is applied to the implementation environment shown in FIG. 1 according to an exemplary embodiment.
  • the access authentication system includes, but is not limited to, a visited device 1302, an access device 1304, and a third party device 1306.
  • the visited device 1302 includes the access authentication device described in FIG. 9 or 10.
  • the access device 1304 includes the access authentication device described in FIG. 7 or 8.
  • the third party device 1306 includes the access authentication device described in FIG. 11 or FIG.
  • the access authentication system obtains the device identifier of the accessed device by using the access device, sends the device identifier and the user account of the accessed device to the third-party device, and queries the third-party device to the login terminal.
  • the access password sent by the third-party device to the access device is received, and the accessed device is accessed according to the access password; since the access device needs to be allowed through the login terminal when accessing the accessed device, the solution is solved due to the need
  • Sexual effect is possible to be performed by the third-party device to the access device is received, and the accessed device is accessed according to the access password; since the access device needs to be allowed through the login terminal when accessing the accessed device, the solution is solved due to the need
  • the access authentication system after receiving the access password sent by the access device, allows the access device to access the accessed device after detecting that the access password is the same as the access password generated by the accessed device; After accessing the password, the access device must be accessed after the authentication and the generated access password are the same. Therefore, if the access password is not verified, the accessed device can still access the accessed device after changing the access password, and the security is low. Problem; achieved the effect of improving the security of the equipment being interviewed.
  • the access authentication system after receiving the device identifier sent by the access device and the user account of the access device, sends an authentication request to the login terminal after detecting that the device identifier is bound, and receiving the feedback from the login terminal. After the access request is enabled, the access password corresponding to the device identifier is sent to the access device.
  • the third-party device can send the access password to the access device after the login terminal is allowed. Therefore, the illegal user can obtain the access password.
  • the access password accesses the Wi-Fi smart device, and the security is relatively poor; the effect of improving the security of the accessed device is achieved.
  • An exemplary embodiment of the present disclosure provides an access authentication apparatus, which is applied to an access device, capable of implementing the access authentication method provided by the present disclosure, the access authentication apparatus comprising: a processor, a memory for storing processor executable instructions ;
  • processor is configured to:
  • the access password is received, and the accessed device is accessed according to the access password.
  • the access password is the device identifier that the third-party device receives from the access device and the user account that accesses the device.
  • the device identifier is bound to the user account and the user account of the device is accessed.
  • the authentication request is sent to the login end of the user account bound to the device identifier, and after receiving the allowable access response fed back by the login terminal according to the authentication request, the device sends the authentication request to the access device.
  • the device identifier corresponds to an access password, and the authentication request is used to request the access device to access the accessed device, and the access response is used to indicate that the access device is allowed to access the accessed device.
  • An exemplary embodiment of the present disclosure provides an access authentication apparatus, which is applied to a visited device, capable of implementing an access authentication method provided by the present disclosure, the access authentication apparatus comprising: a processor, and a processor for storing processor executable instructions Memory
  • processor is configured to:
  • the access password sent by the access device is received.
  • the access password is a device identifier that the third-party device receives from the access device and the user account that accesses the device.
  • the device identifier is bound to the user account and the user account and device identifier of the access device are bound.
  • the authentication request is sent to the login end of the user account bound to the device identifier.
  • the access password corresponding to the device identifier sent to the access device the authentication request is used to request the access device to access the accessed device, and the access response is used to indicate that the access is allowed.
  • the device accesses the accessed device;
  • the access device When the access password is detected to be the same as the access password generated by the accessed device, the access device is allowed to access the accessed device.
  • An exemplary embodiment of the present disclosure provides an access authentication apparatus, which is applied to a third-party device, and can implement an access authentication method provided by the present disclosure, the access authentication apparatus including: a processor, and a processor-executable instruction Memory
  • processor is configured to:
  • the authentication request is sent to the login end of the user account bound to the device identifier, and the authentication request is used for Requesting access to the device to access the accessed device;
  • the access password is sent to the access device, and the access device is configured to access the accessed device according to the access password, and the access response is used to indicate that the access device is allowed to access.
  • FIG. 14 is a block diagram of an apparatus for accessing a visited device, according to an exemplary embodiment.
  • device 1400 can be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a gaming console, a tablet device, a medical device, a fitness device, a personal digital assistant, and the like.
  • apparatus 1400 can include one or more of the following components: processing component 1402, memory 1404, power component 1406, multimedia component 1408, audio component 1410, input/output (I/O) interface 1412, sensor component 1414, and Communication component 1416.
  • Processing component 1402 typically controls the overall operation of device 1400, such as operations associated with display, telephone calls, data communications, camera operations, and recording operations.
  • Processing component 1402 can include one or more processors 1418 to execute instructions to perform all or part of the steps described above.
  • processing component 1402 can include one or more modules to facilitate interaction between component 1402 and other components.
  • processing component 1402 can include a multimedia module to facilitate interaction between multimedia component 1408 and processing component 1402.
  • Memory 1404 is configured to store various types of data to support operation at device 1400. Examples of such data include instructions for any application or method operating on device 1400, contact data, phone book data, messages, pictures, videos, and the like.
  • the memory 1404 can be implemented by any type of volatile or non-volatile storage device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read only memory (EEPROM), erasable.
  • SRAM static random access memory
  • EEPROM electrically erasable programmable read only memory
  • EPROM Programmable Read Only Memory
  • PROM Programmable Read Only Memory
  • ROM Read Only Memory
  • Magnetic Memory Flash Memory
  • Disk Disk or Optical Disk.
  • Power component 1406 provides power to various components of device 1400.
  • Power component 1406 can include a power management system, one or more power sources, and other components associated with generating, managing, and distributing power for device 1400.
  • the multimedia component 1408 includes a screen between the device 1400 and the user that provides an output interface.
  • the screen can include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from the user.
  • the touch panel includes one or more touch sensors to sense touches, slides, and gestures on the touch panel. The touch sensor can sense not only the boundaries of the touch or sliding action, but also the duration and pressure associated with the touch or slide operation.
  • the multimedia component 1408 includes a front camera and/or a rear camera. When the device 1400 is in an operation mode, such as a shooting mode or a video mode, the front camera and/or the rear camera can receive external multimedia data. Each front and rear camera can be a fixed optical lens system or have focal length and optical zoom capabilities.
  • the audio component 1410 is configured to output and/or input an audio signal.
  • the audio component 1410 includes a microphone (MIC) that is configured to receive an external audio signal when the device 1400 is in an operational mode, such as a call mode, a recording mode, and a voice recognition mode.
  • the received audio signal may be further stored in memory 1404 or transmitted via communication component 1416.
  • the audio component 1410 also includes a speaker for outputting an audio signal.
  • the I/O interface 1412 provides an interface between the processing component 1402 and the peripheral interface module, which may be a keyboard, a click wheel, a button, or the like. These buttons may include, but are not limited to, a home button, a volume button, a start button, and a lock button.
  • Sensor assembly 1414 includes one or more sensors for providing a status assessment of various aspects to device 1400.
  • sensor component 1414 can detect an open/closed state of device 1400, a relative positioning of components, such as a display and a keypad of device 1400, and sensor component 1414 can also detect a change in position of a component of device 1400 or device 1400, the user The presence or absence of contact with device 1400, device 1400 orientation or acceleration/deceleration and temperature variation of device 1400.
  • Sensor assembly 1414 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact.
  • Sensor assembly 1414 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications.
  • the sensor component 1414 can also include an acceleration sensor, a gyro sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.
  • Communication component 1416 is configured to facilitate wired or wireless communication between device 1400 and other devices.
  • the device 1400 can access a wireless network based on a communication standard, such as Wi-Fi, 2G or 3G, or a combination thereof.
  • communication component 1416 receives broadcast signals or broadcast associated information from an external broadcast management system via a broadcast channel.
  • communication component 1416 also includes a near field communication (NFC) module to facilitate short range communication.
  • NFC near field communication
  • the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.
  • RFID radio frequency identification
  • IrDA infrared data association
  • UWB ultra-wideband
  • Bluetooth Bluetooth
  • device 1400 may be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable Gate array (FPGA), controller, microcontroller, microprocessor or other electronic component implementation for execution
  • ASICs application specific integrated circuits
  • DSPs digital signal processors
  • DSPDs digital signal processing devices
  • PLDs programmable logic devices
  • FPGA field programmable Gate array
  • controller microcontroller, microprocessor or other electronic component implementation for execution
  • microcontroller microprocessor or other electronic component implementation for execution
  • the access device or the accessed device is the access authentication method of the executing entity.
  • non-transitory computer readable storage medium comprising instructions, such as a memory 1404 comprising instructions executable by processor 1418 of apparatus 1400 to complete access to a device or device under investigation
  • the authentication method for accessing the principal can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device.
  • FIG. 15 is a block diagram of an apparatus for verifying an access device, according to an exemplary embodiment.
  • device 1500 can be provided as a server.
  • apparatus 1500 includes a processing component 1502 that further includes one or more processors, and memory resources represented by memory 1504 for storing instructions executable by processing component 1502, such as an application.
  • An application stored in memory 1504 may include one or more modules each corresponding to a set of instructions.
  • the processing component 1502 is configured to execute instructions to perform an access authentication method with a third party device as an execution subject.
  • Apparatus 1500 can also include a power supply component 1506 configured to perform power management of apparatus 1500, a wired or wireless network interface 1508 configured to connect apparatus 1500 to the network, and an input/output (I/O) interface 1510.
  • Device 1500 can operate based on an operating system stored in memory 1504, such as Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, FreeBSDTM or the like.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Information Transfer Between Computers (AREA)
  • Storage Device Security (AREA)

Abstract

本公开揭示了一种访问认证方法、装置及系统,属于计算机技术领域。所述访问认证方法包括:获取受访设备的设备标识;向第三方设备发送设备标识和访问设备的用户帐号,第三方设备用于在设备标识绑定有用户帐号且该用户帐号与访问设备的用户帐号不同时,向登录端发送鉴权请求,在接收到登录端反馈的允许访问应答后,向访问设备发送受访设备的访问密码;根据接收到的访问密码访问受访设备。通过在第三方设备中向登录端进行鉴权,鉴权成功后向访问设备发送访问密码,访问设备根据访问密码访问受访设备;解决了由于需要用户在手机App上手动输入访问密码,非法使用者很容易获取到该访问密码,安全性比较差的问题;达到了提高受访设备安全性的效果。

Description

访问认证方法、装置及系统
本申请基于申请号为CN 201410403939.2、申请日为2014年8月15日的中国专利申请提出,并要求该中国专利申请的优先权,该中国专利申请的全部内容在此引入本申请作为参考。
技术领域
本公开涉及计算机技术领域,特别涉及一种访问认证方法、装置及系统。
背景技术
随着Wi-Fi(Wireless-Fidelity,无线保真)的普及,带Wi-Fi的智能设备越来越多,一般Wi-Fi智能设备连上网络后,需要配合手机App(Application,应用程序)来使用,手机App可以查看智能设备的状态和结果,并可以发送指令控制智能设备。而智能设备如何认证手机App,让手机App安全访问控制智能设备的问题,显得尤为重要。
在相关技术中提供的一种访问认证方法是:用户通过手机App对Wi-Fi智能设备进行访问时,需要用户在手机App上手动输入访问密码,手机App将用户输入的访问密码发送给Wi-Fi智能设备,Wi-Fi智能设备在匹配到该访问密码成功之后,允许该手机App进行访问。
发明人在实现本公开的过程中,发现相关技术至少存在如下缺陷:由于需要用户在手机App上手动输入访问密码,非法使用者很容易获取到该访问密码,并利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差。
发明内容
为了解决相关技术中由于需要用户在手机App上手动输入访问密码,非法使用者很容易获取到该访问密码,并利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差的问题,本公开提供一种访问认证方法、装置及系统。所述技术方案如下:
根据本公开实施例的第一方面,提供一种访问认证方法,应用于访问设备中,所述方法包括:
获取受访设备的设备标识;
向第三方设备发送所述设备标识和所述访问设备的用户帐号;
接收所述访问密码,根据所述访问密码访问所述受访设备,所述访问密码是第三方设备在接收到所述访问设备发送的所述设备标识和所述访问设备的用户帐号,在所述设备标识已绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送的与所述设备标识对应的访问 密码,所述鉴权请求用于请求允许所述访问设备访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备。
可选的,所述获取受访设备的设备标识,包括:
接收所述受访设备广播发送的携带有所述受访设备的设备标识的广播消息,从所述广播消息中获取所述受访设备的设备标识;或,
通过扫描所述受访设备上的图形码获取所述受访设备的设备标识。
根据本公开实施例的第二方面,提供一种访问认证方法,应用于受访设备中,所述方法包括:
接收访问设备发送的访问密码,所述访问密码是第三方设备在接收到所述访问设备发送的设备标识和所述访问设备的用户帐号,在所述设备标识已绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送的与所述设备标识对应的访问密码,所述鉴权请求用于请求允许所述访问设备访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备;
检测所述访问密码是否与所述受访设备生成的所述访问密码相同;
在检测出所述访问密码与所述受访设备生成的所述访问密码相同时,允许所述访问设备访问所述受访设备。
可选的,所述方法还包括:
生成所述访问密码;
向所述第三方设备发送所述访问密码和所述受访设备的设备标识,所述第三方设备用于将所述访问密码和所述设备标识进行绑定并保存。
可选的,所述方法还包括:
定期更改所述访问密码,得到更改后的访问密码;
将更改后的访问密码以及所述受访设备的设备标识发送给第三方设备,所述第三方设备将预存的所述设备标识所绑定的访问密码更新绑定为所述更改后的访问密码。
根据本公开实施例的第三方面,提供一种访问认证方法,应用于第三方设备中,所述方法包括:
接收访问设备发送的受访设备的设备标识和所述访问设备的用户帐号;
在检测到所述设备标识绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,所述鉴权请求用于请求允许所述访问设备访问所述受访设备;
在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送与所述设备标识对应的访问密码,所述访问设备用于根据所述访问密码访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备。
可选的,所述方法还包括:
检测所述设备标识是否绑定有用户帐号;
在检测出所述设备标识未绑定有用户帐号时,将所述设备标识和所述访问设备的用户帐号进行绑定,将所述访问设备确定为所述登录端。
可选的,所述在检测到所述设备标识绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,包括:
在检测到所述设备标识绑定有用户帐号时,检测所述访问设备的用户帐号是否与所述设备标识所绑定的用户帐号相同;
在检测出所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,执行所述向与所述设备标识绑定的用户帐号的登录端发送鉴权请求的步骤。
可选的,所述向所述访问设备发送与所述设备标识对应的访问密码,包括:
在检测出所述访问设备的用户帐号与所述设备标识所绑定的用户帐号相同时,执行所述向所述访问设备发送与所述设备标识对应的访问密码的步骤。
可选的,所述方法还包括:
接收所述受访设备发送的所述访问密码和所述受访设备的设备标识;
当所述受访设备的设备标识不存在绑定的访问密码时,将所述访问密码和所述受访设备的设备标识进行绑定并保存。
可选的,所述方法还包括:
当所述受访设备的设备标识存在绑定的访问密码,检测接收到的所述访问密码是否与绑定的访问密码相同;
在接收到的所述访问密码与绑定的访问密码不同时,所述设备标识绑定的访问密码更新绑定为接收到的所述访问密码。
根据本公开实施例的第四方面,提供一种访问认证装置,应用于访问设备中,所述装置包括:
获取模块,被配置为获取受访设备的设备标识;
第一发送模块,被配置为向第三方设备发送所述设备标识和所述访问设备的用户帐号;
访问模块,被配置为接收所述访问密码,根据所述访问密码访问所述受访设备,所述访问密码是第三方设备在接收到所述访问设备发送的所述设备标识和所述访问设备的用户帐号,在所述设备标识已绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送的与所述设备标识对应的访问密码,所述鉴权请求用于请求允许所述访问设备访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备。
可选的,所述获取模块,包括:
第一获取子模块,被配置为接收所述受访设备广播发送的携带有所述受访设备的设备标识的广播消息,从所述广播消息中获取所述受访设备的设备标识;或,
第二获取子模块,被配置为通过扫描所述受访设备上的图形码获取所述受访设备的设备标识。
根据本公开实施例的第五方面,提供一种访问认证装置,应用于受访设备中,所述装置包括:
第一接收模块,被配置为接收访问设备发送的访问密码,所述访问密码是第三方设备在接收到所述访问设备发送的设备标识和所述访问设备的用户帐号,在所述设备标识已绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送的与所述设备标识对应的访问密码,所述鉴权请求用于请求允许所述访问设备访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备;
第一检测模块,被配置为检测所述访问密码是否与所述受访设备生成的所述访问密码相同;
允许模块,被配置为在所述第一检测模块检测出所述访问密码与所述受访设备生成的所述访问密码相同时,允许所述访问设备访问所述受访设备。
可选的,所述装置还包括:
生成模块,被配置为生成所述访问密码;
第二发送模块,被配置为向所述第三方设备发送所述访问密码和所述受访设备的设备标识,所述第三方设备用于将所述访问密码和所述设备标识进行绑定并保存。
可选的,所述装置还包括:
更改模块,被配置为定期更改所述访问密码,得到更改后的访问密码;
第三发送模块,被配置为将更改后的访问密码以及所述受访设备的设备标识发送给第三方设备,所述第三方设备将预存的所述设备标识所绑定的访问密码更新绑定为所述更改后的访问密码。
根据本公开实施例的第六方面,提供一种访问认证装置,应用于第三方设备中,所述装置包括:
第二接收模块,被配置为接收访问设备发送的受访设备的设备标识和所述访问设备的用户帐号;
第四发送模块,被配置为在检测到所述设备标识绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,所述鉴权请求用于请求允许所述访问设备访问所述受访设备;
第五发送模块,被配置为在接收到所述登录端根据所述鉴权请求反馈的允许访问应答 后,向所述访问设备发送与所述设备标识对应的访问密码,所述访问设备用于根据所述访问密码访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备。
可选的,所述装置还包括:
第二检测模块,被配置为检测所述设备标识是否绑定有用户帐号;
第一绑定模块,被配置为在所述第二检测模块检测出所述设备标识未绑定有用户帐号时,将所述设备标识和所述访问设备的用户帐号进行绑定,将所述访问设备确定为所述登录端。
可选的,所述第四发送模块,包括:
检测子模块,被配置为在在所述第二检测模块检测到所述设备标识绑定有用户帐号时,检测所述访问设备的用户帐号是否与所述设备标识所绑定的用户帐号相同;
发送子模块,被配置为在所述检测子模块检测出所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求。
可选的,所述第五发送模块,还被配置为在所述检测子模块检测出所述访问设备的用户帐号与所述设备标识所绑定的用户帐号相同时,向所述访问设备发送与所述设备标识对应的访问密码。
可选的,所述装置还包括:
第三接收模块,被配置为接收所述受访设备发送的所述访问密码和所述受访设备的设备标识;
第二绑定模块,被配置为当所述受访设备的设备标识不存在绑定的访问密码时,将所述访问密码和所述受访设备的设备标识进行绑定并保存。
可选的,所述装置还包括:
第三检测模块,被配置为当所述受访设备的设备标识存在绑定的访问密码时,检测接收到的所述访问密码是否与绑定的访问密码相同;
第三绑定模块,被配置为当接收到的所述访问密码与绑定的访问密码不同时,所述设备标识绑定的访问密码更新绑定为接收到的所述访问密码。
根据本公开实施例的第七方面,提供一种访问认证系统,所述访问认证系统包括访问设备、受访设备和第三方设备;
所述访问设备包括如上述第四方面或第四方面各种可选方案中任一所述的访问认证装置;
所述受访设备包括上述第五方面或第五方面各种可选方案中任一所述的访问认证装置;
所述第三方设备包括如上述第六方面或第六方面各种可选方案中任一所述的访问认证装置。
根据本公开实施例的第八方面,提供一种访问认证装置,应用于访问设备中,所述装置包括:
处理器;
用于存储所述处理器可执行指令的存储器;
其中,所述处理器被配置为:
获取受访设备的设备标识;
向第三方设备发送所述设备标识和所述访问设备的用户帐号;
接收所述访问密码,根据所述访问密码访问所述受访设备,所述访问密码是第三方设备在接收到所述访问设备发送的所述设备标识和所述访问设备的用户帐号,在所述设备标识已绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送的与所述设备标识对应的访问密码,所述鉴权请求用于请求允许所述访问设备访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备。
根据本公开实施例的第九方面,提供一种访问认证装置,应用于受访设备中,所述装置包括:
处理器;
用于存储所述处理器可执行指令的存储器;
其中,所述处理器被配置为:
接收访问设备发送的访问密码,所述访问密码是第三方设备在接收到所述访问设备发送的设备标识和所述访问设备的用户帐号,在所述设备标识已绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送的与所述设备标识对应的访问密码,所述鉴权请求用于请求允许所述访问设备访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备;
检测所述访问密码是否与所述受访设备生成的所述访问密码相同;
在检测出所述访问密码与所述受访设备生成的所述访问密码相同时,允许所述访问设备访问所述受访设备。
根据本公开实施例的第十方面,提供一种访问认证装置,应用于第三方设备中,所述装置包括:
处理器;
用于存储所述处理器可执行指令的存储器;
其中,所述处理器被配置为:
接收访问设备发送的设备标识和所述访问设备的用户帐号;
在检测到所述设备标识绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,所述鉴权请求用于请求允许所述访问设备访问所述受访设备;
在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送与所述设备标识对应的访问密码,所述访问设备用于根据所述访问密码访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备。
本公开的实施例提供的技术方案可以包括以下有益效果:
通过利用访问设备获取受访设备的设备标识,向第三方设备发送设备标识和访问设备的用户帐号,在第三方设备向登录端询问确定允许访问设备访问受访设备后,接收第三方设备发送的访问密码,并根据访问密码访问受访设备;由于访问设备访问受访设备时需要通过登录端允许,因此解决了由于需要用户在手机App上手动输入访问密码,非法使用者很容易获取到该访问密码,并利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差的问题;达到了提高受访设备安全性的效果。
应当理解的是,以上的一般描述和后文的细节描述仅是示例性的,并不能限制本公开。
附图说明
此处的附图被并入说明书中并构成本说明书的一部分,示出了符合本公开的实施例,并于说明书一起用于解释本公开的原理。
图1是根据部分示例性实施例示出的一种访问认证方法所涉及的实施环境的示意图;
图2是根据一示例性实施例示出的一种访问认证方法的流程图;
图3是根据另一示例性实施例示出的一种访问认证方法的流程图;
图4是根据再一示例性实施例示出的一种访问认证方法的流程图;
图5A是根据还一示例性实施例示出的一种访问认证方法的流程图;
图5B是根据一示例性实施例示出的一种第三方设备向访问设备发送绑定请求的示意图;
图6A是根据还一示例性实施例示出的一种访问认证方法的流程图;
图6B是根据一示例性实施例示出的一种通过局域网广播获取受访设备的设备标识的示意图;
图6C是根据一示例性实施例示出的一种通过扫描受访设备上图形码获取受访设备的设备标识的示意图;
图6D是根据一示例性实施例示出的一种第三方设备向登录端发送鉴权请求的示意图;
图7是根据一示例性实施例示出的一种访问认证装置的框图;
图8是根据另一示例性实施例示出的一种访问认证装置的框图;
图9是根据再一示例性实施例示出的一种访问认证装置的框图;
图10是根据再一示例性实施例示出的一种访问认证装置的框图;
图11是根据再一示例性实施例示出的一种访问认证装置的框图;
图12是根据再一示例性实施例示出的一种访问认证装置的框图;
图13是根据一示例性实施例示出的一种访问认证系统的框图;
图14是根据一示例性实施例示出的一种用于访问受访设备的装置的框图;
图15是根据一示例性实施例示出的一种用于验证访问设备的装置的框图。
具体实施方式
这里将详细地对示例性实施例进行说明,其示例表示在附图中。下面的描述涉及附图时,除非另有表示,不同附图中的相同数字表示相同或相似的要素。以下示例性实施例中所描述的实施方式并不代表与本公开相一致的所有实施方式。相反,它们仅是与如所附权利要求书中所详述的、本公开的一些方面相一致的装置和方法的例子。
图1是根据部分示例性实施例示出的一种访问认证方法所涉及的实施环境的示意图,如图1所示,该实施环境可以包括受访设备120、访问设备140、第三方设备160和登录端180。
受访设备120可以是带Wi-Fi的智能设备,该智能设备可以是摄像头、路由器、智能电视等等。该受访设备120带有恢复出厂设置功能,能够解除与受访设备120绑定的用户帐号。该受访设备120可以通过路由器与互联网相连。
访问设备140可以是能够安装App的电子设备,该电子设备可以是智能手机、平板电脑、智能电视、电子书阅读器、MP4(Moving Picture Experts Group Audio Layer IV,动态影像专家压缩标准音频层面4)播放器、膝上型便携计算机和台式计算机等等。
第三方设备160可以是具有绑定、鉴权等功能的服务器、路由器等。当第三方设备160为服务器时,可以是一台服务器,或者由若干台服务器组成的服务器集群,或者是一个云计算服务中心。
登录端180可以是能够安装App的电子设备,该电子设备可以是智能手机、平板电脑、智能电视、电子书阅读器、MP4(Moving Picture Experts Group Audio Layer IV,动态影像专家压缩标准音频层面4)播放器、膝上型便携计算机和台式计算机等等。该登录端180上登录的用户帐号对受访设备120具有拥有者权限。
受访设备120、访问设备140、第三方设备160和登录端180之间可以通过无线网络连接,该无线网络可以是Wi-Fi、蓝牙、红外线等等。
图2是根据一示例性实施例示出的一种访问认证方法的流程图,如图2所示,该访问认证方法应用于图1所示的实施环境中的访问设备140中,包括以下步骤。
在步骤201中,获取受访设备的设备标识。
在步骤202中,向第三方设备发送设备标识和访问设备的用户帐号。
在步骤203中,接收访问密码,根据访问密码访问受访设备,访问密码是第三方设备在接收到访问设备发送的设备标识和访问设备的用户帐号,在设备标识已绑定有用户帐号且访问设备的用户帐号与设备标识所绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到登录端根据鉴权请求反馈的允许访问应答后,向访问设备发送的与设备标识对应的访问密码。
这里的鉴权请求用于请求允许访问设备访问受访设备,允许访问应答用于指示允许访问设备访问受访设备。
综上所述,本公开实施例中提供的访问认证方法,通过利用访问设备获取受访设备的设备标识,向第三方设备发送设备标识和访问设备的用户帐号,在第三方设备向登录端询问确定允许访问设备访问受访设备后,接收第三方设备发送的访问密码,并根据访问密码访问受访设备;由于访问设备访问受访设备时需要通过登录端允许,因此解决了由于需要用户在手机App上手动输入访问密码,非法使用者很容易获取到该访问密码,并利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差的问题;达到了提高受访设备安全性的效果。
图3是根据另一示例性实施例示出的一种访问认证方法的流程图,如图3所示,该访问认证方法应用于图1所示的实施环境中的受访设备120中,包括以下步骤。
在步骤301中,接收访问设备发送的访问密码,访问密码是第三方设备在接收到访问设备发送的设备标识和访问设备的用户帐号,在设备标识已绑定有用户帐号且访问设备的用户帐号与设备标识所绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到登录端根据鉴权请求反馈的允许访问应答后,向访问设备发送的与设备标识对应的访问密码。
这里的鉴权请求用于请求允许访问设备访问受访设备,允许访问应答用于指示允许访问设备访问受访设备。
在步骤302中,检测访问密码是否与受访设备生成的访问密码相同。
在步骤303中,在检测出访问密码与受访设备生成的访问密码相同时,允许访问设备访问受访设备。
综上所述,本公开实施例中提供的访问认证方法,通过接收访问设备发送的访问密码,在检测到访问密码与受访设备生成的访问密码相同后,允许该访问设备访问受访设备;由于受访设备接收访问密码后需要在验证与生成的访问密码相同后才允许访问设备访问,因此解决了若不对访问密码进行验证,受访设备在更改访问密码后,访问设备仍能够访问受访设备,安全性低的问题;达到了提高受访设备安全性的效果。
图4是根据再一示例性实施例示出的一种访问认证方法的流程图,如图4所示,该访 问认证方法应用于图1所示的实施环境中的第三方设备160中,包括以下步骤。
在步骤401中,接收访问设备发送的设备标识和访问设备的用户帐号。
在步骤402中,在检测到设备标识绑定有用户帐号且访问设备的用户帐号与设备标识所绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求。
这里的鉴权请求用于请求允许访问设备访问受访设备。
在步骤403中,在接收到登录端根据鉴权请求反馈的允许访问应答后,向访问设备发送与设备标识对应的访问密码,访问设备用于根据访问密码访问受访设备。
这里的允许访问应答用于指示允许访问设备访问受访设备。
综上所述,本公开实施例中提供的访问认证方法,通过接收访问设备发送的设备标识和访问设备的用户帐号,在检测到设备标识被绑定后向登录端发送鉴权请求,在接收到登录端反馈的允许访问应答后向访问设备发送与设备标识对应的访问密码;由于需要登录端允许后,第三方设备才能将访问密码发送给访问设备,因此解决了非法使用者获取到访问密码后,就能利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差的问题;达到了提高受访设备安全性的效果。
在访问设备访问受访设备之前,受访设备需要先生成访问密码,将生成的访问密码与受访设备的设备标识发送给第三方设备进行绑定。当第一个访问设备访问受访设备时,第三方设备将该访问设备的用户帐号与受访设备的设备标识绑定,使得该用户帐号获得该受访设备的拥有者权限。具体实现步骤请参见图5A。
图5A是根据还一示例性实施例示出的一种访问认证方法的流程图,如图5A所示,该访问认证方法应用于图1所示的实施环境中,包括以下步骤。
在步骤501中,受访设备生成访问密码。
可选的,受访设备可以随机生成访问密码。
可选的,受访设备可以定期更改访问密码;或者在接收到与该受访设备对应的登录端发送的更改访问密码指令后,更改受访设备的访问密码。
在步骤502中,受访设备向第三方设备发送该访问密码和受访设备的设备标识。
这里的设备标识可以是受访设备在被生产的时候赋予的,该设备标识唯一标识受访设备。实际应用中,该设备标识可以是字符串,该字符串可以由数字、字母或其他类型字符中的至少一类组合而成。
可选的,为了保证访问密码的安全性,受访设备可以通过加密通道将生成的访问密码和设备标识发送给第三方设备,其中的加密通道可以降低访问密码泄露的可能性。
在步骤503中,第三方设备接收受访设备发送的访问密码和受访设备的设备标识。
在步骤504中,当受访设备的设备标识不存在绑定的访问密码,第三方设备则将该访问密码和受访设备的设备标识进行绑定并保存。
第三方设备在接收受访设备发送的访问密码和受访设备的设备标识之后,首先检测该 设备标识是否被绑定有访问密码,如果检测到接收到的设备标识没有绑定访问密码时,则将接收到的访问密码与设备标识进行绑定并保存。
在一种情况下,受访设备为了保证安全性,可以随时更改绑定的访问密码,即首先定期更改访问密码,得到更改后的访问密码,并将更改后的访问密码以及该受访设备的设备标识发送给第三方设备;第三方设备在检测到接收到的设备标识存在绑定的访问密码时,则检测接收到的访问密码是否与该绑定的访问密码相同,若接收到的访问密码与该绑定的访问密码相同,第三方设备不作操作,若接收到的访问密码与该绑定的访问密码不同,第三方设备将该绑定的访问密码与设备标识解除绑定,将接收到的访问密码与设备标识进行绑定并保存。也即,当第三方设备接收到受访设备发送的访问密码和设备标识之后,如果检测到该访问密码和与该设备标识已经绑定的访问密码不同时,则将预存的该设备标识所绑定的访问密码更新绑定为更改后的访问密码。
根据上述步骤501至步骤504可知,第三方设备绑定了受访设备的设备标识和受访设备生成的访问密码。
在步骤505中,访问设备获取受访设备的设备标识。
访问设备在获取受访设备的设备标识时,可以接收受访设备广播发送的携带有受访设备的设备标识的广播消息,从广播消息中获取受访设备的设备标识;或者可以通过扫描受访设备上的图形码获取受访设备的设备标识。
需要说明的是,本实施例对访问设备获取受访设备的设备标识的具体方式不作限定。
在步骤506中,访问设备向第三方设备发送该设备标识和访问设备的用户帐号。
这里的用户帐号是用户在第三方设备上注册的,用户可以在不同的访问设备上登录该用户帐号。
访问设备在获取受访设备的设备标识后,将该设备标识和访问设备登录的用户帐号发送给第三方设备。
在步骤507中,第三方设备接收访问设备发送的设备标识和访问设备的用户帐号。
在步骤508中,第三方设备在检测到接收的设备标识未绑定有用户帐号时,将接收到的访问设备的用户帐号与该设备标识进行绑定。
第三方设备在接收到访问设备发送的设备标识和访问设备的用户帐号之后,会检测该设备标识是否绑定有用户账号。
在第三方设备检测到设备标识未绑定有用户帐号时,将接收到的访问设备的用户帐号与该设备标识进行绑定。可选的,可以向访问设备发送绑定请求,绑定请求用于向访问设备询问是否将受访设备的设备标识和访问设备的用户帐号进行绑定。
举例来讲,请参见图5B,其是根据一示例性实施例示出的一种第三方设备向访问设备发送绑定请求的示意图。如图5B所示,访问设备在接收到第三方设备发送的绑定请求后,在屏幕上显示“是否与设备:9527进行绑定?”的请求,此时用户可以通过点击:“是”选项,同意与设备:9527进行绑定,也可以点击“否”选项,放弃与设备:9527进行绑 定。
若访问设备同意和受访设备进行绑定,第三方设备则将该访问设备的用户帐号和受访设备的设备标识绑定,同时该访问设备的用户帐号获得该受访设备的拥有者权限。
为了区分与其他普通访问设备(即不具有该受访设备的拥有者权限的访问设备),将该具有受访设备的拥有者权限的访问设备确定为登录端。但需要说明的是,登录端是一种具有该受访设备的拥有者权限的访问设备,该登录端的命名并不用于限制本发明的保护范围,在实际应用中,该登录端还可以有其他命名。
在步骤509中,第三方设备向访问设备发送与设备标识对应的访问密码。
也即,第三方设备在将该访问设备(也即登录端)的用户帐号与受访设备的设备标识绑定之后,则可以直接向该访问设备发送与该设备标识对应的访问密码,以便该访问设备根据该访问密码直接访问该受访设备。
在步骤510中,访问设备接收访问密码。
可选的,访问设备(也即登录端)在接收访问密码时,可以通过无线网络或者短信等方式进行接收。
需要说明的是,本实施例对访问设备接收访问密码的具体方式不作限定。
在步骤511中,访问设备向受访设备发送访问密码。
访问设备在接收到访问密码之后,则根据该访问密码访问受访设备。
在一种使用场景中,访问设备(也即登录端)根据该访问密码访问受访设备,可以向受访设备发送访问密码,此时可以由该访问设备将通过无线网络获取的访问密码直接发送给受访设备,在这种场景中,该访问设备可以不显示接收到的访问密码,以此加强受访设备的访问密码的安全性。
可选的,在该访问设备向受访设备发送访问密码时,该访问设备将接收到的访问密码显示给用户,并弹出密码输入框,由用户将接收到的访问密码输入密码输入框,该访问设备在接收到用户输入的密码之后,将该密码发送给受访设备。
在步骤512中,受访设备接收该访问密码。
在步骤513中,受访设备检测该访问密码是否与受访设备生成的访问密码相同。
由于受访设备会更改访问密码,因此需要检测接收到的访问密码是否与受访设备生成的访问密码相同。
在步骤514中,若检测出访问密码与受访设备生成的访问密码相同,受访设备则允许该访问设备访问受访设备。
需要说明的是,在该访问设备(也即登录端)再次访问该受访设备时,第三方设备检测到该访问设备的用户帐号与受访设备的设备标识是绑定关系后,将直接向该访问设备发送该受访设备的访问密码,该访问设备接收并根据该访问密码对受访设备进行访问。
综上所述,本公开实施例中提供的访问认证方法,通过第三方设备在检测到设备标识未被绑定时,将接收到的用户帐号与该设备标识绑定,并确定该用户帐号对该受访设备具 有拥有者权限;由于通过将用户帐号与受访设备的设备标识进行绑定确定了拥有者权限,访问设备需要得到登录端允许才能访问受访设备,解决了由于需要用户在手机App上手动输入访问密码,非法使用者很容易获取到该访问密码,并利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差的问题;达到了提高受访设备安全性的效果。
在第一个访问受访设备的访问设备的用户帐号获得该受访设备的拥有者权限后,普通的访问设备在访问该受访设备时,需要获得与该具有拥有者权限的用户帐号对应的访问设备的允许才能对该受访设备进行访问。具体实现步骤请参见图6A。
图6A是根据还一示例性实施例示出的一种访问认证方法的流程图,如图6A所示,该访问认证方法应用于图1所示的实施环境中,包括以下步骤。
在步骤601中,访问设备获取受访设备的设备标识。
访问设备在获取受访设备的设备标识时,可以接收受访设备广播发送的携带有受访设备的设备标识的广播消息,从广播消息中获取受访设备的设备标识;或者可以通过扫描受访设备上的图形码获取受访设备的设备标识。
举例来讲,请参见图6B,其是根据一示例性实施例示出的一种通过局域网广播获取受访设备的设备标识的示意图。如图6B所示,访问设备通过局域网广播搜索到附近的受访设备后,将搜索结果显示在屏幕上,此时用户可以点击想要连接的受访设备的设备标识进行连接,在用户点击设备标识:9527后,访问设备弹出“是否与设备:9527建立连接?”的询问。
举例来讲,请参见图6C,其是根据一示例性实施例示出的一种通过扫描受访设备上图形码获取受访设备的设备标识的示意图。如图6C所示,访问设备在扫描受访设备上的二维码后,直接弹出“是否与设备:9527建立连接?”的询问。
需要说明的是,本实施例对获取受访设备的设备标识的具体方法不作限定。
在步骤602中,访问设备向第三方设备发送设备标识和访问设备的用户帐号。
这里的用户帐号是用户在第三方设备上注册的,用户可以在不同的访问设备上登录该用户帐号。
访问设备在获取受访设备的设备标识后,将该设备标识和访问设备登录的用户帐号发送给第三方设备。
举例来讲,仍请参见图6B或图6C,在访问设备弹出“是否与设备:9527建立连接?”的询问后,用户可以通过点击“否”选项放弃与设备:9527建立连接,或者可以点击“是”选项确定与设备:9527建立连接,此时访问设备将该受访设备的设备标识:9527和访问设备登录的用户帐号发送给第三方设备。
在步骤603中,第三方设备接收访问设备发送的设备标识和访问设备的用户帐号。
在步骤604中,第三方设备在检测到设备标识绑定有用户帐号且接收到的用户帐号与绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求。
第三方设备接收访问设备发送的设备标识和访问设备的用户帐号之后,检测该设备标识是否绑定有用户账号,在检测到该设备标识绑定有用户帐号时,检测该访问设备的用户帐号是否与该设备标识所绑定的用户帐号相同,在检测出该访问设备的用户帐号与该设备标识所绑定的用户帐号不同时,向与该设备标识绑定的用户帐号的登录端发送鉴权请求。
也即,第三方设备在检测到设备标识绑定有用户帐号且接收到的用户帐号与绑定的用户帐号不同时,则表明发送该用户帐号的访问设备不具有该受访设备的拥有者权限,也即该访问设备为普通访问设备,此时需要向该受访设备的拥有者进行鉴权,即向该受访设备的登录端进行鉴权。
这里的登录端是指在该登录端上登录的用户帐号与该设备标识存在绑定关系,即该登录端拥有该受访设备的拥有者权限。
这里的鉴权请求用于请求允许该访问设备访问受访设备。比如,该鉴权请求中可以携带有该访问设备上发送的用户账号。
而第三方设备在检测到设备标识绑定有用户帐号且接收到的用户帐号与绑定的用户帐号相同时,则表明该访问设备为具有该受访设备的拥有者权限,此时可以直接向该访问设备发送与该设备标识对应的访问密码。
在步骤605中,登录端接收该鉴权请求。
登录端接收第三方设备发送的鉴权请求后,可以根据该鉴权请求向该登录端的用户进行提示,比如可以将该鉴权请求显示在登录端的屏幕上。
举例来讲,请参见图6D,其是根据一示例性实施例示出的一种第三方设备向登录端发送鉴权请求的示意图。如图6D所示,登录端接收第三方设备发送的鉴权请求后,在屏幕上显示“是否同意设备:visitor对设备:9527进行访问?”的询问。
在步骤606中,登录端向第三方设备发送允许访问应答。
这里的允许访问应答用于指示允许访问设备访问受访设备。
在一种使用场景中,登录端的用户如果允许访问设备对受访设备进行访问,则向第三方设备发送允许访问应答。
举例来讲,仍请参见图6D,当登录端的用户允许访问设备:visitor对受访设备:9527进行访问时,用户可以点击“是”选项,此时登录端向第三方设备发送允许访问应答。相反的,当登录端的用户禁止访问设备:visitor对受访设备:9527进行访问时,用户可以点击“否”选项,此时登录端向第三方设备发送禁止访问应答,可选的,第三方设备在接收到禁止访问应答后,可以向访问设备:visitor发送错误码,以此说明该访问设备:visitor不能访问受访设备。
在步骤607中,第三方设备接收该允许访问应答。
在步骤608中,第三方设备向访问设备发送与设备标识对应的访问密码。
在步骤609中,访问设备接收该访问密码。
可选的,访问设备在接收该访问密码时,可以通过无线网络或者短信等方式进行接收。
需要说明的是,本实施例对访问设备接收访问密码的具体方式不作限定。
在步骤610中,访问设备向受访设备发送该访问密码。
访问设备在接收到访问密码之后,则根据该访问密码访问受访设备。
在一种使用场景中,访问设备(也即登录端)根据该访问密码访问受访设备,可以向受访设备发送访问密码,此时可以由访问设备将通过无线网络获取的访问密码直接发送给受访设备,在这种场景中,访问设备可以不显示接收到的访问密码,以此加强受访设备的访问密码的安全性。
可选的,在访问设备向受访设备发送访问密码时,访问设备将接收到的访问密码显示给用户,并弹出密码输入框,由用户将接收到的访问密码输入密码输入框,访问设备在接收到用户输入的密码之后,将该密码发送给受访设备。
在步骤611中,受访设备接收该访问密码。
在步骤612中,受访设备检测该访问密码是否与受访设备生成的访问密码相同。
由于受访设备会更改访问密码,因此需要检测接收到的访问密码是否与受访设备生成的访问密码相同。举例来讲,如果受访设备不再继续让已经访问过的访问设备进行访问,除了在登录端禁止其访问外,受访设备还可以将原有访问密码修改为了现有访问密码,此时访问设备如果利用原来得知的原有访问密码再次访问受访设备时,由于受访设备可以对接收到的原有访问密码与更新后的现有访问密码进行匹配,在匹配不成功时,禁止该访问设备进行访问,从而可以保证受访设备被访问时所需的最新权限。
在步骤613中,若检测出访问密码与受访设备生成的访问密码相同,受访设备则允许访问设备访问受访设备。
可选的,若检测出接收到的访问密码与受访设备生成的访问密码不同,受访设备则禁止访问设备访问受访设备,此时受访设备可以向访问设备发送错误码,以此说明该访问设备不能访问受访设备。
需要说明的是,访问设备访问受访设备的访问权限只保留一段时间,受访设备可以通过更改访问密码来取消访问设备的访问权限。
综上所述,本公开实施例中提供的访问认证方法,通过利用访问设备获取受访设备的设备标识,向第三方设备发送设备标识和访问设备的用户帐号,在第三方设备向登录端询问确定允许访问设备访问受访设备后,接收第三方设备向访问设备发送的访问密码,并根据访问密码访问受访设备;由于访问设备访问受访设备时需要通过登录端允许,因此解决了由于需要用户在手机App上手动输入访问密码,非法使用者很容易获取到该访问密码,并利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差的问题;达到了提高受访设备安全性的效果。
本公开实施例中提供的访问认证方法,通过接收访问设备发送的访问密码,在检测到访问密码与受访设备生成的访问密码相同后,允许该访问设备访问受访设备;由于受访设备接收访问密码后需要在验证与生成的访问密码相同后才允许访问设备访问,因此解决了 若不对访问密码进行验证,受访设备在更改访问密码后,访问设备仍能够访问受访设备,安全性低的问题;达到了提高受访设备安全性的效果。
本公开实施例中提供的访问认证方法,通过接收访问设备发送的设备标识和访问设备的用户帐号,在检测到设备标识被绑定后向登录端发送鉴权请求,在接收到登录端反馈的允许访问应答后向访问设备发送与设备标识对应的访问密码;由于需要登录端允许后,第三方设备才能将访问密码发送给访问设备,因此解决了非法使用者获取到访问密码后,就能利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差的问题;达到了提高受访设备安全性的效果。
下述为本公开装置实施例,可以用于执行本公开方法实施例。对于本公开装置实施例中未披露的细节,请参照本公开方法实施例。
图7是根据一示例性实施例示出的一种访问认证装置的框图,如图7所示,该访问认证装置应用于图1所示实施环境中的访问设备140中。该访问认证装置包括但不限于:获取模块702、第一发送模块704和访问模块706。
该获取模块702,被配置为获取受访设备的设备标识。
该第一发送模块704,被配置为向第三方设备发送设备标识和访问设备的用户帐号。
该访问模块706,被配置为接收访问密码,根据访问密码访问受访设备,访问密码是第三方设备在接收到访问设备发送的设备标识和访问设备的用户帐号,在设备标识已绑定有用户帐号且访问设备的用户帐号与设备标识所绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到登录端根据鉴权请求反馈的允许访问应答后,向访问设备发送的与设备标识对应的访问密码,鉴权请求用于请求允许访问设备访问受访设备,允许访问应答用于指示允许访问设备访问受访设备。
综上所述,本公开实施例中提供的访问认证装置,通过访问设备获取受访设备的设备标识,向第三方设备发送设备标识和访问设备的用户帐号,在第三方设备向登录端询问确定允许访问设备访问受访设备后,第三方设备向访问设备发送访问密码,访问设备根据访问密码访问受访设备;由于访问设备访问受访设备时需要通过登录端允许,因此解决了由于需要用户在手机App上手动输入访问密码,非法使用者很容易获取到该访问密码,并利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差的问题;达到了提高受访设备安全性的效果。
图8是根据另一示例性实施例示出的一种访问认证装置的框图,如图8所示,该访问认证装置应用于图1所示实施环境中的访问设备140中。该访问认证装置包括但不限于:获取模块802、第一发送模块804和访问模块806。
该获取模块802,被配置为获取受访设备的设备标识。
该第一发送模块804,被配置为向第三方设备发送设备标识和访问设备的用户帐号。
该访问模块806,被配置为接收访问密码,根据访问密码访问受访设备,访问密码是第三方设备在接收到访问设备发送的设备标识和访问设备的用户帐号,在设备标识已绑定有用户帐号且访问设备的用户帐号与设备标识所绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到登录端根据鉴权请求反馈的允许访问应答后,向访问设备发送的与设备标识对应的访问密码,鉴权请求用于请求允许访问设备访问受访设备,允许访问应答用于指示允许访问设备访问受访设备。
在一种可能的实施例中,该获取模块802可以包括:第一获取子模块802a或第二获取子模块802b。
该第一获取子模块802a,被配置为接收受访设备广播发送的携带有受访设备的设备标识的广播消息,从广播消息中获取受访设备的设备标识。或,
该第二获取子模块802b,被配置为通过扫描受访设备上的图形码获取受访设备的设备标识。
综上所述,本公开实施例中提供的访问认证装置,通过访问设备获取受访设备的设备标识,向第三方设备发送设备标识和访问设备的用户帐号,在第三方设备向登录端询问确定允许访问设备访问受访设备后,第三方设备向访问设备发送访问密码,访问设备根据访问密码访问受访设备;由于访问设备访问受访设备时需要通过登录端允许,因此解决了由于需要用户在手机App上手动输入访问密码,非法使用者很容易获取到该访问密码,并利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差的问题;达到了提高受访设备安全性的效果。
图9是根据再一示例性实施例示出的一种访问认证装置的框图,如图9所示,该访问认证装置应用于图1所示实施环境中的受访设备120中。该访问认证装置包括但不限于:第一接收模块902、第一检测模块904和允许模块906。
该第一接收模块902,被配置为接收访问设备发送的访问密码,访问密码是第三方设备在接收到访问设备发送的设备标识和访问设备的用户帐号,在设备标识已绑定有用户帐号且访问设备的用户帐号与设备标识所绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到登录端根据鉴权请求反馈的允许访问应答后,向访问设备发送的与设备标识对应的访问密码,鉴权请求用于请求允许访问设备访问受访设备,允许访问应答用于指示允许访问设备访问受访设备。
该第一检测模块904,被配置为检测访问密码是否与受访设备生成的访问密码相同。
该允许模块906,被配置为在第一检测模块904检测出访问密码与受访设备生成的访问密码相同时,允许访问设备访问受访设备。
综上所述,本公开实施例中提供的访问认证装置,通过接收访问设备发送的访问密码,检测到访问密码与受访设备生成的访问密码相同后,允许该访问设备访问受访设备;由于受访设备接收访问密码后需要进行验证与生成的访问密码相同后才能允许访问设备访问, 因此解决了若不对访问密码进行验证,受访设备在更改访问密码后,访问设备仍能够访问受访设备,安全性低的问题;达到了提高受访设备安全性的效果。
图10是根据再一示例性实施例示出的一种访问认证装置的框图,如图10所示,该访问认证装置应用于图1所示实施环境中的受访设备120中。该访问认证装置包括但不限于:第一接收模块1002、第一检测模块1004和允许模块1006。
该第一接收模块1002,被配置为接收访问设备发送的访问密码,访问密码是第三方设备在接收到访问设备发送的设备标识和访问设备的用户帐号,在设备标识已绑定有用户帐号且访问设备的用户帐号与设备标识所绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到登录端根据鉴权请求反馈的允许访问应答后,向访问设备发送的与设备标识对应的访问密码,鉴权请求用于请求允许访问设备访问受访设备,允许访问应答用于指示允许访问设备访问受访设备。
该第一检测模块1004,被配置为检测访问密码是否与受访设备生成的访问密码相同。
该允许模块1006,被配置为在第一检测模块1004检测出访问密码与受访设备生成的访问密码相同时,允许访问设备访问受访设备。
在一种可能的实施例中,该装置还包括:生成模块1008和第二发送模块1010。
该生成模块1008,被配置为生成访问密码。
该第二发送模块1010,被配置为向第三方设备发送访问密码和受访设备的设备标识,第三方设备用于将访问密码和设备标识进行绑定并保存。
在一种可能的实施例中,该装置还包括:更改模块1012和第三发送模块1014。
该更改模块1012,被配置为定期更改访问密码,得到更改后的访问密码。
该第三发送模块1014,被配置为将更改后的访问密码以及受访设备的设备标识发送给第三方设备,第三方设备将预存的设备标识所绑定的访问密码更新绑定为更改后的访问密码。
综上所述,本公开实施例中提供的访问认证装置,通过接收访问设备发送的访问密码,检测到访问密码与受访设备生成的访问密码相同后,允许该访问设备访问受访设备;由于受访设备接收访问密码后需要进行验证与生成的访问密码相同后才能允许访问设备访问,因此解决了若不对访问密码进行验证,受访设备在更改访问密码后,访问设备仍能够访问受访设备,安全性低的问题;达到了提高受访设备安全性的效果。
图11是根据再一示例性实施例示出的一种访问认证装置的框图,如图11所示,该访问认证装置应用于图1所示实施环境中的第三方设备160中。该访问认证装置包括但不限于:第二接收模块1102、第四发送模块1104和第五发送模块1106。
该第二接收模块1102,被配置为接收访问设备发送的受访设备的设备标识和访问设备的用户帐号。
该第四发送模块1104,被配置为在检测到设备标识绑定有用户帐号且访问设备的用户帐号与设备标识所绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求,鉴权请求用于请求允许访问设备访问受访设备。
该第五发送模块1106,被配置为在接收到登录端根据鉴权请求反馈的允许访问应答后,向访问设备发送与设备标识对应的访问密码,访问设备用于根据访问密码访问受访设备,允许访问应答用于指示允许访问设备访问受访设备。
综上所述,本公开实施例中提供的访问认证装置,通过接收访问设备发送的设备标识和访问设备的用户帐号,在检测到设备标识被绑定后向登录端发送鉴权请求,在接收到登录端反馈的允许访问应答后向访问设备发送与设备标识对应的访问密码;由于需要登录端允许后,第三方设备才能将访问密码发送给访问设备,因此解决了非法使用者获取到访问密码后,就能利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差的问题;达到了提高受访设备安全性的效果。
图12是根据再一示例性实施例示出的一种访问认证装置的框图,如图12所示,该访问认证装置应用于图1所示实施环境中的第三方设备160中。该访问认证装置包括但不限于:第二接收模块1202、第四发送模块1204和第五发送模块1206。
该第二接收模块1202,被配置为接收访问设备发送的设备标识和访问设备的用户帐号。
该第四发送模块1204,被配置为在检测到设备标识绑定有用户帐号且访问设备的用户帐号与设备标识所绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求,鉴权请求用于请求允许访问设备访问受访设备。
该第五发送模块1206,被配置为在接收到登录端根据鉴权请求反馈的允许访问应答后,向访问设备发送与设备标识对应的访问密码,访问设备用于根据访问密码访问受访设备,允许访问应答用于指示允许访问设备访问受访设备。
在一种可能的实施例中,该装置还包括:第二检测模块1208和第一绑定模块1210。
该第二检测模块1208,被配置为检测设备标识是否绑定有用户帐号。
该第一绑定模块1210,被配置为在第二检测模块1208检测出设备标识未绑定有用户帐号时,将设备标识和访问设备的用户帐号进行绑定,将访问设备确定为登录端。
在一种可能的实施例中,该第四发送模块1204可以包括:检测子模块1204a和发送子模块1204b。
该检测子模块1204a,被配置为在第二检测模块1208检测到设备标识绑定有用户帐号时,检测访问设备的用户帐号是否与设备标识所绑定的用户帐号相同。
该发送子模块1204b,被配置为在检测子模块1204a检测出访问设备的用户帐号与设备标识所绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求。
在一种可能的实施例中,该第五发送模块1206还被配置为在检测子模块1204a检测 出访问设备的用户帐号与设备标识所绑定的用户帐号相同时,向访问设备发送与设备标识对应的访问密码。
在一种可能的实施例中,该装置还包括:第三接收模块1212和第二绑定模块1214。
该第三接收模块1212,被配置为接收受访设备发送的访问密码和受访设备的设备标识。
该第二绑定模块1214,被配置为当受访设备的设备标识不存在绑定的访问密码时,将访问密码和受访设备的设备标识进行绑定并保存。
在一种可能的实施例中,该装置还包括:第三检测模块1216和第三绑定模块1218。
该第三检测模块1216,被配置为当受访设备的设备标识存在绑定的访问密码时,检测接收到的访问密码是否与绑定的访问密码相同。
该第三绑定模块1218,被配置为当接收到的访问密码与绑定的访问密码不同时,设备标识绑定的访问密码更新绑定为接收到的访问密码。
综上所述,本公开实施例中提供的访问认证装置,通过接收访问设备发送的设备标识和访问设备的用户帐号,在检测到设备标识被绑定后向登录端发送鉴权请求,在接收到登录端反馈的允许访问应答后向访问设备发送与设备标识对应的访问密码;由于需要登录端允许后,第三方设备才能将访问密码发送给访问设备,因此解决了非法使用者获取到访问密码后,就能利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差的问题;达到了提高受访设备安全性的效果。
关于上述实施例中的装置,其中各个模块执行操作的具体方式已经在有关该方法的实施例中进行了详细描述,此处将不做详细阐述说明。
图13是根据一示例性实施例示出的一种访问认证系统的框图,如图13所示,该访问认证系统应用于图1所示实施环境中。该访问认证系统包括但不限于:受访设备1302、访问设备1304和第三方设备1306。
该受访设备1302包括图9或图10中所描述的访问认证装置。
该访问设备1304包括图7或图8中所描述的访问认证装置。
该第三方设备1306包括图11或图12中所描述的访问认证装置。
综上所述,本公开实施例中提供的访问认证系统,通过利用访问设备获取受访设备的设备标识,向第三方设备发送设备标识和访问设备的用户帐号,在第三方设备向登录端询问确定允许访问设备访问受访设备后,接收第三方设备向访问设备发送的访问密码,并根据访问密码访问受访设备;由于访问设备访问受访设备时需要通过登录端允许,因此解决了由于需要用户在手机App上手动输入访问密码,非法使用者很容易获取到该访问密码,并利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差的问题;达到了提高受访设备安全性的效果。
本公开实施例中提供的访问认证系统,通过接收访问设备发送的访问密码,在检测到访问密码与受访设备生成的访问密码相同后,允许该访问设备访问受访设备;由于受访设备接收访问密码后需要在验证与生成的访问密码相同后才允许访问设备访问,因此解决了若不对访问密码进行验证,受访设备在更改访问密码后,访问设备仍能够访问受访设备,安全性低的问题;达到了提高受访设备安全性的效果。
本公开实施例中提供的访问认证系统,通过接收访问设备发送的设备标识和访问设备的用户帐号,在检测到设备标识被绑定后向登录端发送鉴权请求,在接收到登录端反馈的允许访问应答后向访问设备发送与设备标识对应的访问密码;由于需要登录端允许后,第三方设备才能将访问密码发送给访问设备,因此解决了非法使用者获取到访问密码后,就能利用该访问密码对该Wi-Fi智能设备进行访问,安全性比较差的问题;达到了提高受访设备安全性的效果。
关于上述实施例中的系统,其执行操作的具体方式已经在有关该方法的实施例中进行了详细描述,此处将不做详细阐述说明。
本公开一示例性实施例提供了一种访问认证装置,应用于访问设备中,能够实现本公开提供的访问认证方法,该访问认证装置包括:处理器、用于存储处理器可执行指令的存储器;
其中,处理器被配置为:
获取受访设备的设备标识;
向第三方设备发送设备标识和访问设备的用户帐号;
接收访问密码,根据访问密码访问受访设备,访问密码是第三方设备在接收到访问设备发送的设备标识和访问设备的用户帐号,在设备标识已绑定有用户帐号且访问设备的用户帐号与设备标识所绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到登录端根据鉴权请求反馈的允许访问应答后,向访问设备发送的与设备标识对应的访问密码,鉴权请求用于请求允许访问设备访问受访设备,允许访问应答用于指示允许访问设备访问受访设备。
本公开一示例性实施例提供了一种访问认证装置,应用于受访设备中,能够实现本公开提供的访问认证方法,该访问认证装置包括:处理器、用于存储处理器可执行指令的存储器;
其中,处理器被配置为:
接收访问设备发送的访问密码,访问密码是第三方设备在接收到访问设备发送的设备标识和访问设备的用户帐号,在设备标识已绑定有用户帐号且访问设备的用户帐号与设备标识所绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求,在 接收到登录端根据鉴权请求反馈的允许访问应答后,向访问设备发送的与设备标识对应的访问密码,鉴权请求用于请求允许访问设备访问受访设备,允许访问应答用于指示允许访问设备访问受访设备;
检测访问密码是否与受访设备生成的访问密码相同;
在检测出访问密码与受访设备生成的访问密码相同时,允许访问设备访问受访设备。
本公开一示例性实施例提供了一种访问认证装置,应用于第三方设备中,能够实现本公开提供的访问认证方法,该访问认证装置包括:处理器、用于存储处理器可执行指令的存储器;
其中,处理器被配置为:
接收访问设备发送的设备标识和访问设备的用户帐号;
在检测到设备标识绑定有用户帐号且访问设备的用户帐号与设备标识所绑定的用户帐号不同时,向与设备标识绑定的用户帐号的登录端发送鉴权请求,鉴权请求用于请求允许访问设备访问受访设备;
在接收到登录端根据鉴权请求反馈的允许访问应答后,向访问设备发送与设备标识对应的访问密码,访问设备用于根据访问密码访问受访设备,允许访问应答用于指示允许访问设备访问受访设备。
图14是根据一示例性实施例示出的一种用于访问受访设备的装置的框图。例如,装置1400可以是移动电话,计算机,数字广播终端,消息收发设备,游戏控制台,平板设备,医疗设备,健身设备,个人数字助理等。
参照图14,装置1400可以包括以下一个或多个组件:处理组件1402,存储器1404,电源组件1406,多媒体组件1408,音频组件1410,输入/输出(I/O)接口1412,传感器组件1414,以及通信组件1416。
处理组件1402通常控制装置1400的整体操作,诸如与显示,电话呼叫,数据通信,相机操作和记录操作相关联的操作。处理组件1402可以包括一个或多个处理器1418来执行指令,以完成上述的方法的全部或部分步骤。此外,处理组件1402可以包括一个或多个模块,便于处理组件1402和其他组件之间的交互。例如,处理组件1402可以包括多媒体模块,以方便多媒体组件1408和处理组件1402之间的交互。
存储器1404被配置为存储各种类型的数据以支持在装置1400的操作。这些数据的示例包括用于在装置1400上操作的任何应用程序或方法的指令,联系人数据,电话簿数据,消息,图片,视频等。存储器1404可以由任何类型的易失性或非易失性存储设备或者它们的组合实现,如静态随机存取存储器(SRAM),电可擦除可编程只读存储器(EEPROM),可擦除可编程只读存储器(EPROM),可编程只读存储器(PROM),只读存储器(ROM),磁存储器,快闪存储器,磁盘或光盘。
电源组件1406为装置1400的各种组件提供电力。电源组件1406可以包括电源管理系统,一个或多个电源,及其他与为装置1400生成、管理和分配电力相关联的组件。
多媒体组件1408包括在装置1400和用户之间的提供一个输出接口的屏幕。在一些实施例中,屏幕可以包括液晶显示器(LCD)和触摸面板(TP)。如果屏幕包括触摸面板,屏幕可以被实现为触摸屏,以接收来自用户的输入信号。触摸面板包括一个或多个触摸传感器以感测触摸、滑动和触摸面板上的手势。触摸传感器可以不仅感测触摸或滑动动作的边界,而且还检测与触摸或滑动操作相关的持续时间和压力。在一些实施例中,多媒体组件1408包括一个前置摄像头和/或后置摄像头。当装置1400处于操作模式,如拍摄模式或视频模式时,前置摄像头和/或后置摄像头可以接收外部的多媒体数据。每个前置摄像头和后置摄像头可以是一个固定的光学透镜系统或具有焦距和光学变焦能力。
音频组件1410被配置为输出和/或输入音频信号。例如,音频组件1410包括一个麦克风(MIC),当装置1400处于操作模式,如呼叫模式、记录模式和语音识别模式时,麦克风被配置为接收外部音频信号。所接收的音频信号可以被进一步存储在存储器1404或经由通信组件1416发送。在一些实施例中,音频组件1410还包括一个扬声器,用于输出音频信号。
I/O接口1412为处理组件1402和外围接口模块之间提供接口,上述外围接口模块可以是键盘,点击轮,按钮等。这些按钮可包括但不限于:主页按钮、音量按钮、启动按钮和锁定按钮。
传感器组件1414包括一个或多个传感器,用于为装置1400提供各个方面的状态评估。例如,传感器组件1414可以检测到装置1400的打开/关闭状态,组件的相对定位,例如组件为装置1400的显示器和小键盘,传感器组件1414还可以检测装置1400或装置1400一个组件的位置改变,用户与装置1400接触的存在或不存在,装置1400方位或加速/减速和装置1400的温度变化。传感器组件1414可以包括接近传感器,被配置用来在没有任何的物理接触时检测附近物体的存在。传感器组件1414还可以包括光传感器,如CMOS或CCD图像传感器,用于在成像应用中使用。在一些实施例中,该传感器组件1414还可以包括加速度传感器,陀螺仪传感器,磁传感器,压力传感器或温度传感器。
通信组件1416被配置为便于装置1400和其他设备之间有线或无线方式的通信。装置1400可以接入基于通信标准的无线网络,如Wi-Fi,2G或3G,或它们的组合。在一个示例性实施例中,通信组件1416经由广播信道接收来自外部广播管理系统的广播信号或广播相关信息。在一个示例性实施例中,通信组件1416还包括近场通信(NFC)模块,以促进短程通信。例如,在NFC模块可基于射频识别(RFID)技术,红外数据协会(IrDA)技术,超宽带(UWB)技术,蓝牙(BT)技术和其他技术来实现。
在示例性实施例中,装置1400可以被一个或多个应用专用集成电路(ASIC)、数字信号处理器(DSP)、数字信号处理设备(DSPD)、可编程逻辑器件(PLD)、现场可编程门阵列(FPGA)、控制器、微控制器、微处理器或其他电子元件实现,用于执行以 访问设备或受访设备为执行主体的访问认证方法。
在示例性实施例中,还提供了一种包括指令的非临时性计算机可读存储介质,例如包括指令的存储器1404,上述指令可由装置1400的处理器1418执行以完成以访问设备或受访设备为执行主体的访问认证方法。例如,非临时性计算机可读存储介质可以是ROM、随机存取存储器(RAM)、CD-ROM、磁带、软盘和光数据存储设备等。
图15是根据一示例性实施例示出的一种用于验证访问设备的装置的框图。例如,装置1500可以被提供为一服务器。参照图15,装置1500包括处理组件1502,其进一步包括一个或多个处理器,以及由存储器1504所代表的存储器资源,用于存储可由处理组件1502的执行的指令,例如应用程序。存储器1504中存储的应用程序可以包括一个或一个以上的每一个对应于一组指令的模块。此外,处理组件1502被配置为执行指令,以执行以第三方设备为执行主体的访问认证方法。
装置1500还可以包括一个电源组件1506被配置为执行装置1500的电源管理,一个有线或无线网络接口1508被配置为将装置1500连接到网络,和一个输入输出(I/O)接口1510。装置1500可以操作基于存储在存储器1504的操作系统,例如Windows ServerTM,Mac OS XTM,UnixTM,LinuxTM,FreeBSDTM或类似。
本领域技术人员在考虑说明书及实践这里公开的发明后,将容易想到本公开的其它实施方案。本申请旨在涵盖本公开的任何变型、用途或者适应性变化,这些变型、用途或者适应性变化遵循本公开的一般性原理并包括本公开未公开的本技术领域中的公知常识或惯用技术手段。说明书和实施例仅被视为示例性的,本公开的真正范围和精神由下面的权利要求指出。
应当理解的是,本公开并不局限于上面已经描述并在附图中示出的精确结构,并且可以在不脱离其范围进行各种修改和改变。本公开的范围仅由所附的权利要求来限制。

Claims (26)

  1. 一种访问认证方法,其特征在于,应用于访问设备中,所述方法包括:
    获取受访设备的设备标识;
    向第三方设备发送所述设备标识和所述访问设备的用户帐号;
    接收所述访问密码,根据所述访问密码访问所述受访设备,所述访问密码是第三方设备在接收到所述访问设备发送的所述设备标识和所述访问设备的用户帐号,在所述设备标识已绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送的与所述设备标识对应的访问密码,所述鉴权请求用于请求允许所述访问设备访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备。
  2. 根据权利要求1所述的方法,其特征在于,所述获取受访设备的设备标识,包括:
    接收所述受访设备广播发送的携带有所述受访设备的设备标识的广播消息,从所述广播消息中获取所述受访设备的设备标识;或,
    通过扫描所述受访设备上的图形码获取所述受访设备的设备标识。
  3. 一种访问认证方法,其特征在于,应用于受访设备中,所述方法包括:
    接收访问设备发送的访问密码,所述访问密码是第三方设备在接收到所述访问设备发送的设备标识和所述访问设备的用户帐号,在所述设备标识已绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送的与所述设备标识对应的访问密码,所述鉴权请求用于请求允许所述访问设备访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备;
    检测所述访问密码是否与所述受访设备生成的所述访问密码相同;
    在检测出所述访问密码与所述受访设备生成的所述访问密码相同时,允许所述访问设备访问所述受访设备。
  4. 根据权利要求3所述的方法,其特征在于,所述方法还包括:
    生成所述访问密码;
    向所述第三方设备发送所述访问密码和所述受访设备的设备标识,所述第三方设备用于将所述访问密码和所述设备标识进行绑定并保存。
  5. 根据权利要求4所述的方法,其特征在于,所述方法还包括:
    定期更改所述访问密码,得到更改后的访问密码;
    将更改后的访问密码以及所述受访设备的设备标识发送给第三方设备,所述第三方设备将预存的所述设备标识所绑定的访问密码更新绑定为所述更改后的访问密码。
  6. 一种访问认证方法,其特征在于,应用于第三方设备中,所述方法包括:
    接收访问设备发送的受访设备的设备标识和所述访问设备的用户帐号;
    在检测到所述设备标识绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,所述鉴权请求用于请求允许所述访问设备访问所述受访设备;
    在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送与所述设备标识对应的访问密码,所述访问设备用于根据所述访问密码访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备。
  7. 根据权利要求6所述的方法,其特征在于,所述方法还包括:
    检测所述设备标识是否绑定有用户帐号;
    在检测出所述设备标识未绑定有用户帐号时,将所述设备标识和所述访问设备的用户帐号进行绑定,将所述访问设备确定为所述登录端。
  8. 根据权利要求6所述的方法,其特征在于,所述在检测到所述设备标识绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,包括:
    在检测到所述设备标识绑定有用户帐号时,检测所述访问设备的用户帐号是否与所述设备标识所绑定的用户帐号相同;
    在检测出所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,执行所述向与所述设备标识绑定的用户帐号的登录端发送鉴权请求的步骤。
  9. 根据权利要求8所述的方法,其特征在于,所述向所述访问设备发送与所述设备标识对应的访问密码,包括:
    在检测出所述访问设备的用户帐号与所述设备标识所绑定的用户帐号相同时,执行所述向所述访问设备发送与所述设备标识对应的访问密码的步骤。
  10. 根据权利要求6至9中任一所述的方法,其特征在于,所述方法还包括:
    接收所述受访设备发送的所述访问密码和所述受访设备的设备标识;
    当所述受访设备的设备标识不存在绑定的访问密码时,将所述访问密码和所述受访设备的设备标识进行绑定并保存。
  11. 根据权利要求10所述的方法,其特征在于,所述方法还包括:
    当所述受访设备的设备标识存在绑定的访问密码,检测接收到的所述访问密码是否与绑定的访问密码相同;
    当接收到的所述访问密码与绑定的访问密码不同时,所述设备标识绑定的访问密码更新绑定为接收到的所述访问密码。
  12. 一种访问认证装置,其特征在于,应用于访问设备中,所述装置包括:
    获取模块,被配置为获取受访设备的设备标识;
    第一发送模块,被配置为向第三方设备发送所述设备标识和所述访问设备的用户帐号;
    访问模块,被配置为接收所述访问密码,根据所述访问密码访问所述受访设备,所述访问密码是第三方设备在接收到所述访问设备发送的所述设备标识和所述访问设备的用户帐号,在所述设备标识已绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送的与所述设备标识对应的访问密码,所述鉴权请求用于请求允许所述访问设备访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备。
  13. 根据权利要求12所述的装置,其特征在于,所述获取模块,包括:
    第一获取子模块,被配置为接收所述受访设备广播发送的携带有所述受访设备的设备标识的广播消息,从所述广播消息中获取所述受访设备的设备标识;或,
    第二获取子模块,被配置为通过扫描所述受访设备上的图形码获取所述受访设备的设备标识。
  14. 一种访问认证装置,其特征在于,应用于受访设备中,所述装置包括:
    第一接收模块,被配置为接收访问设备发送的访问密码,所述访问密码是第三方设备在接收到所述访问设备发送的设备标识和所述访问设备的用户帐号,在所述设备标识已绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送的与所述设备标识对应的访问密码,所述鉴权请求用于请求允许所述访问设备访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备;
    第一检测模块,被配置为检测所述访问密码是否与所述受访设备生成的所述访问密码相同;
    允许模块,被配置为在所述第一检测模块检测出所述访问密码与所述受访设备生成的所述访问密码相同时,允许所述访问设备访问所述受访设备。
  15. 根据权利要求14所述的装置,其特征在于,所述装置还包括:
    生成模块,被配置为生成所述访问密码;
    第二发送模块,被配置为向所述第三方设备发送所述访问密码和所述受访设备的设备标识,所述第三方设备用于将所述访问密码和所述设备标识进行绑定并保存。
  16. 根据权利要求15所述的装置,其特征在于,所述装置还包括:
    更改模块,被配置为定期更改所述访问密码,得到更改后的访问密码;
    第三发送模块,被配置为将更改后的访问密码以及所述受访设备的设备标识发送给第三方设备,所述第三方设备将预存的所述设备标识所绑定的访问密码更新绑定为所述更改后的访问密码。
  17. 一种访问认证装置,其特征在于,应用于第三方设备中,所述装置包括:
    第二接收模块,被配置为接收访问设备发送的受访设备的设备标识和所述访问设备的用户帐号;
    第四发送模块,被配置为在检测到所述设备标识绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,所述鉴权请求用于请求允许所述访问设备访问所述受访设备;
    第五发送模块,被配置为在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送与所述设备标识对应的访问密码,所述访问设备用于根据所述访问密码访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备。
  18. 根据权利要求17所述的装置,其特征在于,所述装置还包括:
    第二检测模块,被配置为检测所述设备标识是否绑定有用户帐号;
    第一绑定模块,被配置为在所述第二检测模块检测出所述设备标识未绑定有用户帐号时,将所述设备标识和所述访问设备的用户帐号进行绑定,将所述访问设备确定为所述登录端。
  19. 根据权利要求17所述的装置,其特征在于,所述第四发送模块,包括:
    检测子模块,被配置为在所述第二检测模块检测到所述设备标识绑定有用户帐号时,检测所述访问设备的用户帐号是否与所述设备标识所绑定的用户帐号相同;
    发送子模块,被配置为在所述检测子模块检测出所述访问设备的用户帐号与所述设备 标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求。
  20. 根据权利要求19所述的装置,其特征在于,
    所述第五发送模块,还被配置为在所述检测子模块检测出所述访问设备的用户帐号与所述设备标识所绑定的用户帐号相同时,向所述访问设备发送与所述设备标识对应的访问密码。
  21. 根据权利要求17至20中任一所述的装置,其特征在于,所述装置还包括:
    第三接收模块,被配置为接收所述受访设备发送的所述访问密码和所述受访设备的设备标识;
    第二绑定模块,被配置为当所述受访设备的设备标识不存在绑定的访问密码时,将所述访问密码和所述受访设备的设备标识进行绑定并保存。
  22. 根据权利要求21所述的装置,其特征在于,所述装置还包括:
    第三检测模块,被配置为当所述受访设备的设备标识存在绑定的访问密码时,检测接收到的所述访问密码是否与绑定的访问密码相同;
    第三绑定模块,被配置为当接收到的所述访问密码与绑定的访问密码不同时,所述设备标识绑定的访问密码更新绑定为接收到的所述访问密码。
  23. 一种访问认证系统,其特征在于,所述访问认证系统包括访问设备、受访设备和第三方设备;
    所述访问设备包括如权利要求12或13所述的访问认证装置;
    所述受访设备包括如权利要求14至16中任一所述的访问认证装置;
    所述第三方设备包括如权利要求17至22中任一所述的访问认证装置。
  24. 一种访问认证装置,其特征在于,应用于访问设备中,所述装置包括:
    处理器;
    用于存储所述处理器可执行指令的存储器;
    其中,所述处理器被配置为:
    获取受访设备的设备标识;
    向第三方设备发送所述设备标识和所述访问设备的用户帐号;
    接收所述访问密码,根据所述访问密码访问所述受访设备,所述访问密码是第三方设备在接收到所述访问设备发送的所述设备标识和所述访问设备的用户帐号,在所述设备标识已绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同 时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送的与所述设备标识对应的访问密码,所述鉴权请求用于请求允许所述访问设备访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备。
  25. 一种访问认证装置,其特征在于,应用于受访设备中,所述装置包括:
    处理器;
    用于存储所述处理器可执行指令的存储器;
    其中,所述处理器被配置为:
    接收访问设备发送的访问密码,所述访问密码是第三方设备在接收到所述访问设备发送的设备标识和所述访问设备的用户帐号,在所述设备标识已绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送的与所述设备标识对应的访问密码,所述鉴权请求用于请求允许所述访问设备访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备;
    检测所述访问密码是否与所述受访设备生成的所述访问密码相同;
    在检测出所述访问密码与所述受访设备生成的所述访问密码相同时,允许所述访问设备访问所述受访设备。
  26. 一种访问认证装置,其特征在于,应用于第三方设备中,所述装置包括:
    处理器;
    用于存储所述处理器可执行指令的存储器;
    其中,所述处理器被配置为:
    接收访问设备发送的设备标识和所述访问设备的用户帐号;
    在检测到所述设备标识绑定有用户帐号且所述访问设备的用户帐号与所述设备标识所绑定的用户帐号不同时,向与所述设备标识绑定的用户帐号的登录端发送鉴权请求,所述鉴权请求用于请求允许所述访问设备访问所述受访设备;
    在接收到所述登录端根据所述鉴权请求反馈的允许访问应答后,向所述访问设备发送与所述设备标识对应的访问密码,所述访问设备用于根据所述访问密码访问所述受访设备,所述允许访问应答用于指示允许所述访问设备访问所述受访设备。
PCT/CN2015/074876 2014-08-15 2015-03-23 访问认证方法、装置及系统 Ceased WO2016023367A1 (zh)

Priority Applications (6)

Application Number Priority Date Filing Date Title
JP2016541817A JP6105173B2 (ja) 2014-08-15 2015-03-23 アクセス認証方法、装置、システム、プログラム及び記録媒体
MX2015009993A MX359497B (es) 2014-08-15 2015-03-23 Metodo, aparato y sistema para autenticar acceso.
KR1020157013718A KR20160030470A (ko) 2014-08-15 2015-03-23 액세스 인증 방법, 장치, 시스템, 프로그램 및 기록매체
BR112015024562A BR112015024562A2 (pt) 2014-08-15 2015-03-23 método, aparelho e sistema para autenticação de acesso e programa de computador
RU2015140671A RU2611968C1 (ru) 2014-08-15 2015-03-23 Способ, устройство и система для аутентификации доступа
US15/233,212 US10498723B2 (en) 2014-08-15 2016-08-10 Method, and apparatus for authenticating access

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201410403939.2 2014-08-15
CN201410403939.2A CN104202306B (zh) 2014-08-15 2014-08-15 访问认证方法、装置及系统

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US15/233,212 Continuation US10498723B2 (en) 2014-08-15 2016-08-10 Method, and apparatus for authenticating access

Publications (1)

Publication Number Publication Date
WO2016023367A1 true WO2016023367A1 (zh) 2016-02-18

Family

ID=52087531

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/074876 Ceased WO2016023367A1 (zh) 2014-08-15 2015-03-23 访问认证方法、装置及系统

Country Status (9)

Country Link
US (1) US10498723B2 (zh)
EP (1) EP2985975B1 (zh)
JP (1) JP6105173B2 (zh)
KR (1) KR20160030470A (zh)
CN (1) CN104202306B (zh)
BR (1) BR112015024562A2 (zh)
MX (1) MX359497B (zh)
RU (1) RU2611968C1 (zh)
WO (1) WO2016023367A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101856692B1 (ko) * 2016-04-14 2018-05-10 베이징 시아오미 모바일 소프트웨어 컴퍼니 리미티드 무선 액세스 포인트의 액세스 방법, 장치, 프로그램 및 저장매체
WO2026076732A1 (zh) * 2024-10-09 2026-04-16 上海华申智能卡应用系统有限公司 一种基于输入设备的访问方法、装置及鼠标

Families Citing this family (36)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104202306B (zh) 2014-08-15 2015-10-14 小米科技有限责任公司 访问认证方法、装置及系统
CN104780154B (zh) * 2015-03-13 2018-06-19 小米科技有限责任公司 设备绑定方法和装置
CN104780155B (zh) * 2015-03-16 2018-03-06 小米科技有限责任公司 设备绑定方法及装置
CN104660618A (zh) * 2015-03-24 2015-05-27 联想(北京)有限公司 绑定方法和绑定设备
US10206108B2 (en) 2015-03-24 2019-02-12 Lenovo (Beijing) Co., Ltd. Device and method for smart home
CN106161392B (zh) * 2015-04-17 2019-08-23 深圳市腾讯计算机系统有限公司 一种身份验证方法和设备
CN105100190B (zh) * 2015-05-21 2019-05-10 小米科技有限责任公司 对账户与设备的控制关系进行管理的方法、装置和系统
CN105243318B (zh) * 2015-08-28 2020-07-31 小米科技有限责任公司 确定用户设备控制权限的方法、装置及终端设备
CN105357262B (zh) * 2015-09-29 2019-07-23 小米科技有限责任公司 设备控制方法及装置
CN105471974B (zh) * 2015-11-18 2019-01-18 北京京东世纪贸易有限公司 实现远程控制的智能设备、终端设备及方法
CN105472192B (zh) * 2015-11-18 2019-06-04 北京京东世纪贸易有限公司 实现控制安全授权和分享的智能设备、终端设备及方法
CN105245552B (zh) * 2015-11-18 2019-01-18 北京京东世纪贸易有限公司 实现安全控制授权的智能设备、终端设备及方法
US9979554B2 (en) * 2016-01-11 2018-05-22 Panasonic Avionics Corporation Methods and systems for securely accessing line replaceable units
CN105704129B (zh) * 2016-01-26 2019-06-18 深圳市美贝壳科技有限公司 智能硬件设备访客登陆访问的方法
CN105704522A (zh) * 2016-01-28 2016-06-22 深圳国微技术有限公司 电视的实时监控方法及装置
CN105847243B (zh) * 2016-03-18 2021-02-26 北京小米移动软件有限公司 访问智能摄像头的方法及装置
CN105844127A (zh) * 2016-03-23 2016-08-10 乐视网信息技术(北京)股份有限公司 一种将用户权限与设备绑定的方法和装置
CN105871821A (zh) * 2016-03-24 2016-08-17 浙江风向标科技有限公司 设备绑定的方法
CN108933761A (zh) * 2017-05-25 2018-12-04 深圳市鑫科蓝电子科技有限公司 一种智能硬件产品的控制流程加密方法及系统
CN106993003A (zh) * 2017-06-08 2017-07-28 湖南暄程科技有限公司 一种医院外网登录方法和系统
CN107454591A (zh) * 2017-06-19 2017-12-08 湖南海翼电子商务股份有限公司 保障wifi局域网通信安全的方法、装置及系统
US11503015B2 (en) * 2017-10-12 2022-11-15 Mx Technologies, Inc. Aggregation platform portal for displaying and updating data for third-party service providers
CN108200013B (zh) * 2017-12-14 2020-08-21 厦门海为科技有限公司 一种基于云端的远程安全访问的方法、装置以及系统
CN108495292B (zh) * 2018-03-14 2021-08-03 成都科木信息技术有限公司 智能家居短距离设备通信方法
US11082850B2 (en) 2018-06-26 2021-08-03 At&T Intellectual Property I, L.P. Blockchain based wireless access point password management
CN109802886B (zh) * 2019-01-28 2021-10-19 奥克斯空调股份有限公司 一种绑定第三方公众号的方法、装置、空调器及存储介质
CN110166427B (zh) * 2019-04-11 2020-06-02 口碑(上海)信息技术有限公司 商家管理设备使用的安全处理方法、装置及系统
CN112422479B (zh) * 2019-08-22 2024-05-14 北京奇虎科技有限公司 一种设备绑定方法及装置、系统
CN112836208A (zh) * 2019-11-25 2021-05-25 英业达科技有限公司 同一用户的多重登入系统及其方法
US11824856B1 (en) * 2020-07-10 2023-11-21 Amazon Technologies, Inc. Chaining of authorizations
CN112131192B (zh) * 2020-09-16 2024-11-26 北京金山云网络技术有限公司 请求的响应方法、装置及系统、存储介质、电子装置
CN112560015A (zh) * 2020-12-17 2021-03-26 北京百度网讯科技有限公司 电子设备的密码更新方法、装置、设备以及存储介质
CN112632588A (zh) * 2020-12-30 2021-04-09 中国农业银行股份有限公司 一种文本加密方法及装置
CN113162935B (zh) * 2021-04-25 2022-06-24 东风汽车集团股份有限公司 一种车载终端车主账户防异常登录的方法及系统
JP7655121B2 (ja) * 2021-07-08 2025-04-02 ブラザー工業株式会社 通信装置、通信装置のためのコンピュータプログラム、サーバのためのコンピュータプログラム、及び、サーバ
CN114091075B (zh) * 2021-11-25 2024-07-12 北京字节跳动网络技术有限公司 密码输入方法、装置、存储介质及电子设备

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103078875A (zh) * 2013-01-31 2013-05-01 中国科学院计算机网络信息中心 一种智能设备双向认证方法及系统
CN103716161A (zh) * 2012-10-04 2014-04-09 (株)庆东One 能够通过互联网远程控制的智能设备的服务器认证方法及基于该方法的认证装置
US20140098247A1 (en) * 1999-06-04 2014-04-10 Ip Holdings, Inc. Home Automation And Smart Home Control Using Mobile Devices And Wireless Enabled Electrical Switches
CN103761597A (zh) * 2013-11-27 2014-04-30 北京软通科技有限责任公司 产品信息处理方法及其装置
CN104202306A (zh) * 2014-08-15 2014-12-10 小米科技有限责任公司 访问认证方法、装置及系统

Family Cites Families (15)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP4303905B2 (ja) * 2001-09-27 2009-07-29 株式会社リコー 無線通信方式切替装置
JP2004072546A (ja) * 2002-08-08 2004-03-04 Hitachi Ltd 無線通信システム
JP2006332863A (ja) * 2005-05-24 2006-12-07 Fujitsu Ltd 情報携帯端末装置、及び無線通信システム
CN101980233B (zh) * 2010-10-15 2013-11-06 上海聚力传媒技术有限公司 一种用于基于设备标识进行服务认证的方法和设备
JP5535104B2 (ja) * 2011-03-04 2014-07-02 エンカレッジ・テクノロジ株式会社 情報処理システム、管理サーバ、端末装置、情報処理方法、及びプログラム
US9438575B2 (en) * 2011-12-22 2016-09-06 Paypal, Inc. Smart phone login using QR code
JP2013143616A (ja) * 2012-01-10 2013-07-22 Nec Access Technica Ltd 無線通信端末、情報提供媒体、アクセスポイント、無線通信方法およびプログラム
JP5950691B2 (ja) * 2012-02-09 2016-07-13 シャープ株式会社 情報処理システム、情報処理装置、及び通信接続方法
US9113320B2 (en) * 2012-06-15 2015-08-18 Tangome, Inc. Transferring an account between devices
CN103067919B (zh) * 2012-12-21 2017-03-29 北京奇虎科技有限公司 计算设备和移动设备之间的连接建立方法和认证方法
US9277401B2 (en) * 2013-01-22 2016-03-01 Qualcomm Incorporated Device utilizing an optical signal to access an access point
CN103974257B (zh) * 2013-01-29 2018-08-14 华为终端有限公司 接入点的接入方法及相关设备
CN103369715A (zh) * 2013-07-03 2013-10-23 福建富士通信息软件有限公司 移动终端wifi一键上网的实现方法
KR102091606B1 (ko) * 2013-10-30 2020-03-20 엘지전자 주식회사 단말기 및 그 제어 방법
CN103795571B (zh) * 2014-01-24 2017-10-17 北京搜狗科技发展有限公司 设备之间的绑定方法及装置

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20140098247A1 (en) * 1999-06-04 2014-04-10 Ip Holdings, Inc. Home Automation And Smart Home Control Using Mobile Devices And Wireless Enabled Electrical Switches
CN103716161A (zh) * 2012-10-04 2014-04-09 (株)庆东One 能够通过互联网远程控制的智能设备的服务器认证方法及基于该方法的认证装置
CN103078875A (zh) * 2013-01-31 2013-05-01 中国科学院计算机网络信息中心 一种智能设备双向认证方法及系统
CN103761597A (zh) * 2013-11-27 2014-04-30 北京软通科技有限责任公司 产品信息处理方法及其装置
CN104202306A (zh) * 2014-08-15 2014-12-10 小米科技有限责任公司 访问认证方法、装置及系统

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR101856692B1 (ko) * 2016-04-14 2018-05-10 베이징 시아오미 모바일 소프트웨어 컴퍼니 리미티드 무선 액세스 포인트의 액세스 방법, 장치, 프로그램 및 저장매체
US10462829B2 (en) 2016-04-14 2019-10-29 Beijing Xiaomi Mobile Software Co., Ltd. Method and apparatus for accessing wireless access point
WO2026076732A1 (zh) * 2024-10-09 2026-04-16 上海华申智能卡应用系统有限公司 一种基于输入设备的访问方法、装置及鼠标

Also Published As

Publication number Publication date
JP2016535367A (ja) 2016-11-10
EP2985975B1 (en) 2018-11-21
BR112015024562A2 (pt) 2017-07-18
EP2985975A1 (en) 2016-02-17
MX2015009993A (es) 2016-05-20
JP6105173B2 (ja) 2017-03-29
MX359497B (es) 2018-09-24
US20160352723A1 (en) 2016-12-01
KR20160030470A (ko) 2016-03-18
US10498723B2 (en) 2019-12-03
CN104202306B (zh) 2015-10-14
RU2611968C1 (ru) 2017-03-01
CN104202306A (zh) 2014-12-10

Similar Documents

Publication Publication Date Title
WO2016023367A1 (zh) 访问认证方法、装置及系统
KR102044113B1 (ko) 스마트 카메라에 액세스하는 방법 및 장치
CN105656948A (zh) 账号登录方法及装置
CN104376273A (zh) 一种数据访问控制方法和装置
CN106453052B (zh) 消息交互方法及装置
WO2017035988A1 (zh) 确定用户设备控制权限的方法、装置及终端设备
WO2017166582A1 (zh) 支付方法及装置
WO2017045313A1 (zh) 短信读取方法及装置
WO2016074586A1 (zh) 权限验证的方法及装置
WO2017177571A1 (zh) 一种执行业务处理的方法、装置及系统
WO2015196665A1 (zh) 绑定账号与令牌密钥的方法、装置
CN107070914A (zh) 基于可穿戴设备的授权方法、装置和设备
KR101903262B1 (ko) 기기 제어 방법 및 장치
CN106102061A (zh) 网络连接方法及装置
CN106126986B (zh) 加锁数据分区的解锁处理方法及装置
CN106471513B (zh) 权限控制方法及装置
US9667424B2 (en) Methods and apparatuses for binding token key to account
WO2017045314A1 (zh) 短信读取方法及装置
CN107231338B (zh) 网络连接方法、装置以及用于网络连接的装置
CN112163192A (zh) root权限获取方法、装置、介质和电子设备
CN106611112A (zh) 应用程序安全处理方法、装置及设备
CN106066968A (zh) 数据保护方法及装置
CN106453257A (zh) 安全验证方法、装置、系统、终端设备和网络服务器
US9674768B2 (en) Method and device for accessing wireless network
WO2018049611A1 (zh) 权限控制方法及装置

Legal Events

Date Code Title Description
ENP Entry into the national phase

Ref document number: 2016541817

Country of ref document: JP

Kind code of ref document: A

ENP Entry into the national phase

Ref document number: 20157013718

Country of ref document: KR

Kind code of ref document: A

WWE Wipo information: entry into national phase

Ref document number: MX/A/2015/009993

Country of ref document: MX

ENP Entry into the national phase

Ref document number: 2015140671

Country of ref document: RU

Kind code of ref document: A

REG Reference to national code

Ref country code: BR

Ref legal event code: B01A

Ref document number: 112015024562

Country of ref document: BR

121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15831362

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 112015024562

Country of ref document: BR

Kind code of ref document: A2

Effective date: 20150924

122 Ep: pct application non-entry in european phase

Ref document number: 15831362

Country of ref document: EP

Kind code of ref document: A1