WO2022027364A1 - Access authentication method for bluetooth device, electronic device, and storage medium - Google Patents

Access authentication method for bluetooth device, electronic device, and storage medium Download PDF

Info

Publication number
WO2022027364A1
WO2022027364A1 PCT/CN2020/107207 CN2020107207W WO2022027364A1 WO 2022027364 A1 WO2022027364 A1 WO 2022027364A1 CN 2020107207 W CN2020107207 W CN 2020107207W WO 2022027364 A1 WO2022027364 A1 WO 2022027364A1
Authority
WO
WIPO (PCT)
Prior art keywords
gateway
cloud platform
bluetooth device
verification
platform
Prior art date
Application number
PCT/CN2020/107207
Other languages
French (fr)
Chinese (zh)
Inventor
张军
罗朝明
茹昭
吕小强
Original Assignee
Oppo广东移动通信有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Oppo广东移动通信有限公司 filed Critical Oppo广东移动通信有限公司
Priority to PCT/CN2020/107207 priority Critical patent/WO2022027364A1/en
Priority to CN202080104853.3A priority patent/CN116210246A/en
Publication of WO2022027364A1 publication Critical patent/WO2022027364A1/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/80Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication

Definitions

  • the present application relates to the field of wireless communication technologies, and in particular, to a Bluetooth device access authentication method, an electronic device, and a storage medium.
  • Embodiments of the present application provide a Bluetooth device access authentication method, an electronic device, and a storage medium, which can improve the versatility of Bluetooth device access authentication.
  • an embodiment of the present application provides a Bluetooth device access authentication method, including: a gateway determining a verification credential of the Bluetooth device;
  • the gateway sends the verification credential of the Bluetooth device to the cloud platform, and the verification credential of the Bluetooth device is used by the cloud platform to determine the validity of the Bluetooth device.
  • an embodiment of the present application provides a Bluetooth device access authentication method, including: a cloud platform receiving a verification credential of a Bluetooth device sent by a gateway;
  • the cloud platform determines the validity of the Bluetooth device based on the verification certificate of the Bluetooth device.
  • an embodiment of the present application provides a method for authentication of Bluetooth device access, including: the device authentication platform receives a fifth request message sent by a cloud platform; the fifth request message includes a verification credential of the Bluetooth device;
  • the device authentication platform verifies the validity of the Bluetooth device according to the verification certificate of the Bluetooth device.
  • an embodiment of the present application provides a method for authenticating access to a Bluetooth device, including: a Bluetooth device sending a verification credential of the Bluetooth device to a gateway, where the verification credential of the Bluetooth device is used to determine the validity of the Bluetooth device .
  • an embodiment of the present application provides a gateway, where the gateway includes: a first processing unit configured to determine a verification credential of a Bluetooth device;
  • the first sending unit is configured to send the verification certificate of the Bluetooth device to the cloud platform, where the verification certificate of the Bluetooth device is used for the cloud platform to determine the validity of the Bluetooth device.
  • an embodiment of the present application provides a cloud platform, where the cloud platform includes: a first receiving unit configured to receive a verification credential of a Bluetooth device sent by a gateway;
  • the second processing unit is configured to determine the validity of the Bluetooth device based on the verification credential of the Bluetooth device.
  • an embodiment of the present application provides a device authentication platform, where the device authentication platform includes: a second receiving unit configured to receive a fifth request message sent by the cloud platform; the fifth request message includes the authentication of the Bluetooth device. verification certificate;
  • the third processing unit verifies the validity of the Bluetooth device according to the verification certificate of the Bluetooth device.
  • an embodiment of the present application provides a Bluetooth device, where the Bluetooth device includes: a second sending unit configured to send a verification credential of the Bluetooth device to a gateway, where the verification credential of the Bluetooth device is used to determine the Legality of Bluetooth devices.
  • an embodiment of the present application provides a gateway, including a processor and a memory for storing a computer program that can be executed on the processor, wherein the processor is configured to execute the above-mentioned gateway execution when the computer program is executed.
  • the steps of the Bluetooth device access authentication method are performed by the processor and a memory for storing a computer program that can be executed on the processor, wherein the processor is configured to execute the above-mentioned gateway execution when the computer program is executed.
  • an embodiment of the present application provides a cloud platform, including a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the above cloud when running the computer program The steps of the Bluetooth device access authentication method performed by the platform.
  • an embodiment of the present application provides a device authentication platform, including a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the computer program when running the computer program.
  • the steps of the Bluetooth device access authentication method performed by the above device authentication platform.
  • an embodiment of the present application provides a Bluetooth device, including a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the above-mentioned computer program when running the computer program.
  • the steps of the Bluetooth device access authentication method performed by the Bluetooth device.
  • an embodiment of the present application provides a chip, including: a processor for invoking and running a computer program from a memory, so that a device installed with the chip executes the above-mentioned Bluetooth device access authentication method.
  • an embodiment of the present application provides a storage medium storing an executable program, and when the executable program is executed by a processor, the above-mentioned Bluetooth device access authentication method is implemented.
  • an embodiment of the present application provides a computer program product, including computer program instructions, the computer program instructions causing a computer to execute the above-mentioned Bluetooth device access authentication method.
  • an embodiment of the present application provides a computer program, the computer program enables a computer to execute the above-mentioned Bluetooth device access authentication method.
  • the Bluetooth device access authentication method, electronic device, and storage medium provided by the embodiments of the present application include: a gateway determines a verification credential of a Bluetooth device; the gateway sends the verification credential of the Bluetooth device to a cloud platform, and the Bluetooth device The verification credential is used by the cloud platform to determine the validity of the Bluetooth device.
  • the gateway performs network configuration of Bluetooth devices, decouples the functions of network configuration and access authentication of Bluetooth devices from the cloud platform, and improves the versatility of access authentication for Bluetooth devices.
  • FIG. 1 is a schematic diagram of the processing flow of the Bluetooth device access authentication in a cross-platform manner of the application
  • FIG. 2 is a schematic diagram of an optional processing flow of the Bluetooth device access authentication method applied to the gateway provided by the embodiment of the present application;
  • FIG. 3 is a schematic diagram of an optional processing flow of a Bluetooth device access authentication method applied to a cloud platform provided by an embodiment of the present application;
  • FIG. 4 is a schematic diagram of an optional processing flow of the Bluetooth device access authentication method applied to the device authentication platform provided by the embodiment of the present application;
  • FIG. 5 is a schematic diagram of an optional processing flow of a Bluetooth device access authentication method applied to a Bluetooth device provided by an embodiment of the present application;
  • FIG. 6 is a schematic diagram of a first optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application.
  • FIG. 7 is a schematic diagram of a second optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application.
  • FIG. 8 is a schematic diagram of a third optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application.
  • FIG. 9 is a schematic diagram of a fourth optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application.
  • FIG. 10 is a schematic diagram of a fifth optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application.
  • FIG. 11 is a schematic diagram of a sixth optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application.
  • FIG. 12 is a schematic structural diagram of an optional composition of a gateway provided by an embodiment of the present application.
  • FIG. 13 is a schematic diagram of an optional composition structure of a cloud platform provided by an embodiment of the present application.
  • FIG. 14 is a schematic structural diagram of an optional composition of a device authentication platform provided by an embodiment of the present application.
  • 15 is a schematic diagram of an optional composition structure of a Bluetooth device provided by an embodiment of the application.
  • FIG. 16 is a schematic structural diagram of a hardware composition of an electronic device provided by an embodiment of the present application.
  • Bluetooth Mesh (Wireless Mesh Network): A mesh device network based on Bluetooth low energy technology, which can realize many-to-many Bluetooth device communication.
  • Gateway Bluetooth Mesh network configuration device, responsible for configuring devices connected to the Bluetooth Mesh network.
  • the Bluetooth Mesh device to be deployed on the network needs to join the Bluetooth Mesh network through the Bluetooth Mesh network configuration process to become a Bluetooth Mesh device in the Bluetooth Mesh network.
  • Session key used for encryption and decryption of network configuration data in the Bluetooth Mesh network configuration process.
  • the access authentication of the Bluetooth device needs to be performed in a cross-platform (that is, two cloud platforms are required), and the access authentication of the Bluetooth device needs to be processed in a cross-platform manner.
  • the process is shown in Figure 1.
  • Step 1 The Bluetooth device broadcasts the Bluetooth Mesh unconfigured network broadcast packet according to the specification.
  • the Bluetooth device is a Bluetooth Mesh device developed by E company based on the B platform, and the Bluetooth Mesh unconfigured network broadcast package includes the platform identifier (CID) of the B platform.
  • CID platform identifier
  • Step 2 After the gateway accessing the A platform obtains the broadcast information of the unconfigured network broadcast, upload the information to the A platform, and query the type of the device.
  • Step 3 After receiving the device information reported by the gateway, platform A determines that the device is not a device developed based on platform A (requires authorization from other platforms) through CID, and first obtains platform B information corresponding to CID through the interconnection server (including B platform Auth Server and other information), and then obtain the device type through the B platform cloud.
  • platform A determines that the device is not a device developed based on platform A (requires authorization from other platforms) through CID, and first obtains platform B information corresponding to CID through the interconnection server (including B platform Auth Server and other information), and then obtain the device type through the B platform cloud.
  • Step 4 After the gateway and the device of company E complete the invitation, the gateway and the device exchange the Public Key, and the platform B calculates (provisioner confirmation) according to the static OOB information and sends it to the gateway.
  • Step 5 The gateway sends the provisioner confirmation to the device, the device calculates the device confirmation of the device according to the static OOB information and sends it to the gateway, the gateway sends the provisioner random to the device, and the device returns the device random of the device after passing the provisioner confirmation verification.
  • Step 6 The gateway reports the device confirmation and device random of the device to platform A, and platform A sends the device confirmation and device random to platform B for confirmation value authentication, and then returns the authentication result.
  • Step 7 If the authentication result is passed, the gateway and the Bluetooth Mesh device complete the network access configuration, and the Bluetooth Mesh device joins the Bluetooth Mesh network.
  • the cloud platform needs to perform Bluetooth Mesh device authentication in the Bluetooth Mesh distribution network communication process, that is, the cloud platform not only needs to support the functions of Bluetooth Mesh device network distribution such as calculating confirmation values, but also needs to provide Bluetooth device access authentication functions;
  • This Bluetooth device access authentication method is not universal. For example, it is not suitable for access authentication of non-Bluetooth Mesh devices and access authentication of Bluetooth devices belonging to the same manufacturer as the gateway.
  • GSM global system of mobile communication
  • CDMA code division multiple access
  • WCDMA wideband code division multiple access
  • GPRS general packet radio service
  • long term evolution long term evolution
  • LTE long term evolution
  • LTE frequency division duplex frequency division duplex
  • FDD frequency division duplex
  • TDD Time division duplex
  • LTE-A advanced long term evolution
  • NR new radio
  • evolution systems of NR systems LTE on unlicensed bands (LTE-based access to unlicensed spectrum, LTE-U) system, NR (NR-based access to unlicensed spectrum, NR-U) system on unlicensed frequency bands, universal mobile telecommunication system (UMTS), global Worldwide interoperability for microwave access (WiMAX) communication systems, wireless local area networks (WLAN), wireless fidelity (WiFi), next-generation communication systems or other communication systems, etc.
  • GSM global system of mobile communication
  • CDMA code division multiple access
  • WCDMA wideband code division multiple access
  • GPRS general packet radio service
  • LTE long term evolution
  • the network equipment involved in the embodiments of this application may be a common base station (such as a NodeB or eNB or gNB), a new radio controller (NR controller), a centralized network element (centralized unit), a new radio base station, Remote radio module, micro base station, relay, distributed unit (distributed unit), reception point (transmission reception point, TRP), transmission point (transmission point, TP) or any other equipment.
  • a common base station such as a NodeB or eNB or gNB
  • NR controller new radio controller
  • a centralized network element centralized unit
  • a new radio base station Remote radio module
  • micro base station relay, distributed unit (distributed unit)
  • reception point transmission reception point
  • TRP transmission point
  • TP transmission point
  • the terminal device may be any terminal, for example, the terminal device may be user equipment of machine type communication. That is to say, the terminal device can also be called user equipment UE, mobile station (mobile station, MS), mobile terminal (mobile terminal), terminal (terminal), etc. network, RAN) communicates with one or more core networks, for example, the terminal device can be a mobile phone (or "cellular" phone), a computer with a mobile terminal, etc., for example, the terminal device can also be a portable, pocket-sized , handheld, computer built-in or vehicle mounted mobile devices that exchange language and/or data with the radio access network.
  • the terminal device may be any terminal, for example, the terminal device may be user equipment of machine type communication. That is to say, the terminal device can also be called user equipment UE, mobile station (mobile station, MS), mobile terminal (mobile terminal), terminal (terminal), etc. network, RAN) communicates with one or more core networks, for example, the terminal device can be a mobile phone (or "cellular" phone), a computer with a mobile terminal, etc
  • communication between the network device and the terminal device and between the terminal device and the terminal device can be performed through licensed spectrum (licensed spectrum), or through unlicensed spectrum (unlicensed spectrum), or both through licensed spectrum and unlicensed spectrum for communications.
  • Communication between network equipment and terminal equipment and between terminal equipment and terminal equipment can be carried out through the spectrum below 7 gigahertz (GHz), or through the frequency spectrum above 7 GHz, and can also use the frequency spectrum below 7 GHz and the frequency spectrum at the same time.
  • the spectrum above 7GHz is used for communication.
  • the embodiments of the present application do not limit the spectrum resources used between the network device and the terminal device.
  • D2D device to device
  • M2M machine to machine
  • MTC machine type communication
  • V2V vehicle to vehicle
  • An optional processing flow of the Bluetooth device access authentication method applied to the gateway provided by the embodiment of the present application, as shown in FIG. 2 may include the following steps:
  • Step S201 the gateway determines the verification certificate of the Bluetooth device.
  • the Bluetooth Mesh device actively sends the verification credential of the Bluetooth Mesh device to the gateway.
  • the gateway may send a first request message to the Bluetooth Mesh device, where the first request message is used to request to obtain the verification credential of the Bluetooth Mesh device; after receiving the first request message, the Bluetooth Mesh device, Send the verification credentials of the Bluetooth Mesh device to the gateway.
  • Step S202 the gateway sends the verification credential of the Bluetooth device to the cloud platform, where the verification credential of the Bluetooth device is used by the cloud platform to determine the validity of the Bluetooth device.
  • the gateway requests the cloud platform accessed by the gateway to verify the validity of the Bluetooth Mesh device by sending the verification credential of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • the cloud platform connected by the gateway determines that the Bluetooth Mesh device is not a device developed based on the cloud platform according to the CID in the unconfigured broadcast packet broadcast by the Bluetooth device, and the cloud platform connected by the gateway obtains the corresponding CID according to the CID in the unconfigured broadcast packet.
  • Device authentication platform; the cloud platform connected to the gateway sends the verification certificate of the Bluetooth Mesh device to the device authentication platform, and requests the device authentication platform to verify the legitimacy of the Bluetooth Mesh device.
  • the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is a device developed based on the cloud platform according to the CID in the unconfigured network broadcast packet, the cloud platform connected by the gateway verifies the validity of the Bluetooth Mesh device.
  • the method may further include:
  • Step S203 the gateway receives a device verification result sent by the cloud platform, where the device verification result is used to indicate the validity of the Bluetooth device.
  • the method may further include:
  • Step S204 the gateway determines the verification credential of the gateway and/or the cloud platform.
  • the gateway pre-stores the verification credential of the gateway and/or the cloud platform; for example, the verification credential of the gateway and/or the cloud platform is pre-stored when the gateway leaves the factory or when the gateway is powered on and activated.
  • the gateway sends a second request message to the cloud platform, where the second request message is used to request to obtain the verification credential of the gateway and/or the cloud platform; the gateway receives the cloud platform The sent verification credential of the gateway and/or the cloud platform.
  • Step S205 the gateway sends the verification credential of the gateway and/or the cloud platform to the Bluetooth device, and the verification credential of the gateway and/or the cloud platform is used for the Bluetooth device to verify the gateway /or the legality of the cloud platform.
  • the gateway may actively send the verification credential of the gateway and/or the cloud platform to the Bluetooth device.
  • the gateway may also receive a third request message sent by the Bluetooth device, where the third request message is used to request to obtain the verification credential of the gateway and/or the cloud platform; the gateway sends the Bluetooth device according to the third request message Verification credentials of the gateway and/or the cloud platform.
  • Step S206 the gateway receives the gateway and/or the cloud platform verification result sent by the Bluetooth device, and the gateway and/or the cloud platform verification result is used to indicate the gateway and/or the cloud platform. legitimacy.
  • the method may further include:
  • Step S208 the gateway receives the verification credential of the device authentication platform sent by the cloud platform, and the gateway sends the verification credential of the device authentication platform to the Bluetooth device.
  • Step S209 the gateway requests the cloud platform to add the Bluetooth device.
  • the gateway can also Request the cloud platform to add the Bluetooth device; specifically, the gateway sends the information of the Bluetooth device to the cloud platform, and the information of the Bluetooth device is used for the cloud platform to add the Bluetooth device.
  • the Bluetooth device if one of the verification results of the Bluetooth device, the gateway and/or the cloud platform and the device authentication platform is invalid, the Bluetooth device is deleted from the Bluetooth Mesh network or the Bluetooth Mesh network configuration is stopped.
  • the method may further include:
  • Step S200 the gateway receives a check mark sent by the Bluetooth device, where the check mark is used to indicate an object to be checked.
  • the Bluetooth device broadcasts an Unprovisioned Device Beacon to the gateway; wherein, the Universal Unique Identifier (UUID) included in the unprovisioned broadcast packet is the key for identifying the device information.
  • UUID Universal Unique Identifier
  • the format of the device UUID is shown in Table 1 below: the device UUID includes a verification flag (VerifiFlag), and the verification flag is used to indicate the object of legality authentication; for example, the verification flag is used to indicate the following At least one: Certified Bluetooth Mesh Device, Certified Gateway, Certified Cloud Platform, and Certified Device Certification Platform.
  • the device UUID may also include: one or more of CID, DID, and PID; wherein, the CID is used to represent the manufacturer/cloud platform identifier of the device, the DID is used to represent the device identifier, and the PID is used to represent the device type identifier.
  • the check mark is used to indicate the authentication of the Bluetooth Mesh device.
  • An optional processing flow of the Bluetooth device access authentication method applied to the cloud platform provided by the embodiment of the present application, as shown in FIG. 3 may include the following steps:
  • Step S301 the cloud platform receives the verification certificate of the Bluetooth device sent by the gateway.
  • Step S302 the cloud platform determines the validity of the Bluetooth device based on the verification certificate of the Bluetooth device.
  • the cloud platform sends a fifth request message carrying the verification credential of the Bluetooth device to the device authentication platform; the fifth request The message is used to request the device authentication platform to verify the validity of the Bluetooth device; the cloud platform receives the device verification result sent by the device authentication platform, and the device verification result is used to indicate the Bluetooth device's validity. legality.
  • the cloud platform verifies the validity of the Bluetooth device.
  • the method may further include:
  • Step S303 the cloud platform receives a second request message sent by the gateway, where the second request message is used to request to obtain the verification credential of the gateway and/or the cloud platform; the cloud platform confirms the gateway and/or The verification certificate of the cloud platform.
  • the cloud platform determines a device authentication platform corresponding to the Bluetooth device; the cloud platform sends a sixth request message to the device authentication platform ; the sixth request message carries the identifier of the gateway and/or the cloud platform, and is used to request to obtain the verification credential of the gateway and/or the cloud platform.
  • the cloud platform receives the verification credential of the gateway and/or the cloud platform sent by the device authentication platform, and sends the verification credential of the gateway and/or the cloud platform to the gateway.
  • the method may further include:
  • Step S304 the cloud platform receives a fourth request message sent by the gateway, where the fourth request message is used to request to obtain a verification credential of the device authentication platform.
  • Step S305 the cloud platform determines the verification credential of the device authentication platform.
  • the cloud platform sends a seventh request message to the device authentication platform, where the seventh request message is used to request to obtain the verification credential of the device authentication platform; the cloud platform receives the device The verification credential of the device authentication platform sent by the authentication platform, and the verification credential of the device authentication platform is sent to the gateway.
  • the method may further include:
  • Step S306 the cloud platform adds the Bluetooth device.
  • the gateway requests the cloud platform to add the Bluetooth device; specifically, the gateway sends the cloud platform the Information of the Bluetooth device, the information of the Bluetooth device is used for the cloud platform to add the Bluetooth device; the gateway sends configuration information to the Bluetooth device, and the configuration information is used to perform the network access configuration of the Bluetooth device.
  • the Bluetooth device if one of the verification results of the Bluetooth device, the gateway and/or the cloud platform and the device authentication platform is invalid, the Bluetooth device is deleted from the Bluetooth Mesh network or the Bluetooth Mesh network configuration is stopped.
  • An optional processing flow of the Bluetooth device access authentication method applied to the device authentication platform provided by the embodiment of the present application, as shown in FIG. 4 may include the following steps:
  • Step S401 the device authentication platform receives a fifth request message sent by the cloud platform; the fifth request message includes a verification credential of the Bluetooth device.
  • Step S402 the device authentication platform verifies the validity of the Bluetooth device according to the verification certificate of the Bluetooth device.
  • the method may further include:
  • Step S403 the device authentication platform receives the sixth request message sent by the cloud platform; the sixth request message carries the identifier of the gateway and/or the cloud platform, and is used to request to obtain the gateway and/or the The verification certificate of the cloud platform.
  • Step S404 the device authentication platform generates a verification credential of the gateway and/or the cloud platform according to the identifier of the gateway and/or the cloud platform; the device authentication platform sends the gateway to the cloud platform and/or the verification credential of the cloud platform.
  • An optional processing flow of the Bluetooth device access authentication method applied to a Bluetooth device provided by the embodiment of the present application, as shown in FIG. 5 may include the following steps:
  • Step S501 the Bluetooth device sends a verification certificate of the Bluetooth device to the gateway, and the verification certificate of the Bluetooth device is used to determine the validity of the Bluetooth device.
  • the Bluetooth device may actively send the verification credential of the Bluetooth device to the gateway. It can also be that the bluetooth device receives the first request message sent by the gateway, and the first request message is used to request to obtain the verification credential of the bluetooth device; the bluetooth device sends the verification certificate of the bluetooth device to the gateway according to the first request message certificate.
  • the method may further include:
  • Step S502 the Bluetooth device receives the verification credential of the gateway and/or the cloud platform, and the verification credential of the gateway and/or the cloud platform is used by the Bluetooth device to verify the gateway/or The legitimacy of the cloud platform.
  • the Bluetooth device may send a third request message to the gateway, where the third request message is used to request to obtain the verification credential of the gateway and/or the cloud platform. After the gateway obtains the verification credential of the gateway and/or the cloud platform, the gateway sends the verification credential of the gateway and/or the cloud platform to the Bluetooth device.
  • Step S503 the Bluetooth device verifies the validity of the gateway and/or the cloud platform according to the verification credentials of the gateway and/or the cloud platform.
  • Step S504 the bluetooth device sends the gateway and/or the cloud platform verification result sent by the bluetooth device to the gateway, and the gateway and/or the cloud platform verification result is used to indicate the gateway and/or the cloud platform verification result. or the legality of the cloud platform.
  • the method may further include:
  • Step S505 the Bluetooth device receives the verification certificate of the device authentication platform sent by the gateway.
  • Step S506 the Bluetooth device verifies the legitimacy of the device authentication platform based on the verification certificate of the device authentication platform.
  • the Bluetooth device receives the configuration information sent by the gateway, and the configuration information is used to perform network access configuration of the Bluetooth device.
  • the gateway performs the network configuration of the Bluetooth device
  • the cloud platform verifies the legality of the Bluetooth device (that is, the access authentication function), and decouples the network configuration and access authentication functions of the Bluetooth device from the cloud platform.
  • the gateway improves the versatility of Bluetooth device access authentication.
  • the first optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application, as shown in FIG. 6 includes the following step:
  • Step S601 the Bluetooth Mesh device sends an unconfigured network broadcast packet to the gateway.
  • the Bluetooth Mesh device if the Bluetooth Mesh device is in an unconfigured state, the Bluetooth Mesh device broadcasts an unconfigured broadcast packet, wherein the UUID included in the unconfigured broadcast packet is key information for identifying the device.
  • the format of the device UUID is shown in Table 1 above.
  • Steps S602-S603, the Bluetooth Mesh device and the gateway start the Bluetooth Mesh network configuration process.
  • starting the Bluetooth Mesh network configuration process may include: calculating a security key, where the security key is used to encrypt/decrypt the verification credential between the Bluetooth Mesh device and the gateway; wherein the security key may include One or more of session key, device key, network key, and application key.
  • the gateway verifies the validity of the Bluetooth Mesh device; if the gateway verifies that the Bluetooth Mesh device is valid, the Bluetooth Mesh device and the gateway continue to perform the Bluetooth Mesh device network access Configuration; if the gateway verifies that the Bluetooth Mesh device is invalid, it will terminate the Bluetooth Mesh network configuration.
  • Step S604 the gateway obtains the verification certificate of the Bluetooth Mesh device.
  • the verification mark in the unconfigured network broadcast packet indicates to verify the Bluetooth Mesh device, and the Bluetooth Mesh device actively sends the verification certificate of the Bluetooth Mesh device to the gateway.
  • the gateway may send a first request message to the Bluetooth Mesh device, where the first request message is used to request to obtain the verification credential of the Bluetooth Mesh device; after receiving the first request message, the Bluetooth Mesh device, Send the verification credentials of the Bluetooth Mesh device to the gateway.
  • Step S605 the gateway sends the verification certificate of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • the gateway requests the cloud platform accessed by the gateway to verify the validity of the Bluetooth Mesh device by sending the verification credential of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • Step S606 the cloud platform accessed by the gateway requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
  • the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is not a device developed based on the cloud platform according to the CID in the unconfigured broadcast packet
  • the cloud platform accessed by the gateway determines according to the CID in the unconfigured broadcast packet.
  • the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is a device developed based on the cloud platform according to the CID in the unconfigured network broadcast packet, the cloud platform accessed by the gateway verifies the validity of the Bluetooth Mesh device .
  • Step S607 the device authentication platform verifies the validity of the Bluetooth Mesh device.
  • the device authentication platform verifies whether the security certificate is legal; if the security certificate is verified to be legal, it verifies that the Bluetooth Mesh device is legal; If the certificate is invalid, the authentication of the Bluetooth Mesh device is invalid.
  • the device authentication platform can use asymmetric encryption or symmetric encryption to verify the legitimacy of the Bluetooth Mesh device.
  • the Bluetooth Mesh device pre-stores the public key of the device authentication platform, encrypts the verification certificate of the Bluetooth Mesh device with the public key of the device authentication platform, and uses its own private key after receiving the verification certificate. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
  • the device authentication platform and the Bluetooth Mesh device pre-share the same key (ie, the pre-shared key), and the Bluetooth Mesh device uses the pre-shared key to encrypt the verification credentials of the Bluetooth Mesh device. After verifying the certificate, decrypt it with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
  • Step S608 the device authentication platform feeds back the verification result of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • Step S609 the cloud platform connected to the gateway feeds back the verification result of the Bluetooth Mesh device to the gateway.
  • Step S610 if the verification result of the Bluetooth Mesh device is valid, the gateway executes the network access configuration of the Bluetooth Mesh device.
  • the gateway starts the distribution of Bluetooth Mesh network access configuration data, and sends the network address and security key (eg, network key and/or device key) to the Bluetooth Mesh device. Wait for the configuration information to complete the network access configuration process of the Bluetooth Mesh device.
  • the network address and security key eg, network key and/or device key
  • Step S611 the gateway requests the cloud platform accessed by the gateway to add a Bluetooth Mesh device.
  • the gateway sends device information including the UUID of the Bluetooth Mesh device to the cloud platform connected to the gateway, and the cloud platform connected to the gateway adds the device information of the Bluetooth Mesh device.
  • steps S610 to S611 are performed. If the verification result of the Bluetooth Mesh device is invalid, the gateway terminates the network access configuration process of the Bluetooth Mesh device.
  • the first step of the Bluetooth device access authentication method includes the following steps:
  • Step S801 the Bluetooth Mesh device sends an unconfigured network broadcast packet to the gateway.
  • the description for the unconfigured network broadcast packet is the same as that of step S601 in the foregoing embodiment, and details are not repeated here.
  • Steps S802-S803, the Bluetooth Mesh device and the gateway start the Bluetooth Mesh network configuration process.
  • the processing flow of the Bluetooth Mesh device and the gateway to start the Bluetooth Mesh network configuration process is the same as steps S602-S603 in the above-mentioned embodiment, and details are not repeated here.
  • Step S804 the gateway sends the verification certificate of the gateway/platform to the Bluetooth Mesh device.
  • the gateway may actively send the gateway/platform verification credential to the Bluetooth Mesh device.
  • the Bluetooth Mesh device may send a third request message to the gateway according to the check mark, where the third request message is used to request to obtain the calibration of the gateway and/or the cloud platform. Verification certificate.
  • the gateway obtains the verification credential of the gateway and/or the cloud platform.
  • the specific implementation process for the gateway to obtain the verification credential of the gateway and/or the cloud platform may include:
  • Step S804-1 the gateway sends a second request message to the cloud platform, where the second request message is used to request to obtain the verification credential of the gateway and/or the cloud platform.
  • the second request message carries the identifier of the gateway/cloud platform, and is used to request the cloud platform to obtain the verification credential of the gateway and/or the cloud platform.
  • Step S804-2 the cloud platform obtains the device authentication platform information corresponding to the gateway and/or the cloud platform.
  • the cloud platform determines by CID that the Bluetooth Mesh device is not a device developed based on the cloud platform, and requires a device authentication platform for authentication, then the cloud platform obtains the device authentication platform information corresponding to the gateway and/or the cloud platform through the CID.
  • Step S804-3 the cloud platform sends a sixth request message to the device authentication platform; the sixth request message is used to request to obtain the verification credential of the gateway and/or the cloud platform.
  • the sixth request message carries the identifier of the gateway and/or the cloud platform
  • the device authentication platform obtains the gateway and/or the cloud platform according to the identifier of the gateway and/or the cloud platform The verification certificate of the cloud platform.
  • Step S804-4 the device authentication platform sends the verification credential of the gateway and/or the cloud platform to the cloud platform.
  • the device authentication platform generates a general verification credential according to the identifier of the gateway and/or the cloud platform (that is, the verification credential does not distinguish the gateway or the specific cloud platform accessed by the gateway, and the verification credential does not distinguish the gateway or the specific cloud platform accessed by the gateway, and the verification credential is used for all legal gateways or gateways.
  • the cloud platform is universal), or the verification certificate dedicated to the gateway/cloud platform (that is, the verification certificate distinguishes the gateway or the specific cloud platform accessed by the gateway, and different legal gateways or cloud platforms accessed by the gateway use different schools. certificate).
  • the verification credential of the gateway/cloud platform generated by the device authentication platform is a security certificate
  • the security certificate includes the unique identification information of the gateway and/or the cloud platform, which can only be verified by the gateway/cloud platform using the security certificate Passed, the cloud platform accessed by other gateways/gateways cannot pass the verification even if the security certificate is used, which improves the security of access authentication.
  • the cloud platform may store the verification credential of the gateway and/or the platform locally, and the gateway and/or the platform needs to be verified later
  • the cloud platform directly obtains the verification credentials of the gateway and/or the platform from the local, it is no longer necessary to obtain the verification credentials of the gateway and/or the platform from the device authentication platform, which simplifies the verification process of the gateway and/or the platform and reduces the verification time delay.
  • Step S804-5 the cloud platform sends the gateway and/or the verification credential of the cloud platform to the gateway; the gateway sends the verification credential of the gateway and/or the cloud platform to the Bluetooth Mesh device.
  • steps S804-1 to S804-5 are specific implementation processes for the gateway to obtain the verification credentials of the gateway and/or the cloud platform from the network side (cloud platform and device authentication platform).
  • the specific implementation process for the gateway to obtain the verification credential of the gateway and/or the cloud platform may also be that the gateway pre-stores the verification credential of the gateway and/or the cloud platform; and/or verification credentials of the cloud platform.
  • Step S805 the Bluetooth Mesh device verifies the validity of the gateway and/or the cloud platform according to the received verification credentials of the gateway and/or the cloud platform, and feeds back the verification result of the gateway and/or the cloud platform to the gateway.
  • the Bluetooth device access authentication method when the verification result of the Bluetooth Mesh device on the gateway and/or the cloud platform is that the gateway and/or the cloud platform are legal, the Bluetooth device access authentication method provided in this embodiment of the present application performs the following steps S806- S812:
  • Step S806 the gateway obtains the verification certificate of the Bluetooth Mesh device.
  • the verification mark in the unconfigured network broadcast packet indicates to verify the Bluetooth Mesh device, and the Bluetooth Mesh device actively sends the verification certificate of the Bluetooth Mesh device to the gateway.
  • the gateway may send a first request message to the Bluetooth Mesh device, where the first request message is used to request to obtain the verification credential of the Bluetooth Mesh device; after receiving the first request message, the Bluetooth Mesh device, Send the verification credentials of the Bluetooth Mesh device to the gateway.
  • Step S807 the gateway sends the verification certificate of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • the gateway requests the cloud platform accessed by the gateway to verify the validity of the Bluetooth Mesh device by sending the verification credential of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • Step S808 the cloud platform accessed by the gateway requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
  • the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is not a device developed based on the cloud platform according to the CID in the unconfigured broadcast packet
  • the cloud platform accessed by the gateway determines according to the CID in the unconfigured broadcast packet.
  • the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is a device developed based on the cloud platform according to the CID in the unconfigured network broadcast packet, the cloud platform accessed by the gateway verifies the validity of the Bluetooth Mesh device .
  • Step S809 the device authentication platform verifies the validity of the Bluetooth Mesh device.
  • the device authentication platform verifies whether the security certificate is legal; if the security certificate is verified to be legal, it verifies that the Bluetooth Mesh device is legal; If the certificate is invalid, the authentication of the Bluetooth Mesh device is invalid.
  • the device authentication platform can use asymmetric encryption or symmetric encryption to verify the legitimacy of the Bluetooth Mesh device.
  • the Bluetooth Mesh device pre-stores the public key of the device authentication platform, encrypts the verification certificate of the Bluetooth Mesh device with the public key of the device authentication platform, and uses its own private key after receiving the verification certificate. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
  • the device authentication platform and the Bluetooth Mesh device pre-share the same key (ie, the pre-shared key), and the Bluetooth Mesh device uses the pre-shared key to encrypt the verification credentials of the Bluetooth Mesh device. After verifying the certificate, decrypt it with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
  • Step S810 the device authentication platform feeds back the verification result of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • Step S811 the cloud platform connected to the gateway feeds back the verification result of the Bluetooth Mesh device to the gateway.
  • Step S812 if the verification result of the Bluetooth Mesh device is valid, the gateway executes the network access configuration of the Bluetooth Mesh device.
  • the gateway starts the distribution of Bluetooth Mesh network access configuration data, and sends the network address and security key (eg, network key and/or device key) to the Bluetooth Mesh device. Wait for the configuration information to complete the network access configuration process of the Bluetooth Mesh device.
  • the network address and security key eg, network key and/or device key
  • step S812 is executed. If the verification result of the Bluetooth Mesh device is invalid, the gateway terminates the network access configuration process of the Bluetooth Mesh device.
  • Step S813 the gateway requests the cloud platform accessed by the gateway to add a Bluetooth Mesh device.
  • the gateway sends device information including the UUID of the Bluetooth Mesh device to the cloud platform connected to the gateway, and the cloud platform connected to the gateway adds the device information of the Bluetooth Mesh device.
  • the Bluetooth Mesh device verifies the validity of the gateway and/or the cloud platform.
  • the gateway will verify the validity of the gateway and/or the cloud platform. Verify the validity of the Bluetooth Mesh device; if the verification result indicates that the Bluetooth Mesh device is legal, perform the network access configuration of the Bluetooth Mesh device.
  • the processing flow of the Bluetooth device access authentication method shown in Figure 7 adds the Bluetooth Mesh device verification method before the gateway verifies the validity of the Bluetooth Mesh device. Steps to verify the legitimacy of the gateway and/or cloud platform; further improve the security of Bluetooth Mesh network access authentication.
  • the Bluetooth Mesh device verifies the validity of the gateway and/or the cloud platform first, and when the verification result indicates that the gateway and/or the cloud platform is legal, then The validity of the Bluetooth Mesh device is verified by the gateway.
  • the gateway can also verify the validity of the Bluetooth Mesh device first, and when the verification result indicates that the Bluetooth Mesh device is legal, then the Bluetooth Mesh device can verify the validity of the gateway and/or the cloud platform; that is, After steps S801 to S803 are performed, steps S806 to S811 are performed first, and then steps S804 to S805 are performed.
  • the third type of the Bluetooth device access authentication method includes the following steps:
  • Step S901 the Bluetooth Mesh device sends an unconfigured network broadcast packet to the gateway.
  • Steps S902-S903, the Bluetooth Mesh device and the gateway start the Bluetooth Mesh network configuration process.
  • Step S904 the gateway obtains the verification certificate of the Bluetooth Mesh device.
  • Step S905 the gateway sends the verification certificate of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • Step S906 the cloud platform accessed by the gateway requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
  • Step S907 the device authentication platform verifies the validity of the Bluetooth Mesh device.
  • Step S908 the device authentication platform feeds back the verification result of the Bluetooth Mesh device to the cloud platform connected to the gateway.
  • Step S909 the cloud platform connected to the gateway feeds back the verification result of the Bluetooth Mesh device to the gateway.
  • Step S910 the gateway sends a fourth request message to the cloud platform according to the check mark of the Bluetooth device.
  • the fourth request message is used to request to obtain a verification credential of a device authentication platform
  • the verification credential of the device authentication platform is used by the Bluetooth Mesh device to verify the legitimacy of the device authentication platform .
  • the fourth request message may further include a CID, which is used by the cloud platform to determine the device authentication platform corresponding to the Bluetooth Mesh device according to the DCI.
  • Step S911 the cloud platform sends a seventh request message to the device authentication platform.
  • the seventh request message is used to request to obtain the verification credential of the device authentication platform.
  • Step S912 the device authentication platform sends the verification certificate of the device authentication platform to the cloud platform.
  • Step S913 the cloud platform sends the verification certificate of the device authentication platform to the gateway.
  • Step S914 the gateway sends the verification certificate of the device authentication platform to the Bluetooth Mesh device.
  • Step S915 the Bluetooth Mesh device verifies the validity of the device authentication platform.
  • the Bluetooth Mesh device can use asymmetric encryption or symmetric encryption to verify the legitimacy of the device authentication platform.
  • the device authentication platform pre-stores the public key of the Bluetooth Mesh device. After the device authentication platform generates the verification certificate of the device authentication platform, it encrypts the verification certificate with the public key of the Bluetooth Mesh device, and the Bluetooth Mesh device receives the verification certificate. After verifying the certificate, decrypt it with your own private key. If it can be decrypted normally, it proves to be a legitimate device authentication platform. If it cannot be decrypted normally, it proves to be an illegal device authentication platform.
  • the device authentication platform and the Bluetooth Mesh device pre-share the same key (that is, the pre-shared key). After the device authentication platform generates the verification certificate of the device authentication platform, it encrypts the verification certificate with the pre-shared key. The verification certificate received by the Bluetooth Mesh device is decrypted with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate device authentication platform. If it cannot be decrypted normally, it proves to be an illegal device authentication platform.
  • Step S916 if the verification result of the Bluetooth Mesh device is legal, and the verification result of the device authentication platform is legal, the gateway performs network access configuration of the Bluetooth Mesh device.
  • the gateway starts the distribution of the Bluetooth Mesh network access configuration data, and sends the network address and security key ( (such as network key and/or device key) and other configuration information to complete the network access configuration process of the Bluetooth Mesh device.
  • the network address and security key (such as network key and/or device key) and other configuration information to complete the network access configuration process of the Bluetooth Mesh device.
  • Step S917 the gateway requests the cloud platform accessed by the gateway to add a Bluetooth Mesh device.
  • the gateway sends device information including the UUID of the Bluetooth Mesh device to the cloud platform connected to the gateway, and the cloud platform connected to the gateway adds the device information of the Bluetooth Mesh device.
  • the verification result of the Bluetooth Mesh device is taken as an example, and steps S916 to S917 are executed. If at least one of the verification result of the Bluetooth Mesh device and the verification result of the device authentication platform is invalid, the gateway terminates the network access configuration process of the Bluetooth Mesh device.
  • the gateway verifies the validity of the Bluetooth Mesh device first, and when the verification result indicates that the Bluetooth Mesh device is legal, the Bluetooth Mesh device verifies the device authentication the legitimacy of the platform.
  • the Bluetooth Mesh device can also verify the validity of the device authentication platform first, and then the gateway can verify the validity of the Bluetooth Mesh device when the verification result indicates that the device authentication platform is legal; that is, after the execution is completed. After steps S901 to S903, steps S910 to S915 are performed first, and then steps S904-S909 are performed.
  • the validity of the Bluetooth Mesh device is verified by the gateway, and the validity of the gateway/cloud platform is verified by the Bluetooth Mesh device.
  • the Bluetooth device access authentication method provided by the embodiment of the present application is described in detail.
  • the validity of the Bluetooth Mesh device is verified by the gateway, and the validity of the device authentication platform is verified by the Bluetooth Mesh device.
  • the Bluetooth device access authentication method provided by the embodiment of the present application is described in detail.
  • the gateway can verify the validity of the Bluetooth Mesh device
  • the Bluetooth Mesh device can verify the validity of the gateway/cloud platform
  • the Bluetooth Mesh device can verify the legality of the device authentication platform.
  • Bluetooth Mesh device There is no sequence of execution between the validity of the Bluetooth Mesh device, the validity of the gateway/cloud platform verified by the Bluetooth Mesh device, and the validity of the device authentication platform verified by the Bluetooth Mesh device.
  • the Bluetooth device access authentication methods shown in Figures 6 to 8 above all perform Bluetooth Mesh device verification, or gateway/cloud platform verification, or device authentication platform verification before completing the Bluetooth Mesh network configuration.
  • the embodiments of the present application may further perform Bluetooth Mesh device verification, or gateway/cloud platform verification, or device authentication platform verification after completing the Bluetooth Mesh network configuration.
  • the fourth detailed processing flow of the Bluetooth device access authentication method includes:
  • Step S1001 the Bluetooth Mesh device sends an unconfigured network broadcast packet to the gateway.
  • the description of the Bluetooth Mesh device sending an unconfigured network broadcast packet to the gateway is the same as the above step S601, and will not be repeated here.
  • Steps S1002-S1003 the Bluetooth Mesh device and the gateway start the Bluetooth Mesh network configuration process, and complete the Bluetooth Mesh network configuration process.
  • starting the Bluetooth Mesh network configuration process may include: calculating a security key, and the security key is used to encrypt/decrypt the verification credential between the Bluetooth Mesh device and the gateway; wherein, the security key may include a session key, One or more of Device Key, Network Key, and App Key.
  • the process of completing the Bluetooth Mesh network configuration includes: the gateway starts the distribution of configuration data for Bluetooth Mesh network access, sends configuration information such as network addresses and security keys (such as network keys and/or device keys) to the Bluetooth Mesh devices, and completes the network access of the Bluetooth Mesh devices. configuration process.
  • Step S1004 the gateway obtains the verification certificate of the Bluetooth Mesh device.
  • the verification mark in the unconfigured network broadcast packet indicates to verify the Bluetooth Mesh device, and the Bluetooth Mesh device actively sends the verification certificate of the Bluetooth Mesh device to the gateway.
  • the gateway may send a first request message to the Bluetooth Mesh device, where the first request message is used to request to obtain the verification credential of the Bluetooth Mesh device; after receiving the first request message, the Bluetooth Mesh device, Send the verification credentials of the Bluetooth Mesh device to the gateway.
  • Step S1005 the gateway sends the verification certificate of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • the gateway requests the cloud platform accessed by the gateway to verify the validity of the Bluetooth Mesh device by sending the verification credential of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • Step S1006 the cloud platform accessed by the gateway requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
  • the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is not a device developed based on the cloud platform according to the CID in the unconfigured broadcast packet
  • the cloud platform accessed by the gateway determines according to the CID in the unconfigured broadcast packet.
  • the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is a device developed based on the cloud platform according to the CID in the unconfigured network broadcast packet, the cloud platform accessed by the gateway verifies the validity of the Bluetooth Mesh device .
  • Step S1007 the device authentication platform verifies the validity of the Bluetooth Mesh device.
  • the device authentication platform verifies whether the security certificate is legal; if the security certificate is verified to be legal, it verifies that the Bluetooth Mesh device is legal; If the certificate is invalid, the authentication of the Bluetooth Mesh device is invalid.
  • the device authentication platform can use asymmetric encryption or symmetric encryption to verify the legitimacy of the Bluetooth Mesh device.
  • the Bluetooth Mesh device pre-stores the public key of the device authentication platform, encrypts the verification certificate of the Bluetooth Mesh device with the public key of the device authentication platform, and uses its own private key after receiving the verification certificate. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
  • the device authentication platform and the Bluetooth Mesh device pre-share the same key (ie, the pre-shared key), and the Bluetooth Mesh device uses the pre-shared key to encrypt the verification credentials of the Bluetooth Mesh device. After verifying the certificate, decrypt it with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
  • Step S1008 the device authentication platform feeds back the verification result of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • Step S1009 the cloud platform connected by the gateway feeds back the verification result of the Bluetooth Mesh device to the gateway.
  • Step S1010 if the verification result of the Bluetooth Mesh device is valid, the gateway requests the cloud platform accessed by the gateway to add the Bluetooth Mesh device.
  • the gateway sends device information including the UUID of the Bluetooth Mesh device to the cloud platform connected to the gateway, and the cloud platform connected to the gateway adds the device information of the Bluetooth Mesh device.
  • step S1010 is executed. If the verification result of the Bluetooth Mesh device is invalid, delete the Bluetooth Mesh device from the Bluetooth Mesh network.
  • the first step of the Bluetooth device access authentication method is:
  • Step S1101 the Bluetooth Mesh device sends an unconfigured network broadcast packet to the gateway.
  • Steps S1102-S1103, the Bluetooth Mesh device and the gateway start the Bluetooth Mesh network configuration process.
  • starting the Bluetooth Mesh network configuration process may include: calculating a security key, and the security key is used to encrypt/decrypt the verification credential between the Bluetooth Mesh device and the gateway; wherein, the security key may include a session key, One or more of Device Key, Network Key, and App Key.
  • the process of completing the Bluetooth Mesh network configuration includes: the gateway starts the distribution of configuration data for Bluetooth Mesh network access, sends configuration information such as network addresses and security keys (such as network keys and/or device keys) to the Bluetooth Mesh devices, and completes the network access of the Bluetooth Mesh devices. configuration process.
  • Step S1104 the gateway sends the verification certificate of the gateway/platform to the Bluetooth Mesh device.
  • the gateway may actively send the gateway/platform verification credential to the Bluetooth Mesh device.
  • the Bluetooth Mesh device may send a third request message to the gateway according to the verification mark, where the third request message is used to request to obtain the verification credential of the gateway and/or the cloud platform.
  • the gateway obtains the verification credential of the gateway and/or the cloud platform.
  • the specific implementation process for the gateway to obtain the verification credential of the gateway and/or the cloud platform may include:
  • Step S1104-1 the gateway sends a second request message to the cloud platform, where the second request message is used to request to obtain the verification credential of the gateway and/or the cloud platform.
  • the second request message carries the identifier of the gateway/cloud platform, and is used to request the cloud platform to obtain the verification credential of the gateway and/or the cloud platform.
  • Step S1104-2 the cloud platform obtains the device authentication platform information corresponding to the gateway and/or the cloud platform.
  • the cloud platform determines by CID that the Bluetooth Mesh device is not a device developed based on the cloud platform, and requires a device authentication platform for authentication, then the cloud platform obtains the device authentication platform information corresponding to the gateway and/or the cloud platform through the CID.
  • Step S1104-3 the cloud platform requests the device authentication platform to obtain the verification credential of the gateway and/or the cloud platform.
  • the cloud platform sends a sixth request message to the device authentication platform; the sixth request message carries the identifier of the gateway and/or the cloud platform, and is used to request to obtain the gateway and/or the The verification certificate of the cloud platform.
  • Step S1104-4 the device authentication platform sends the verification credential of the gateway and/or the cloud platform to the cloud platform.
  • the device authentication platform generates a general verification credential according to the identifier of the gateway and/or the cloud platform (that is, the verification credential does not distinguish the gateway or the specific cloud platform accessed by the gateway, and the verification credential does not distinguish the gateway or the specific cloud platform accessed by the gateway, and the verification credential is used for all legal gateways or gateways.
  • the cloud platform is universal), or the verification certificate dedicated to the gateway/cloud platform (that is, the verification certificate distinguishes the gateway or the specific cloud platform accessed by the gateway, and different legal gateways or cloud platforms accessed by the gateway use different schools. certificate).
  • the verification credential of the gateway/cloud platform generated by the device authentication platform is a security certificate
  • the security certificate includes the unique identification information of the gateway and/or the cloud platform, which can only be verified by the gateway/cloud platform using the security certificate Passed, the cloud platform accessed by other gateways/gateways cannot pass the verification even if the security certificate is used, which improves the security of access authentication.
  • the cloud platform may store the verification credential of the gateway and/or the platform locally, and the gateway and/or the platform needs to be verified later
  • the cloud platform directly obtains the verification credentials of the gateway and/or the platform from the local, it is no longer necessary to obtain the verification credentials of the gateway and/or the platform from the device authentication platform, which simplifies the verification process of the gateway and/or the platform and reduces the verification time delay.
  • Step S1104-5 the cloud platform sends the gateway and/or the verification credential of the cloud platform to the gateway.
  • the above steps S1104-1 to S1104-5 are specific implementation processes for the gateway to obtain the verification credentials of the gateway and/or the cloud platform from the network side (cloud platform and device authentication platform).
  • the specific implementation process for the gateway to obtain the verification credential of the gateway and/or the cloud platform may also be that the gateway pre-stores the verification credential of the gateway and/or the cloud platform; and/or verification credentials of the cloud platform.
  • Step S1105 the Bluetooth Mesh device verifies the validity of the gateway and/or the cloud platform according to the received verification credentials of the gateway and/or the cloud platform, and feeds back the verification result of the gateway and/or the cloud platform to the gateway.
  • the Bluetooth device access authentication method when the verification result of the Bluetooth Mesh device on the gateway and/or the cloud platform is that the gateway and/or the cloud platform are legal, the Bluetooth device access authentication method provided by the embodiments of the present application performs the following steps S1106- S1112:
  • Step S1106 the gateway obtains the verification certificate of the Bluetooth Mesh device.
  • the verification mark in the unconfigured network broadcast packet indicates to verify the Bluetooth Mesh device, and the Bluetooth Mesh device actively sends the verification certificate of the Bluetooth Mesh device to the gateway.
  • the gateway may send a first request message to the Bluetooth Mesh device, where the first request message is used to request to obtain the verification credential of the Bluetooth Mesh device; after receiving the first request message, the Bluetooth Mesh device, Send the verification credentials of the Bluetooth Mesh device to the gateway.
  • Step S1107 the gateway sends the verification certificate of the Bluetooth Mesh device to the cloud platform.
  • the gateway requests the cloud platform accessed by the gateway to verify the validity of the Bluetooth Mesh device by sending the verification credential of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • Step S1108 the cloud platform requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
  • the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is not a device developed based on the cloud platform according to the CID in the unconfigured broadcast packet
  • the cloud platform accessed by the gateway determines according to the CID in the unconfigured broadcast packet.
  • the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is a device developed based on the cloud platform according to the CID in the unconfigured network broadcast packet, the cloud platform accessed by the gateway verifies the validity of the Bluetooth Mesh device .
  • Step S1109 the device authentication platform verifies the validity of the Bluetooth Mesh device.
  • the device authentication platform verifies whether the security certificate is legal; if the security certificate is verified to be legal, it verifies that the Bluetooth Mesh device is legal; If the certificate is invalid, the authentication of the Bluetooth Mesh device is invalid.
  • the device authentication platform can use asymmetric encryption or symmetric encryption to verify the legitimacy of the Bluetooth Mesh device.
  • the Bluetooth Mesh device pre-stores the public key of the device authentication platform, encrypts the verification certificate of the Bluetooth Mesh device with the public key of the device authentication platform, and uses its own private key after receiving the verification certificate. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
  • the device authentication platform and the Bluetooth Mesh device pre-share the same key (ie, the pre-shared key), and the Bluetooth Mesh device uses the pre-shared key to encrypt the verification credentials of the Bluetooth Mesh device. After verifying the certificate, decrypt it with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
  • Step S1110 the device authentication platform feeds back the verification result of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • Step S1111 the cloud platform connected to the gateway feeds back the verification result of the Bluetooth Mesh device to the gateway.
  • Step S1112 if the verification result of the Bluetooth Mesh device is valid, the gateway requests the cloud platform accessed by the gateway to add the Bluetooth Mesh device.
  • the gateway sends device information including the UUID of the Bluetooth Mesh device to the cloud platform connected to the gateway, and the cloud platform connected to the gateway adds the device information of the Bluetooth Mesh device.
  • the Bluetooth mesh device verifies the legitimacy of the gateway and/or the cloud platform, and when the verification result indicates that the gateway and/or the cloud platform are legal, the gateway verifies the legitimacy of the gateway and/or the cloud platform. Verify the validity of the Bluetooth Mesh device; if the verification result indicates that the Bluetooth Mesh device is legal, perform the network access configuration of the Bluetooth Mesh device.
  • the processing flow of the Bluetooth device access authentication method shown in Figure 7 adds the Bluetooth Mesh device verification method before the gateway verifies the validity of the Bluetooth Mesh device. Steps to verify the legitimacy of the gateway and/or cloud platform; further improve the security of Bluetooth Mesh network access authentication.
  • An optional detailed processing flow includes the following steps:
  • Step S1201 the Bluetooth Mesh device sends an unconfigured network broadcast packet to the gateway.
  • Steps S1202-S1203, the Bluetooth Mesh device and the gateway start the Bluetooth Mesh network configuration process.
  • starting the Bluetooth Mesh network configuration process may include: calculating a security key, and the security key is used to encrypt/decrypt the verification credential between the Bluetooth Mesh device and the gateway; wherein, the security key may include a session key, One or more of Device Key, Network Key, and App Key.
  • the process of completing the Bluetooth Mesh network configuration includes: the gateway starts the distribution of configuration data for Bluetooth Mesh network access, sends configuration information such as network addresses and security keys (such as network keys and/or device keys) to the Bluetooth Mesh devices, and completes the network access of the Bluetooth Mesh devices. configuration process.
  • Step S1204 the gateway sends a fourth request message to the cloud platform according to the check mark of the Bluetooth device.
  • the fourth request message is used to request to obtain a verification credential of a device authentication platform
  • the verification credential of the device authentication platform is used by the Bluetooth Mesh device to verify the legitimacy of the device authentication platform .
  • the fourth request message may further include a CID, which is used by the cloud platform to determine the device authentication platform corresponding to the Bluetooth Mesh device according to the DCI.
  • Step S1205 the cloud platform sends a seventh request message to the device authentication platform.
  • the seventh request message is used to request to obtain the verification credential of the device authentication platform.
  • Step S1206 the device authentication platform sends the verification certificate of the device authentication platform to the cloud platform.
  • Step S1207 the cloud platform sends the verification certificate of the device authentication platform to the gateway.
  • Step S1208 the gateway sends the verification certificate of the device authentication platform to the Bluetooth Mesh device.
  • Step S1209 the Bluetooth Mesh device verifies the validity of the device authentication platform.
  • the Bluetooth Mesh device can use asymmetric encryption or symmetric encryption to verify the legitimacy of the device authentication platform.
  • the device authentication platform pre-stores the public key of the Bluetooth Mesh device. After the device authentication platform generates the verification certificate of the device authentication platform, it encrypts the verification certificate with the public key of the Bluetooth Mesh device, and the Bluetooth Mesh device receives the verification certificate. After verifying the certificate, decrypt it with your own private key. If it can be decrypted normally, it proves to be a legitimate device authentication platform. If it cannot be decrypted normally, it proves to be an illegal device authentication platform.
  • the device authentication platform and the Bluetooth Mesh device pre-share the same key (that is, the pre-shared key). After the device authentication platform generates the verification certificate of the device authentication platform, it encrypts the verification certificate with the pre-shared key. The verification certificate received by the Bluetooth Mesh device is decrypted with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate device authentication platform. If it cannot be decrypted normally, it proves to be an illegal device authentication platform.
  • Step S1210 the gateway obtains the verification certificate of the Bluetooth Mesh device.
  • the verification mark in the unconfigured network broadcast packet indicates to verify the Bluetooth Mesh device, and the Bluetooth Mesh device actively sends the verification certificate of the Bluetooth Mesh device to the gateway.
  • the gateway may send a first request message to the Bluetooth Mesh device, where the first request message is used to request to obtain the verification credential of the Bluetooth Mesh device; after receiving the first request message, the Bluetooth Mesh device, Send the verification credentials of the Bluetooth Mesh device to the gateway.
  • Step S1211 the gateway sends the verification certificate of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • the gateway requests the cloud platform accessed by the gateway to verify the validity of the Bluetooth Mesh device by sending the verification credential of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • Step S1212 the cloud platform accessed by the gateway requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
  • the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is not a device developed based on the cloud platform according to the CID in the unconfigured broadcast packet
  • the cloud platform accessed by the gateway determines according to the CID in the unconfigured broadcast packet.
  • the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is a device developed based on the cloud platform according to the CID in the unconfigured network broadcast packet, the cloud platform accessed by the gateway verifies the validity of the Bluetooth Mesh device .
  • Step S1213 the device authentication platform verifies the validity of the Bluetooth Mesh device.
  • the device authentication platform verifies whether the security certificate is legal; if the security certificate is verified to be legal, it verifies that the Bluetooth Mesh device is legal; If the certificate is invalid, the authentication of the Bluetooth Mesh device is invalid.
  • the device authentication platform can use asymmetric encryption or symmetric encryption to verify the legitimacy of the Bluetooth Mesh device.
  • the Bluetooth Mesh device pre-stores the public key of the device authentication platform, encrypts the verification certificate of the Bluetooth Mesh device with the public key of the device authentication platform, and uses its own private key after receiving the verification certificate. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
  • the device authentication platform and the Bluetooth Mesh device pre-share the same key (ie, the pre-shared key), and the Bluetooth Mesh device uses the pre-shared key to encrypt the verification credentials of the Bluetooth Mesh device. After verifying the certificate, decrypt it with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
  • Step S1214 the device authentication platform feeds back the verification result of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
  • Step S1215 the cloud platform connected to the gateway feeds back the verification result of the Bluetooth Mesh device to the gateway.
  • Step S1216 if the verification result of the Bluetooth Mesh device is valid, the gateway requests the cloud platform accessed by the gateway to add the Bluetooth Mesh device.
  • the gateway sends device information including the UUID of the Bluetooth Mesh device to the cloud platform connected to the gateway, and the cloud platform connected to the gateway adds the device information of the Bluetooth Mesh device.
  • step S1216 is executed. If the verification result of the Bluetooth Mesh device is invalid, delete the Bluetooth Mesh device from the Bluetooth Mesh network.
  • the Bluetooth Mesh device verifies the validity of the device authentication platform first, and when the verification result indicates that the device authentication platform is legal, the gateway verifies the Bluetooth Mesh Legality of the device.
  • the gateway can also verify the validity of the Bluetooth Mesh device first, and when the verification result indicates that the Bluetooth Mesh device is legal, then the Bluetooth Mesh device can verify the validity of the device authentication platform; that is, after the execution is completed. After steps S1201 to S1203, steps S1210 to S1215 are performed first, and then steps S1204-1209 are performed.
  • the validity of the Bluetooth Mesh device is verified by the gateway, and the validity of the gateway/cloud platform is verified by the Bluetooth Mesh device.
  • the Bluetooth device access authentication method provided by the embodiment of the present application is described in detail.
  • the validity of the Bluetooth Mesh device is verified by the gateway, and the validity of the device authentication platform is verified by the Bluetooth Mesh device.
  • the Bluetooth device access authentication method provided by the embodiment of the present application is described in detail.
  • the gateway can verify the validity of the Bluetooth Mesh device
  • the Bluetooth Mesh device can verify the validity of the gateway/cloud platform
  • the Bluetooth Mesh device can verify the legality of the device authentication platform.
  • Bluetooth Mesh device There is no sequence of execution between the validity of the Bluetooth Mesh device, the validity of the gateway/cloud platform verified by the Bluetooth Mesh device, and the validity of the device authentication platform verified by the Bluetooth Mesh device.
  • Bluetooth device described in the embodiments of the present application may also be a Bluetooth Mesh device applied in a Bluetooth Mesh network
  • the “cloud platform” described in the embodiments of the present application is a cloud platform accessed by a gateway.
  • the size of the sequence numbers of the above-mentioned processes does not mean the sequence of execution, and the execution sequence of each process should be determined by its functions and internal logic, and should not be dealt with in the embodiments of the present application. implementation constitutes any limitation.
  • the embodiment of the present application further provides a gateway.
  • the optional composition structure of the gateway 1300 includes:
  • the first processing unit 1301 is configured to determine the verification credential of the Bluetooth device
  • the first sending unit 1302 is configured to send the verification credential of the Bluetooth device to the cloud platform, where the verification credential of the Bluetooth device is used for the cloud platform to determine the validity of the Bluetooth device.
  • the first processing unit 1301 is configured to receive a verification credential of the Bluetooth device sent by the Bluetooth device.
  • the first processing unit 1301 is further configured to send a first request message to the Bluetooth device, where the first request message is used to request to obtain a verification credential of the Bluetooth device.
  • the first processing unit 1301 is configured to receive a device verification result sent by the cloud platform, where the device verification result is used to indicate the validity of the Bluetooth device.
  • the first processing unit 1301 is further configured to determine the verification credential of the gateway and/or the cloud platform.
  • the verification credentials of the gateway and/or the cloud platform are pre-stored.
  • the first processing unit 1301 is configured to send a second request message to the cloud platform, where the second request message is used to request to obtain the verification of the gateway and/or the cloud platform certificate;
  • the first sending unit 1302 is further configured to send the verification credentials of the gateway and/or the cloud platform to the Bluetooth device, the verification credentials of the gateway and/or the cloud platform
  • the verification credential is used by the Bluetooth device to verify the validity of the gateway/or the cloud platform.
  • the first processing unit 1301 is further configured to receive a third request message sent by the Bluetooth device, where the third request message is used to request to obtain the information of the gateway and/or the cloud platform Verify credentials.
  • the first processing unit 1301 is further configured to receive the gateway and/or the cloud platform verification result sent by the Bluetooth device, the gateway and/or the cloud platform verification result using to indicate legitimacy against the gateway and/or the cloud platform.
  • the first sending unit 1302 is configured to send a fourth request message to the cloud platform according to the check mark of the Bluetooth device, where the fourth request message is used to request to obtain a device authentication platform verification certificate;
  • the verification credential of the device authentication platform is used for the Bluetooth device to verify the legitimacy of the device authentication platform.
  • the first processing unit 1301 is further configured to receive the verification credential of the device authentication platform sent by the cloud platform;
  • the first sending unit 1302 is further configured to send the verification credential of the device authentication platform to the Bluetooth device.
  • the first processing unit 1301 is further configured to request the cloud platform to add the Bluetooth device.
  • the first processing unit 1301 is configured to send the information of the Bluetooth device to the cloud platform, where the information of the Bluetooth device is used for the cloud platform to add the Bluetooth device.
  • the first sending unit 1302 is further configured to send configuration information to the Bluetooth device, where the configuration information is used to perform network access configuration of the Bluetooth device.
  • the first processing unit 1301 is further configured to receive a check mark sent by the Bluetooth device, where the check mark is used to indicate an object to be checked.
  • the verification mark includes at least one of: verifying the Bluetooth device, verifying the gateway and/or the cloud platform, and verifying a device authentication platform.
  • the embodiment of the present application further provides a cloud platform.
  • the optional composition structure of the cloud platform 1400 includes:
  • the first receiving unit 1401 is configured to receive the verification certificate of the Bluetooth device sent by the gateway;
  • the second processing unit 1402 is configured to determine the validity of the Bluetooth device based on the verification credential of the Bluetooth device.
  • the second processing unit 1402 is configured to send a fifth request message carrying the verification credential of the Bluetooth device to the device authentication platform if the Bluetooth device is not a device corresponding to the cloud platform ;
  • the fifth request message is used to request the device authentication platform to verify the legitimacy of the Bluetooth device;
  • the Bluetooth device is a device corresponding to the cloud platform, verify the validity of the Bluetooth device.
  • the first receiving unit 1401 is further configured to receive a device verification result sent by the device authentication platform, where the device verification result is used to indicate the validity of the Bluetooth device.
  • the second processing unit 1402 is further configured to send the device verification result to the gateway.
  • the first receiving unit 1401 is further configured to receive a second request message sent by the gateway, where the second request message is used for requesting to obtain the calibration of the gateway and/or the cloud platform verification certificate;
  • the second processing unit 1402 is further configured to confirm the verification credentials of the gateway and/or the cloud platform.
  • the second processing unit 1402 is configured to, if the Bluetooth device is not a device corresponding to the cloud platform, the cloud platform determines a device authentication platform corresponding to the Bluetooth device; The authentication platform sends a sixth request message; the sixth request message carries the identifier of the gateway and/or the cloud platform, and is used to request to obtain the verification credential of the gateway and/or the cloud platform.
  • the first receiving unit 1401 is configured to receive the verification credential of the gateway and/or the cloud platform sent by the device authentication platform.
  • the second processing unit 1402 is further configured to send the gateway and/or the verification credential of the cloud platform to the gateway.
  • the first receiving unit 1401 is further configured to receive a fourth request message sent by the gateway, where the fourth request message is used to request to obtain the verification credential of the device authentication platform; determine the device authentication Platform verification credentials.
  • the second processing unit 1402 is configured to send a seventh request message to the device authentication platform, where the seventh request message is used to request to obtain the verification credential of the device authentication platform;
  • the first receiving unit 1401 is configured to receive the verification credential of the device authentication platform sent by the device authentication platform.
  • the second processing unit 1402 is configured to send the verification credential of the device authentication platform to the gateway.
  • the second processing unit 1402 is further configured to add the Bluetooth device.
  • the second processing unit 1402 is configured to receive the information of the Bluetooth device sent by the gateway; and add the Bluetooth device according to the information of the Bluetooth device.
  • the embodiment of the present application further provides a device authentication platform.
  • the optional composition structure of the device authentication platform 1500 includes:
  • the second receiving unit 1501 is configured to receive a fifth request message sent by the cloud platform; the fifth request message includes the verification credential of the Bluetooth device;
  • the third processing unit 1502 verifies the validity of the Bluetooth device according to the verification certificate of the Bluetooth device.
  • the second receiving unit 1501 is further configured to receive a sixth request message sent by the cloud platform; the sixth request message carries the identifier of the gateway and/or the cloud platform, and uses upon request to obtain the verification credential of the gateway and/or the cloud platform.
  • the third processing unit 1502 is configured to generate a verification credential of the gateway and/or the cloud platform according to the identifier of the gateway and/or the cloud platform;
  • the embodiment of the present application further provides a Bluetooth device.
  • the optional composition structure of the Bluetooth device 1600 includes:
  • the second sending unit 1601 is configured to send a verification certificate of the Bluetooth device to the gateway, where the verification certificate of the Bluetooth device is used to determine the validity of the Bluetooth device.
  • the Bluetooth device 1600 further includes:
  • the fourth processing unit 1602 is configured to receive a first request message sent by the gateway, where the first request message is used to request to obtain a verification credential of the Bluetooth device.
  • the Bluetooth device 1600 further includes:
  • the fifth processing unit 1603 is configured to receive the verification credential of the gateway and/or the cloud platform, and the verification credential of the gateway and/or the cloud platform is used for the Bluetooth device to verify the gateway/ or the legality of the cloud platform.
  • the second sending unit 1601 is further configured to send a third request message to the gateway, where the third request message is used to request to obtain the verification of the gateway and/or the cloud platform certificate.
  • the fifth processing unit 1603 is configured to verify the validity of the gateway and/or the cloud platform according to the verification credentials of the gateway and/or the cloud platform.
  • the second sending unit 1601 is configured to send the gateway and/or the cloud platform verification result sent by the Bluetooth device to the gateway, the gateway and/or the cloud platform verification result.
  • the verification result is used to indicate the legitimacy of the gateway and/or the cloud platform.
  • the Bluetooth device 1600 further includes: the sixth processing unit 1604, configured to receive the verification credential of the device authentication platform sent by the gateway; based on the verification credential of the device authentication platform, the verification Verify the legitimacy of the device authentication platform.
  • the Bluetooth device 1600 further includes: a third receiving unit 1605, configured to receive configuration information sent by the gateway, where the configuration information is used to perform network access configuration of the Bluetooth device.
  • An embodiment of the present application provides a gateway, including a processor and a memory for storing a computer program that can be executed on the processor, wherein the processor is configured to execute the Bluetooth device interface executed by the gateway when the computer program is executed. Enter the steps of the authentication method.
  • An embodiment of the present application provides a cloud platform, including a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the bluetooth executed by the cloud platform when running the computer program The steps of the device access authentication method.
  • An embodiment of the present application provides a device authentication platform, including a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the above-mentioned device authentication platform when running the computer program.
  • the steps of the Bluetooth device access authentication method are performed by the processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the above-mentioned device authentication platform when running the computer program.
  • An embodiment of the present application provides a Bluetooth device, including a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the Bluetooth program executed by the Bluetooth device when the computer program is executed.
  • the steps of the device access authentication method.
  • An embodiment of the present application further provides a chip, including: a processor configured to call and run a computer program from a memory, so that a device installed with the chip executes the above-mentioned Bluetooth device access authentication method.
  • An embodiment of the present application further provides a storage medium storing an executable program, and when the executable program is executed by a processor, the above-mentioned Bluetooth device access authentication method is implemented.
  • the embodiments of the present application further provide a computer program product, including computer program instructions, the computer program instructions enable a computer to execute the above-mentioned Bluetooth device access authentication method.
  • the embodiment of the present application further provides a computer program, the computer program enables a computer to execute the above-mentioned Bluetooth device access authentication method.
  • the electronic device 700 includes: at least one processor 701, memory 702, and at least one network interface 704.
  • the various components in electronic device 700 are coupled together by bus system 705 .
  • bus system 705 is used to implement the connection communication between these components.
  • the bus system 705 also includes a power bus, a control bus and a status signal bus.
  • the various buses are labeled as bus system 705 in FIG. 16 .
  • memory 702 may be either volatile memory or non-volatile memory, and may include both volatile and non-volatile memory.
  • the non-volatile memory can be ROM, Programmable Read-Only Memory (PROM, Programmable Read-Only Memory), Erasable Programmable Read-Only Memory (EPROM, Erasable Programmable Read-Only Memory), Electrically Erasable Programmable Read-Only Memory Programmable read-only memory (EEPROM, Electrically Erasable Programmable Read-Only Memory), magnetic random access memory (FRAM, ferromagnetic random access memory), flash memory (Flash Memory), magnetic surface memory, optical disk, or CD-ROM -ROM, Compact Disc Read-Only Memory); magnetic surface memory can be disk memory or tape memory.
  • RAM Random Access Memory
  • SRAM Static Random Access Memory
  • SSRAM Synchronous Static Random Access Memory
  • DRAM Dynamic Random Access Memory
  • SDRAM Synchronous Dynamic Random Access Memory
  • DDRSDRAM Double Data Rate Synchronous Dynamic Random Access Memory
  • ESDRAM Enhanced Type Synchronous Dynamic Random Access Memory
  • SLDRAM Synchronous Link Dynamic Random Access Memory
  • DRRAM Direct Rambus Random Access Memory
  • the memory 702 described in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memory.
  • the memory 702 in this embodiment of the present application is used to store various types of data to support the operation of the electronic device 700 .
  • Examples of such data include: any computer program used to operate on electronic device 700, such as application 7022.
  • the program for implementing the method of the embodiment of the present application may be included in the application program 7022 .
  • the methods disclosed in the above embodiments of the present application may be applied to the processor 701 or implemented by the processor 701 .
  • the processor 701 may be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above-mentioned method can be completed by an integrated logic circuit of hardware in the processor 701 or an instruction in the form of software.
  • the above-mentioned processor 701 may be a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and the like.
  • the processor 701 may implement or execute the methods, steps, and logical block diagrams disclosed in the embodiments of this application.
  • a general purpose processor may be a microprocessor or any conventional processor or the like.
  • the steps of the method disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor.
  • the software module may be located in a storage medium, and the storage medium is located in the memory 702, and the processor 701 reads the information in the memory 702, and completes the steps of the foregoing method in combination with its hardware.
  • the electronic device 700 may be implemented by one or more Application Specific Integrated Circuits (ASICs), DSPs, Programmable Logic Devices (PLDs), Complex Programmable Logic Devices (CPLDs) , Complex Programmable Logic Device), FPGA, general-purpose processor, controller, MCU, MPU, or other electronic component implementation for performing the aforementioned method.
  • ASICs Application Specific Integrated Circuits
  • DSPs Digital Signal processors
  • PLDs Programmable Logic Devices
  • CPLDs Complex Programmable Logic Devices
  • FPGA general-purpose processor
  • controller MCU, MPU, or other electronic component implementation for performing the aforementioned method.
  • These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory result in an article of manufacture comprising instruction means, the instructions
  • the apparatus implements the functions specified in the flow or flow of the flowcharts and/or the block or blocks of the block diagrams.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

Disclosed is an access authentication method for a Bluetooth device, comprising: a gateway determining a verification credential of a Bluetooth device; and the gateway sending, to a cloud platform, the verification credential of the Bluetooth device, the verification credential of the Bluetooth device being used by the cloud platform to determine the validity of the Bluetooth device. Also disclosed are another access authentication method for a Bluetooth device, an electronic device, and a storage medium.

Description

一种蓝牙设备接入认证方法、电子设备及存储介质A Bluetooth device access authentication method, electronic device and storage medium 技术领域technical field
本申请涉及无线通信技术领域,尤其涉及一种蓝牙设备接入认证方法、电子设备及存储介质。The present application relates to the field of wireless communication technologies, and in particular, to a Bluetooth device access authentication method, an electronic device, and a storage medium.
背景技术Background technique
随着蓝牙Mesh功能的日益完善以及应用的日趋广泛,蓝牙Mesh网状网络如何实现对不同类型的蓝牙设备的接入认证,提高蓝牙设备接入认证的通用性一直是蓝牙网络技术追求的目标。With the increasingly perfect function of Bluetooth Mesh and the widening of applications, how to realize the access authentication of different types of Bluetooth devices and improve the versatility of Bluetooth device access authentication has always been the goal of Bluetooth network technology.
发明内容SUMMARY OF THE INVENTION
本申请实施例提供一种蓝牙设备接入认证方法、电子设备及存储介质,能够提高蓝牙设备接入认证的通用性。Embodiments of the present application provide a Bluetooth device access authentication method, an electronic device, and a storage medium, which can improve the versatility of Bluetooth device access authentication.
第一方面,本申请实施例提供一种蓝牙设备接入认证方法,包括:网关确定蓝牙设备的校验凭证;In a first aspect, an embodiment of the present application provides a Bluetooth device access authentication method, including: a gateway determining a verification credential of the Bluetooth device;
所述网关向云平台发送所述蓝牙设备的校验凭证,所述蓝牙设备的校验凭证用于所述云平台确定所述蓝牙设备的合法性。The gateway sends the verification credential of the Bluetooth device to the cloud platform, and the verification credential of the Bluetooth device is used by the cloud platform to determine the validity of the Bluetooth device.
第二方面,本申请实施例提供一种蓝牙设备接入认证方法,包括:云平台接收网关发送的蓝牙设备的校验凭证;In a second aspect, an embodiment of the present application provides a Bluetooth device access authentication method, including: a cloud platform receiving a verification credential of a Bluetooth device sent by a gateway;
所述云平台基于所述蓝牙设备的校验凭证,确定所述蓝牙设备的合法性。The cloud platform determines the validity of the Bluetooth device based on the verification certificate of the Bluetooth device.
第三方面,本申请实施例提供一种蓝牙设备接入认证方法,包括:设备认证平台接收云平台发送的第五请求消息;所述第五请求消息包括蓝牙设备的校验凭证;In a third aspect, an embodiment of the present application provides a method for authentication of Bluetooth device access, including: the device authentication platform receives a fifth request message sent by a cloud platform; the fifth request message includes a verification credential of the Bluetooth device;
所述设备认证平台根据所述蓝牙设备的校验凭证,校验所述蓝牙设备的合法性。The device authentication platform verifies the validity of the Bluetooth device according to the verification certificate of the Bluetooth device.
第四方面,本申请实施例提供一种蓝牙设备接入认证方法,包括:蓝牙设备向网关发送蓝牙设备的校验凭证,所述蓝牙设备的校验凭证用于确定所述蓝牙设备的合法性。In a fourth aspect, an embodiment of the present application provides a method for authenticating access to a Bluetooth device, including: a Bluetooth device sending a verification credential of the Bluetooth device to a gateway, where the verification credential of the Bluetooth device is used to determine the validity of the Bluetooth device .
第五方面,本申请实施例提供一种网关,所述网关包括:第一处理单元,配置为确定蓝牙设备的校验凭证;In a fifth aspect, an embodiment of the present application provides a gateway, where the gateway includes: a first processing unit configured to determine a verification credential of a Bluetooth device;
第一发送单元,配置为向云平台发送所述蓝牙设备的校验凭证,所述蓝牙设备的校验凭证用于所述云平台确定所述蓝牙设备的合法性。The first sending unit is configured to send the verification certificate of the Bluetooth device to the cloud platform, where the verification certificate of the Bluetooth device is used for the cloud platform to determine the validity of the Bluetooth device.
第六方面,本申请实施例提供一种云平台,所述云平台包括:第一接收单元,配置为接收网关发送的蓝牙设备的校验凭证;In a sixth aspect, an embodiment of the present application provides a cloud platform, where the cloud platform includes: a first receiving unit configured to receive a verification credential of a Bluetooth device sent by a gateway;
第二处理单元,配置为基于所述蓝牙设备的校验凭证,确定所述蓝牙设备的合法性。The second processing unit is configured to determine the validity of the Bluetooth device based on the verification credential of the Bluetooth device.
第七方面,本申请实施例提供一种设备认证平台,所述设备认证平台包括:第二接收单元,配置为接收云平台发送的第五请求消息;所述第五请求消息包括蓝牙设备的校验凭证;In a seventh aspect, an embodiment of the present application provides a device authentication platform, where the device authentication platform includes: a second receiving unit configured to receive a fifth request message sent by the cloud platform; the fifth request message includes the authentication of the Bluetooth device. verification certificate;
第三处理单元,根据所述蓝牙设备的校验凭证,校验所述蓝牙设备的合法性。The third processing unit verifies the validity of the Bluetooth device according to the verification certificate of the Bluetooth device.
第八方面,本申请实施例提供一种蓝牙设备,所述蓝牙设备包括:第二发送单元,配置为向网关发送蓝牙设备的校验凭证,所述蓝牙设备的校验凭证用于确定所述蓝牙设备的合法性。In an eighth aspect, an embodiment of the present application provides a Bluetooth device, where the Bluetooth device includes: a second sending unit configured to send a verification credential of the Bluetooth device to a gateway, where the verification credential of the Bluetooth device is used to determine the Legality of Bluetooth devices.
第九方面,本申请实施例提供一种网关,包括处理器和用于存储能够在处理器上运行的计算机程序的存储器,其中,所述处理器用于运行所述计算机程序时,执行上述网关执行的蓝牙设备接入认证方法的步骤。In a ninth aspect, an embodiment of the present application provides a gateway, including a processor and a memory for storing a computer program that can be executed on the processor, wherein the processor is configured to execute the above-mentioned gateway execution when the computer program is executed. The steps of the Bluetooth device access authentication method.
第十方面,本申请实施例提供一种云平台,包括处理器和用于存储能够在处理器上运行的 计算机程序的存储器,其中,所述处理器用于运行所述计算机程序时,执行上述云平台执行的蓝牙设备接入认证方法的步骤。In a tenth aspect, an embodiment of the present application provides a cloud platform, including a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the above cloud when running the computer program The steps of the Bluetooth device access authentication method performed by the platform.
第十一方面,本申请实施例提供一种设备认证平台,包括处理器和用于存储能够在处理器上运行的计算机程序的存储器,其中,所述处理器用于运行所述计算机程序时,执行上述设备认证平台执行的蓝牙设备接入认证方法的步骤。In an eleventh aspect, an embodiment of the present application provides a device authentication platform, including a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the computer program when running the computer program. The steps of the Bluetooth device access authentication method performed by the above device authentication platform.
第十二方面,本申请实施例提供一种蓝牙设备,包括处理器和用于存储能够在处理器上运行的计算机程序的存储器,其中,所述处理器用于运行所述计算机程序时,执行上述蓝牙设备执行的蓝牙设备接入认证方法的步骤。In a twelfth aspect, an embodiment of the present application provides a Bluetooth device, including a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the above-mentioned computer program when running the computer program. The steps of the Bluetooth device access authentication method performed by the Bluetooth device.
第十三方面,本申请实施例提供一种芯片,包括:处理器,用于从存储器中调用并运行计算机程序,使得安装有所述芯片的设备执行上述蓝牙设备接入认证方法。In a thirteenth aspect, an embodiment of the present application provides a chip, including: a processor for invoking and running a computer program from a memory, so that a device installed with the chip executes the above-mentioned Bluetooth device access authentication method.
第十四方面,本申请实施例提供一种存储介质,存储有可执行程序,所述可执行程序被处理器执行时,实现上述蓝牙设备接入认证方法。In a fourteenth aspect, an embodiment of the present application provides a storage medium storing an executable program, and when the executable program is executed by a processor, the above-mentioned Bluetooth device access authentication method is implemented.
第十五方面,本申请实施例提供一种计算机程序产品,包括计算机程序指令,该计算机程序指令使得计算机执行上述蓝牙设备接入认证方法。In a fifteenth aspect, an embodiment of the present application provides a computer program product, including computer program instructions, the computer program instructions causing a computer to execute the above-mentioned Bluetooth device access authentication method.
第十六方面,本申请实施例提供一种计算机程序,所述计算机程序使得计算机执行上述蓝牙设备接入认证方法。In a sixteenth aspect, an embodiment of the present application provides a computer program, the computer program enables a computer to execute the above-mentioned Bluetooth device access authentication method.
本申请实施例提供的蓝牙设备接入认证方法、电子设备及存储介质,包括:网关确定蓝牙设备的校验凭证;所述网关向云平台发送所述蓝牙设备的校验凭证,所述蓝牙设备的校验凭证用于所述云平台确定所述蓝牙设备的合法性。如此,由网关执行蓝牙设备配网,将蓝牙设备配网和接入认证功能从云平台中解耦,提高对蓝牙设备接入认证的通用性。The Bluetooth device access authentication method, electronic device, and storage medium provided by the embodiments of the present application include: a gateway determines a verification credential of a Bluetooth device; the gateway sends the verification credential of the Bluetooth device to a cloud platform, and the Bluetooth device The verification credential is used by the cloud platform to determine the validity of the Bluetooth device. In this way, the gateway performs network configuration of Bluetooth devices, decouples the functions of network configuration and access authentication of Bluetooth devices from the cloud platform, and improves the versatility of access authentication for Bluetooth devices.
附图说明Description of drawings
图1为本申请跨平台的方式对蓝牙设备接入认证的处理流程示意图;FIG. 1 is a schematic diagram of the processing flow of the Bluetooth device access authentication in a cross-platform manner of the application;
图2为本申请实施例提供的应用于网关的蓝牙设备接入认证方法的一种可选处理流程示意图;FIG. 2 is a schematic diagram of an optional processing flow of the Bluetooth device access authentication method applied to the gateway provided by the embodiment of the present application;
图3为本申请实施例提供的应用于云平台的蓝牙设备接入认证方法的一种可选处理流程示意图;FIG. 3 is a schematic diagram of an optional processing flow of a Bluetooth device access authentication method applied to a cloud platform provided by an embodiment of the present application;
图4为本申请实施例提供的应用于设备认证平台的蓝牙设备接入认证方法的一种可选处理流程示意图;4 is a schematic diagram of an optional processing flow of the Bluetooth device access authentication method applied to the device authentication platform provided by the embodiment of the present application;
图5为本申请实施例提供的应用于蓝牙设备的蓝牙设备接入认证方法的一种可选处理流程示意图;FIG. 5 is a schematic diagram of an optional processing flow of a Bluetooth device access authentication method applied to a Bluetooth device provided by an embodiment of the present application;
图6为本申请实施例提供的蓝牙设备接入认证方法的第一种可选详细处理流程示意图;FIG. 6 is a schematic diagram of a first optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application;
图7为本申请实施例提供的蓝牙设备接入认证方法的第二种可选详细处理流程示意图;FIG. 7 is a schematic diagram of a second optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application;
图8为本申请实施例提供的蓝牙设备接入认证方法的第三种可选详细处理流程示意图;FIG. 8 is a schematic diagram of a third optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application;
图9为本申请实施例提供的蓝牙设备接入认证方法的第四种可选详细处理流程示意图;FIG. 9 is a schematic diagram of a fourth optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application;
图10为本申请实施例提供的蓝牙设备接入认证方法的第五种可选详细处理流程示意图;10 is a schematic diagram of a fifth optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application;
图11为本申请实施例提供的蓝牙设备接入认证方法的第六种可选详细处理流程示意图;11 is a schematic diagram of a sixth optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application;
图12为本申请实施例提供的网关的一种可选组成结构示意图;FIG. 12 is a schematic structural diagram of an optional composition of a gateway provided by an embodiment of the present application;
图13为本申请实施例提供的云平台的一种可选组成结构示意图;FIG. 13 is a schematic diagram of an optional composition structure of a cloud platform provided by an embodiment of the present application;
图14为本申请实施例提供的设备认证平台的一种可选组成结构示意图;FIG. 14 is a schematic structural diagram of an optional composition of a device authentication platform provided by an embodiment of the present application;
图15为本申请实施例提供的蓝牙设备的一种可选组成结构示意图;15 is a schematic diagram of an optional composition structure of a Bluetooth device provided by an embodiment of the application;
图16为本申请实施例提供的电子设备的硬件组成结构示意图。FIG. 16 is a schematic structural diagram of a hardware composition of an electronic device provided by an embodiment of the present application.
具体实施方式detailed description
为了能够更加详尽地了解本申请实施例的特点和技术内容,下面结合附图对本申请实施例的实现进行详细阐述,所附附图仅供参考说明之用,并非用来限定本申请实施例。In order to understand the features and technical contents of the embodiments of the present application in more detail, the implementation of the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
在对本申请实施例进行说明之前,对相关内容进行简要说明。Before describing the embodiments of the present application, relevant contents are briefly described.
蓝牙Mesh(无线网格网络):一种基于低功耗蓝牙技术构建的网状设备网络,可以实现多对多的蓝牙设备通信。Bluetooth Mesh (Wireless Mesh Network): A mesh device network based on Bluetooth low energy technology, which can realize many-to-many Bluetooth device communication.
网关:蓝牙Mesh配网设备,负责配置接入蓝牙Mesh网络的设备。Gateway: Bluetooth Mesh network configuration device, responsible for configuring devices connected to the Bluetooth Mesh network.
蓝牙设备:待配网蓝牙Mesh设备,需要通过蓝牙Mesh配网流程加入蓝牙Mesh网络,成为蓝牙Mesh网络中的蓝牙Mesh设备。Bluetooth device: The Bluetooth Mesh device to be deployed on the network needs to join the Bluetooth Mesh network through the Bluetooth Mesh network configuration process to become a Bluetooth Mesh device in the Bluetooth Mesh network.
会话密钥:用于蓝牙Mesh配网流程中配网数据加解密。Session key: used for encryption and decryption of network configuration data in the Bluetooth Mesh network configuration process.
设备密钥:用于蓝牙Mesh设备配网成功以后,蓝牙Mesh设备的后续配置,只有网关和蓝牙Mesh设备知道,用于二者之间的安全通信。Device key: used for the subsequent configuration of the Bluetooth Mesh device after the successful network configuration of the Bluetooth Mesh device. Only the gateway and the Bluetooth Mesh device know it for secure communication between the two.
相关技术中,在蓝牙设备与网关不属于同一个厂商时,需要通过跨平台(即需要两个云平台)的方式对蓝牙设备进行接入认证,跨平台的方式对蓝牙设备接入认证的处理流程,如图1所示。In the related art, when the Bluetooth device and the gateway do not belong to the same manufacturer, the access authentication of the Bluetooth device needs to be performed in a cross-platform (that is, two cloud platforms are required), and the access authentication of the Bluetooth device needs to be processed in a cross-platform manner. The process is shown in Figure 1.
步骤1、蓝牙设备按规范广播蓝牙Mesh未配网广播包。Step 1. The Bluetooth device broadcasts the Bluetooth Mesh unconfigured network broadcast packet according to the specification.
其中,蓝牙设备为E公司基于B平台开发的蓝牙Mesh设备,蓝牙Mesh未配网广播包中包括B平台的平台标识(CID)。Among them, the Bluetooth device is a Bluetooth Mesh device developed by E company based on the B platform, and the Bluetooth Mesh unconfigured network broadcast package includes the platform identifier (CID) of the B platform.
步骤2、接入A平台的网关获取广播的未配网广播信息后,将该信息上传至A平台,查询该设备的类型。Step 2: After the gateway accessing the A platform obtains the broadcast information of the unconfigured network broadcast, upload the information to the A platform, and query the type of the device.
步骤3、A平台在收到网关上报的设备信息后,通过CID判断该设备不是基于A平台开发的设备(需要其它平台进行授权),则先通过互联互通服务器获取CID对应的B平台信息(包含B平台Auth Server等信息),之后通过B平台云获取该设备类型。Step 3. After receiving the device information reported by the gateway, platform A determines that the device is not a device developed based on platform A (requires authorization from other platforms) through CID, and first obtains platform B information corresponding to CID through the interconnection server (including B platform Auth Server and other information), and then obtain the device type through the B platform cloud.
步骤4、网关和E公司设备完成邀请后,网关和设备交换完Public Key,由B平台根据静态OOB信息计算(provisioner confirmation)并发给网关。Step 4. After the gateway and the device of company E complete the invitation, the gateway and the device exchange the Public Key, and the platform B calculates (provisioner confirmation) according to the static OOB information and sends it to the gateway.
步骤5、网关将provisioner confirmation发送给设备,设备根据静态OOB信息计算设备端的device confirmation并发给网关,网关将provisioner random发送给设备,设备对provisioner confirmation校验通过后返回设备端的device random。Step 5. The gateway sends the provisioner confirmation to the device, the device calculates the device confirmation of the device according to the static OOB information and sends it to the gateway, the gateway sends the provisioner random to the device, and the device returns the device random of the device after passing the provisioner confirmation verification.
步骤6、网关上报设备的device confirmation及device random至A平台,然后A平台将device confirmation及device random发送给B平台云进行确认值认证,之后返回认证结果。Step 6. The gateway reports the device confirmation and device random of the device to platform A, and platform A sends the device confirmation and device random to platform B for confirmation value authentication, and then returns the authentication result.
步骤7、如果认证结果通过,网关和蓝牙Mesh设备完成入网配置,蓝牙Mesh设备加入蓝牙Mesh网络。Step 7. If the authentication result is passed, the gateway and the Bluetooth Mesh device complete the network access configuration, and the Bluetooth Mesh device joins the Bluetooth Mesh network.
由图1可知,云平台需要在蓝牙Mesh配网通信流程中进行蓝牙Mesh设备认证,即云平台不仅需要支持计算确认值等蓝牙Mesh设备配网的功能,还需要提供蓝牙设备接入认证功能;这种蓝牙设备接入认证方式不具备通用性,如不适用于非蓝牙Mesh设备的接入认证、以及不适用于与网关属于同一个厂商的蓝牙设备的接入认证。As can be seen from Figure 1, the cloud platform needs to perform Bluetooth Mesh device authentication in the Bluetooth Mesh distribution network communication process, that is, the cloud platform not only needs to support the functions of Bluetooth Mesh device network distribution such as calculating confirmation values, but also needs to provide Bluetooth device access authentication functions; This Bluetooth device access authentication method is not universal. For example, it is not suitable for access authentication of non-Bluetooth Mesh devices and access authentication of Bluetooth devices belonging to the same manufacturer as the gateway.
本申请实施例的技术方案可以应用于各种通信系统,例如:全球移动通讯(global system of mobile communication,GSM)系统、码分多址(code division multiple access,CDMA)系统、宽带码分多址(wideband code division multiple access,WCDMA)系统、通用分组无线业务(general packet radio service,GPRS)、长期演进(long term evolution,LTE)系统、LTE频分双工(frequency division duplex,FDD)系统、LTE时分双工(time division duplex,TDD)系统、先进的长期演进(advanced long term evolution,LTE-A)系统、新无线(new radio,NR)系统、NR系统的演进系统、非授权频段上的LTE(LTE-based access to unlicensed spectrum,LTE-U)系统、非授权频段上的NR(NR-based access to unlicensed spectrum,NR-U)系统、通用移动通信系统(universal mobile telecommunication system,UMTS)、全球互联微波接入(worldwide interoperability for microwave access,WiMAX)通信系统、无线局域网(wireless local  area networks,WLAN)、无线保真(wireless fidelity,WiFi)、下一代通信系统或其他通信系统等。The technical solutions of the embodiments of the present application can be applied to various communication systems, such as: global system of mobile communication (GSM) system, code division multiple access (CDMA) system, wideband code division multiple access (wideband code division multiple access, WCDMA) system, general packet radio service (general packet radio service, GPRS), long term evolution (long term evolution, LTE) system, LTE frequency division duplex (frequency division duplex, FDD) system, LTE Time division duplex (TDD) systems, advanced long term evolution (LTE-A) systems, new radio (NR) systems, evolution systems of NR systems, LTE on unlicensed bands (LTE-based access to unlicensed spectrum, LTE-U) system, NR (NR-based access to unlicensed spectrum, NR-U) system on unlicensed frequency bands, universal mobile telecommunication system (UMTS), global Worldwide interoperability for microwave access (WiMAX) communication systems, wireless local area networks (WLAN), wireless fidelity (WiFi), next-generation communication systems or other communication systems, etc.
本申请实施例描述的系统架构以及业务场景是为了更加清楚的说明本申请实施例的技术方案,并不构成对于本申请实施例提供的技术方案的限定,本领域普通技术人员可知,随着网络架构的演变和新业务场景的出现,本申请实施例提供的技术方案对于类似的技术问题,同样适用。The system architecture and service scenarios described in the embodiments of the present application are for the purpose of illustrating the technical solutions of the embodiments of the present application more clearly, and do not constitute limitations on the technical solutions provided by the embodiments of the present application. The evolution of the architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
本申请实施例中涉及的网络设备,可以是普通的基站(如NodeB或eNB或者gNB)、新无线控制器(new radio controller,NR controller)、集中式网元(centralized unit)、新无线基站、射频拉远模块、微基站、中继(relay)、分布式网元(distributed unit)、接收点(transmission reception point,TRP)、传输点(transmission point,TP)或者任何其它设备。本申请的实施例对网络设备所采用的具体技术和具体设备形态不做限定。为方便描述,本申请所有实施例中,上述为终端设备提供无线通信功能的装置统称为网络设备。The network equipment involved in the embodiments of this application may be a common base station (such as a NodeB or eNB or gNB), a new radio controller (NR controller), a centralized network element (centralized unit), a new radio base station, Remote radio module, micro base station, relay, distributed unit (distributed unit), reception point (transmission reception point, TRP), transmission point (transmission point, TP) or any other equipment. The embodiments of the present application do not limit the specific technology and specific device form adopted by the network device. For the convenience of description, in all the embodiments of this application, the above-mentioned apparatuses for providing wireless communication functions for terminal equipment are collectively referred to as network equipment.
在本申请实施例中,终端设备可以是任意的终端,比如,终端设备可以是机器类通信的用户设备。也就是说,该终端设备也可称之为用户设备UE、移动台(mobile station,MS)、移动终端(mobile terminal)、终端(terminal)等,该终端设备可以经无线接入网(radio access network,RAN)与一个或多个核心网进行通信,例如,终端设备可以是移动电话(或称为“蜂窝”电话)、具有移动终端的计算机等,例如,终端设备还可以是便携式、袖珍式、手持式、计算机内置的或者车载的移动装置,它们与无线接入网交换语言和/或数据。本申请实施例中不做具体限定。In this embodiment of the present application, the terminal device may be any terminal, for example, the terminal device may be user equipment of machine type communication. That is to say, the terminal device can also be called user equipment UE, mobile station (mobile station, MS), mobile terminal (mobile terminal), terminal (terminal), etc. network, RAN) communicates with one or more core networks, for example, the terminal device can be a mobile phone (or "cellular" phone), a computer with a mobile terminal, etc., for example, the terminal device can also be a portable, pocket-sized , handheld, computer built-in or vehicle mounted mobile devices that exchange language and/or data with the radio access network. There is no specific limitation in the embodiments of the present application.
可选的,网络设备和终端设备可以部署在陆地上,包括室内或室外、手持或车载;也可以部署在水面上;还可以部署在空中的飞机、气球和人造卫星上。本申请的实施例对网络设备和终端设备的应用场景不做限定。Optionally, network equipment and terminal equipment can be deployed on land, including indoor or outdoor, handheld or vehicle-mounted; they can also be deployed on water; they can also be deployed on aircraft, balloons and artificial satellites in the air. The embodiments of the present application do not limit the application scenarios of the network device and the terminal device.
可选的,网络设备和终端设备之间以及终端设备和终端设备之间可以通过授权频谱(licensed spectrum)进行通信,也可以通过非授权频谱(unlicensed spectrum)进行通信,也可以同时通过授权频谱和非授权频谱进行通信。网络设备和终端设备之间以及终端设备和终端设备之间可以通过7吉兆赫(gigahertz,GHz)以下的频谱进行通信,也可以通过7GHz以上的频谱进行通信,还可以同时使用7GHz以下的频谱和7GHz以上的频谱进行通信。本申请的实施例对网络设备和终端设备之间所使用的频谱资源不做限定。Optionally, communication between the network device and the terminal device and between the terminal device and the terminal device can be performed through licensed spectrum (licensed spectrum), or through unlicensed spectrum (unlicensed spectrum), or both through licensed spectrum and unlicensed spectrum for communications. Communication between network equipment and terminal equipment and between terminal equipment and terminal equipment can be carried out through the spectrum below 7 gigahertz (GHz), or through the frequency spectrum above 7 GHz, and can also use the frequency spectrum below 7 GHz and the frequency spectrum at the same time. The spectrum above 7GHz is used for communication. The embodiments of the present application do not limit the spectrum resources used between the network device and the terminal device.
通常来说,传统的通信系统支持的连接数有限,也易于实现,然而,随着通信技术的发展,移动通信系统将不仅支持传统的通信,还将支持例如,设备到设备(device to device,D2D)通信,机器到机器(machine to machine,M2M)通信,机器类型通信(machine type communication,MTC),以及车辆间(vehicle to vehicle,V2V)通信等,本申请实施例也可以应用于这些通信系统。Generally speaking, traditional communication systems support a limited number of connections and are easy to implement. However, with the development of communication technology, mobile communication systems will not only support traditional communication, but also support, for example, device to device (device to device, D2D) communication, machine to machine (M2M) communication, machine type communication (MTC), and vehicle to vehicle (V2V) communication, etc., the embodiments of the present application can also be applied to these communications system.
本申请实施例提供的应用于网关的蓝牙设备接入认证方法的一种可选处理流程,如图2所示,可以包括以下步骤:An optional processing flow of the Bluetooth device access authentication method applied to the gateway provided by the embodiment of the present application, as shown in FIG. 2 , may include the following steps:
步骤S201,网关确定蓝牙设备的校验凭证。Step S201, the gateway determines the verification certificate of the Bluetooth device.
在一些实施例中,蓝牙Mesh设备主动向网关发送蓝牙Mesh设备的校验凭证。In some embodiments, the Bluetooth Mesh device actively sends the verification credential of the Bluetooth Mesh device to the gateway.
在另一些实施例中,可以由网关向蓝牙Mesh设备发送第一请求消息,所述第一请求消息用于请求获取蓝牙Mesh设备的校验凭证;蓝牙Mesh设备在接收到第一请求消息之后,向网关发送蓝牙Mesh设备的校验凭证。In other embodiments, the gateway may send a first request message to the Bluetooth Mesh device, where the first request message is used to request to obtain the verification credential of the Bluetooth Mesh device; after receiving the first request message, the Bluetooth Mesh device, Send the verification credentials of the Bluetooth Mesh device to the gateway.
步骤S202,网关向云平台发送所述蓝牙设备的校验凭证,所述蓝牙设备的校验凭证用于所述云平台确定所述蓝牙设备的合法性。Step S202, the gateway sends the verification credential of the Bluetooth device to the cloud platform, where the verification credential of the Bluetooth device is used by the cloud platform to determine the validity of the Bluetooth device.
在一些实施例中,网关通过向网关接入的云平台发送蓝牙Mesh设备的校验凭证,请求网关接入的云平台校验蓝牙Mesh设备的合法性。网关接入的云平台根据蓝牙设备广播的未配网广播包中的CID判断蓝牙Mesh设备不是基于云平台开发的设备,则网关接入的云平台根据未配网广播包中的CID获取对应的设备认证平台;网关接入的云平台向设备认证平台发送蓝牙Mesh设备的校验凭证,请求设备认证平台校验蓝牙Mesh设备的合法性。或者,若网关接入的云平台根据未配网广播包中的CID判断蓝牙Mesh设备是基于云平台开发的设备,则网关接入 的云平台校验蓝牙Mesh设备的合法性。In some embodiments, the gateway requests the cloud platform accessed by the gateway to verify the validity of the Bluetooth Mesh device by sending the verification credential of the Bluetooth Mesh device to the cloud platform accessed by the gateway. The cloud platform connected by the gateway determines that the Bluetooth Mesh device is not a device developed based on the cloud platform according to the CID in the unconfigured broadcast packet broadcast by the Bluetooth device, and the cloud platform connected by the gateway obtains the corresponding CID according to the CID in the unconfigured broadcast packet. Device authentication platform; the cloud platform connected to the gateway sends the verification certificate of the Bluetooth Mesh device to the device authentication platform, and requests the device authentication platform to verify the legitimacy of the Bluetooth Mesh device. Or, if the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is a device developed based on the cloud platform according to the CID in the unconfigured network broadcast packet, the cloud platform connected by the gateway verifies the validity of the Bluetooth Mesh device.
在一些实施例中,所述方法还可以包括:In some embodiments, the method may further include:
步骤S203,所述网关接收所述云平台发送的设备校验结果,所述设备校验结果用于指示所述蓝牙设备的合法性。Step S203, the gateway receives a device verification result sent by the cloud platform, where the device verification result is used to indicate the validity of the Bluetooth device.
在一些实施例中,所述方法还可以包括:In some embodiments, the method may further include:
步骤S204,网关确定所述网关和/或所述的云平台的校验凭证。Step S204, the gateway determines the verification credential of the gateway and/or the cloud platform.
在一些实施方式中,网关预先存储了网关和/或云平台的校验凭证;如在网关出厂时或者网关上电激活时预先存储了网关和/或云平台的校验凭证。In some embodiments, the gateway pre-stores the verification credential of the gateway and/or the cloud platform; for example, the verification credential of the gateway and/or the cloud platform is pre-stored when the gateway leaves the factory or when the gateway is powered on and activated.
在另一些实施方式中,网关向云平台发送第二请求消息,所述第二请求消息用于请求获取所述网关和/或所述云平台的校验凭证;所述网关接收所述云平台发送的所述网关和/或所述云平台的校验凭证。In other embodiments, the gateway sends a second request message to the cloud platform, where the second request message is used to request to obtain the verification credential of the gateway and/or the cloud platform; the gateway receives the cloud platform The sent verification credential of the gateway and/or the cloud platform.
步骤S205,网关向所述蓝牙设备发送所述网关和/或所述云平台的校验凭证,所述网关和/或所述云平台的校验凭证用于所述蓝牙设备校验所述网关/或所述云平台的合法性。Step S205, the gateway sends the verification credential of the gateway and/or the cloud platform to the Bluetooth device, and the verification credential of the gateway and/or the cloud platform is used for the Bluetooth device to verify the gateway /or the legality of the cloud platform.
在一些实施例中,网关可以主动向蓝牙设备发送所述网关和/或所述云平台的校验凭证。网关也可以接收所述蓝牙设备发送的第三请求消息,所述第三请求消息用于请求获取所述网关和/或所述云平台的校验凭证;网关根据第三请求消息向蓝牙设备发送所述网关和/或所述云平台的校验凭证。In some embodiments, the gateway may actively send the verification credential of the gateway and/or the cloud platform to the Bluetooth device. The gateway may also receive a third request message sent by the Bluetooth device, where the third request message is used to request to obtain the verification credential of the gateway and/or the cloud platform; the gateway sends the Bluetooth device according to the third request message Verification credentials of the gateway and/or the cloud platform.
步骤S206,网关接收所述蓝牙设备发送的网关和/或所述云平台校验结果,所述网关和/或所述云平台校验结果用于指示针对所述网关和/或所述云平台的合法性。Step S206, the gateway receives the gateway and/or the cloud platform verification result sent by the Bluetooth device, and the gateway and/or the cloud platform verification result is used to indicate the gateway and/or the cloud platform. legitimacy.
在一些实施例中,所述方法还可以包括:In some embodiments, the method may further include:
步骤S207,网关根据所述蓝牙设备的校验标记,向云平台发送第四请求消息,所述第四请求消息用于请求获取设备认证平台的校验凭证;所述设备认证平台的校验凭证用于所述蓝牙设备校验所述设备认证平台的合法性。Step S207, the gateway sends a fourth request message to the cloud platform according to the verification mark of the Bluetooth device, where the fourth request message is used to request to obtain the verification credential of the device authentication platform; the verification credential of the device authentication platform It is used for the Bluetooth device to verify the legitimacy of the device authentication platform.
步骤S208,网关接收所述云平台发送的所述设备认证平台的校验凭证,所述网关向所述蓝牙设备发送所述设备认证平台的校验凭证。Step S208, the gateway receives the verification credential of the device authentication platform sent by the cloud platform, and the gateway sends the verification credential of the device authentication platform to the Bluetooth device.
步骤S209,所述网关请求所述云平台添加所述蓝牙设备。Step S209, the gateway requests the cloud platform to add the Bluetooth device.
在一些实施例中,若蓝牙设备、网关和/或云平台、设备认证平台的校验结果均合法,网关向所述蓝牙设备发送用于蓝牙设备入网配置的配置信息之后,所述网关也可以请求所述云平台添加所述蓝牙设备;具体的,所述网关向所述云平台发送所述蓝牙设备的信息,所述蓝牙设备的信息用于所述云平台添加所述蓝牙设备。In some embodiments, if the verification results of the Bluetooth device, the gateway and/or the cloud platform and the device authentication platform are all valid, after the gateway sends the configuration information for the network access configuration of the Bluetooth device to the Bluetooth device, the gateway can also Request the cloud platform to add the Bluetooth device; specifically, the gateway sends the information of the Bluetooth device to the cloud platform, and the information of the Bluetooth device is used for the cloud platform to add the Bluetooth device.
在一些实施例中,若蓝牙设备、网关和/或云平台、设备认证平台的校验结果中的一个不合法,则将蓝牙设备从蓝牙Mesh网络中删除或者停止蓝牙Mesh配网。In some embodiments, if one of the verification results of the Bluetooth device, the gateway and/or the cloud platform and the device authentication platform is invalid, the Bluetooth device is deleted from the Bluetooth Mesh network or the Bluetooth Mesh network configuration is stopped.
在一些实施例中,所述方法还可以包括:In some embodiments, the method may further include:
步骤S200,网关接收所述蓝牙设备发送的校验标记,所述校验标记用于指示需要检验的对象。Step S200, the gateway receives a check mark sent by the Bluetooth device, where the check mark is used to indicate an object to be checked.
在一些实施例中,蓝牙设备向网关广播未配网广播包(Unprovisioned Device Beacon);其中,未配网广播包中包括的设备通用唯一标识(Universally Unique Identifier,UUID)是用于识别设备的关键信息。In some embodiments, the Bluetooth device broadcasts an Unprovisioned Device Beacon to the gateway; wherein, the Universal Unique Identifier (UUID) included in the unprovisioned broadcast packet is the key for identifying the device information.
在一些实施例中,设备UUID的格式如下表1所示:设备UUID包括校验标记(VerifiFlag),校验标记用于指示合法性认证的对象;如:校验标记用于指示下述中的至少一项:认证蓝牙Mesh设备、认证网关、认证云平台和认证设备认证平台。设备UUID还可以包括:CID、DID和PID中的一项或多项;其中,CID用于表征设备的厂商/云平台标识,DID用于表征设备标识,PID用于表征设备类型标识。本申请实施例中,校验标记用于指示认证蓝牙Mesh设备。In some embodiments, the format of the device UUID is shown in Table 1 below: the device UUID includes a verification flag (VerifiFlag), and the verification flag is used to indicate the object of legality authentication; for example, the verification flag is used to indicate the following At least one: Certified Bluetooth Mesh Device, Certified Gateway, Certified Cloud Platform, and Certified Device Certification Platform. The device UUID may also include: one or more of CID, DID, and PID; wherein, the CID is used to represent the manufacturer/cloud platform identifier of the device, the DID is used to represent the device identifier, and the PID is used to represent the device type identifier. In the embodiment of the present application, the check mark is used to indicate the authentication of the Bluetooth Mesh device.
表1:设备UUID格式Table 1: Device UUID Format
Figure PCTCN2020107207-appb-000001
Figure PCTCN2020107207-appb-000001
Figure PCTCN2020107207-appb-000002
Figure PCTCN2020107207-appb-000002
本申请实施例提供的应用于云平台的蓝牙设备接入认证方法的一种可选处理流程,如图3所示,可以包括以下步骤:An optional processing flow of the Bluetooth device access authentication method applied to the cloud platform provided by the embodiment of the present application, as shown in FIG. 3 , may include the following steps:
步骤S301,云平台接收网关发送的蓝牙设备的校验凭证。Step S301, the cloud platform receives the verification certificate of the Bluetooth device sent by the gateway.
步骤S302,云平台基于所述蓝牙设备的校验凭证,确定所述蓝牙设备的合法性。Step S302, the cloud platform determines the validity of the Bluetooth device based on the verification certificate of the Bluetooth device.
在一些实施例中,若所述蓝牙设备不是所述云平台对应的设备,则所述云平台向设备认证平台发送携带所述蓝牙设备的校验凭证的第五请求消息;所述第五请求消息用于请求所述设备认证平台校验所述蓝牙设备的合法性;所述云平台接收所述设备认证平台发送的设备校验结果,所述设备校验结果用于指示所述蓝牙设备的合法性。In some embodiments, if the Bluetooth device is not a device corresponding to the cloud platform, the cloud platform sends a fifth request message carrying the verification credential of the Bluetooth device to the device authentication platform; the fifth request The message is used to request the device authentication platform to verify the validity of the Bluetooth device; the cloud platform receives the device verification result sent by the device authentication platform, and the device verification result is used to indicate the Bluetooth device's validity. legality.
在一些实施例中,若所述蓝牙设备是所述云平台对应的设备,则所述云平台校验所述蓝牙设备的合法性。In some embodiments, if the Bluetooth device is a device corresponding to the cloud platform, the cloud platform verifies the validity of the Bluetooth device.
在一些实施例中,所述方法还可以包括:In some embodiments, the method may further include:
步骤S303,云平台接收所述网关发送的第二请求消息,所述第二请求消息用于请求获取所述网关和/或所述云平台的校验凭证;云平台确认所述网关和/或所述云平台的校验凭证。Step S303, the cloud platform receives a second request message sent by the gateway, where the second request message is used to request to obtain the verification credential of the gateway and/or the cloud platform; the cloud platform confirms the gateway and/or The verification certificate of the cloud platform.
在具体实施时,若所述蓝牙设备不是所述云平台对应的设备,则所述云平台确定所述蓝牙设备对应的设备认证平台;所述云平台向所述设备认证平台发送第六请求消息;所述第六请求消息携带所述网关和/或所述云平台的标识,用于请求获取所述网关和/或所述云平台的校验凭证。所述云平台接收所述设备认证平台发送的所述网关和/或所述云平台的校验凭证,并向所述网关发送所述网关和/或所述云平台的校验凭证。During specific implementation, if the Bluetooth device is not a device corresponding to the cloud platform, the cloud platform determines a device authentication platform corresponding to the Bluetooth device; the cloud platform sends a sixth request message to the device authentication platform ; the sixth request message carries the identifier of the gateway and/or the cloud platform, and is used to request to obtain the verification credential of the gateway and/or the cloud platform. The cloud platform receives the verification credential of the gateway and/or the cloud platform sent by the device authentication platform, and sends the verification credential of the gateway and/or the cloud platform to the gateway.
在一些实施例中,所述方法还可以包括:In some embodiments, the method may further include:
步骤S304,云平台接收所述网关发送第四请求消息,所述第四请求消息用于请求获取设备认证平台的校验凭证。Step S304, the cloud platform receives a fourth request message sent by the gateway, where the fourth request message is used to request to obtain a verification credential of the device authentication platform.
步骤S305,所述云平台确定所述设备认证平台的校验凭证。Step S305, the cloud platform determines the verification credential of the device authentication platform.
在一些实施例中,所述云平台向所述设备认证平台发送第七请求消息,所述第七请求消息用于请求获取所述设备认证平台的校验凭证;所述云平台接收所述设备认证平台发送的所述设备认证平台的校验凭证,并向所述网关发送所述设备认证平台的校验凭证。In some embodiments, the cloud platform sends a seventh request message to the device authentication platform, where the seventh request message is used to request to obtain the verification credential of the device authentication platform; the cloud platform receives the device The verification credential of the device authentication platform sent by the authentication platform, and the verification credential of the device authentication platform is sent to the gateway.
在一些实施例中,所述方法还可以包括:In some embodiments, the method may further include:
步骤S306,云平台添加所述蓝牙设备。Step S306, the cloud platform adds the Bluetooth device.
若蓝牙设备、网关和/或云平台、设备认证平台的校验结果均合法,则所述网关请求所述云平台添加所述蓝牙设备;具体的,所述网关向所述云平台发送所述蓝牙设备的信息,所述蓝牙设备的信息用于所述云平台添加所述蓝牙设备;网关向所述蓝牙设备发送配置信息,所述配置信息用于执行蓝牙设备入网配置。If the verification results of the Bluetooth device, the gateway and/or the cloud platform and the device authentication platform are all valid, the gateway requests the cloud platform to add the Bluetooth device; specifically, the gateway sends the cloud platform the Information of the Bluetooth device, the information of the Bluetooth device is used for the cloud platform to add the Bluetooth device; the gateway sends configuration information to the Bluetooth device, and the configuration information is used to perform the network access configuration of the Bluetooth device.
在一些实施例中,若蓝牙设备、网关和/或云平台、设备认证平台的校验结果中的一个不合法,则将蓝牙设备从蓝牙Mesh网络中删除或者停止蓝牙Mesh配网。In some embodiments, if one of the verification results of the Bluetooth device, the gateway and/or the cloud platform and the device authentication platform is invalid, the Bluetooth device is deleted from the Bluetooth Mesh network or the Bluetooth Mesh network configuration is stopped.
本申请实施例提供的应用于设备认证平台的蓝牙设备接入认证方法的一种可选处理流程,如图4所示,可以包括以下步骤:An optional processing flow of the Bluetooth device access authentication method applied to the device authentication platform provided by the embodiment of the present application, as shown in FIG. 4 , may include the following steps:
步骤S401,设备认证平台接收云平台发送的第五请求消息;所述第五请求消息包括蓝牙设备的校验凭证。Step S401, the device authentication platform receives a fifth request message sent by the cloud platform; the fifth request message includes a verification credential of the Bluetooth device.
步骤S402,设备认证平台根据所述蓝牙设备的校验凭证,校验所述蓝牙设备的合法性。Step S402, the device authentication platform verifies the validity of the Bluetooth device according to the verification certificate of the Bluetooth device.
在一些实施例中,所述方法还可以包括:In some embodiments, the method may further include:
步骤S403,设备认证平台接收所述云平台发送的第六请求消息;所述第六请求消息携带所述网关和/或所述云平台的标识,用于请求获取所述网关和/或所述云平台的校验凭证。Step S403, the device authentication platform receives the sixth request message sent by the cloud platform; the sixth request message carries the identifier of the gateway and/or the cloud platform, and is used to request to obtain the gateway and/or the The verification certificate of the cloud platform.
步骤S404,设备认证平台根据所述网关和/或所述云平台的标识,生成所述网关和/或所述云平台的校验凭证;所述设备认证平台向所述云平台发送所述网关和/或所述云平台的校验凭证。Step S404, the device authentication platform generates a verification credential of the gateway and/or the cloud platform according to the identifier of the gateway and/or the cloud platform; the device authentication platform sends the gateway to the cloud platform and/or the verification credential of the cloud platform.
本申请实施例提供的应用于蓝牙设备的蓝牙设备接入认证方法的一种可选处理流程,如图5所示,可以包括以下步骤:An optional processing flow of the Bluetooth device access authentication method applied to a Bluetooth device provided by the embodiment of the present application, as shown in FIG. 5 , may include the following steps:
步骤S501,蓝牙设备向网关发送蓝牙设备的校验凭证,所述蓝牙设备的校验凭证用于确定所述蓝牙设备的合法性。Step S501, the Bluetooth device sends a verification certificate of the Bluetooth device to the gateway, and the verification certificate of the Bluetooth device is used to determine the validity of the Bluetooth device.
在一些实施例中,可以是蓝牙设备主动向网关发送蓝牙设备的校验凭证。也可以是蓝牙设备接收所述网关发送的第一请求消息,所述第一请求消息用于请求获取所述蓝牙设备的校验凭证;蓝牙设备根据第一请求消息向网关发送蓝牙设备的校验凭证。In some embodiments, the Bluetooth device may actively send the verification credential of the Bluetooth device to the gateway. It can also be that the bluetooth device receives the first request message sent by the gateway, and the first request message is used to request to obtain the verification credential of the bluetooth device; the bluetooth device sends the verification certificate of the bluetooth device to the gateway according to the first request message certificate.
在一些实施例中,所述方法还可以包括:In some embodiments, the method may further include:
步骤S502,所述蓝牙设备接收所述网关和/或所述云平台的校验凭证,所述网关和/或所述云平台的校验凭证用于所述蓝牙设备校验所述网关/或所述云平台的合法性。Step S502, the Bluetooth device receives the verification credential of the gateway and/or the cloud platform, and the verification credential of the gateway and/or the cloud platform is used by the Bluetooth device to verify the gateway/or The legitimacy of the cloud platform.
在一些实施例中,可以是蓝牙设备向网关发送第三请求消息,所述第三请求消息用于请求获取所述网关和/或所述云平台的校验凭证。网关获取到所述网关和/或所述云平台的校验凭证之后,网关向蓝牙设备发送所述网关和/或所述云平台的校验凭证。In some embodiments, the Bluetooth device may send a third request message to the gateway, where the third request message is used to request to obtain the verification credential of the gateway and/or the cloud platform. After the gateway obtains the verification credential of the gateway and/or the cloud platform, the gateway sends the verification credential of the gateway and/or the cloud platform to the Bluetooth device.
步骤S503,蓝牙设备根据所述网关和/或所述云平台的校验凭证,校验所述网关和/或所述云平台的合法性。Step S503, the Bluetooth device verifies the validity of the gateway and/or the cloud platform according to the verification credentials of the gateway and/or the cloud platform.
步骤S504,蓝牙设备向所述网关发送所述蓝牙设备发送的网关和/或所述云平台校验结果,所述网关和/或所述云平台校验结果用于指示针对所述网关和/或所述云平台的合法性。Step S504, the bluetooth device sends the gateway and/or the cloud platform verification result sent by the bluetooth device to the gateway, and the gateway and/or the cloud platform verification result is used to indicate the gateway and/or the cloud platform verification result. or the legality of the cloud platform.
在一些实施例中,所述方法还可以包括:In some embodiments, the method may further include:
步骤S505,蓝牙设备接收所述网关发送的设备认证平台的校验凭证.Step S505, the Bluetooth device receives the verification certificate of the device authentication platform sent by the gateway.
步骤S506,蓝牙设备基于所述设备认证平台的校验凭证,校验所述设备认证平台的合法性。Step S506, the Bluetooth device verifies the legitimacy of the device authentication platform based on the verification certificate of the device authentication platform.
若蓝牙设备、网关和/或云平台、设备认证平台的校验结果均合法,则蓝牙设备接收所述网关发送的配置信息,所述配置信息用于执行蓝牙设备入网配置。If the verification results of the Bluetooth device, the gateway and/or the cloud platform and the device authentication platform are all valid, the Bluetooth device receives the configuration information sent by the gateway, and the configuration information is used to perform network access configuration of the Bluetooth device.
本申请实施例中,由网关执行蓝牙设备配网,由云平台来校验蓝牙设备的合法性(即接入认证功能),将蓝牙设备配网和接入认证功能从云平台中解耦,提高对蓝牙设备接入认证的通用性。In the embodiment of this application, the gateway performs the network configuration of the Bluetooth device, the cloud platform verifies the legality of the Bluetooth device (that is, the access authentication function), and decouples the network configuration and access authentication functions of the Bluetooth device from the cloud platform. Improve the versatility of Bluetooth device access authentication.
在完成蓝牙Mesh配网之前,由网关校验蓝牙设备的合法性为例,本申请实施例提供的蓝牙设备接入认证方法的第一种可选详细处理流程,如图6所示,包括以下步骤:Before completing the Bluetooth Mesh network configuration, the validity of the Bluetooth device is checked by the gateway as an example. The first optional detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application, as shown in FIG. 6 , includes the following step:
步骤S601,蓝牙Mesh设备向网关发送未配网广播包。Step S601, the Bluetooth Mesh device sends an unconfigured network broadcast packet to the gateway.
在一些实施例中,若蓝牙Mesh设备处于未配网状态,则蓝牙Mesh设备广播未配网广播包;其中,未配网广播包中包括的UUID是用于识别设备的关键信息。其中,设备UUID的格式上述表1所示。In some embodiments, if the Bluetooth Mesh device is in an unconfigured state, the Bluetooth Mesh device broadcasts an unconfigured broadcast packet, wherein the UUID included in the unconfigured broadcast packet is key information for identifying the device. The format of the device UUID is shown in Table 1 above.
步骤S602-S603,蓝牙Mesh设备和网关启动蓝牙Mesh配网流程。Steps S602-S603, the Bluetooth Mesh device and the gateway start the Bluetooth Mesh network configuration process.
在一些实施例中,启动蓝牙Mesh配网流程可以包括:计算安全密钥,安全密钥用于在蓝牙Mesh设备和网关之间对校验凭证进行加密/解密处理;其中,安全密钥可以包括会话密钥、设备密钥、网络密钥和应用密钥中的一种或多种。In some embodiments, starting the Bluetooth Mesh network configuration process may include: calculating a security key, where the security key is used to encrypt/decrypt the verification credential between the Bluetooth Mesh device and the gateway; wherein the security key may include One or more of session key, device key, network key, and application key.
本申请实施例中,在蓝牙Mesh设备和网关执行蓝牙Mesh配网之前,网关校验蓝牙Mesh设备的合法性;若网关校验蓝牙Mesh设备合法,则蓝牙Mesh设备和网关继续执行蓝牙Mesh设备入网配置;若网关校验蓝牙Mesh设备不合法,终止蓝牙Mesh配网。In the embodiment of the present application, before the Bluetooth Mesh device and the gateway perform the Bluetooth Mesh configuration network, the gateway verifies the validity of the Bluetooth Mesh device; if the gateway verifies that the Bluetooth Mesh device is valid, the Bluetooth Mesh device and the gateway continue to perform the Bluetooth Mesh device network access Configuration; if the gateway verifies that the Bluetooth Mesh device is invalid, it will terminate the Bluetooth Mesh network configuration.
步骤S604,网关获取蓝牙Mesh设备的校验凭证。Step S604, the gateway obtains the verification certificate of the Bluetooth Mesh device.
在一些实施例中,未配网广播包中的校验标记指示校验蓝牙Mesh设备,则蓝牙Mesh设备主动向网关发送蓝牙Mesh设备的校验凭证。In some embodiments, the verification mark in the unconfigured network broadcast packet indicates to verify the Bluetooth Mesh device, and the Bluetooth Mesh device actively sends the verification certificate of the Bluetooth Mesh device to the gateway.
在另一些实施例中,可以由网关向蓝牙Mesh设备发送第一请求消息,所述第一请求消息 用于请求获取蓝牙Mesh设备的校验凭证;蓝牙Mesh设备在接收到第一请求消息之后,向网关发送蓝牙Mesh设备的校验凭证。In other embodiments, the gateway may send a first request message to the Bluetooth Mesh device, where the first request message is used to request to obtain the verification credential of the Bluetooth Mesh device; after receiving the first request message, the Bluetooth Mesh device, Send the verification credentials of the Bluetooth Mesh device to the gateway.
步骤S605,网关向网关接入的云平台发送蓝牙Mesh设备的校验凭证。Step S605, the gateway sends the verification certificate of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
在一些实施例中,网关通过向网关接入的云平台发送蓝牙Mesh设备的校验凭证,请求网关接入的云平台校验蓝牙Mesh设备的合法性。In some embodiments, the gateway requests the cloud platform accessed by the gateway to verify the validity of the Bluetooth Mesh device by sending the verification credential of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
步骤S606,网关接入的云平台请求设备认证平台校验蓝牙Mesh设备的合法性。Step S606, the cloud platform accessed by the gateway requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
在一些实施例中,若网关接入的云平台根据未配网广播包中的CID判断蓝牙Mesh设备不是基于云平台开发的设备,则网关接入的云平台根据未配网广播包中的CID获取对应的设备认证平台;网关接入的云平台向设备认证平台发送蓝牙Mesh设备的校验凭证,请求设备认证平台校验蓝牙Mesh设备的合法性。In some embodiments, if the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is not a device developed based on the cloud platform according to the CID in the unconfigured broadcast packet, the cloud platform accessed by the gateway determines according to the CID in the unconfigured broadcast packet. Obtain the corresponding device authentication platform; the cloud platform connected to the gateway sends the verification certificate of the Bluetooth Mesh device to the device authentication platform, and requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
在另一些实施例中,若网关接入的云平台根据未配网广播包中的CID判断蓝牙Mesh设备是基于云平台开发的设备,则网关接入的云平台校验蓝牙Mesh设备的合法性。In other embodiments, if the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is a device developed based on the cloud platform according to the CID in the unconfigured network broadcast packet, the cloud platform accessed by the gateway verifies the validity of the Bluetooth Mesh device .
步骤S607,设备认证平台校验蓝牙Mesh设备的合法性。Step S607, the device authentication platform verifies the validity of the Bluetooth Mesh device.
在一些实施例中,若蓝牙Mesh设备的校验凭证是安全证书,则设备认证平台校验该安全证书是否合法;若校验该安全证书合法,则认证蓝牙Mesh设备合法;若校验该安全证书不合法,则认证蓝牙Mesh设备不合法。In some embodiments, if the verification certificate of the Bluetooth Mesh device is a security certificate, the device authentication platform verifies whether the security certificate is legal; if the security certificate is verified to be legal, it verifies that the Bluetooth Mesh device is legal; If the certificate is invalid, the authentication of the Bluetooth Mesh device is invalid.
在具体实施时,设备认证平台可以采用非对称加密或对称加密方法校验蓝牙Mesh设备的合法性。例如,对于非对称加密方法,蓝牙Mesh设备预存设备认证平台的公钥,用设备认证平台的公钥加密该蓝牙Mesh设备的校验凭证,设备认证平台收到的校验凭证后用自己的私钥进行解密,如果能正常解密,证明是合法的蓝牙Mesh设备,如果不能正常解密,则证明是非法的蓝牙Mesh设备。对于对称加密方法,设备认证平台和蓝牙Mesh设备预共享相同的密钥(即预共享密钥),蓝牙Mesh设备用预共享密钥加密蓝牙Mesh设备的校验凭证,设备认证平台收到的校验凭证后用相同的预共享密钥进行解密,如果能正常解密,证明是合法的蓝牙Mesh设备;如果不能正常解密,则证明是非法的蓝牙Mesh设备。During specific implementation, the device authentication platform can use asymmetric encryption or symmetric encryption to verify the legitimacy of the Bluetooth Mesh device. For example, for the asymmetric encryption method, the Bluetooth Mesh device pre-stores the public key of the device authentication platform, encrypts the verification certificate of the Bluetooth Mesh device with the public key of the device authentication platform, and uses its own private key after receiving the verification certificate. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device. For the symmetric encryption method, the device authentication platform and the Bluetooth Mesh device pre-share the same key (ie, the pre-shared key), and the Bluetooth Mesh device uses the pre-shared key to encrypt the verification credentials of the Bluetooth Mesh device. After verifying the certificate, decrypt it with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
步骤S608,设备认证平台向网关接入的云平台反馈蓝牙Mesh设备的校验结果。Step S608, the device authentication platform feeds back the verification result of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
步骤S609,网关接入的云平台向网关反馈蓝牙Mesh设备的校验结果。Step S609, the cloud platform connected to the gateway feeds back the verification result of the Bluetooth Mesh device to the gateway.
步骤S610,若蓝牙Mesh设备的校验结果为合法,则网关执行蓝牙Mesh设备入网配置。Step S610, if the verification result of the Bluetooth Mesh device is valid, the gateway executes the network access configuration of the Bluetooth Mesh device.
在一些实施例中,若蓝牙Mesh设备的校验结果为合法,则网关启动蓝牙Mesh入网配置数据分发,向蓝牙Mesh设备发送网络地址和安全密钥(如网络密钥和/或设备密钥)等配置信息,完成蓝牙Mesh设备的入网配置过程。In some embodiments, if the verification result of the Bluetooth Mesh device is valid, the gateway starts the distribution of Bluetooth Mesh network access configuration data, and sends the network address and security key (eg, network key and/or device key) to the Bluetooth Mesh device. Wait for the configuration information to complete the network access configuration process of the Bluetooth Mesh device.
步骤S611,网关请求网关接入的云平台添加蓝牙Mesh设备。Step S611, the gateway requests the cloud platform accessed by the gateway to add a Bluetooth Mesh device.
在一些实施例中,网关向网关接入的云平台发送包括蓝牙Mesh设备的UUID在内的设备信息,网关接入的云平台添加蓝牙Mesh设备的设备信息。In some embodiments, the gateway sends device information including the UUID of the Bluetooth Mesh device to the cloud platform connected to the gateway, and the cloud platform connected to the gateway adds the device information of the Bluetooth Mesh device.
上述以蓝牙Mesh设备的校验结果为合法为例,执行步骤S610至S611。若蓝牙Mesh设备的校验结果为不合法,则网关终止蓝牙Mesh设备的入网配置流程。In the above, taking the verification result of the Bluetooth Mesh device as valid as an example, steps S610 to S611 are performed. If the verification result of the Bluetooth Mesh device is invalid, the gateway terminates the network access configuration process of the Bluetooth Mesh device.
以在完成蓝牙Mesh配网之前,由网关校验蓝牙设备的合法性,并且由蓝牙Mesh设备校验网关/云平台的合法性为例,本申请实施例提供的蓝牙设备接入认证方法的第二种可选详细处理流程,如图7所示,包括以下步骤:Taking the validity of the Bluetooth device verified by the gateway and the validity of the gateway/cloud platform verified by the Bluetooth Mesh device before completing the Bluetooth Mesh network distribution as an example, the first step of the Bluetooth device access authentication method provided by the embodiment of the present application is: Two optional detailed processing flows, as shown in Figure 7, include the following steps:
步骤S801,蓝牙Mesh设备向网关发送未配网广播包。Step S801, the Bluetooth Mesh device sends an unconfigured network broadcast packet to the gateway.
在一些实施例中,针对未配网广播包的说明与上述实施例中步骤S601相同,这里不再赘述。In some embodiments, the description for the unconfigured network broadcast packet is the same as that of step S601 in the foregoing embodiment, and details are not repeated here.
步骤S802-S803,蓝牙Mesh设备和网关启动蓝牙Mesh配网流程。Steps S802-S803, the Bluetooth Mesh device and the gateway start the Bluetooth Mesh network configuration process.
在一些实施例中,蓝牙Mesh设备和网关启动蓝牙Mesh配网流程的处理流程与上述实施例中步骤S 602-S603相同,这里不再赘述。In some embodiments, the processing flow of the Bluetooth Mesh device and the gateway to start the Bluetooth Mesh network configuration process is the same as steps S602-S603 in the above-mentioned embodiment, and details are not repeated here.
步骤S804,网关向蓝牙Mesh设备发送网关/平台的校验凭证。Step S804, the gateway sends the verification certificate of the gateway/platform to the Bluetooth Mesh device.
在一些实施例中,可以由网关主动向蓝牙Mesh设备发送网关/平台的校验凭证。In some embodiments, the gateway may actively send the gateway/platform verification credential to the Bluetooth Mesh device.
在另一些实施例中,如图步骤S804A所示,可以由蓝牙Mesh设备根据校验标记,向网关发送第三请求消息,所述第三请求消息用于请求获取网关和/或云平台的校验凭证。In other embodiments, as shown in step S804A, the Bluetooth Mesh device may send a third request message to the gateway according to the check mark, where the third request message is used to request to obtain the calibration of the gateway and/or the cloud platform. Verification certificate.
在该场景下,网关接收到第三请求消息之后,网关获取网关和/或云平台的校验凭证。网关获取网关和/或云平台的校验凭证的具体实现过程可以包括:In this scenario, after the gateway receives the third request message, the gateway obtains the verification credential of the gateway and/or the cloud platform. The specific implementation process for the gateway to obtain the verification credential of the gateway and/or the cloud platform may include:
步骤S804-1,网关向云平台发送第二请求消息,所述第二请求消息用于请求获取网关和/或云平台的校验凭证。Step S804-1, the gateway sends a second request message to the cloud platform, where the second request message is used to request to obtain the verification credential of the gateway and/or the cloud platform.
在一些实施例中,第二请求消息中携带网关/云平台的标识,用于向云平台请求获取网关和/或云平台的校验凭证。In some embodiments, the second request message carries the identifier of the gateway/cloud platform, and is used to request the cloud platform to obtain the verification credential of the gateway and/or the cloud platform.
步骤S804-2,云平台获取网关和/或云平台对应的设备认证平台信息。Step S804-2, the cloud platform obtains the device authentication platform information corresponding to the gateway and/or the cloud platform.
在一些实施例中,云平台通过CID判断蓝牙Mesh设备不是基于云平台开发的设备,需要设备认证平台进行认证,则云平台通过CID获取网关和/或云平台对应的设备认证平台信息。In some embodiments, the cloud platform determines by CID that the Bluetooth Mesh device is not a device developed based on the cloud platform, and requires a device authentication platform for authentication, then the cloud platform obtains the device authentication platform information corresponding to the gateway and/or the cloud platform through the CID.
步骤S804-3,云平台向设备认证平台发送第六请求消息;所述第六请求消用于请求获取网关和/或云平台的校验凭证。Step S804-3, the cloud platform sends a sixth request message to the device authentication platform; the sixth request message is used to request to obtain the verification credential of the gateway and/or the cloud platform.
在一些实施例中,第六请求消息中携带所述网关和/或所述云平台的标识,设备认证平台根据所述网关和/或所述云平台的标识获取所述网关和/或所述云平台的校验凭证。In some embodiments, the sixth request message carries the identifier of the gateway and/or the cloud platform, and the device authentication platform obtains the gateway and/or the cloud platform according to the identifier of the gateway and/or the cloud platform The verification certificate of the cloud platform.
步骤S804-4,设备认证平台向云平台发送网关和/或云平台的校验凭证。Step S804-4, the device authentication platform sends the verification credential of the gateway and/or the cloud platform to the cloud platform.
在一些实施例中,设备认证平台根据网关和/或云平台的标识生成通用的校验凭证(即校验凭证不区分网关或网关接入的具体云平台,对所有合法网关或网关接入的云平台是通用的),或专用于该网关/云平台的校验凭证(即校验凭证区分网关或网关接入的具体云平台,不同的合法网关或网关接入的云平台使用不同的校验凭证)。例如,设备认证平台生成的网关/云平台的校验凭证为安全证书,该安全证书中包括网关和/或云平台的唯一标识信息,只能由该网关/云平台使用该安全证书才能校验通过,其他网关/网关接入的云平台即使使用该安全证书也无法校验通过,提高接入认证的安全性。In some embodiments, the device authentication platform generates a general verification credential according to the identifier of the gateway and/or the cloud platform (that is, the verification credential does not distinguish the gateway or the specific cloud platform accessed by the gateway, and the verification credential does not distinguish the gateway or the specific cloud platform accessed by the gateway, and the verification credential is used for all legal gateways or gateways. The cloud platform is universal), or the verification certificate dedicated to the gateway/cloud platform (that is, the verification certificate distinguishes the gateway or the specific cloud platform accessed by the gateway, and different legal gateways or cloud platforms accessed by the gateway use different schools. certificate). For example, the verification credential of the gateway/cloud platform generated by the device authentication platform is a security certificate, and the security certificate includes the unique identification information of the gateway and/or the cloud platform, which can only be verified by the gateway/cloud platform using the security certificate Passed, the cloud platform accessed by other gateways/gateways cannot pass the verification even if the security certificate is used, which improves the security of access authentication.
在一些实施例中,云平台接收到设备认证平台返回的网关和/或云平台的校验凭证后,可以在本地存储网关和/或平台的校验凭证,后续需要校验网关和/或平台时,云平台直接从本地获取网关和/或平台的校验凭证,而不必再从设备认证平台获取网关和/或平台的校验凭证,简化网关和/或平台的校验流程,减少校验时延。In some embodiments, after receiving the verification credential of the gateway and/or the cloud platform returned by the device authentication platform, the cloud platform may store the verification credential of the gateway and/or the platform locally, and the gateway and/or the platform needs to be verified later When the cloud platform directly obtains the verification credentials of the gateway and/or the platform from the local, it is no longer necessary to obtain the verification credentials of the gateway and/or the platform from the device authentication platform, which simplifies the verification process of the gateway and/or the platform and reduces the verification time delay.
步骤S804-5,云平台向网关发送网关和/或云平台的校验凭证;网关将网关和/或云平台的校验凭证发送至蓝牙Mesh设备。Step S804-5, the cloud platform sends the gateway and/or the verification credential of the cloud platform to the gateway; the gateway sends the verification credential of the gateway and/or the cloud platform to the Bluetooth Mesh device.
上述步骤S804-1至S804-5是针对网关向网络侧(云平台和设备认证平台)获取网关和/或云平台的校验凭证的具体实现过程。The above steps S804-1 to S804-5 are specific implementation processes for the gateway to obtain the verification credentials of the gateway and/or the cloud platform from the network side (cloud platform and device authentication platform).
网关获取网关和/或云平台的校验凭证的具体实现过程还可以是,网关预先存储了网关和/或云平台的校验凭证;如在网关出厂时或者网关上电激活时预先存储了网关和/或云平台的校验凭证。The specific implementation process for the gateway to obtain the verification credential of the gateway and/or the cloud platform may also be that the gateway pre-stores the verification credential of the gateway and/or the cloud platform; and/or verification credentials of the cloud platform.
步骤S805,蓝牙Mesh设备根据接收的网关和/云平台的校验凭证,校验网关和/或云平台的合法性,并向网关反馈网关和/或云平台的校验结果。Step S805, the Bluetooth Mesh device verifies the validity of the gateway and/or the cloud platform according to the received verification credentials of the gateway and/or the cloud platform, and feeds back the verification result of the gateway and/or the cloud platform to the gateway.
在一些实施例中,在蓝牙Mesh设备对网关和/或云平台的校验结果为网关和/或云平台合法的情况下,本申请实施例提供的蓝牙设备接入认证方法执行如下步骤S806-S812:In some embodiments, when the verification result of the Bluetooth Mesh device on the gateway and/or the cloud platform is that the gateway and/or the cloud platform are legal, the Bluetooth device access authentication method provided in this embodiment of the present application performs the following steps S806- S812:
步骤S806,网关获取蓝牙Mesh设备的校验凭证。Step S806, the gateway obtains the verification certificate of the Bluetooth Mesh device.
在一些实施例中,未配网广播包中的校验标记指示校验蓝牙Mesh设备,则蓝牙Mesh设备主动向网关发送蓝牙Mesh设备的校验凭证。In some embodiments, the verification mark in the unconfigured network broadcast packet indicates to verify the Bluetooth Mesh device, and the Bluetooth Mesh device actively sends the verification certificate of the Bluetooth Mesh device to the gateway.
在另一些实施例中,可以由网关向蓝牙Mesh设备发送第一请求消息,所述第一请求消息用于请求获取蓝牙Mesh设备的校验凭证;蓝牙Mesh设备在接收到第一请求消息之后,向网关发送蓝牙Mesh设备的校验凭证。In other embodiments, the gateway may send a first request message to the Bluetooth Mesh device, where the first request message is used to request to obtain the verification credential of the Bluetooth Mesh device; after receiving the first request message, the Bluetooth Mesh device, Send the verification credentials of the Bluetooth Mesh device to the gateway.
步骤S807,网关向网关接入的云平台发送蓝牙Mesh设备的校验凭证。Step S807, the gateway sends the verification certificate of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
在一些实施例中,网关通过向网关接入的云平台发送蓝牙Mesh设备的校验凭证,请求网关接入的云平台校验蓝牙Mesh设备的合法性。In some embodiments, the gateway requests the cloud platform accessed by the gateway to verify the validity of the Bluetooth Mesh device by sending the verification credential of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
步骤S808,网关接入的云平台请求设备认证平台校验蓝牙Mesh设备的合法性。Step S808, the cloud platform accessed by the gateway requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
在一些实施例中,若网关接入的云平台根据未配网广播包中的CID判断蓝牙Mesh设备不 是基于云平台开发的设备,则网关接入的云平台根据未配网广播包中的CID获取对应的设备认证平台;网关接入的云平台向设备认证平台发送蓝牙Mesh设备的校验凭证,请求设备认证平台校验蓝牙Mesh设备的合法性。In some embodiments, if the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is not a device developed based on the cloud platform according to the CID in the unconfigured broadcast packet, the cloud platform accessed by the gateway determines according to the CID in the unconfigured broadcast packet. Obtain the corresponding device authentication platform; the cloud platform connected to the gateway sends the verification certificate of the Bluetooth Mesh device to the device authentication platform, and requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
在另一些实施例中,若网关接入的云平台根据未配网广播包中的CID判断蓝牙Mesh设备是基于云平台开发的设备,则网关接入的云平台校验蓝牙Mesh设备的合法性。In other embodiments, if the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is a device developed based on the cloud platform according to the CID in the unconfigured network broadcast packet, the cloud platform accessed by the gateway verifies the validity of the Bluetooth Mesh device .
步骤S809,设备认证平台校验蓝牙Mesh设备的合法性。Step S809, the device authentication platform verifies the validity of the Bluetooth Mesh device.
在一些实施例中,若蓝牙Mesh设备的校验凭证是安全证书,则设备认证平台校验该安全证书是否合法;若校验该安全证书合法,则认证蓝牙Mesh设备合法;若校验该安全证书不合法,则认证蓝牙Mesh设备不合法。In some embodiments, if the verification certificate of the Bluetooth Mesh device is a security certificate, the device authentication platform verifies whether the security certificate is legal; if the security certificate is verified to be legal, it verifies that the Bluetooth Mesh device is legal; If the certificate is invalid, the authentication of the Bluetooth Mesh device is invalid.
在具体实施时,设备认证平台可以采用非对称加密或对称加密方法校验蓝牙Mesh设备的合法性。例如,对于非对称加密方法,蓝牙Mesh设备预存设备认证平台的公钥,用设备认证平台的公钥加密该蓝牙Mesh设备的校验凭证,设备认证平台收到的校验凭证后用自己的私钥进行解密,如果能正常解密,证明是合法的蓝牙Mesh设备,如果不能正常解密,则证明是非法的蓝牙Mesh设备。对于对称加密方法,设备认证平台和蓝牙Mesh设备预共享相同的密钥(即预共享密钥),蓝牙Mesh设备用预共享密钥加密蓝牙Mesh设备的校验凭证,设备认证平台收到的校验凭证后用相同的预共享密钥进行解密,如果能正常解密,证明是合法的蓝牙Mesh设备;如果不能正常解密,则证明是非法的蓝牙Mesh设备。During specific implementation, the device authentication platform can use asymmetric encryption or symmetric encryption to verify the legitimacy of the Bluetooth Mesh device. For example, for the asymmetric encryption method, the Bluetooth Mesh device pre-stores the public key of the device authentication platform, encrypts the verification certificate of the Bluetooth Mesh device with the public key of the device authentication platform, and uses its own private key after receiving the verification certificate. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device. For the symmetric encryption method, the device authentication platform and the Bluetooth Mesh device pre-share the same key (ie, the pre-shared key), and the Bluetooth Mesh device uses the pre-shared key to encrypt the verification credentials of the Bluetooth Mesh device. After verifying the certificate, decrypt it with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
步骤S810,设备认证平台向网关接入的云平台反馈蓝牙Mesh设备的校验结果。Step S810, the device authentication platform feeds back the verification result of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
步骤S811,网关接入的云平台向网关反馈蓝牙Mesh设备的校验结果。Step S811, the cloud platform connected to the gateway feeds back the verification result of the Bluetooth Mesh device to the gateway.
步骤S812,若蓝牙Mesh设备的校验结果为合法,则网关执行蓝牙Mesh设备入网配置。Step S812, if the verification result of the Bluetooth Mesh device is valid, the gateway executes the network access configuration of the Bluetooth Mesh device.
在一些实施例中,若蓝牙Mesh设备的校验结果为合法,则网关启动蓝牙Mesh入网配置数据分发,向蓝牙Mesh设备发送网络地址和安全密钥(如网络密钥和/或设备密钥)等配置信息,完成蓝牙Mesh设备的入网配置过程。In some embodiments, if the verification result of the Bluetooth Mesh device is valid, the gateway starts the distribution of Bluetooth Mesh network access configuration data, and sends the network address and security key (eg, network key and/or device key) to the Bluetooth Mesh device. Wait for the configuration information to complete the network access configuration process of the Bluetooth Mesh device.
上述以蓝牙Mesh设备的校验结果为合法为例,执行步骤S812。若蓝牙Mesh设备的校验结果为不合法,则网关终止蓝牙Mesh设备的入网配置流程。In the above, the verification result of the Bluetooth Mesh device is taken as an example, and step S812 is executed. If the verification result of the Bluetooth Mesh device is invalid, the gateway terminates the network access configuration process of the Bluetooth Mesh device.
步骤S813,网关请求网关接入的云平台添加蓝牙Mesh设备。Step S813, the gateway requests the cloud platform accessed by the gateway to add a Bluetooth Mesh device.
在一些实施例中,网关向网关接入的云平台发送包括蓝牙Mesh设备的UUID在内的设备信息,网关接入的云平台添加蓝牙Mesh设备的设备信息。In some embodiments, the gateway sends device information including the UUID of the Bluetooth Mesh device to the cloud platform connected to the gateway, and the cloud platform connected to the gateway adds the device information of the Bluetooth Mesh device.
因此,图7所示的蓝牙设备接入认证方法,由蓝牙Mesh设备校验网关和/或云平台的合法性,在校验结果指示网关和/或云平台合法的情况下,再由网关校验蓝牙Mesh设备的合法性;若校验结果指示蓝牙Mesh设备合法,则执行蓝牙Mesh设备入网配置。与图6所示的蓝牙设备接入认证方法的处理流程相比较,图7所示的蓝牙设备接入认证方法的处理流程在网关校验蓝牙Mesh设备的合法性之前,增加了蓝牙Mesh设备校验网关和/或云平台的合法性的步骤;进一步提高了蓝牙Mesh网络接入认证的安全性。Therefore, in the Bluetooth device access authentication method shown in Figure 7, the Bluetooth Mesh device verifies the validity of the gateway and/or the cloud platform. When the verification result indicates that the gateway and/or the cloud platform are legal, the gateway will verify the validity of the gateway and/or the cloud platform. Verify the validity of the Bluetooth Mesh device; if the verification result indicates that the Bluetooth Mesh device is legal, perform the network access configuration of the Bluetooth Mesh device. Compared with the processing flow of the Bluetooth device access authentication method shown in Figure 6, the processing flow of the Bluetooth device access authentication method shown in Figure 7 adds the Bluetooth Mesh device verification method before the gateway verifies the validity of the Bluetooth Mesh device. Steps to verify the legitimacy of the gateway and/or cloud platform; further improve the security of Bluetooth Mesh network access authentication.
图7所示的蓝牙设备接入认证方法的处理流程中,先由蓝牙Mesh设备校验网关和/或云平台的合法性,在校验结果指示网关和/或云平台合法的情况下,再由网关校验蓝牙Mesh设备的合法性。再具体实施时,也可以先由网关校验蓝牙Mesh设备的合法性,在校验结果指示蓝牙Mesh设备合法的情况下,再由蓝牙Mesh设备校验网关和/或云平台的合法性;即在执行完步骤S801至步骤S803之后,先执行步骤S806至S811,再执行步骤S804-S805。In the processing flow of the Bluetooth device access authentication method shown in FIG. 7 , the Bluetooth Mesh device verifies the validity of the gateway and/or the cloud platform first, and when the verification result indicates that the gateway and/or the cloud platform is legal, then The validity of the Bluetooth Mesh device is verified by the gateway. In specific implementation, the gateway can also verify the validity of the Bluetooth Mesh device first, and when the verification result indicates that the Bluetooth Mesh device is legal, then the Bluetooth Mesh device can verify the validity of the gateway and/or the cloud platform; that is, After steps S801 to S803 are performed, steps S806 to S811 are performed first, and then steps S804 to S805 are performed.
以在完成蓝牙Mesh配网之前由网关校验蓝牙设备的合法性,并且由蓝牙Mesh设备校验设备认证平台的合法性为例,本申请实施例提供的蓝牙设备接入认证方法的第三种可选详细处理流程,如图8所示,包括以下步骤:Taking the validity of the Bluetooth device verified by the gateway and the validity of the device authentication platform verified by the Bluetooth Mesh device before completing the Bluetooth Mesh distribution network as an example, the third type of the Bluetooth device access authentication method provided by the embodiments of the present application The optional detailed processing flow, as shown in Figure 8, includes the following steps:
步骤S901,蓝牙Mesh设备向网关发送未配网广播包。Step S901, the Bluetooth Mesh device sends an unconfigured network broadcast packet to the gateway.
步骤S902-S903,蓝牙Mesh设备和网关启动蓝牙Mesh配网流程。Steps S902-S903, the Bluetooth Mesh device and the gateway start the Bluetooth Mesh network configuration process.
步骤S904,网关获取蓝牙Mesh设备的校验凭证。Step S904, the gateway obtains the verification certificate of the Bluetooth Mesh device.
步骤S905,网关向网关接入的云平台发送蓝牙Mesh设备的校验凭证。Step S905, the gateway sends the verification certificate of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
步骤S906,网关接入的云平台请求设备认证平台校验蓝牙Mesh设备的合法性。Step S906, the cloud platform accessed by the gateway requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
步骤S907,设备认证平台校验蓝牙Mesh设备的合法性。Step S907, the device authentication platform verifies the validity of the Bluetooth Mesh device.
步骤S908,设备认证平台向网关接入的云平台反馈蓝牙Mesh设备的校验结果。Step S908, the device authentication platform feeds back the verification result of the Bluetooth Mesh device to the cloud platform connected to the gateway.
步骤S909,网关接入的云平台向网关反馈蓝牙Mesh设备的校验结果。Step S909, the cloud platform connected to the gateway feeds back the verification result of the Bluetooth Mesh device to the gateway.
本申请实施例中步骤S901至S909的详细处理流程,与上述实施例中步骤S601至S609的处理流程相同,这里不再赘述。The detailed processing flow of steps S901 to S909 in this embodiment of the present application is the same as the processing flow of steps S601 to S609 in the foregoing embodiment, and details are not repeated here.
步骤S910,网关根据所述蓝牙设备的校验标记,向所述云平台发送第四请求消息。Step S910, the gateway sends a fourth request message to the cloud platform according to the check mark of the Bluetooth device.
在一些实施例中,所述第四请求消息用于请求获取设备认证平台的校验凭证,所述设备认证平台的校验凭证用于所述蓝牙Mesh设备校验所述设备认证平台的合法性。In some embodiments, the fourth request message is used to request to obtain a verification credential of a device authentication platform, and the verification credential of the device authentication platform is used by the Bluetooth Mesh device to verify the legitimacy of the device authentication platform .
在一些实施例中,所述第四请求消息还可以包括CID,用于云平台根据DCI确定蓝牙Mesh设备对应的设备认证平台。In some embodiments, the fourth request message may further include a CID, which is used by the cloud platform to determine the device authentication platform corresponding to the Bluetooth Mesh device according to the DCI.
步骤S911,云平台向设备认证平台发送第七请求消息。Step S911, the cloud platform sends a seventh request message to the device authentication platform.
在一些实施例中,所述第七请求消息用于请求获取所述设备认证平台的校验凭证。In some embodiments, the seventh request message is used to request to obtain the verification credential of the device authentication platform.
步骤S912,设备认证平台向云平台发送设备认证平台的校验凭证。Step S912, the device authentication platform sends the verification certificate of the device authentication platform to the cloud platform.
步骤S913,云平台向网关发送设备认证平台的校验凭证。Step S913, the cloud platform sends the verification certificate of the device authentication platform to the gateway.
步骤S914,网关向蓝牙Mesh设备发送设备认证平台的校验凭证。Step S914, the gateway sends the verification certificate of the device authentication platform to the Bluetooth Mesh device.
步骤S915,蓝牙Mesh设备校验设备认证平台的合法性。Step S915, the Bluetooth Mesh device verifies the validity of the device authentication platform.
在一些实施例中,蓝牙Mesh设备可以采用非对称加密或对称加密方法校验设备认证平台的合法性。例如,对于非对称加密方法,设备认证平台预存蓝牙Mesh设备的公钥,设备认证平台生成设备认证平台的校验凭证后,用蓝牙Mesh设备的公钥加密该校验凭证,蓝牙Mesh设备收到的校验凭证后用自己的私钥进行解密,如果能正常解密,证明是合法的设备认证平台,如果不能正常解密,则证明是非法的设备认证平台。对于对称加密方法,设备认证平台和蓝牙Mesh设备预共享相同的密钥(即预共享密钥),设备认证平台生成设备认证平台的校验凭证后,用预共享密钥加密该校验凭证,蓝牙Mesh设备收到的校验凭证后用相同的预共享密钥进行解密,如果能正常解密,证明是合法的设备认证平台,如果不能正常解密,则证明是非法的设备认证平台。In some embodiments, the Bluetooth Mesh device can use asymmetric encryption or symmetric encryption to verify the legitimacy of the device authentication platform. For example, for the asymmetric encryption method, the device authentication platform pre-stores the public key of the Bluetooth Mesh device. After the device authentication platform generates the verification certificate of the device authentication platform, it encrypts the verification certificate with the public key of the Bluetooth Mesh device, and the Bluetooth Mesh device receives the verification certificate. After verifying the certificate, decrypt it with your own private key. If it can be decrypted normally, it proves to be a legitimate device authentication platform. If it cannot be decrypted normally, it proves to be an illegal device authentication platform. For the symmetric encryption method, the device authentication platform and the Bluetooth Mesh device pre-share the same key (that is, the pre-shared key). After the device authentication platform generates the verification certificate of the device authentication platform, it encrypts the verification certificate with the pre-shared key. The verification certificate received by the Bluetooth Mesh device is decrypted with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate device authentication platform. If it cannot be decrypted normally, it proves to be an illegal device authentication platform.
步骤S916,若蓝牙Mesh设备的校验结果为合法,且设备认证平台的校验结果为合法,则网关执行蓝牙Mesh设备入网配置。Step S916, if the verification result of the Bluetooth Mesh device is legal, and the verification result of the device authentication platform is legal, the gateway performs network access configuration of the Bluetooth Mesh device.
在一些实施例中,若蓝牙Mesh设备的校验结果为合法、且设备认证平台的校验结果为合法,则网关启动蓝牙Mesh入网配置数据分发,向蓝牙Mesh设备发送网络地址和安全密钥(如网络密钥和/或设备密钥)等配置信息,完成蓝牙Mesh设备的入网配置过程。In some embodiments, if the verification result of the Bluetooth Mesh device is legal and the verification result of the device authentication platform is legal, the gateway starts the distribution of the Bluetooth Mesh network access configuration data, and sends the network address and security key ( (such as network key and/or device key) and other configuration information to complete the network access configuration process of the Bluetooth Mesh device.
步骤S917,网关请求网关接入的云平台添加蓝牙Mesh设备。Step S917, the gateway requests the cloud platform accessed by the gateway to add a Bluetooth Mesh device.
在一些实施例中,网关向网关接入的云平台发送包括蓝牙Mesh设备的UUID在内的设备信息,网关接入的云平台添加蓝牙Mesh设备的设备信息。In some embodiments, the gateway sends device information including the UUID of the Bluetooth Mesh device to the cloud platform connected to the gateway, and the cloud platform connected to the gateway adds the device information of the Bluetooth Mesh device.
上述以蓝牙Mesh设备的校验结果为合法为例,执行步骤S916至S917。若蓝牙Mesh设备的校验结果和设备认证平台的校验结果中至少一个为不合法,则网关终止蓝牙Mesh设备的入网配置流程。In the above, the verification result of the Bluetooth Mesh device is taken as an example, and steps S916 to S917 are executed. If at least one of the verification result of the Bluetooth Mesh device and the verification result of the device authentication platform is invalid, the gateway terminates the network access configuration process of the Bluetooth Mesh device.
图8所示的蓝牙设备接入认证方法的处理流程中,先由网关校验蓝牙Mesh设备的合法性,在校验结果指示蓝牙Mesh设备合法的情况下,再由蓝牙Mesh设备校验设备认证平台的合法性。再具体实施时,也可以先由蓝牙Mesh设备校验设备认证平台的合法性,再校验结果指示设备认证平台合法的情况下,再由网关校验蓝牙Mesh设备的合法性;即在执行完步骤S901至步骤S903之后,先执行步骤S910至S915,再执行步骤S904-S909。In the processing flow of the Bluetooth device access authentication method shown in Figure 8, the gateway verifies the validity of the Bluetooth Mesh device first, and when the verification result indicates that the Bluetooth Mesh device is legal, the Bluetooth Mesh device verifies the device authentication the legitimacy of the platform. In specific implementation, the Bluetooth Mesh device can also verify the validity of the device authentication platform first, and then the gateway can verify the validity of the Bluetooth Mesh device when the verification result indicates that the device authentication platform is legal; that is, after the execution is completed. After steps S901 to S903, steps S910 to S915 are performed first, and then steps S904-S909 are performed.
基于上述图7所示,由网关校验蓝牙Mesh设备的合法性,以及由蓝牙Mesh设备校验网关/云平台的合法性对本申请实施例提供的蓝牙设备接入认证方法进行详细说明。基于上述图8所示,由网关校验蓝牙Mesh设备的合法性,以及由蓝牙Mesh设备校验设备认证平台的合法性对本申请实施例提供的蓝牙设备接入认证方法进行详细说明。在具体实施时,网关校验蓝牙Mesh设备的合法性、由蓝牙Mesh设备校验网关/云平台的合法性、以及由蓝牙Mesh设备校验设备认证平台的合法性可以均执行;且网关校验蓝牙Mesh设备的合法性、由蓝牙Mesh设备校验网 关/云平台的合法性、以及由蓝牙Mesh设备校验设备认证平台的合法性之间不存在执行的先后顺序。其中,蓝牙Mesh设备校验网关/云平台的合法性、与由蓝牙Mesh设备校验设备认证平台的合法性之间可以存在优先级,如蓝牙Mesh设备校验网关/云平台的合法性的优先级高于由蓝牙Mesh设备校验设备认证平台的合法性的优先级,则蓝牙Mesh设备优先校验网关/云平台的合法性。Based on the above-mentioned FIG. 7 , the validity of the Bluetooth Mesh device is verified by the gateway, and the validity of the gateway/cloud platform is verified by the Bluetooth Mesh device. The Bluetooth device access authentication method provided by the embodiment of the present application is described in detail. Based on the above-mentioned FIG. 8 , the validity of the Bluetooth Mesh device is verified by the gateway, and the validity of the device authentication platform is verified by the Bluetooth Mesh device. The Bluetooth device access authentication method provided by the embodiment of the present application is described in detail. In specific implementation, the gateway can verify the validity of the Bluetooth Mesh device, the Bluetooth Mesh device can verify the validity of the gateway/cloud platform, and the Bluetooth Mesh device can verify the legality of the device authentication platform. There is no sequence of execution between the validity of the Bluetooth Mesh device, the validity of the gateway/cloud platform verified by the Bluetooth Mesh device, and the validity of the device authentication platform verified by the Bluetooth Mesh device. Among them, there may be a priority between the Bluetooth Mesh device verifying the legitimacy of the gateway/cloud platform and the Bluetooth Mesh device verifying the legitimacy of the device authentication platform, such as the Bluetooth Mesh device verifying the legitimacy of the gateway/cloud platform. If the level is higher than the priority of the Bluetooth Mesh device verifying the validity of the device authentication platform, the Bluetooth Mesh device will give priority to verifying the validity of the gateway/cloud platform.
上述图6至图8所示的蓝牙设备接入认证方法均是在完成蓝牙Mesh配网之前,执行蓝牙Mesh设备校验、或网关/云平台校验、或设备认证平台校验。再具体实施时,本申请实施例还可以在完成蓝牙Mesh配网之后执行蓝牙Mesh设备校验、或网关/云平台校验、或设备认证平台校验。The Bluetooth device access authentication methods shown in Figures 6 to 8 above all perform Bluetooth Mesh device verification, or gateway/cloud platform verification, or device authentication platform verification before completing the Bluetooth Mesh network configuration. In further specific implementation, the embodiments of the present application may further perform Bluetooth Mesh device verification, or gateway/cloud platform verification, or device authentication platform verification after completing the Bluetooth Mesh network configuration.
下面以在完成蓝牙Mesh配网之后执行蓝牙Mesh设备校验为例,对本申请实施例提供的蓝牙设备接入认证方法的第四种详细处理流程,如图9所示,包括:The fourth detailed processing flow of the Bluetooth device access authentication method provided by the embodiment of the present application, as shown in Figure 9, includes:
步骤S1001,蓝牙Mesh设备向网关发送未配网广播包。Step S1001, the Bluetooth Mesh device sends an unconfigured network broadcast packet to the gateway.
在一些实施例中,针对蓝牙Mesh设备向网关发送未配网广播包的说明,与上述步骤S601相同,这里不再赘述In some embodiments, the description of the Bluetooth Mesh device sending an unconfigured network broadcast packet to the gateway is the same as the above step S601, and will not be repeated here.
步骤S1002-S1003,蓝牙Mesh设备和网关启动蓝牙Mesh配网流程,并完成蓝牙Mesh配网流程。Steps S1002-S1003, the Bluetooth Mesh device and the gateway start the Bluetooth Mesh network configuration process, and complete the Bluetooth Mesh network configuration process.
其中,启动蓝牙Mesh配网流程可以包括:计算安全密钥,安全密钥用于在蓝牙Mesh设备和网关之间对校验凭证进行加密/解密处理;其中,安全密钥可以包括会话密钥、设备密钥、网络密钥和应用密钥中的一种或多种。Wherein, starting the Bluetooth Mesh network configuration process may include: calculating a security key, and the security key is used to encrypt/decrypt the verification credential between the Bluetooth Mesh device and the gateway; wherein, the security key may include a session key, One or more of Device Key, Network Key, and App Key.
完成蓝牙Mesh配网流程包括:网关启动蓝牙Mesh入网配置数据分发,向蓝牙Mesh设备发送网络地址和安全密钥(如网络密钥和/或设备密钥)等配置信息,完成蓝牙Mesh设备的入网配置过程。The process of completing the Bluetooth Mesh network configuration includes: the gateway starts the distribution of configuration data for Bluetooth Mesh network access, sends configuration information such as network addresses and security keys (such as network keys and/or device keys) to the Bluetooth Mesh devices, and completes the network access of the Bluetooth Mesh devices. configuration process.
步骤S1004,网关获取蓝牙Mesh设备的校验凭证。Step S1004, the gateway obtains the verification certificate of the Bluetooth Mesh device.
在一些实施例中,未配网广播包中的校验标记指示校验蓝牙Mesh设备,则蓝牙Mesh设备主动向网关发送蓝牙Mesh设备的校验凭证。In some embodiments, the verification mark in the unconfigured network broadcast packet indicates to verify the Bluetooth Mesh device, and the Bluetooth Mesh device actively sends the verification certificate of the Bluetooth Mesh device to the gateway.
在另一些实施例中,可以由网关向蓝牙Mesh设备发送第一请求消息,所述第一请求消息用于请求获取蓝牙Mesh设备的校验凭证;蓝牙Mesh设备在接收到第一请求消息之后,向网关发送蓝牙Mesh设备的校验凭证。In other embodiments, the gateway may send a first request message to the Bluetooth Mesh device, where the first request message is used to request to obtain the verification credential of the Bluetooth Mesh device; after receiving the first request message, the Bluetooth Mesh device, Send the verification credentials of the Bluetooth Mesh device to the gateway.
步骤S1005,网关向网关接入的云平台发送蓝牙Mesh设备的校验凭证。Step S1005, the gateway sends the verification certificate of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
在一些实施例中,网关通过向网关接入的云平台发送蓝牙Mesh设备的校验凭证,请求网关接入的云平台校验蓝牙Mesh设备的合法性。In some embodiments, the gateway requests the cloud platform accessed by the gateway to verify the validity of the Bluetooth Mesh device by sending the verification credential of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
步骤S1006,网关接入的云平台请求设备认证平台校验蓝牙Mesh设备的合法性。Step S1006, the cloud platform accessed by the gateway requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
在一些实施例中,若网关接入的云平台根据未配网广播包中的CID判断蓝牙Mesh设备不是基于云平台开发的设备,则网关接入的云平台根据未配网广播包中的CID获取对应的设备认证平台;网关接入的云平台向设备认证平台发送蓝牙Mesh设备的校验凭证,请求设备认证平台校验蓝牙Mesh设备的合法性。In some embodiments, if the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is not a device developed based on the cloud platform according to the CID in the unconfigured broadcast packet, the cloud platform accessed by the gateway determines according to the CID in the unconfigured broadcast packet. Obtain the corresponding device authentication platform; the cloud platform connected to the gateway sends the verification certificate of the Bluetooth Mesh device to the device authentication platform, and requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
在另一些实施例中,若网关接入的云平台根据未配网广播包中的CID判断蓝牙Mesh设备是基于云平台开发的设备,则网关接入的云平台校验蓝牙Mesh设备的合法性。In other embodiments, if the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is a device developed based on the cloud platform according to the CID in the unconfigured network broadcast packet, the cloud platform accessed by the gateway verifies the validity of the Bluetooth Mesh device .
步骤S1007,设备认证平台校验蓝牙Mesh设备的合法性。Step S1007, the device authentication platform verifies the validity of the Bluetooth Mesh device.
在一些实施例中,若蓝牙Mesh设备的校验凭证是安全证书,则设备认证平台校验该安全证书是否合法;若校验该安全证书合法,则认证蓝牙Mesh设备合法;若校验该安全证书不合法,则认证蓝牙Mesh设备不合法。In some embodiments, if the verification certificate of the Bluetooth Mesh device is a security certificate, the device authentication platform verifies whether the security certificate is legal; if the security certificate is verified to be legal, it verifies that the Bluetooth Mesh device is legal; If the certificate is invalid, the authentication of the Bluetooth Mesh device is invalid.
在具体实施时,设备认证平台可以采用非对称加密或对称加密方法校验蓝牙Mesh设备的合法性。例如,对于非对称加密方法,蓝牙Mesh设备预存设备认证平台的公钥,用设备认证平台的公钥加密该蓝牙Mesh设备的校验凭证,设备认证平台收到的校验凭证后用自己的私钥进行解密,如果能正常解密,证明是合法的蓝牙Mesh设备,如果不能正常解密,则证明是非法的蓝牙Mesh设备。对于对称加密方法,设备认证平台和蓝牙Mesh设备预共享相同的密钥(即 预共享密钥),蓝牙Mesh设备用预共享密钥加密蓝牙Mesh设备的校验凭证,设备认证平台收到的校验凭证后用相同的预共享密钥进行解密,如果能正常解密,证明是合法的蓝牙Mesh设备;如果不能正常解密,则证明是非法的蓝牙Mesh设备。During specific implementation, the device authentication platform can use asymmetric encryption or symmetric encryption to verify the legitimacy of the Bluetooth Mesh device. For example, for the asymmetric encryption method, the Bluetooth Mesh device pre-stores the public key of the device authentication platform, encrypts the verification certificate of the Bluetooth Mesh device with the public key of the device authentication platform, and uses its own private key after receiving the verification certificate. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device. For the symmetric encryption method, the device authentication platform and the Bluetooth Mesh device pre-share the same key (ie, the pre-shared key), and the Bluetooth Mesh device uses the pre-shared key to encrypt the verification credentials of the Bluetooth Mesh device. After verifying the certificate, decrypt it with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
步骤S1008,设备认证平台向网关接入的云平台反馈蓝牙Mesh设备的校验结果。Step S1008, the device authentication platform feeds back the verification result of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
步骤S1009,网关接入的云平台向网关反馈蓝牙Mesh设备的校验结果。Step S1009, the cloud platform connected by the gateway feeds back the verification result of the Bluetooth Mesh device to the gateway.
步骤S1010,若蓝牙Mesh设备的校验结果为合法,网关请求网关接入的云平台添加蓝牙Mesh设备。Step S1010, if the verification result of the Bluetooth Mesh device is valid, the gateway requests the cloud platform accessed by the gateway to add the Bluetooth Mesh device.
在一些实施例中,网关向网关接入的云平台发送包括蓝牙Mesh设备的UUID在内的设备信息,网关接入的云平台添加蓝牙Mesh设备的设备信息。In some embodiments, the gateway sends device information including the UUID of the Bluetooth Mesh device to the cloud platform connected to the gateway, and the cloud platform connected to the gateway adds the device information of the Bluetooth Mesh device.
上述以蓝牙Mesh设备的校验结果为合法为例,执行步骤S1010。若蓝牙Mesh设备的校验结果为不合法,则从蓝牙Mesh网络中删除蓝牙Mesh设备。In the above, taking the verification result of the Bluetooth Mesh device as valid as an example, step S1010 is executed. If the verification result of the Bluetooth Mesh device is invalid, delete the Bluetooth Mesh device from the Bluetooth Mesh network.
以在完成蓝牙Mesh配网之后,由网关校验蓝牙设备的合法性,并且由蓝牙Mesh设备校验网关/云平台的合法性为例,本申请实施例提供的蓝牙设备接入认证方法的第五种可选详细处理流程,如图10所示,包括以下步骤:Taking the validity of the Bluetooth device verified by the gateway and the validity of the gateway/cloud platform verified by the Bluetooth Mesh device after the Bluetooth Mesh network configuration is completed as an example, the first step of the Bluetooth device access authentication method provided by the embodiment of the present application is: Five optional detailed processing flows, as shown in Figure 10, include the following steps:
步骤S1101,蓝牙Mesh设备向网关发送未配网广播包。Step S1101, the Bluetooth Mesh device sends an unconfigured network broadcast packet to the gateway.
步骤S1102-S1103,蓝牙Mesh设备和网关启动蓝牙Mesh配网流程。Steps S1102-S1103, the Bluetooth Mesh device and the gateway start the Bluetooth Mesh network configuration process.
其中,启动蓝牙Mesh配网流程可以包括:计算安全密钥,安全密钥用于在蓝牙Mesh设备和网关之间对校验凭证进行加密/解密处理;其中,安全密钥可以包括会话密钥、设备密钥、网络密钥和应用密钥中的一种或多种。Wherein, starting the Bluetooth Mesh network configuration process may include: calculating a security key, and the security key is used to encrypt/decrypt the verification credential between the Bluetooth Mesh device and the gateway; wherein, the security key may include a session key, One or more of Device Key, Network Key, and App Key.
完成蓝牙Mesh配网流程包括:网关启动蓝牙Mesh入网配置数据分发,向蓝牙Mesh设备发送网络地址和安全密钥(如网络密钥和/或设备密钥)等配置信息,完成蓝牙Mesh设备的入网配置过程。The process of completing the Bluetooth Mesh network configuration includes: the gateway starts the distribution of configuration data for Bluetooth Mesh network access, sends configuration information such as network addresses and security keys (such as network keys and/or device keys) to the Bluetooth Mesh devices, and completes the network access of the Bluetooth Mesh devices. configuration process.
步骤S1104,网关向蓝牙Mesh设备发送网关/平台的校验凭证。Step S1104, the gateway sends the verification certificate of the gateway/platform to the Bluetooth Mesh device.
在一些实施例中,可以由网关主动向蓝牙Mesh设备发送网关/平台的校验凭证。In some embodiments, the gateway may actively send the gateway/platform verification credential to the Bluetooth Mesh device.
在另一些实施例中,可以由蓝牙Mesh设备根据校验标记,向网关发送第三请求消息,所述第三请求消息用于请求获取网关和/或云平台的校验凭证。In other embodiments, the Bluetooth Mesh device may send a third request message to the gateway according to the verification mark, where the third request message is used to request to obtain the verification credential of the gateway and/or the cloud platform.
在该场景下,网关接收到第三请求消息之后,网关获取网关和/或云平台的校验凭证。网关获取网关和/或云平台的校验凭证的具体实现过程可以包括:In this scenario, after the gateway receives the third request message, the gateway obtains the verification credential of the gateway and/or the cloud platform. The specific implementation process for the gateway to obtain the verification credential of the gateway and/or the cloud platform may include:
步骤S1104-1,网关向云平台发送第二请求消息,所述第二请求消息用于请求获取网关和/或云平台的校验凭证。Step S1104-1, the gateway sends a second request message to the cloud platform, where the second request message is used to request to obtain the verification credential of the gateway and/or the cloud platform.
在一些实施例中,第二请求消息中携带网关/云平台的标识,用于向云平台请求获取网关和/或云平台的校验凭证。In some embodiments, the second request message carries the identifier of the gateway/cloud platform, and is used to request the cloud platform to obtain the verification credential of the gateway and/or the cloud platform.
步骤S1104-2,云平台获取网关和/或云平台对应的设备认证平台信息。Step S1104-2, the cloud platform obtains the device authentication platform information corresponding to the gateway and/or the cloud platform.
在一些实施例中,云平台通过CID判断蓝牙Mesh设备不是基于云平台开发的设备,需要设备认证平台进行认证,则云平台通过CID获取网关和/或云平台对应的设备认证平台信息。In some embodiments, the cloud platform determines by CID that the Bluetooth Mesh device is not a device developed based on the cloud platform, and requires a device authentication platform for authentication, then the cloud platform obtains the device authentication platform information corresponding to the gateway and/or the cloud platform through the CID.
步骤S1104-3,云平台向设备认证平台请求获取网关和/或云平台的校验凭证。Step S1104-3, the cloud platform requests the device authentication platform to obtain the verification credential of the gateway and/or the cloud platform.
在一些实施例中,云平台向设备认证平台发送第六请求消息;所述第六请求消息携带所述网关和/或所述云平台的标识,用于请求获取所述网关和/或所述云平台的校验凭证。In some embodiments, the cloud platform sends a sixth request message to the device authentication platform; the sixth request message carries the identifier of the gateway and/or the cloud platform, and is used to request to obtain the gateway and/or the The verification certificate of the cloud platform.
步骤S1104-4,设备认证平台向云平台发送网关和/或云平台的校验凭证。Step S1104-4, the device authentication platform sends the verification credential of the gateway and/or the cloud platform to the cloud platform.
在一些实施例中,设备认证平台根据网关和/或云平台的标识生成通用的校验凭证(即校验凭证不区分网关或网关接入的具体云平台,对所有合法网关或网关接入的云平台是通用的),或专用于该网关/云平台的校验凭证(即校验凭证区分网关或网关接入的具体云平台,不同的合法网关或网关接入的云平台使用不同的校验凭证)。例如,设备认证平台生成的网关/云平台的校验凭证为安全证书,该安全证书中包括网关和/或云平台的唯一标识信息,只能由该网关/云平台使用该安全证书才能校验通过,其他网关/网关接入的云平台即使使用该安全证书也无法校验通过,提高接入认证的安全性。In some embodiments, the device authentication platform generates a general verification credential according to the identifier of the gateway and/or the cloud platform (that is, the verification credential does not distinguish the gateway or the specific cloud platform accessed by the gateway, and the verification credential does not distinguish the gateway or the specific cloud platform accessed by the gateway, and the verification credential is used for all legal gateways or gateways. The cloud platform is universal), or the verification certificate dedicated to the gateway/cloud platform (that is, the verification certificate distinguishes the gateway or the specific cloud platform accessed by the gateway, and different legal gateways or cloud platforms accessed by the gateway use different schools. certificate). For example, the verification credential of the gateway/cloud platform generated by the device authentication platform is a security certificate, and the security certificate includes the unique identification information of the gateway and/or the cloud platform, which can only be verified by the gateway/cloud platform using the security certificate Passed, the cloud platform accessed by other gateways/gateways cannot pass the verification even if the security certificate is used, which improves the security of access authentication.
在一些实施例中,云平台接收到设备认证平台返回的网关和/或云平台的校验凭证后,可以 在本地存储网关和/或平台的校验凭证,后续需要校验网关和/或平台时,云平台直接从本地获取网关和/或平台的校验凭证,而不必再从设备认证平台获取网关和/或平台的校验凭证,简化网关和/或平台的校验流程,减少校验时延。In some embodiments, after receiving the verification credential of the gateway and/or the cloud platform returned by the device authentication platform, the cloud platform may store the verification credential of the gateway and/or the platform locally, and the gateway and/or the platform needs to be verified later When the cloud platform directly obtains the verification credentials of the gateway and/or the platform from the local, it is no longer necessary to obtain the verification credentials of the gateway and/or the platform from the device authentication platform, which simplifies the verification process of the gateway and/or the platform and reduces the verification time delay.
步骤S1104-5,云平台向网关发送网关和/或云平台的校验凭证。Step S1104-5, the cloud platform sends the gateway and/or the verification credential of the cloud platform to the gateway.
上述步骤S1104-1至S1104-5是针对网关向网络侧(云平台和设备认证平台)获取网关和/或云平台的校验凭证的具体实现过程。The above steps S1104-1 to S1104-5 are specific implementation processes for the gateway to obtain the verification credentials of the gateway and/or the cloud platform from the network side (cloud platform and device authentication platform).
网关获取网关和/或云平台的校验凭证的具体实现过程还可以是,网关预先存储了网关和/或云平台的校验凭证;如在网关出厂时或者网关上电激活时预先存储了网关和/或云平台的校验凭证。The specific implementation process for the gateway to obtain the verification credential of the gateway and/or the cloud platform may also be that the gateway pre-stores the verification credential of the gateway and/or the cloud platform; and/or verification credentials of the cloud platform.
步骤S1105,蓝牙Mesh设备根据接收的网关和/云平台的校验凭证,校验网关和/或云平台的合法性,并向网关反馈网关和/或云平台的校验结果。Step S1105, the Bluetooth Mesh device verifies the validity of the gateway and/or the cloud platform according to the received verification credentials of the gateway and/or the cloud platform, and feeds back the verification result of the gateway and/or the cloud platform to the gateway.
在一些实施例中,在蓝牙Mesh设备对网关和/或云平台的校验结果为网关和/或云平台合法的情况下,本申请实施例提供的蓝牙设备接入认证方法执行如下步骤S1106-S1112:In some embodiments, when the verification result of the Bluetooth Mesh device on the gateway and/or the cloud platform is that the gateway and/or the cloud platform are legal, the Bluetooth device access authentication method provided by the embodiments of the present application performs the following steps S1106- S1112:
步骤S1106,网关获取蓝牙Mesh设备的校验凭证。Step S1106, the gateway obtains the verification certificate of the Bluetooth Mesh device.
在一些实施例中,未配网广播包中的校验标记指示校验蓝牙Mesh设备,则蓝牙Mesh设备主动向网关发送蓝牙Mesh设备的校验凭证。In some embodiments, the verification mark in the unconfigured network broadcast packet indicates to verify the Bluetooth Mesh device, and the Bluetooth Mesh device actively sends the verification certificate of the Bluetooth Mesh device to the gateway.
在另一些实施例中,可以由网关向蓝牙Mesh设备发送第一请求消息,所述第一请求消息用于请求获取蓝牙Mesh设备的校验凭证;蓝牙Mesh设备在接收到第一请求消息之后,向网关发送蓝牙Mesh设备的校验凭证。In other embodiments, the gateway may send a first request message to the Bluetooth Mesh device, where the first request message is used to request to obtain the verification credential of the Bluetooth Mesh device; after receiving the first request message, the Bluetooth Mesh device, Send the verification credentials of the Bluetooth Mesh device to the gateway.
步骤S1107,网关向云平台发送蓝牙Mesh设备的校验凭证。Step S1107, the gateway sends the verification certificate of the Bluetooth Mesh device to the cloud platform.
在一些实施例中,网关通过向网关接入的云平台发送蓝牙Mesh设备的校验凭证,请求网关接入的云平台校验蓝牙Mesh设备的合法性。In some embodiments, the gateway requests the cloud platform accessed by the gateway to verify the validity of the Bluetooth Mesh device by sending the verification credential of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
步骤S1108,云平台请求设备认证平台校验蓝牙Mesh设备的合法性。Step S1108, the cloud platform requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
在一些实施例中,若网关接入的云平台根据未配网广播包中的CID判断蓝牙Mesh设备不是基于云平台开发的设备,则网关接入的云平台根据未配网广播包中的CID获取对应的设备认证平台;网关接入的云平台向设备认证平台发送蓝牙Mesh设备的校验凭证,请求设备认证平台校验蓝牙Mesh设备的合法性。In some embodiments, if the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is not a device developed based on the cloud platform according to the CID in the unconfigured broadcast packet, the cloud platform accessed by the gateway determines according to the CID in the unconfigured broadcast packet. Obtain the corresponding device authentication platform; the cloud platform connected to the gateway sends the verification certificate of the Bluetooth Mesh device to the device authentication platform, and requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
在另一些实施例中,若网关接入的云平台根据未配网广播包中的CID判断蓝牙Mesh设备是基于云平台开发的设备,则网关接入的云平台校验蓝牙Mesh设备的合法性。In other embodiments, if the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is a device developed based on the cloud platform according to the CID in the unconfigured network broadcast packet, the cloud platform accessed by the gateway verifies the validity of the Bluetooth Mesh device .
步骤S1109,设备认证平台校验蓝牙Mesh设备的合法性。Step S1109, the device authentication platform verifies the validity of the Bluetooth Mesh device.
在一些实施例中,若蓝牙Mesh设备的校验凭证是安全证书,则设备认证平台校验该安全证书是否合法;若校验该安全证书合法,则认证蓝牙Mesh设备合法;若校验该安全证书不合法,则认证蓝牙Mesh设备不合法。In some embodiments, if the verification certificate of the Bluetooth Mesh device is a security certificate, the device authentication platform verifies whether the security certificate is legal; if the security certificate is verified to be legal, it verifies that the Bluetooth Mesh device is legal; If the certificate is invalid, the authentication of the Bluetooth Mesh device is invalid.
在具体实施时,设备认证平台可以采用非对称加密或对称加密方法校验蓝牙Mesh设备的合法性。例如,对于非对称加密方法,蓝牙Mesh设备预存设备认证平台的公钥,用设备认证平台的公钥加密该蓝牙Mesh设备的校验凭证,设备认证平台收到的校验凭证后用自己的私钥进行解密,如果能正常解密,证明是合法的蓝牙Mesh设备,如果不能正常解密,则证明是非法的蓝牙Mesh设备。对于对称加密方法,设备认证平台和蓝牙Mesh设备预共享相同的密钥(即预共享密钥),蓝牙Mesh设备用预共享密钥加密蓝牙Mesh设备的校验凭证,设备认证平台收到的校验凭证后用相同的预共享密钥进行解密,如果能正常解密,证明是合法的蓝牙Mesh设备;如果不能正常解密,则证明是非法的蓝牙Mesh设备。During specific implementation, the device authentication platform can use asymmetric encryption or symmetric encryption to verify the legitimacy of the Bluetooth Mesh device. For example, for the asymmetric encryption method, the Bluetooth Mesh device pre-stores the public key of the device authentication platform, encrypts the verification certificate of the Bluetooth Mesh device with the public key of the device authentication platform, and uses its own private key after receiving the verification certificate. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device. For the symmetric encryption method, the device authentication platform and the Bluetooth Mesh device pre-share the same key (ie, the pre-shared key), and the Bluetooth Mesh device uses the pre-shared key to encrypt the verification credentials of the Bluetooth Mesh device. After verifying the certificate, decrypt it with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
步骤S1110,设备认证平台向网关接入的云平台反馈蓝牙Mesh设备的校验结果。Step S1110, the device authentication platform feeds back the verification result of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
步骤S1111,网关接入的云平台向网关反馈蓝牙Mesh设备的校验结果。Step S1111, the cloud platform connected to the gateway feeds back the verification result of the Bluetooth Mesh device to the gateway.
步骤S1112,若蓝牙Mesh设备的校验结果为合法,则网关请求网关接入的云平台添加蓝牙Mesh设备。Step S1112, if the verification result of the Bluetooth Mesh device is valid, the gateway requests the cloud platform accessed by the gateway to add the Bluetooth Mesh device.
在一些实施例中,网关向网关接入的云平台发送包括蓝牙Mesh设备的UUID在内的设备信息,网关接入的云平台添加蓝牙Mesh设备的设备信息。In some embodiments, the gateway sends device information including the UUID of the Bluetooth Mesh device to the cloud platform connected to the gateway, and the cloud platform connected to the gateway adds the device information of the Bluetooth Mesh device.
因此,图10所示的蓝牙设备接入认证方法,由蓝牙Mesh设备校验网关和/或云平台的合法性,在校验结果指示网关和/或云平台合法的情况下,再由网关校验蓝牙Mesh设备的合法性;若校验结果指示蓝牙Mesh设备合法,则执行蓝牙Mesh设备入网配置。与图9所示的蓝牙设备接入认证方法的处理流程相比较,图7所示的蓝牙设备接入认证方法的处理流程在网关校验蓝牙Mesh设备的合法性之前,增加了蓝牙Mesh设备校验网关和/或云平台的合法性的步骤;进一步提高了蓝牙Mesh网络接入认证的安全性。Therefore, in the Bluetooth device access authentication method shown in Figure 10, the Bluetooth mesh device verifies the legitimacy of the gateway and/or the cloud platform, and when the verification result indicates that the gateway and/or the cloud platform are legal, the gateway verifies the legitimacy of the gateway and/or the cloud platform. Verify the validity of the Bluetooth Mesh device; if the verification result indicates that the Bluetooth Mesh device is legal, perform the network access configuration of the Bluetooth Mesh device. Compared with the processing flow of the Bluetooth device access authentication method shown in Figure 9, the processing flow of the Bluetooth device access authentication method shown in Figure 7 adds the Bluetooth Mesh device verification method before the gateway verifies the validity of the Bluetooth Mesh device. Steps to verify the legitimacy of the gateway and/or cloud platform; further improve the security of Bluetooth Mesh network access authentication.
以在完成蓝牙Mesh配网之后,由网关校验蓝牙设备的合法性,并且由蓝牙Mesh设备校验设备认证平台的合法性为例,本申请实施例提供的蓝牙设备接入认证方法的第六种可选详细处理流程,如图11所示,包括以下步骤:Taking the validity of the Bluetooth device verified by the gateway and the legality of the device authentication platform verified by the Bluetooth Mesh device after the Bluetooth Mesh network configuration is completed as an example, the sixth step of the Bluetooth device access authentication method provided by the embodiment of the present application is: An optional detailed processing flow, as shown in Figure 11, includes the following steps:
步骤S1201,蓝牙Mesh设备向网关发送未配网广播包。Step S1201, the Bluetooth Mesh device sends an unconfigured network broadcast packet to the gateway.
步骤S1202-S1203,蓝牙Mesh设备和网关启动蓝牙Mesh配网流程。Steps S1202-S1203, the Bluetooth Mesh device and the gateway start the Bluetooth Mesh network configuration process.
其中,启动蓝牙Mesh配网流程可以包括:计算安全密钥,安全密钥用于在蓝牙Mesh设备和网关之间对校验凭证进行加密/解密处理;其中,安全密钥可以包括会话密钥、设备密钥、网络密钥和应用密钥中的一种或多种。Wherein, starting the Bluetooth Mesh network configuration process may include: calculating a security key, and the security key is used to encrypt/decrypt the verification credential between the Bluetooth Mesh device and the gateway; wherein, the security key may include a session key, One or more of Device Key, Network Key, and App Key.
完成蓝牙Mesh配网流程包括:网关启动蓝牙Mesh入网配置数据分发,向蓝牙Mesh设备发送网络地址和安全密钥(如网络密钥和/或设备密钥)等配置信息,完成蓝牙Mesh设备的入网配置过程。The process of completing the Bluetooth Mesh network configuration includes: the gateway starts the distribution of configuration data for Bluetooth Mesh network access, sends configuration information such as network addresses and security keys (such as network keys and/or device keys) to the Bluetooth Mesh devices, and completes the network access of the Bluetooth Mesh devices. configuration process.
步骤S1204,网关根据所述蓝牙设备的校验标记,向所述云平台发送第四请求消息。Step S1204, the gateway sends a fourth request message to the cloud platform according to the check mark of the Bluetooth device.
在一些实施例中,所述第四请求消息用于请求获取设备认证平台的校验凭证,所述设备认证平台的校验凭证用于所述蓝牙Mesh设备校验所述设备认证平台的合法性。In some embodiments, the fourth request message is used to request to obtain a verification credential of a device authentication platform, and the verification credential of the device authentication platform is used by the Bluetooth Mesh device to verify the legitimacy of the device authentication platform .
在一些实施例中,所述第四请求消息还可以包括CID,用于云平台根据DCI确定蓝牙Mesh设备对应的设备认证平台。In some embodiments, the fourth request message may further include a CID, which is used by the cloud platform to determine the device authentication platform corresponding to the Bluetooth Mesh device according to the DCI.
步骤S1205,云平台向设备认证平台发送第七请求消息。Step S1205, the cloud platform sends a seventh request message to the device authentication platform.
在一些实施例中,所述第七请求消息用于请求获取所述设备认证平台的校验凭证。In some embodiments, the seventh request message is used to request to obtain the verification credential of the device authentication platform.
步骤S1206,设备认证平台向云平台发送设备认证平台的校验凭证。Step S1206, the device authentication platform sends the verification certificate of the device authentication platform to the cloud platform.
步骤S1207,云平台向网关发送设备认证平台的校验凭证。Step S1207, the cloud platform sends the verification certificate of the device authentication platform to the gateway.
步骤S1208,网关向蓝牙Mesh设备发送设备认证平台的校验凭证。Step S1208, the gateway sends the verification certificate of the device authentication platform to the Bluetooth Mesh device.
步骤S1209,蓝牙Mesh设备校验设备认证平台的合法性。Step S1209, the Bluetooth Mesh device verifies the validity of the device authentication platform.
在一些实施例中,蓝牙Mesh设备可以采用非对称加密或对称加密方法校验设备认证平台的合法性。例如,对于非对称加密方法,设备认证平台预存蓝牙Mesh设备的公钥,设备认证平台生成设备认证平台的校验凭证后,用蓝牙Mesh设备的公钥加密该校验凭证,蓝牙Mesh设备收到的校验凭证后用自己的私钥进行解密,如果能正常解密,证明是合法的设备认证平台,如果不能正常解密,则证明是非法的设备认证平台。对于对称加密方法,设备认证平台和蓝牙Mesh设备预共享相同的密钥(即预共享密钥),设备认证平台生成设备认证平台的校验凭证后,用预共享密钥加密该校验凭证,蓝牙Mesh设备收到的校验凭证后用相同的预共享密钥进行解密,如果能正常解密,证明是合法的设备认证平台,如果不能正常解密,则证明是非法的设备认证平台。In some embodiments, the Bluetooth Mesh device can use asymmetric encryption or symmetric encryption to verify the legitimacy of the device authentication platform. For example, for the asymmetric encryption method, the device authentication platform pre-stores the public key of the Bluetooth Mesh device. After the device authentication platform generates the verification certificate of the device authentication platform, it encrypts the verification certificate with the public key of the Bluetooth Mesh device, and the Bluetooth Mesh device receives the verification certificate. After verifying the certificate, decrypt it with your own private key. If it can be decrypted normally, it proves to be a legitimate device authentication platform. If it cannot be decrypted normally, it proves to be an illegal device authentication platform. For the symmetric encryption method, the device authentication platform and the Bluetooth Mesh device pre-share the same key (that is, the pre-shared key). After the device authentication platform generates the verification certificate of the device authentication platform, it encrypts the verification certificate with the pre-shared key. The verification certificate received by the Bluetooth Mesh device is decrypted with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate device authentication platform. If it cannot be decrypted normally, it proves to be an illegal device authentication platform.
步骤S1210,网关获取蓝牙Mesh设备的校验凭证。Step S1210, the gateway obtains the verification certificate of the Bluetooth Mesh device.
在一些实施例中,未配网广播包中的校验标记指示校验蓝牙Mesh设备,则蓝牙Mesh设备主动向网关发送蓝牙Mesh设备的校验凭证。In some embodiments, the verification mark in the unconfigured network broadcast packet indicates to verify the Bluetooth Mesh device, and the Bluetooth Mesh device actively sends the verification certificate of the Bluetooth Mesh device to the gateway.
在另一些实施例中,可以由网关向蓝牙Mesh设备发送第一请求消息,所述第一请求消息用于请求获取蓝牙Mesh设备的校验凭证;蓝牙Mesh设备在接收到第一请求消息之后,向网关发送蓝牙Mesh设备的校验凭证。In other embodiments, the gateway may send a first request message to the Bluetooth Mesh device, where the first request message is used to request to obtain the verification credential of the Bluetooth Mesh device; after receiving the first request message, the Bluetooth Mesh device, Send the verification credentials of the Bluetooth Mesh device to the gateway.
步骤S1211,网关向网关接入的云平台发送蓝牙Mesh设备的校验凭证。Step S1211, the gateway sends the verification certificate of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
在一些实施例中,网关通过向网关接入的云平台发送蓝牙Mesh设备的校验凭证,请求网关接入的云平台校验蓝牙Mesh设备的合法性。In some embodiments, the gateway requests the cloud platform accessed by the gateway to verify the validity of the Bluetooth Mesh device by sending the verification credential of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
步骤S1212,网关接入的云平台请求设备认证平台校验蓝牙Mesh设备的合法性。Step S1212, the cloud platform accessed by the gateway requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
在一些实施例中,若网关接入的云平台根据未配网广播包中的CID判断蓝牙Mesh设备不是基于云平台开发的设备,则网关接入的云平台根据未配网广播包中的CID获取对应的设备认证平台;网关接入的云平台向设备认证平台发送蓝牙Mesh设备的校验凭证,请求设备认证平台校验蓝牙Mesh设备的合法性。In some embodiments, if the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is not a device developed based on the cloud platform according to the CID in the unconfigured broadcast packet, the cloud platform accessed by the gateway determines according to the CID in the unconfigured broadcast packet. Obtain the corresponding device authentication platform; the cloud platform connected to the gateway sends the verification certificate of the Bluetooth Mesh device to the device authentication platform, and requests the device authentication platform to verify the validity of the Bluetooth Mesh device.
在另一些实施例中,若网关接入的云平台根据未配网广播包中的CID判断蓝牙Mesh设备是基于云平台开发的设备,则网关接入的云平台校验蓝牙Mesh设备的合法性。In other embodiments, if the cloud platform accessed by the gateway determines that the Bluetooth Mesh device is a device developed based on the cloud platform according to the CID in the unconfigured network broadcast packet, the cloud platform accessed by the gateway verifies the validity of the Bluetooth Mesh device .
步骤S1213,设备认证平台校验蓝牙Mesh设备的合法性。Step S1213, the device authentication platform verifies the validity of the Bluetooth Mesh device.
在一些实施例中,若蓝牙Mesh设备的校验凭证是安全证书,则设备认证平台校验该安全证书是否合法;若校验该安全证书合法,则认证蓝牙Mesh设备合法;若校验该安全证书不合法,则认证蓝牙Mesh设备不合法。In some embodiments, if the verification certificate of the Bluetooth Mesh device is a security certificate, the device authentication platform verifies whether the security certificate is legal; if the security certificate is verified to be legal, it verifies that the Bluetooth Mesh device is legal; If the certificate is invalid, the authentication of the Bluetooth Mesh device is invalid.
在具体实施时,设备认证平台可以采用非对称加密或对称加密方法校验蓝牙Mesh设备的合法性。例如,对于非对称加密方法,蓝牙Mesh设备预存设备认证平台的公钥,用设备认证平台的公钥加密该蓝牙Mesh设备的校验凭证,设备认证平台收到的校验凭证后用自己的私钥进行解密,如果能正常解密,证明是合法的蓝牙Mesh设备,如果不能正常解密,则证明是非法的蓝牙Mesh设备。对于对称加密方法,设备认证平台和蓝牙Mesh设备预共享相同的密钥(即预共享密钥),蓝牙Mesh设备用预共享密钥加密蓝牙Mesh设备的校验凭证,设备认证平台收到的校验凭证后用相同的预共享密钥进行解密,如果能正常解密,证明是合法的蓝牙Mesh设备;如果不能正常解密,则证明是非法的蓝牙Mesh设备。During specific implementation, the device authentication platform can use asymmetric encryption or symmetric encryption to verify the legitimacy of the Bluetooth Mesh device. For example, for the asymmetric encryption method, the Bluetooth Mesh device pre-stores the public key of the device authentication platform, encrypts the verification certificate of the Bluetooth Mesh device with the public key of the device authentication platform, and uses its own private key after receiving the verification certificate. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device. For the symmetric encryption method, the device authentication platform and the Bluetooth Mesh device pre-share the same key (ie, the pre-shared key), and the Bluetooth Mesh device uses the pre-shared key to encrypt the verification credentials of the Bluetooth Mesh device. After verifying the certificate, decrypt it with the same pre-shared key. If it can be decrypted normally, it proves to be a legitimate Bluetooth Mesh device; if it cannot be decrypted normally, it proves to be an illegal Bluetooth Mesh device.
步骤S1214,设备认证平台向网关接入的云平台反馈蓝牙Mesh设备的校验结果。Step S1214, the device authentication platform feeds back the verification result of the Bluetooth Mesh device to the cloud platform accessed by the gateway.
步骤S1215,网关接入的云平台向网关反馈蓝牙Mesh设备的校验结果。Step S1215, the cloud platform connected to the gateway feeds back the verification result of the Bluetooth Mesh device to the gateway.
步骤S1216,若蓝牙Mesh设备的校验结果为合法,网关请求网关接入的云平台添加蓝牙Mesh设备。Step S1216, if the verification result of the Bluetooth Mesh device is valid, the gateway requests the cloud platform accessed by the gateway to add the Bluetooth Mesh device.
在一些实施例中,网关向网关接入的云平台发送包括蓝牙Mesh设备的UUID在内的设备信息,网关接入的云平台添加蓝牙Mesh设备的设备信息。In some embodiments, the gateway sends device information including the UUID of the Bluetooth Mesh device to the cloud platform connected to the gateway, and the cloud platform connected to the gateway adds the device information of the Bluetooth Mesh device.
上述以蓝牙Mesh设备的校验结果为合法为例,执行步骤S1216。若蓝牙Mesh设备的校验结果为不合法,则从蓝牙Mesh网络中删除蓝牙Mesh设备。In the above, taking the verification result of the Bluetooth Mesh device as valid as an example, step S1216 is executed. If the verification result of the Bluetooth Mesh device is invalid, delete the Bluetooth Mesh device from the Bluetooth Mesh network.
图11所示的蓝牙设备接入认证方法的处理流程中,先由蓝牙Mesh设备校验设备认证平台的合法性,在校验结果指示设备认证平台合法的情况下,再由网关校验蓝牙Mesh设备的合法性。再具体实施时,也可以先由网关校验蓝牙Mesh设备的合法性,在校验结果指示蓝牙Mesh设备合法的情况下,再由蓝牙Mesh设备校验设备认证平台的合法性;即在执行完步骤S1201至步骤S1203之后,先执行步骤S1210至S1215,再执行步骤S1204-1209。In the processing flow of the Bluetooth device access authentication method shown in Figure 11, the Bluetooth Mesh device verifies the validity of the device authentication platform first, and when the verification result indicates that the device authentication platform is legal, the gateway verifies the Bluetooth Mesh Legality of the device. In specific implementation, the gateway can also verify the validity of the Bluetooth Mesh device first, and when the verification result indicates that the Bluetooth Mesh device is legal, then the Bluetooth Mesh device can verify the validity of the device authentication platform; that is, after the execution is completed. After steps S1201 to S1203, steps S1210 to S1215 are performed first, and then steps S1204-1209 are performed.
基于上述图10所示,由网关校验蓝牙Mesh设备的合法性,以及由蓝牙Mesh设备校验网关/云平台的合法性对本申请实施例提供的蓝牙设备接入认证方法进行详细说明。基于上述图11所示,由网关校验蓝牙Mesh设备的合法性,以及由蓝牙Mesh设备校验设备认证平台的合法性对本申请实施例提供的蓝牙设备接入认证方法进行详细说明。在具体实施时,网关校验蓝牙Mesh设备的合法性、由蓝牙Mesh设备校验网关/云平台的合法性、以及由蓝牙Mesh设备校验设备认证平台的合法性可以均执行;且网关校验蓝牙Mesh设备的合法性、由蓝牙Mesh设备校验网关/云平台的合法性、以及由蓝牙Mesh设备校验设备认证平台的合法性之间不存在执行的先后顺序。其中,蓝牙Mesh设备校验网关/云平台的合法性、与由蓝牙Mesh设备校验设备认证平台的合法性之间可以存在优先级,如蓝牙Mesh设备校验网关/云平台的合法性的优先级高于由蓝牙Mesh设备校验设备认证平台的合法性的优先级,则蓝牙Mesh设备优先校验网关/云平台的合法性。Based on the above-mentioned FIG. 10 , the validity of the Bluetooth Mesh device is verified by the gateway, and the validity of the gateway/cloud platform is verified by the Bluetooth Mesh device. The Bluetooth device access authentication method provided by the embodiment of the present application is described in detail. Based on the above-mentioned FIG. 11 , the validity of the Bluetooth Mesh device is verified by the gateway, and the validity of the device authentication platform is verified by the Bluetooth Mesh device. The Bluetooth device access authentication method provided by the embodiment of the present application is described in detail. In specific implementation, the gateway can verify the validity of the Bluetooth Mesh device, the Bluetooth Mesh device can verify the validity of the gateway/cloud platform, and the Bluetooth Mesh device can verify the legality of the device authentication platform. There is no sequence of execution between the validity of the Bluetooth Mesh device, the validity of the gateway/cloud platform verified by the Bluetooth Mesh device, and the validity of the device authentication platform verified by the Bluetooth Mesh device. Among them, there may be a priority between the Bluetooth Mesh device verifying the legitimacy of the gateway/cloud platform and the Bluetooth Mesh device verifying the legitimacy of the device authentication platform, such as the Bluetooth Mesh device verifying the legitimacy of the gateway/cloud platform. If the level is higher than the priority of the Bluetooth Mesh device verifying the validity of the device authentication platform, the Bluetooth Mesh device will give priority to verifying the validity of the gateway/cloud platform.
需要说明的是,本申请实施例所述的“蓝牙设备”也可以是应用于蓝牙Mesh网络中的蓝牙Mesh设备,本申请实施例所述的“云平台”为网关接入的云平台。It should be noted that the "Bluetooth device" described in the embodiments of the present application may also be a Bluetooth Mesh device applied in a Bluetooth Mesh network, and the "cloud platform" described in the embodiments of the present application is a cloud platform accessed by a gateway.
应理解,在本申请的各种实施例中,上述各过程的序号的大小并不意味着执行顺序的先后,各过程的执行顺序应以其功能和内在逻辑确定,而不应对本申请实施例的实施过程构成任何限定。It should be understood that, in various embodiments of the present application, the size of the sequence numbers of the above-mentioned processes does not mean the sequence of execution, and the execution sequence of each process should be determined by its functions and internal logic, and should not be dealt with in the embodiments of the present application. implementation constitutes any limitation.
为实现本申请实施例提供的蓝牙设备接入认证方法,本申请实施例还提供一种网关,所述网关1300的可选组成结构,如图12所示,包括:In order to implement the Bluetooth device access authentication method provided by the embodiment of the present application, the embodiment of the present application further provides a gateway. The optional composition structure of the gateway 1300, as shown in FIG. 12 , includes:
第一处理单元1301,配置为确定蓝牙设备的校验凭证;The first processing unit 1301 is configured to determine the verification credential of the Bluetooth device;
第一发送单元1302,配置为向云平台发送所述蓝牙设备的校验凭证,所述蓝牙设备的校验凭证用于所述云平台确定所述蓝牙设备的合法性。The first sending unit 1302 is configured to send the verification credential of the Bluetooth device to the cloud platform, where the verification credential of the Bluetooth device is used for the cloud platform to determine the validity of the Bluetooth device.
在一些实施例中,所述第一处理单元1301,配置为接收所述蓝牙设备发送的所述蓝牙设备的校验凭证。In some embodiments, the first processing unit 1301 is configured to receive a verification credential of the Bluetooth device sent by the Bluetooth device.
在一些实施例中,所述第一处理单元1301,还配置为向所述蓝牙设备发送第一请求消息,所述第一请求消息用于请求获取所述蓝牙设备的校验凭证。In some embodiments, the first processing unit 1301 is further configured to send a first request message to the Bluetooth device, where the first request message is used to request to obtain a verification credential of the Bluetooth device.
在一些实施例中,所述第一处理单元1301,配置为接收所述云平台发送的设备校验结果,所述设备校验结果用于指示所述蓝牙设备的合法性。In some embodiments, the first processing unit 1301 is configured to receive a device verification result sent by the cloud platform, where the device verification result is used to indicate the validity of the Bluetooth device.
在一些实施例中,所述第一处理单元1301,还配置为确定所述网关和/或所述的云平台的校验凭证。In some embodiments, the first processing unit 1301 is further configured to determine the verification credential of the gateway and/or the cloud platform.
在一些实施例中,所述网关和/或所述云平台的校验凭证为预先存储的。In some embodiments, the verification credentials of the gateway and/or the cloud platform are pre-stored.
在一些实施例中,所述第一处理单元1301,配置为向所述云平台发送第二请求消息,所述第二请求消息用于请求获取所述网关和/或所述云平台的校验凭证;In some embodiments, the first processing unit 1301 is configured to send a second request message to the cloud platform, where the second request message is used to request to obtain the verification of the gateway and/or the cloud platform certificate;
接收所述云平台发送的所述网关和/或所述云平台的校验凭证。Receive the verification credential of the gateway and/or the cloud platform sent by the cloud platform.
在一些实施例中,所述第一发送单元1302,还配置为向所述蓝牙设备发送所述网关和/或所述云平台的校验凭证,所述网关和/或所述云平台的校验凭证用于所述蓝牙设备校验所述网关/或所述云平台的合法性。In some embodiments, the first sending unit 1302 is further configured to send the verification credentials of the gateway and/or the cloud platform to the Bluetooth device, the verification credentials of the gateway and/or the cloud platform The verification credential is used by the Bluetooth device to verify the validity of the gateway/or the cloud platform.
在一些实施例中,所述第一处理单元1301,还配置为接收所述蓝牙设备发送的第三请求消息,所述第三请求消息用于请求获取所述网关和/或所述云平台的校验凭证。In some embodiments, the first processing unit 1301 is further configured to receive a third request message sent by the Bluetooth device, where the third request message is used to request to obtain the information of the gateway and/or the cloud platform Verify credentials.
在一些实施例中,所述第一处理单元1301,还配置为接收所述蓝牙设备发送的网关和/或所述云平台校验结果,所述网关和/或所述云平台校验结果用于指示针对所述网关和/或所述云平台的合法性。In some embodiments, the first processing unit 1301 is further configured to receive the gateway and/or the cloud platform verification result sent by the Bluetooth device, the gateway and/or the cloud platform verification result using to indicate legitimacy against the gateway and/or the cloud platform.
在一些实施例中,所述第一发送单元1302,配置为根据所述蓝牙设备的校验标记,向所述云平台发送第四请求消息,所述第四请求消息用于请求获取设备认证平台的校验凭证;In some embodiments, the first sending unit 1302 is configured to send a fourth request message to the cloud platform according to the check mark of the Bluetooth device, where the fourth request message is used to request to obtain a device authentication platform verification certificate;
所述设备认证平台的校验凭证用于所述蓝牙设备校验所述设备认证平台的合法性。The verification credential of the device authentication platform is used for the Bluetooth device to verify the legitimacy of the device authentication platform.
在一些实施例中,所述第一处理单元1301,还配置为接收所述云平台发送的所述设备认证平台的校验凭证;In some embodiments, the first processing unit 1301 is further configured to receive the verification credential of the device authentication platform sent by the cloud platform;
所述第一发送单元1302,还配置为向所述蓝牙设备发送所述设备认证平台的校验凭证。The first sending unit 1302 is further configured to send the verification credential of the device authentication platform to the Bluetooth device.
在一些实施例中,所述第一处理单元1301,还配置为请求所述云平台添加所述蓝牙设备。In some embodiments, the first processing unit 1301 is further configured to request the cloud platform to add the Bluetooth device.
在一些实施例中,所述第一处理单元1301,配置为向所述云平台发送所述蓝牙设备的信息,所述蓝牙设备的信息用于所述云平台添加所述蓝牙设备。In some embodiments, the first processing unit 1301 is configured to send the information of the Bluetooth device to the cloud platform, where the information of the Bluetooth device is used for the cloud platform to add the Bluetooth device.
在一些实施例中,所述第一发送单元1302,还配置为向所述蓝牙设备发送配置信息,所述配置信息用于执行蓝牙设备入网配置。In some embodiments, the first sending unit 1302 is further configured to send configuration information to the Bluetooth device, where the configuration information is used to perform network access configuration of the Bluetooth device.
在一些实施例中,所述第一处理单元1301,还配置为接收所述蓝牙设备发送的校验标记,所述校验标记用于指示需要检验的对象。In some embodiments, the first processing unit 1301 is further configured to receive a check mark sent by the Bluetooth device, where the check mark is used to indicate an object to be checked.
在一些实施例中,所述校验标记包括下述至少一项:校验所述蓝牙设备、检验所述网关和/或所述云平台、以及校验设备认证平台。In some embodiments, the verification mark includes at least one of: verifying the Bluetooth device, verifying the gateway and/or the cloud platform, and verifying a device authentication platform.
为实现本申请实施例提供的蓝牙设备接入认证方法,本申请实施例还提供一种云平台,所述云平台1400的可选组成结构,如图13所示,包括:In order to implement the Bluetooth device access authentication method provided by the embodiment of the present application, the embodiment of the present application further provides a cloud platform. The optional composition structure of the cloud platform 1400, as shown in FIG. 13 , includes:
第一接收单元1401,配置为接收网关发送的蓝牙设备的校验凭证;The first receiving unit 1401 is configured to receive the verification certificate of the Bluetooth device sent by the gateway;
第二处理单元1402,配置为基于所述蓝牙设备的校验凭证,确定所述蓝牙设备的合法性。The second processing unit 1402 is configured to determine the validity of the Bluetooth device based on the verification credential of the Bluetooth device.
在一些实施例中,所述第二处理单元1402,配置为若所述蓝牙设备不是所述云平台对应的设备,则向设备认证平台发送携带所述蓝牙设备的校验凭证的第五请求消息;所述第五请求消息用于请求所述设备认证平台校验所述蓝牙设备的合法性;In some embodiments, the second processing unit 1402 is configured to send a fifth request message carrying the verification credential of the Bluetooth device to the device authentication platform if the Bluetooth device is not a device corresponding to the cloud platform ; The fifth request message is used to request the device authentication platform to verify the legitimacy of the Bluetooth device;
若所述蓝牙设备是所述云平台对应的设备,则校验所述蓝牙设备的合法性。If the Bluetooth device is a device corresponding to the cloud platform, verify the validity of the Bluetooth device.
在一些实施例中,所述第一接收单元1401,还配置为接收所述设备认证平台发送的设备校验结果,所述设备校验结果用于指示所述蓝牙设备的合法性。In some embodiments, the first receiving unit 1401 is further configured to receive a device verification result sent by the device authentication platform, where the device verification result is used to indicate the validity of the Bluetooth device.
在一些实施例中,所述第二处理单元1402,还配置为向所述网关发送所述设备校验结果。In some embodiments, the second processing unit 1402 is further configured to send the device verification result to the gateway.
在一些实施例中,所述第一接收单元1401,还配置为接收所述网关发送的第二请求消息,所述第二请求消息用于请求获取所述网关和/或所述云平台的校验凭证;In some embodiments, the first receiving unit 1401 is further configured to receive a second request message sent by the gateway, where the second request message is used for requesting to obtain the calibration of the gateway and/or the cloud platform verification certificate;
所述第二处理单元1402,还配置为确认所述网关和/或所述云平台的校验凭证。The second processing unit 1402 is further configured to confirm the verification credentials of the gateway and/or the cloud platform.
在一些实施例中,所述第二处理单元1402,配置为若所述蓝牙设备不是所述云平台对应的设备,则所述云平台确定所述蓝牙设备对应的设备认证平台;向所述设备认证平台发送第六请求消息;所述第六请求消息携带所述网关和/或所述云平台的标识,用于请求获取所述网关和/或所述云平台的校验凭证。In some embodiments, the second processing unit 1402 is configured to, if the Bluetooth device is not a device corresponding to the cloud platform, the cloud platform determines a device authentication platform corresponding to the Bluetooth device; The authentication platform sends a sixth request message; the sixth request message carries the identifier of the gateway and/or the cloud platform, and is used to request to obtain the verification credential of the gateway and/or the cloud platform.
所述第一接收单元1401,配置为接收所述设备认证平台发送的所述网关和/或所述云平台的校验凭证。The first receiving unit 1401 is configured to receive the verification credential of the gateway and/or the cloud platform sent by the device authentication platform.
在一些实施例中,所述第二处理单元1402,还配置为向所述网关发送所述网关和/或所述云平台的校验凭证。In some embodiments, the second processing unit 1402 is further configured to send the gateway and/or the verification credential of the cloud platform to the gateway.
在一些实施例中,所述第一接收单元1401,还配置为接收所述网关发送第四请求消息,所述第四请求消息用于请求获取设备认证平台的校验凭证;确定所述设备认证平台的校验凭证。In some embodiments, the first receiving unit 1401 is further configured to receive a fourth request message sent by the gateway, where the fourth request message is used to request to obtain the verification credential of the device authentication platform; determine the device authentication Platform verification credentials.
在一些实施例中,所述第二处理单元1402,配置为向所述设备认证平台发送第七请求消息,所述第七请求消息用于请求获取所述设备认证平台的校验凭证;In some embodiments, the second processing unit 1402 is configured to send a seventh request message to the device authentication platform, where the seventh request message is used to request to obtain the verification credential of the device authentication platform;
所述第一接收单元1401,配置为接收所述设备认证平台发送的所述设备认证平台的校验凭证。The first receiving unit 1401 is configured to receive the verification credential of the device authentication platform sent by the device authentication platform.
在一些实施例中,所述第二处理单元1402,配置为向所述网关发送所述设备认证平台的校验凭证。In some embodiments, the second processing unit 1402 is configured to send the verification credential of the device authentication platform to the gateway.
在一些实施例中,所述第二处理单元1402,还配置为添加所述蓝牙设备。In some embodiments, the second processing unit 1402 is further configured to add the Bluetooth device.
在一些实施例中,所述第二处理单元1402,配置为接收所述网关发送的所述蓝牙设备的信息;根据所述蓝牙设备的信息,添加所述蓝牙设备。In some embodiments, the second processing unit 1402 is configured to receive the information of the Bluetooth device sent by the gateway; and add the Bluetooth device according to the information of the Bluetooth device.
为实现本申请实施例提供的蓝牙设备接入认证方法,本申请实施例还提供一种设备认证平台,所述设备认证平台1500的可选组成结构,如图14所示,包括:In order to realize the Bluetooth device access authentication method provided by the embodiment of the present application, the embodiment of the present application further provides a device authentication platform. The optional composition structure of the device authentication platform 1500, as shown in FIG. 14 , includes:
第二接收单元1501,配置为接收云平台发送的第五请求消息;所述第五请求消息包括蓝牙设备的校验凭证;The second receiving unit 1501 is configured to receive a fifth request message sent by the cloud platform; the fifth request message includes the verification credential of the Bluetooth device;
第三处理单元1502,根据所述蓝牙设备的校验凭证,校验所述蓝牙设备的合法性。The third processing unit 1502 verifies the validity of the Bluetooth device according to the verification certificate of the Bluetooth device.
在一些实施例中,所述第二接收单元1501,还配置为接收所述云平台发送的第六请求消息;所述第六请求消息携带所述网关和/或所述云平台的标识,用于请求获取所述网关和/或所述云平台的校验凭证。In some embodiments, the second receiving unit 1501 is further configured to receive a sixth request message sent by the cloud platform; the sixth request message carries the identifier of the gateway and/or the cloud platform, and uses upon request to obtain the verification credential of the gateway and/or the cloud platform.
在一些实施例中,所述第三处理单元1502,配置为根据所述网关和/或所述云平台的标识,生成所述网关和/或所述云平台的校验凭证;In some embodiments, the third processing unit 1502 is configured to generate a verification credential of the gateway and/or the cloud platform according to the identifier of the gateway and/or the cloud platform;
向所述云平台发送所述网关和/或所述云平台的校验凭证。Send the verification credential of the gateway and/or the cloud platform to the cloud platform.
为实现本申请实施例提供的蓝牙设备接入认证方法,本申请实施例还提供一种蓝牙设备,所述蓝牙设备1600的可选组成结构,如图15所示,包括:In order to implement the Bluetooth device access authentication method provided by the embodiment of the present application, the embodiment of the present application further provides a Bluetooth device. The optional composition structure of the Bluetooth device 1600, as shown in FIG. 15 , includes:
第二发送单元1601,配置为向网关发送蓝牙设备的校验凭证,所述蓝牙设备的校验凭证用于确定所述蓝牙设备的合法性。The second sending unit 1601 is configured to send a verification certificate of the Bluetooth device to the gateway, where the verification certificate of the Bluetooth device is used to determine the validity of the Bluetooth device.
在一些实施例中,所述蓝牙设备1600还包括:In some embodiments, the Bluetooth device 1600 further includes:
第四处理单元1602,配置为接收所述网关发送的第一请求消息,所述第一请求消息用于请求获取所述蓝牙设备的校验凭证。The fourth processing unit 1602 is configured to receive a first request message sent by the gateway, where the first request message is used to request to obtain a verification credential of the Bluetooth device.
在一些实施例中,所述蓝牙设备1600还包括:In some embodiments, the Bluetooth device 1600 further includes:
第五处理单元1603,配置为接收所述网关和/或所述云平台的校验凭证,所述网关和/或所述云平台的校验凭证用于所述蓝牙设备校验所述网关/或所述云平台的合法性。The fifth processing unit 1603 is configured to receive the verification credential of the gateway and/or the cloud platform, and the verification credential of the gateway and/or the cloud platform is used for the Bluetooth device to verify the gateway/ or the legality of the cloud platform.
在一些实施例中,所述第二发送单元1601,还配置为向所述网关发送第三请求消息,所述第三请求消息用于请求获取所述网关和/或所述云平台的校验凭证。In some embodiments, the second sending unit 1601 is further configured to send a third request message to the gateway, where the third request message is used to request to obtain the verification of the gateway and/or the cloud platform certificate.
在一些实施例中,所述第五处理单元1603,配置为根据所述网关和/或所述云平台的校验凭证,校验所述网关和/或所述云平台的合法性。In some embodiments, the fifth processing unit 1603 is configured to verify the validity of the gateway and/or the cloud platform according to the verification credentials of the gateway and/or the cloud platform.
在一些实施例中,所述第二发送单元1601,配置为向所述网关发送所述蓝牙设备发送的网关和/或所述云平台校验结果,所述网关和/或所述云平台校验结果用于指示针对所述网关和/或所述云平台的合法性。In some embodiments, the second sending unit 1601 is configured to send the gateway and/or the cloud platform verification result sent by the Bluetooth device to the gateway, the gateway and/or the cloud platform verification result. The verification result is used to indicate the legitimacy of the gateway and/or the cloud platform.
在一些实施例中,所述蓝牙设备1600还包括:所述第六处理单元1604,配置为接收所述网关发送的设备认证平台的校验凭证;基于所述设备认证平台的校验凭证,校验所述设备认证平台的合法性。In some embodiments, the Bluetooth device 1600 further includes: the sixth processing unit 1604, configured to receive the verification credential of the device authentication platform sent by the gateway; based on the verification credential of the device authentication platform, the verification Verify the legitimacy of the device authentication platform.
在一些实施例中,所述蓝牙设备1600还包括:第三接收单元1605,配置为接收所述网关发送的配置信息,所述配置信息用于执行蓝牙设备入网配置。In some embodiments, the Bluetooth device 1600 further includes: a third receiving unit 1605, configured to receive configuration information sent by the gateway, where the configuration information is used to perform network access configuration of the Bluetooth device.
本申请实施例提供一种网关,包括处理器和用于存储能够在处理器上运行的计算机程序的存储器,其中,所述处理器用于运行所述计算机程序时,执行上述网关执行的蓝牙设备接入认证方法的步骤。An embodiment of the present application provides a gateway, including a processor and a memory for storing a computer program that can be executed on the processor, wherein the processor is configured to execute the Bluetooth device interface executed by the gateway when the computer program is executed. Enter the steps of the authentication method.
本申请实施例提供一种云平台,包括处理器和用于存储能够在处理器上运行的计算机程序的存储器,其中,所述处理器用于运行所述计算机程序时,执行上述云平台执行的蓝牙设备接入认证方法的步骤。An embodiment of the present application provides a cloud platform, including a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the bluetooth executed by the cloud platform when running the computer program The steps of the device access authentication method.
本申请实施例提供一种设备认证平台,包括处理器和用于存储能够在处理器上运行的计算机程序的存储器,其中,所述处理器用于运行所述计算机程序时,执行上述设备认证平台执行的蓝牙设备接入认证方法的步骤。An embodiment of the present application provides a device authentication platform, including a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the above-mentioned device authentication platform when running the computer program. The steps of the Bluetooth device access authentication method.
本申请实施例提供一种蓝牙设备,包括处理器和用于存储能够在处理器上运行的计算机程序的存储器,其中,所述处理器用于运行所述计算机程序时,执行上述蓝牙设备执行的蓝牙设备接入认证方法的步骤。An embodiment of the present application provides a Bluetooth device, including a processor and a memory for storing a computer program that can be run on the processor, wherein the processor is configured to execute the Bluetooth program executed by the Bluetooth device when the computer program is executed. The steps of the device access authentication method.
本申请实施例还提供一种芯片,包括:处理器,用于从存储器中调用并运行计算机程序,使得安装有所述芯片的设备执行上述蓝牙设备接入认证方法。An embodiment of the present application further provides a chip, including: a processor configured to call and run a computer program from a memory, so that a device installed with the chip executes the above-mentioned Bluetooth device access authentication method.
本申请实施例还提供一种存储介质,存储有可执行程序,所述可执行程序被处理器执行时,实现上述蓝牙设备接入认证方法。An embodiment of the present application further provides a storage medium storing an executable program, and when the executable program is executed by a processor, the above-mentioned Bluetooth device access authentication method is implemented.
本申请实施例还提供一种计算机程序产品,包括计算机程序指令,该计算机程序指令使得计算机执行上述蓝牙设备接入认证方法。The embodiments of the present application further provide a computer program product, including computer program instructions, the computer program instructions enable a computer to execute the above-mentioned Bluetooth device access authentication method.
本申请实施例还提供一种计算机程序,所述计算机程序使得计算机执行上述蓝牙设备接入认证方法。The embodiment of the present application further provides a computer program, the computer program enables a computer to execute the above-mentioned Bluetooth device access authentication method.
图16是本申请实施例的电子设备(网关、或云平台、或蓝牙设备、或设备认证平台)的硬件组成结构示意图,电子设备700包括:至少一个处理器701、存储器702和至少一个网络接口704。电子设备700中的各个组件通过总线系统705耦合在一起。可理解,总线系统705用于实现这些组件之间的连接通信。总线系统705除包括数据总线之外,还包括电源总线、控制总线和状态信号总线。但是为了清楚说明起见,在图16中将各种总线都标为总线系统705。16 is a schematic diagram of the hardware composition of an electronic device (gateway, or cloud platform, or Bluetooth device, or device authentication platform) according to an embodiment of the present application. The electronic device 700 includes: at least one processor 701, memory 702, and at least one network interface 704. The various components in electronic device 700 are coupled together by bus system 705 . It can be understood that the bus system 705 is used to implement the connection communication between these components. In addition to the data bus, the bus system 705 also includes a power bus, a control bus and a status signal bus. However, for the sake of clarity, the various buses are labeled as bus system 705 in FIG. 16 .
可以理解,存储器702可以是易失性存储器或非易失性存储器,也可包括易失性和非易失性存储器两者。其中,非易失性存储器可以是ROM、可编程只读存储器(PROM,Programmable Read-Only Memory)、可擦除可编程只读存储器(EPROM,Erasable Programmable Read-Only Memory)、电可擦除可编程只读存储器(EEPROM,Electrically Erasable Programmable Read-Only Memory)、磁性随机存取存储器(FRAM,ferromagnetic random access memory)、快闪存储器(Flash Memory)、磁表面存储器、光盘、或只读光盘(CD-ROM,Compact Disc Read-Only Memory);磁表面存储器可以是磁盘存储器或磁带存储器。易失性存储器可以是随机存取存储器(RAM,Random Access Memory),其用作外部高速缓存。通过示例性但不是限制性说明,许多形式的RAM可用,例如静态随机存取存储器(SRAM,Static Random Access Memory)、同步静态随机存取存储器(SSRAM,Synchronous Static Random Access Memory)、动态随机存 取存储器(DRAM,Dynamic Random Access Memory)、同步动态随机存取存储器(SDRAM,Synchronous Dynamic Random Access Memory)、双倍数据速率同步动态随机存取存储器(DDRSDRAM,Double Data Rate Synchronous Dynamic Random Access Memory)、增强型同步动态随机存取存储器(ESDRAM,Enhanced Synchronous Dynamic Random Access Memory)、同步连接动态随机存取存储器(SLDRAM,SyncLink Dynamic Random Access Memory)、直接内存总线随机存取存储器(DRRAM,Direct Rambus Random Access Memory)。本申请实施例描述的存储器702旨在包括但不限于这些和任意其它适合类型的存储器。It will be appreciated that memory 702 may be either volatile memory or non-volatile memory, and may include both volatile and non-volatile memory. Among them, the non-volatile memory can be ROM, Programmable Read-Only Memory (PROM, Programmable Read-Only Memory), Erasable Programmable Read-Only Memory (EPROM, Erasable Programmable Read-Only Memory), Electrically Erasable Programmable Read-Only Memory Programmable read-only memory (EEPROM, Electrically Erasable Programmable Read-Only Memory), magnetic random access memory (FRAM, ferromagnetic random access memory), flash memory (Flash Memory), magnetic surface memory, optical disk, or CD-ROM -ROM, Compact Disc Read-Only Memory); magnetic surface memory can be disk memory or tape memory. Volatile memory may be Random Access Memory (RAM), which acts as an external cache. By way of example but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory Memory (DRAM, Dynamic Random Access Memory), Synchronous Dynamic Random Access Memory (SDRAM, Synchronous Dynamic Random Access Memory), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM, Double Data Rate Synchronous Dynamic Random Access Memory), Enhanced Type Synchronous Dynamic Random Access Memory (ESDRAM, Enhanced Synchronous Dynamic Random Access Memory), Synchronous Link Dynamic Random Access Memory (SLDRAM, SyncLink Dynamic Random Access Memory), Direct Memory Bus Random Access Memory (DRRAM, Direct Rambus Random Access Memory) ). The memory 702 described in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memory.
本申请实施例中的存储器702用于存储各种类型的数据以支持电子设备700的操作。这些数据的示例包括:用于在电子设备700上操作的任何计算机程序,如应用程序7022。实现本申请实施例方法的程序可以包含在应用程序7022中。The memory 702 in this embodiment of the present application is used to store various types of data to support the operation of the electronic device 700 . Examples of such data include: any computer program used to operate on electronic device 700, such as application 7022. The program for implementing the method of the embodiment of the present application may be included in the application program 7022 .
上述本申请实施例揭示的方法可以应用于处理器701中,或者由处理器701实现。处理器701可能是一种集成电路芯片,具有信号的处理能力。在实现过程中,上述方法的各步骤可以通过处理器701中的硬件的集成逻辑电路或者软件形式的指令完成。上述的处理器701可以是通用处理器、数字信号处理器(DSP,Digital Signal Processor),或者其他可编程逻辑器件、分立门或者晶体管逻辑器件、分立硬件组件等。处理器701可以实现或者执行本申请实施例中的公开的各方法、步骤及逻辑框图。通用处理器可以是微处理器或者任何常规的处理器等。结合本申请实施例所公开的方法的步骤,可以直接体现为硬件译码处理器执行完成,或者用译码处理器中的硬件及软件模块组合执行完成。软件模块可以位于存储介质中,该存储介质位于存储器702,处理器701读取存储器702中的信息,结合其硬件完成前述方法的步骤。The methods disclosed in the above embodiments of the present application may be applied to the processor 701 or implemented by the processor 701 . The processor 701 may be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above-mentioned method can be completed by an integrated logic circuit of hardware in the processor 701 or an instruction in the form of software. The above-mentioned processor 701 may be a general-purpose processor, a digital signal processor (DSP, Digital Signal Processor), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and the like. The processor 701 may implement or execute the methods, steps, and logical block diagrams disclosed in the embodiments of this application. A general purpose processor may be a microprocessor or any conventional processor or the like. The steps of the method disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium, and the storage medium is located in the memory 702, and the processor 701 reads the information in the memory 702, and completes the steps of the foregoing method in combination with its hardware.
在示例性实施例中,电子设备700可以被一个或多个应用专用集成电路(ASIC,Application Specific Integrated Circuit)、DSP、可编程逻辑器件(PLD,Programmable Logic Device)、复杂可编程逻辑器件(CPLD,Complex Programmable Logic Device)、FPGA、通用处理器、控制器、MCU、MPU、或其他电子元件实现,用于执行前述方法。In an exemplary embodiment, the electronic device 700 may be implemented by one or more Application Specific Integrated Circuits (ASICs), DSPs, Programmable Logic Devices (PLDs), Complex Programmable Logic Devices (CPLDs) , Complex Programmable Logic Device), FPGA, general-purpose processor, controller, MCU, MPU, or other electronic component implementation for performing the aforementioned method.
本申请是参照根据本申请实施例的方法、设备(系统)、和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。The present application is described with reference to flowchart illustrations and/or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present application. It will be understood that each flow and/or block in the flowchart illustrations and/or block diagrams, and combinations of flows and/or blocks in the flowchart illustrations and/or block diagrams, can be implemented by computer program instructions. These computer program instructions may be provided to the processor of a general purpose computer, special purpose computer, embedded processor or other programmable data processing device to produce a machine such that the instructions executed by the processor of the computer or other programmable data processing device produce Means for implementing the functions specified in a flow or flow of a flowchart and/or a block or blocks of a block diagram.
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory result in an article of manufacture comprising instruction means, the instructions The apparatus implements the functions specified in the flow or flow of the flowcharts and/or the block or blocks of the block diagrams.
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。These computer program instructions can also be loaded on a computer or other programmable data processing device to cause a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process such that The instructions provide steps for implementing the functions specified in the flow or blocks of the flowcharts and/or the block or blocks of the block diagrams.
应理解,本申请中术语“系统”和“网络”在本文中常被可互换使用。本申请中术语“和/或”,仅仅是一种描述关联对象的关联关系,表示可以存在三种关系,例如,A和/或B,可以表示:单独存在A,同时存在A和B,单独存在B这三种情况。另外,本申请中字符“/”,一般表示前后关联对象是一种“或”的关系。It should be understood that the terms "system" and "network" in this application are often used interchangeably herein. The term "and/or" in this application is only an association relationship to describe associated objects, which means that there can be three kinds of relationships, for example, A and/or B, which can mean that A exists alone, A and B exist at the same time, independently There are three cases of B. In addition, the character "/" in this application generally indicates that the related objects are an "or" relationship.
以上所述,仅为本申请的较佳实施例而已,并非用于限定本申请的保护范围,凡在本申请的精神和原则之内所作的任何修改、等同替换和改进等,均应包含在本申请的保护范围之内。The above descriptions are only preferred embodiments of the present application, and are not intended to limit the protection scope of the present application. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present application shall be included in the within the scope of protection of this application.

Claims (100)

  1. 一种蓝牙设备接入认证方法,所述方法包括:A Bluetooth device access authentication method, the method comprising:
    网关确定蓝牙设备的校验凭证;The gateway determines the verification certificate of the Bluetooth device;
    所述网关向云平台发送所述蓝牙设备的校验凭证,所述蓝牙设备的校验凭证用于所述云平台确定所述蓝牙设备的合法性。The gateway sends the verification credential of the Bluetooth device to the cloud platform, and the verification credential of the Bluetooth device is used by the cloud platform to determine the validity of the Bluetooth device.
  2. 根据权利要求1所述的方法,其中,所述网关确定蓝牙设备的校验凭证,包括:The method according to claim 1, wherein the gateway determines the verification credential of the Bluetooth device, comprising:
    所述网关接收所述蓝牙设备发送的所述蓝牙设备的校验凭证。The gateway receives the verification credential of the Bluetooth device sent by the Bluetooth device.
  3. 根据权利要求2所述的方法,其中,所述网关确定蓝牙设备的校验凭证,还包括:The method according to claim 2, wherein the gateway determines the verification credential of the Bluetooth device, further comprising:
    所述网关向所述蓝牙设备发送第一请求消息,所述第一请求消息用于请求获取所述蓝牙设备的校验凭证。The gateway sends a first request message to the Bluetooth device, where the first request message is used to request to obtain a verification credential of the Bluetooth device.
  4. 根据权利要求1至3任一项所述的方法,其中,所述方法还包括:The method according to any one of claims 1 to 3, wherein the method further comprises:
    所述网关接收所述云平台发送的设备校验结果,所述设备校验结果用于指示所述蓝牙设备的合法性。The gateway receives a device verification result sent by the cloud platform, where the device verification result is used to indicate the validity of the Bluetooth device.
  5. 根据权利要求1至4任一项所述的方法,其中,所述方法还包括:The method according to any one of claims 1 to 4, wherein the method further comprises:
    所述网关确定所述网关和/或所述的云平台的校验凭证。The gateway determines the verification credential of the gateway and/or the cloud platform.
  6. 根据权利要求5所述的方法,其中,所述网关和/或所述云平台的校验凭证为预先存储的。The method according to claim 5, wherein the verification credentials of the gateway and/or the cloud platform are pre-stored.
  7. 根据权利要求5所述的方法,其中,所述网关确定所述网关和/或所述云平台的校验凭证,包括:The method according to claim 5, wherein the gateway determines the verification credential of the gateway and/or the cloud platform, comprising:
    所述网关向所述云平台发送第二请求消息,所述第二请求消息用于请求获取所述网关和/或所述云平台的校验凭证;sending, by the gateway, a second request message to the cloud platform, where the second request message is used to request to obtain the verification credential of the gateway and/or the cloud platform;
    所述网关接收所述云平台发送的所述网关和/或所述云平台的校验凭证。The gateway receives the verification credential of the gateway and/or the cloud platform sent by the cloud platform.
  8. 根据权利要求5至7任一项所述的方法,其中,所述方法还包括:The method according to any one of claims 5 to 7, wherein the method further comprises:
    所述网关向所述蓝牙设备发送所述网关和/或所述云平台的校验凭证,所述网关和/或所述云平台的校验凭证用于所述蓝牙设备校验所述网关/或所述云平台的合法性。The gateway sends the verification credential of the gateway and/or the cloud platform to the Bluetooth device, and the verification credential of the gateway and/or the cloud platform is used by the Bluetooth device to verify the gateway/ or the legality of the cloud platform.
  9. 根据权利要求8所述的方法,其中,所述方法还包括:The method of claim 8, wherein the method further comprises:
    所述网关接收所述蓝牙设备发送的第三请求消息,所述第三请求消息用于请求获取所述网关和/或所述云平台的校验凭证。The gateway receives a third request message sent by the Bluetooth device, where the third request message is used to request to obtain the verification credential of the gateway and/or the cloud platform.
  10. 根据权利要求8或9所述的方法,其中,所述方法还包括:The method according to claim 8 or 9, wherein the method further comprises:
    所述网关接收所述蓝牙设备发送的网关和/或所述云平台校验结果,所述网关和/或所述云平台校验结果用于指示针对所述网关和/或所述云平台的合法性。The gateway receives the gateway and/or the cloud platform verification result sent by the Bluetooth device, and the gateway and/or the cloud platform verification result is used to indicate the gateway and/or the cloud platform. legality.
  11. 根据权利要求1至10任一项所述的方法,其中,所述方法还包括:The method according to any one of claims 1 to 10, wherein the method further comprises:
    所述网关根据所述蓝牙设备的校验标记,向所述云平台发送第四请求消息,所述第四请求消息用于请求获取设备认证平台的校验凭证;The gateway sends a fourth request message to the cloud platform according to the verification mark of the Bluetooth device, where the fourth request message is used to request to obtain the verification credential of the device authentication platform;
    所述设备认证平台的校验凭证用于所述蓝牙设备校验所述设备认证平台的合法性。The verification credential of the device authentication platform is used for the Bluetooth device to verify the legitimacy of the device authentication platform.
  12. 根据权利要求11所述的方法,其中,所述方法还包括:The method of claim 11, wherein the method further comprises:
    所述网关接收所述云平台发送的所述设备认证平台的校验凭证;receiving, by the gateway, the verification credential of the device authentication platform sent by the cloud platform;
    所述网关向所述蓝牙设备发送所述设备认证平台的校验凭证。The gateway sends the verification credential of the device authentication platform to the Bluetooth device.
  13. 根据权利1至12任一项所述的方法,其中,所述方法还包括:The method according to any one of claims 1 to 12, wherein the method further comprises:
    所述网关请求所述云平台在添加所述蓝牙设备。The gateway requests the cloud platform to add the Bluetooth device.
  14. 根据权利要求13所述的方法,其中,所述网关请求所述云平台添加所述蓝牙设备,包括:The method of claim 13, wherein the gateway requests the cloud platform to add the Bluetooth device, comprising:
    所述网关向所述云平台发送所述蓝牙设备的信息,所述蓝牙设备的信息用于所述云平台添加所述蓝牙设备。The gateway sends the information of the Bluetooth device to the cloud platform, and the information of the Bluetooth device is used by the cloud platform to add the Bluetooth device.
  15. 根据权利要求1至14任一项所述的方法,其中,所述方法还包括:The method according to any one of claims 1 to 14, wherein the method further comprises:
    所述网关向所述蓝牙设备发送配置信息,所述配置信息用于执行蓝牙设备入网配置。The gateway sends configuration information to the Bluetooth device, where the configuration information is used to perform network access configuration of the Bluetooth device.
  16. 根据权利要求1至15任一项所述的方法,其中,所述方法还包括:The method according to any one of claims 1 to 15, wherein the method further comprises:
    所述网关接收所述蓝牙设备发送的校验标记,所述校验标记用于指示需要检验的对象。The gateway receives a check mark sent by the Bluetooth device, where the check mark is used to indicate an object to be checked.
  17. 根据权利要求16所述的方法,其中,所述校验标记包括下述至少一项:The method of claim 16, wherein the check mark comprises at least one of the following:
    校验所述蓝牙设备;verifying the bluetooth device;
    检验所述网关和/或所述云平台;verifying the gateway and/or the cloud platform;
    校验设备认证平台。Verify the device authentication platform.
  18. 一种蓝牙设备接入认证方法,所述方法包括:A Bluetooth device access authentication method, the method comprising:
    云平台接收网关发送的蓝牙设备的校验凭证;The cloud platform receives the verification certificate of the Bluetooth device sent by the gateway;
    所述云平台基于所述蓝牙设备的校验凭证,确定所述蓝牙设备的合法性。The cloud platform determines the validity of the Bluetooth device based on the verification certificate of the Bluetooth device.
  19. 根据权利要求18所述的方法,其中,所述云平台基于所述蓝牙设备的校验凭证,确定所述蓝牙设备的合法性包括:The method according to claim 18, wherein the cloud platform determining the validity of the Bluetooth device based on the verification credential of the Bluetooth device comprises:
    若所述蓝牙设备不是所述云平台对应的设备,则所述云平台向设备认证平台发送携带所述蓝牙设备的校验凭证的第五请求消息;所述第五请求消息用于请求所述设备认证平台校验所述蓝牙设备的合法性;If the Bluetooth device is not a device corresponding to the cloud platform, the cloud platform sends a fifth request message carrying the verification credential of the Bluetooth device to the device authentication platform; the fifth request message is used to request the The device authentication platform verifies the validity of the Bluetooth device;
    若所述蓝牙设备是所述云平台对应的设备,则所述云平台校验所述蓝牙设备的合法性。If the Bluetooth device is a device corresponding to the cloud platform, the cloud platform verifies the validity of the Bluetooth device.
  20. 根据权利要求19所述的方法,其中,所述方法还包括:The method of claim 19, wherein the method further comprises:
    所述云平台接收所述设备认证平台发送的设备校验结果,所述设备校验结果用于指示所述蓝牙设备的合法性。The cloud platform receives a device verification result sent by the device authentication platform, where the device verification result is used to indicate the validity of the Bluetooth device.
  21. 根据权利要求20所述的方法,其中,所述方法还包括:The method of claim 20, wherein the method further comprises:
    所述云平台向所述网关发送所述设备校验结果。The cloud platform sends the device verification result to the gateway.
  22. 根据权利要求18至21任一项所述的方法,其中,所述方法还包括:The method of any one of claims 18 to 21, wherein the method further comprises:
    所述云平台接收所述网关发送的第二请求消息,所述第二请求消息用于请求获取所述网关和/或所述云平台的校验凭证;receiving, by the cloud platform, a second request message sent by the gateway, where the second request message is used to request to obtain the verification credential of the gateway and/or the cloud platform;
    所述云平台确认所述网关和/或所述云平台的校验凭证。The cloud platform confirms the verification credentials of the gateway and/or the cloud platform.
  23. 根据权利要求22所述的方法,其中,所述云平台确认所述网关和/或所述云平台的合法性,包括:The method according to claim 22, wherein the cloud platform confirms the legitimacy of the gateway and/or the cloud platform, comprising:
    若所述蓝牙设备不是所述云平台对应的设备,则所述云平台确定所述蓝牙设备对应的设备认证平台;If the Bluetooth device is not a device corresponding to the cloud platform, the cloud platform determines a device authentication platform corresponding to the Bluetooth device;
    所述云平台向所述设备认证平台发送第六请求消息;所述第六请求消息携带所述网关和/或所述云平台的标识,用于请求获取所述网关和/或所述云平台的校验凭证;The cloud platform sends a sixth request message to the device authentication platform; the sixth request message carries the identifier of the gateway and/or the cloud platform, and is used to request to obtain the gateway and/or the cloud platform verification certificate;
    所述云平台接收所述设备认证平台发送的所述网关和/或所述云平台的校验凭证。The cloud platform receives the verification credential of the gateway and/or the cloud platform sent by the device authentication platform.
  24. 根据权利要求22或23所述的方法,其中,所述方法还包括:The method of claim 22 or 23, wherein the method further comprises:
    所述云平台向所述网关发送所述网关和/或所述云平台的校验凭证。The cloud platform sends the gateway and/or the verification credential of the cloud platform to the gateway.
  25. 根据权利要求18至24任一项所述的方法,其中,所述方法还包括:The method of any one of claims 18 to 24, wherein the method further comprises:
    所述云平台接收所述网关发送第四请求消息,所述第四请求消息用于请求获取设备认证平台的校验凭证;receiving, by the cloud platform, a fourth request message sent by the gateway, where the fourth request message is used to request to obtain the verification credential of the device authentication platform;
    所述云平台确定所述设备认证平台的校验凭证。The cloud platform determines the verification credential of the device authentication platform.
  26. 根据权利要求25所述的方法,其中,所述云平台确定所述设备认证平台的校验凭证,包括:The method according to claim 25, wherein the cloud platform determines the verification credential of the device authentication platform, comprising:
    所述云平台向所述设备认证平台发送第七请求消息,所述第七请求消息用于请求获取所述设备认证平台的校验凭证;The cloud platform sends a seventh request message to the device authentication platform, where the seventh request message is used to request to obtain the verification credential of the device authentication platform;
    所述云平台接收所述设备认证平台发送的所述设备认证平台的校验凭证。The cloud platform receives the verification certificate of the device authentication platform sent by the device authentication platform.
  27. 根据权利要求25或26所述的方法,其中,所述方法还包括:The method of claim 25 or 26, wherein the method further comprises:
    所述云平台向所述网关发送所述设备认证平台的校验凭证。The cloud platform sends the verification credential of the device authentication platform to the gateway.
  28. 根据权利要求18至27任一项所述的方法,其中,所述方法还包括:The method of any one of claims 18 to 27, wherein the method further comprises:
    所述云平台添加所述蓝牙设备。The cloud platform adds the Bluetooth device.
  29. 根据权利要求28所述的方法,其中,所述云平台添加所述蓝牙设备,包括:The method of claim 28, wherein adding the Bluetooth device to the cloud platform comprises:
    所述云平台接收所述网关发送的所述蓝牙设备的信息;receiving, by the cloud platform, the information of the Bluetooth device sent by the gateway;
    所述云平台根据所述蓝牙设备的信息,添加所述蓝牙设备。The cloud platform adds the Bluetooth device according to the information of the Bluetooth device.
  30. 一种蓝牙设备接入认证方法,所述方法包括:A Bluetooth device access authentication method, the method comprising:
    设备认证平台接收云平台发送的第五请求消息;所述第五请求消息包括蓝牙设备的校验凭证;The device authentication platform receives the fifth request message sent by the cloud platform; the fifth request message includes the verification certificate of the Bluetooth device;
    所述设备认证平台根据所述蓝牙设备的校验凭证,校验所述蓝牙设备的合法性。The device authentication platform verifies the validity of the Bluetooth device according to the verification certificate of the Bluetooth device.
  31. 根据权利要求30所述的方法,其中,所述方法还包括:The method of claim 30, wherein the method further comprises:
    所述设备认证平台接收所述云平台发送的第六请求消息;所述第六请求消息携带所述网关和/或所述云平台的标识,用于请求获取所述网关和/或所述云平台的校验凭证。The device authentication platform receives the sixth request message sent by the cloud platform; the sixth request message carries the identifier of the gateway and/or the cloud platform, and is used to request to obtain the gateway and/or the cloud platform Platform verification credentials.
  32. 根据权利要求31所述的方法,其中,所述方法还包括:The method of claim 31, wherein the method further comprises:
    所述设备认证平台根据所述网关和/或所述云平台的标识,生成所述网关和/或所述云平台的校验凭证;The device authentication platform generates the verification credential of the gateway and/or the cloud platform according to the identifier of the gateway and/or the cloud platform;
    所述设备认证平台向所述云平台发送所述网关和/或所述云平台的校验凭证。The device authentication platform sends the verification credential of the gateway and/or the cloud platform to the cloud platform.
  33. 一种蓝牙设备接入认证方法,所述方法包括:A Bluetooth device access authentication method, the method comprising:
    蓝牙设备向网关发送蓝牙设备的校验凭证,所述蓝牙设备的校验凭证用于确定所述蓝牙设备的合法性。The Bluetooth device sends a verification certificate of the Bluetooth device to the gateway, where the verification certificate of the Bluetooth device is used to determine the validity of the Bluetooth device.
  34. 根据权利要求33所述的方法,其中,所述方法还包括:The method of claim 33, wherein the method further comprises:
    所述蓝牙设备接收所述网关发送的第一请求消息,所述第一请求消息用于请求获取所述蓝牙设备的校验凭证。The Bluetooth device receives a first request message sent by the gateway, where the first request message is used to request to obtain a verification credential of the Bluetooth device.
  35. 根据权利要求33或34所述的方法,其中,所述方法还包括:The method of claim 33 or 34, wherein the method further comprises:
    所述蓝牙设备接收所述网关和/或所述云平台的校验凭证,所述网关和/或所述云平台的校验凭证用于所述蓝牙设备校验所述网关/或所述云平台的合法性。The Bluetooth device receives the verification credential of the gateway and/or the cloud platform, and the verification credential of the gateway and/or the cloud platform is used by the Bluetooth device to verify the gateway/or the cloud the legitimacy of the platform.
  36. 根据权利要求35所述的方法,其中,所述方法还包括:The method of claim 35, wherein the method further comprises:
    所述蓝牙设备向所述网关发送第三请求消息,所述第三请求消息用于请求获取所述网关和/或所述云平台的校验凭证。The Bluetooth device sends a third request message to the gateway, where the third request message is used to request to obtain the verification credential of the gateway and/or the cloud platform.
  37. 根据权利要求35或36所述的方法,其中,所述方法还包括:The method of claim 35 or 36, wherein the method further comprises:
    所述蓝牙设备根据所述网关和/或所述云平台的校验凭证,校验所述网关和/或所述云平台的合法性。The Bluetooth device verifies the validity of the gateway and/or the cloud platform according to the verification credentials of the gateway and/or the cloud platform.
  38. 根据权利要求35至37任一项所述的方法,其中,所述方法还包括:The method of any one of claims 35 to 37, wherein the method further comprises:
    所述蓝牙设备向所述网关发送所述蓝牙设备发送的网关和/或所述云平台校验结果,所述网关和/或所述云平台校验结果用于指示针对所述网关和/或所述云平台的合法性。The bluetooth device sends the gateway and/or the cloud platform verification result sent by the bluetooth device to the gateway, and the gateway and/or the cloud platform verification result is used to indicate the gateway and/or the cloud platform verification result. The legitimacy of the cloud platform.
  39. 根据权利要求33至38任一项所述的方法,其中,所述方法还包括:The method of any one of claims 33 to 38, wherein the method further comprises:
    所述蓝牙设备接收所述网关发送的设备认证平台的校验凭证;The Bluetooth device receives the verification certificate of the device authentication platform sent by the gateway;
    所述蓝牙设备基于所述设备认证平台的校验凭证,校验所述设备认证平台的合法性。The Bluetooth device verifies the legitimacy of the device authentication platform based on the verification credential of the device authentication platform.
  40. 根据权利要求33至39任一项所述的方法,其中,所述方法还包括:The method of any one of claims 33 to 39, wherein the method further comprises:
    所述蓝牙设备接收所述网关发送的配置信息,所述配置信息用于执行蓝牙设备入网配置。The Bluetooth device receives configuration information sent by the gateway, where the configuration information is used to perform network access configuration of the Bluetooth device.
  41. 一种网关,包括:A gateway that includes:
    第一处理单元,配置为确定蓝牙设备的校验凭证;a first processing unit, configured to determine the verification credential of the Bluetooth device;
    第一发送单元,配置为向云平台发送所述蓝牙设备的校验凭证,所述蓝牙设备的校验凭证用于所述云平台确定所述蓝牙设备的合法性。The first sending unit is configured to send the verification certificate of the Bluetooth device to the cloud platform, where the verification certificate of the Bluetooth device is used for the cloud platform to determine the validity of the Bluetooth device.
  42. 根据权利要求41所述的网关,其中,所述第一处理单元,配置为接收所述蓝牙设备发送的所述蓝牙设备的校验凭证。The gateway according to claim 41, wherein the first processing unit is configured to receive a verification credential of the Bluetooth device sent by the Bluetooth device.
  43. 根据权利要求42所述的网关,其中,The gateway of claim 42, wherein,
    所述第一处理单元,还配置为向所述蓝牙设备发送第一请求消息,所述第一请求消息用于请求获取所述蓝牙设备的校验凭证。The first processing unit is further configured to send a first request message to the Bluetooth device, where the first request message is used to request to obtain a verification credential of the Bluetooth device.
  44. 根据权利要求41至43任一项所述的网关,其中,所述第一处理单元,配置为接收所 述云平台发送的设备校验结果,所述设备校验结果用于指示所述蓝牙设备的合法性。The gateway according to any one of claims 41 to 43, wherein the first processing unit is configured to receive a device verification result sent by the cloud platform, where the device verification result is used to indicate the Bluetooth device legitimacy.
  45. 根据权利要求41至44任一项所述的网关,其中,A gateway according to any one of claims 41 to 44, wherein,
    所述第一处理单元,还配置为确定所述网关和/或所述的云平台的校验凭证。The first processing unit is further configured to determine the verification credential of the gateway and/or the cloud platform.
  46. 根据权利要求45所述的网关,其中,所述网关和/或所述云平台的校验凭证为预先存储的。The gateway according to claim 45, wherein the verification credentials of the gateway and/or the cloud platform are pre-stored.
  47. 根据权利要求45所述的网关,其中,The gateway of claim 45, wherein,
    所述第一处理单元,配置为向所述云平台发送第二请求消息,所述第二请求消息用于请求获取所述网关和/或所述云平台的校验凭证;The first processing unit is configured to send a second request message to the cloud platform, where the second request message is used to request to obtain the verification credential of the gateway and/or the cloud platform;
    接收所述云平台发送的所述网关和/或所述云平台的校验凭证。Receive the verification credential of the gateway and/or the cloud platform sent by the cloud platform.
  48. 根据权利要求45至47任一项所述的网关,其中,A gateway according to any one of claims 45 to 47, wherein,
    所述第一发送单元,还配置为向所述蓝牙设备发送所述网关和/或所述云平台的校验凭证,所述网关和/或所述云平台的校验凭证用于所述蓝牙设备校验所述网关/或所述云平台的合法性。The first sending unit is further configured to send the verification credential of the gateway and/or the cloud platform to the Bluetooth device, and the verification credential of the gateway and/or the cloud platform is used for the Bluetooth The device verifies the validity of the gateway and/or the cloud platform.
  49. 根据权利要求48所述的网关,其中,The gateway of claim 48, wherein,
    所述第一处理单元,还配置为接收所述蓝牙设备发送的第三请求消息,所述第三请求消息用于请求获取所述网关和/或所述云平台的校验凭证。The first processing unit is further configured to receive a third request message sent by the Bluetooth device, where the third request message is used to request to obtain the verification credential of the gateway and/or the cloud platform.
  50. 根据权利要求48或49所述的网关,其中,A gateway according to claim 48 or 49, wherein,
    所述第一处理单元,还配置为接收所述蓝牙设备发送的网关和/或所述云平台校验结果,所述网关和/或所述云平台校验结果用于指示针对所述网关和/或所述云平台的合法性。The first processing unit is further configured to receive the gateway and/or the cloud platform verification result sent by the Bluetooth device, where the gateway and/or the cloud platform verification result is used to indicate the gateway and/or the cloud platform verification result. /or the legality of the cloud platform.
  51. 根据权利要求41至50任一项所述的网关,其中,A gateway according to any one of claims 41 to 50, wherein,
    所述第一发送单元,配置为根据所述蓝牙设备的校验标记,向所述云平台发送第四请求消息,所述第四请求消息用于请求获取设备认证平台的校验凭证;The first sending unit is configured to send a fourth request message to the cloud platform according to the verification mark of the Bluetooth device, where the fourth request message is used to request to obtain the verification credential of the device authentication platform;
    所述设备认证平台的校验凭证用于所述蓝牙设备校验所述设备认证平台的合法性。The verification credential of the device authentication platform is used for the Bluetooth device to verify the legitimacy of the device authentication platform.
  52. 根据权利要求51所述的网关,其中,The gateway of claim 51, wherein,
    所述第一处理单元,还配置为接收所述云平台发送的所述设备认证平台的校验凭证;The first processing unit is further configured to receive the verification certificate of the device authentication platform sent by the cloud platform;
    所述第一发送单元,还配置为向所述蓝牙设备发送所述设备认证平台的校验凭证。The first sending unit is further configured to send the verification credential of the device authentication platform to the Bluetooth device.
  53. 根据权利要求41至52任一项所述的网关,其中,A gateway according to any one of claims 41 to 52, wherein,
    所述第一处理单元,还配置为请求所述云平台添加所述蓝牙设备。The first processing unit is further configured to request the cloud platform to add the Bluetooth device.
  54. 根据权利要求53所述的网关,其中,The gateway of claim 53, wherein,
    所述第一处理单元,配置为向所述云平台发送所述蓝牙设备的信息,所述蓝牙设备的信息用于所述云平台添加所述蓝牙设备。The first processing unit is configured to send the information of the Bluetooth device to the cloud platform, where the information of the Bluetooth device is used for the cloud platform to add the Bluetooth device.
  55. 根据权利要求41至54任一项所述的网关,其中,A gateway according to any one of claims 41 to 54, wherein,
    所述第一发送单元,还配置为向所述蓝牙设备发送配置信息,所述配置信息用于执行蓝牙设备入网配置。The first sending unit is further configured to send configuration information to the Bluetooth device, where the configuration information is used to perform network access configuration of the Bluetooth device.
  56. 根据权利要求41至55任一项所述的网关,其中,A gateway according to any one of claims 41 to 55, wherein,
    所述第一处理单元,还配置为接收所述蓝牙设备发送的校验标记,所述校验标记用于指示需要检验的对象。The first processing unit is further configured to receive a check mark sent by the Bluetooth device, where the check mark is used to indicate an object to be checked.
  57. 根据权利要求56所述的网关,其中,所述校验标记包括下述至少一项:The gateway of claim 56, wherein the check mark comprises at least one of the following:
    校验所述蓝牙设备;verifying the bluetooth device;
    检验所述网关和/或所述云平台;verifying the gateway and/or the cloud platform;
    校验设备认证平台。Verify the device authentication platform.
  58. 一种云平台,包括:A cloud platform that includes:
    第一接收单元,配置为接收网关发送的蓝牙设备的校验凭证;a first receiving unit, configured to receive the verification certificate of the Bluetooth device sent by the gateway;
    第二处理单元,配置为基于所述蓝牙设备的校验凭证,确定所述蓝牙设备的合法性。The second processing unit is configured to determine the validity of the Bluetooth device based on the verification credential of the Bluetooth device.
  59. 根据权利要求58所述的云平台,其中,The cloud platform of claim 58, wherein,
    所述第二处理单元,配置为若所述蓝牙设备不是所述云平台对应的设备,则向设备认证平台发送携带所述蓝牙设备的校验凭证的第五请求消息;所述第五请求消息用于请求所述设备认证平台校验所述蓝牙设备的合法性;The second processing unit is configured to send a fifth request message carrying the verification credential of the Bluetooth device to the device authentication platform if the Bluetooth device is not a device corresponding to the cloud platform; the fifth request message for requesting the device authentication platform to verify the validity of the Bluetooth device;
    若所述蓝牙设备是所述云平台对应的设备,则校验所述蓝牙设备的合法性。If the Bluetooth device is a device corresponding to the cloud platform, verify the validity of the Bluetooth device.
  60. 根据权利要求59所述的云平台,其中,The cloud platform of claim 59, wherein,
    所述第一接收单元,还配置为接收所述设备认证平台发送的设备校验结果,所述设备校验结果用于指示所述蓝牙设备的合法性。The first receiving unit is further configured to receive a device verification result sent by the device authentication platform, where the device verification result is used to indicate the validity of the Bluetooth device.
  61. 根据权利要求60所述的云平台,其中,The cloud platform of claim 60, wherein,
    所述第二处理单元,还配置为向所述网关发送所述设备校验结果。The second processing unit is further configured to send the device verification result to the gateway.
  62. 根据权利要求58至61任一项所述的云平台,其中,The cloud platform according to any one of claims 58 to 61, wherein,
    所述第一接收单元,还配置为接收所述网关发送的第二请求消息,所述第二请求消息用于请求获取所述网关和/或所述云平台的校验凭证;The first receiving unit is further configured to receive a second request message sent by the gateway, where the second request message is used to request to obtain the verification credential of the gateway and/or the cloud platform;
    所述第二处理单元,还配置为确认所述网关和/或所述云平台的校验凭证。The second processing unit is further configured to confirm the verification credentials of the gateway and/or the cloud platform.
  63. 根据权利要求62所述的云平台,其中,The cloud platform of claim 62, wherein,
    所述第二处理单元,配置为若所述蓝牙设备不是所述云平台对应的设备,则所述云平台确定所述蓝牙设备对应的设备认证平台;向所述设备认证平台发送第六请求消息;所述第六请求消息携带所述网关和/或所述云平台的标识,用于请求获取所述网关和/或所述云平台的校验凭证;The second processing unit is configured to, if the Bluetooth device is not a device corresponding to the cloud platform, the cloud platform determines a device authentication platform corresponding to the Bluetooth device; and sends a sixth request message to the device authentication platform ; The sixth request message carries the identifier of the gateway and/or the cloud platform, and is used to request to obtain the verification credential of the gateway and/or the cloud platform;
    所述第一接收单元,配置为接收所述设备认证平台发送的所述网关和/或所述云平台的校验凭证。The first receiving unit is configured to receive the verification credential of the gateway and/or the cloud platform sent by the device authentication platform.
  64. 根据权利要求62或63所述的云平台,其中,The cloud platform according to claim 62 or 63, wherein,
    所述第二处理单元,还配置为向所述网关发送所述网关和/或所述云平台的校验凭证。The second processing unit is further configured to send the gateway and/or the verification credential of the cloud platform to the gateway.
  65. 根据权利要求58至64任一项所述的云平台,其中,The cloud platform according to any one of claims 58 to 64, wherein,
    所述第一接收单元,还配置为接收所述网关发送第四请求消息,所述第四请求消息用于请求获取设备认证平台的校验凭证;确定所述设备认证平台的校验凭证。The first receiving unit is further configured to receive a fourth request message sent by the gateway, where the fourth request message is used to request to obtain the verification credential of the device authentication platform; and determine the verification credential of the device authentication platform.
  66. 根据权利要求65所述的云平台,其中,The cloud platform of claim 65, wherein,
    所述第二处理单元,配置为向所述设备认证平台发送第七请求消息,所述第七请求消息用于请求获取所述设备认证平台的校验凭证;The second processing unit is configured to send a seventh request message to the device authentication platform, where the seventh request message is used to request to obtain the verification credential of the device authentication platform;
    所述第一接收单元,配置为接收所述设备认证平台发送的所述设备认证平台的校验凭证。The first receiving unit is configured to receive the verification certificate of the device authentication platform sent by the device authentication platform.
  67. 根据权利要求65或66所述的云平台,其中,The cloud platform according to claim 65 or 66, wherein,
    所述第二处理单元,配置为向所述网关发送所述设备认证平台的校验凭证。The second processing unit is configured to send the verification credential of the device authentication platform to the gateway.
  68. 根据权利要求58至67任一项所述的云平台,其中,The cloud platform according to any one of claims 58 to 67, wherein,
    所述第二处理单元,还配置为添加所述蓝牙设备。The second processing unit is further configured to add the Bluetooth device.
  69. 根据权利要求68所述的云平台,其中,The cloud platform of claim 68, wherein,
    所述第二处理单元,配置为接收所述网关发送的所述蓝牙设备的信息;根据所述蓝牙设备的信息,添加所述蓝牙设备。The second processing unit is configured to receive the information of the Bluetooth device sent by the gateway; and add the Bluetooth device according to the information of the Bluetooth device.
  70. 一种设备认证平台,包括:A device authentication platform including:
    第二接收单元,配置为接收云平台发送的第五请求消息;所述第五请求消息包括蓝牙设备的校验凭证;The second receiving unit is configured to receive the fifth request message sent by the cloud platform; the fifth request message includes the verification credential of the Bluetooth device;
    第三处理单元,根据所述蓝牙设备的校验凭证,校验所述蓝牙设备的合法性。The third processing unit verifies the validity of the Bluetooth device according to the verification certificate of the Bluetooth device.
  71. 根据权利要求70所述的设备认证平台,其中,The device authentication platform of claim 70, wherein,
    所述第二接收单元,还配置为接收所述云平台发送的第六请求消息;所述第六请求消息携带所述网关和/或所述云平台的标识,用于请求获取所述网关和/或所述云平台的校验凭证。The second receiving unit is further configured to receive a sixth request message sent by the cloud platform; the sixth request message carries the identifier of the gateway and/or the cloud platform, and is used to request to obtain the gateway and/or the cloud platform. /or the verification certificate of the cloud platform.
  72. 根据权利要求71所述的设备认证平台,其中,The device authentication platform of claim 71, wherein,
    所述第三处理单元,配置为根据所述网关和/或所述云平台的标识,生成所述网关和/或所述云平台的校验凭证;the third processing unit, configured to generate a verification credential of the gateway and/or the cloud platform according to the identifier of the gateway and/or the cloud platform;
    向所述云平台发送所述网关和/或所述云平台的校验凭证。Send the verification credential of the gateway and/or the cloud platform to the cloud platform.
  73. 一种蓝牙设备,包括:A Bluetooth device comprising:
    第二发送单元,配置为向网关发送蓝牙设备的校验凭证,所述蓝牙设备的校验凭证用于确定所述蓝牙设备的合法性。The second sending unit is configured to send the verification certificate of the Bluetooth device to the gateway, where the verification certificate of the Bluetooth device is used to determine the validity of the Bluetooth device.
  74. 根据权利要求73所述的蓝牙设备,其中,所述蓝牙设备还包括:The Bluetooth device of claim 73, wherein the Bluetooth device further comprises:
    第四处理单元,配置为接收所述网关发送的第一请求消息,所述第一请求消息用于请求获取所述蓝牙设备的校验凭证。The fourth processing unit is configured to receive a first request message sent by the gateway, where the first request message is used to request to obtain a verification credential of the Bluetooth device.
  75. 根据权利要求73或74所述的蓝牙设备,其中,所述蓝牙设备还包括:The Bluetooth device of claim 73 or 74, wherein the Bluetooth device further comprises:
    第五处理单元,配置为接收所述网关和/或所述云平台的校验凭证,所述网关和/或所述云平台的校验凭证用于所述蓝牙设备校验所述网关/或所述云平台的合法性。A fifth processing unit, configured to receive a verification credential of the gateway and/or the cloud platform, and the verification credential of the gateway and/or the cloud platform is used for the Bluetooth device to verify the gateway/or The legitimacy of the cloud platform.
  76. 根据权利要求75所述的蓝牙设备,其中,The Bluetooth device of claim 75, wherein,
    所述第二发送单元,还配置为向所述网关发送第三请求消息,所述第三请求消息用于请求获取所述网关和/或所述云平台的校验凭证。The second sending unit is further configured to send a third request message to the gateway, where the third request message is used to request to obtain the verification credential of the gateway and/or the cloud platform.
  77. 根据权利要求75或76所述的蓝牙设备,其中,A Bluetooth device according to claim 75 or 76, wherein,
    所述第五处理单元,配置为根据所述网关和/或所述云平台的校验凭证,校验所述网关和/或所述云平台的合法性。The fifth processing unit is configured to verify the validity of the gateway and/or the cloud platform according to the verification credentials of the gateway and/or the cloud platform.
  78. 根据权利要求75至77任一项所述的蓝牙设备,其中,A Bluetooth device according to any one of claims 75 to 77, wherein,
    所述第二发送单元,配置为向所述网关发送所述蓝牙设备发送的网关和/或所述云平台校验结果,所述网关和/或所述云平台校验结果用于指示针对所述网关和/或所述云平台的合法性。The second sending unit is configured to send the gateway and/or the cloud platform verification result sent by the Bluetooth device to the gateway, where the gateway and/or the cloud platform verification result is used to indicate the legality of the gateway and/or the cloud platform.
  79. 根据权利要求73至78任一项所述的蓝牙设备,其中,所述蓝牙设备还包括:The Bluetooth device according to any one of claims 73 to 78, wherein the Bluetooth device further comprises:
    所述第六处理单元,配置为接收所述网关发送的设备认证平台的校验凭证;基于所述设备认证平台的校验凭证,校验所述设备认证平台的合法性。The sixth processing unit is configured to receive the verification credential of the device authentication platform sent by the gateway; based on the verification credential of the device authentication platform, verify the legitimacy of the device authentication platform.
  80. 根据权利要求73至79任一项所述的蓝牙设备,其中,所述蓝牙设备还包括:The Bluetooth device according to any one of claims 73 to 79, wherein the Bluetooth device further comprises:
    第三接收单元,配置为接收所述网关发送的配置信息,所述配置信息用于执行蓝牙设备入网配置。The third receiving unit is configured to receive configuration information sent by the gateway, where the configuration information is used to perform network access configuration of the Bluetooth device.
  81. 一种网关,包括处理器和用于存储能够在处理器上运行的计算机程序的存储器,其中,A gateway comprising a processor and a memory for storing a computer program executable on the processor, wherein,
    所述处理器用于运行所述计算机程序时,执行权利要求1至17任一项所述的蓝牙设备接入认证方法的步骤。The processor is configured to execute the steps of the Bluetooth device access authentication method according to any one of claims 1 to 17 when running the computer program.
  82. 一种云平台,包括处理器和用于存储能够在处理器上运行的计算机程序的存储器,其中,A cloud platform comprising a processor and a memory for storing a computer program executable on the processor, wherein,
    所述处理器用于运行所述计算机程序时,执行权利要求18至29任一项所述的蓝牙设备接入认证方法的步骤。The processor is configured to execute the steps of the Bluetooth device access authentication method according to any one of claims 18 to 29 when running the computer program.
  83. 一种设备认证平台,包括处理器和用于存储能够在处理器上运行的计算机程序的存储器,其中,A device authentication platform includes a processor and a memory for storing a computer program executable on the processor, wherein,
    所述处理器用于运行所述计算机程序时,执行权利要求30至32任一项所述的蓝牙设备接入认证方法的步骤。The processor is configured to execute the steps of the Bluetooth device access authentication method according to any one of claims 30 to 32 when running the computer program.
  84. 一种云平台,包括处理器和用于存储能够在处理器上运行的计算机程序的存储器,其中,A cloud platform comprising a processor and a memory for storing a computer program executable on the processor, wherein,
    所述处理器用于运行所述计算机程序时,执行权利要求33至40任一项所述的蓝牙设备接入认证方法的步骤。The processor is configured to execute the steps of the Bluetooth device access authentication method according to any one of claims 33 to 40 when running the computer program.
  85. 一种存储介质,存储有可执行程序,所述可执行程序被处理器执行时,实现权利要求1至17任一项所述的蓝牙设备接入认证方法。A storage medium stores an executable program, and when the executable program is executed by a processor, implements the Bluetooth device access authentication method according to any one of claims 1 to 17.
  86. 一种存储介质,存储有可执行程序,所述可执行程序被处理器执行时,实现权利要求18至29任一项所述的蓝牙设备接入认证方法。A storage medium stores an executable program, and when the executable program is executed by a processor, implements the Bluetooth device access authentication method according to any one of claims 18 to 29.
  87. 一种存储介质,存储有可执行程序,所述可执行程序被处理器执行时,实现权利要求30至32任一项所述的蓝牙设备接入认证方法。A storage medium stores an executable program, and when the executable program is executed by a processor, implements the Bluetooth device access authentication method according to any one of claims 30 to 32.
  88. 一种存储介质,存储有可执行程序,所述可执行程序被处理器执行时,实现权利要求33至40任一项所述的蓝牙设备接入认证方法。A storage medium stores an executable program, and when the executable program is executed by a processor, implements the Bluetooth device access authentication method according to any one of claims 33 to 40.
  89. 一种计算机程序产品,包括计算机程序指令,该计算机程序指令使得计算机执行如权利要求1至17任一项所述的蓝牙设备接入认证方法。A computer program product comprising computer program instructions, the computer program instructions causing a computer to execute the Bluetooth device access authentication method according to any one of claims 1 to 17.
  90. 一种计算机程序产品,包括计算机程序指令,该计算机程序指令使得计算机执行如权 利要求18至29任一项所述的蓝牙设备接入认证方法。A computer program product comprising computer program instructions that cause a computer to perform the Bluetooth device access authentication method as claimed in any one of claims 18 to 29.
  91. 一种计算机程序产品,包括计算机程序指令,该计算机程序指令使得计算机执行如权利要求30至32任一项所述的蓝牙设备接入认证方法。A computer program product comprising computer program instructions, the computer program instructions causing a computer to execute the Bluetooth device access authentication method as claimed in any one of claims 30 to 32.
  92. 一种计算机程序产品,包括计算机程序指令,该计算机程序指令使得计算机执行如权利要求33至40任一项所述的蓝牙设备接入认证方法。A computer program product comprising computer program instructions, the computer program instructions causing a computer to execute the Bluetooth device access authentication method as claimed in any one of claims 33 to 40.
  93. 一种计算机程序,所述计算机程序使得计算机执行如权利要求1至17任一项所述的蓝牙设备接入认证方法。A computer program, the computer program causing a computer to execute the Bluetooth device access authentication method according to any one of claims 1 to 17.
  94. 一种计算机程序,所述计算机程序使得计算机执行如权利要求18至29任一项所述的蓝牙设备接入认证方法。A computer program, the computer program causing a computer to execute the Bluetooth device access authentication method according to any one of claims 18 to 29.
  95. 一种计算机程序,所述计算机程序使得计算机执行如权利要求30至32任一项所述的蓝牙设备接入认证方法。A computer program, the computer program causing a computer to execute the Bluetooth device access authentication method according to any one of claims 30 to 32.
  96. 一种计算机程序,所述计算机程序使得计算机执行如权利要求33至40任一项所述的蓝牙设备接入认证方法。A computer program, the computer program causing a computer to execute the Bluetooth device access authentication method according to any one of claims 33 to 40.
  97. 一种芯片,包括:处理器,用于从存储器中调用并运行计算机程序,使得安装有所述芯片的设备执行如权利要求1至17任一项所述的蓝牙设备接入认证方法。A chip, comprising: a processor for calling and running a computer program from a memory, so that a device installed with the chip executes the Bluetooth device access authentication method according to any one of claims 1 to 17.
  98. 一种芯片,包括:处理器,用于从存储器中调用并运行计算机程序,使得安装有所述芯片的设备执行如权利要求18至29任一项所述的蓝牙设备接入认证方法。A chip, comprising: a processor for calling and running a computer program from a memory, so that a device installed with the chip executes the Bluetooth device access authentication method according to any one of claims 18 to 29.
  99. 一种芯片,包括:处理器,用于从存储器中调用并运行计算机程序,使得安装有所述芯片的设备执行如权利要求30至32任一项所述的蓝牙设备接入认证方法。A chip, comprising: a processor for calling and running a computer program from a memory, so that a device installed with the chip executes the Bluetooth device access authentication method according to any one of claims 30 to 32.
  100. 一种芯片,包括:处理器,用于从存储器中调用并运行计算机程序,使得安装有所述芯片的设备执行如权利要求33至40任一项所述的蓝牙设备接入认证方法。A chip, comprising: a processor for calling and running a computer program from a memory, so that a device installed with the chip executes the Bluetooth device access authentication method according to any one of claims 33 to 40.
PCT/CN2020/107207 2020-08-05 2020-08-05 Access authentication method for bluetooth device, electronic device, and storage medium WO2022027364A1 (en)

Priority Applications (2)

Application Number Priority Date Filing Date Title
PCT/CN2020/107207 WO2022027364A1 (en) 2020-08-05 2020-08-05 Access authentication method for bluetooth device, electronic device, and storage medium
CN202080104853.3A CN116210246A (en) 2020-08-05 2020-08-05 Bluetooth equipment access authentication method, electronic equipment and storage medium

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2020/107207 WO2022027364A1 (en) 2020-08-05 2020-08-05 Access authentication method for bluetooth device, electronic device, and storage medium

Publications (1)

Publication Number Publication Date
WO2022027364A1 true WO2022027364A1 (en) 2022-02-10

Family

ID=80118782

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2020/107207 WO2022027364A1 (en) 2020-08-05 2020-08-05 Access authentication method for bluetooth device, electronic device, and storage medium

Country Status (2)

Country Link
CN (1) CN116210246A (en)
WO (1) WO2022027364A1 (en)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106211152A (en) * 2015-04-30 2016-12-07 杭州华三通信技术有限公司 A kind of wireless access authentication method and device
CN107071776A (en) * 2017-05-23 2017-08-18 上海斐讯数据通信技术有限公司 It is a kind of to match somebody with somebody network method and its system, a kind of server automatically
CN110493758A (en) * 2018-05-14 2019-11-22 阿里巴巴集团控股有限公司 Bluetooth Mesh network and its match network method, equipment and storage medium
CN110505606A (en) * 2018-05-18 2019-11-26 阿里巴巴集团控股有限公司 Bluetooth Mesh network and its distribution method for authenticating, equipment and storage medium
US10673630B2 (en) * 2017-05-11 2020-06-02 Airties Kablosuz Iletisim Sanayi Ve Dis Ticaret A.S. Cloud based WiFi network setup for multiple access points

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106211152A (en) * 2015-04-30 2016-12-07 杭州华三通信技术有限公司 A kind of wireless access authentication method and device
US10673630B2 (en) * 2017-05-11 2020-06-02 Airties Kablosuz Iletisim Sanayi Ve Dis Ticaret A.S. Cloud based WiFi network setup for multiple access points
CN107071776A (en) * 2017-05-23 2017-08-18 上海斐讯数据通信技术有限公司 It is a kind of to match somebody with somebody network method and its system, a kind of server automatically
CN110493758A (en) * 2018-05-14 2019-11-22 阿里巴巴集团控股有限公司 Bluetooth Mesh network and its match network method, equipment and storage medium
CN110505606A (en) * 2018-05-18 2019-11-26 阿里巴巴集团控股有限公司 Bluetooth Mesh network and its distribution method for authenticating, equipment and storage medium

Also Published As

Publication number Publication date
CN116210246A (en) 2023-06-02

Similar Documents

Publication Publication Date Title
CN113225176B (en) Key obtaining method and device
CN110798833B (en) Method and device for verifying user equipment identification in authentication process
KR101869368B1 (en) Authentication in secure user plane location (supl) systems
WO2022057736A1 (en) Authorization method and device
WO2019041802A1 (en) Discovery method and apparatus based on service-oriented architecture
WO2014025563A1 (en) Apparatus and method for secure private location information transfer during next generation emergency calls
WO2021120924A1 (en) Method and device for certificate application
WO2022170994A1 (en) Pc5 root key processing method and apparatus, and ausf and remote terminal
CN113784343A (en) Method and apparatus for securing communications
CN112449323B (en) Communication method, device and system
WO2019196766A1 (en) Communication method and apparatus
WO2023125293A1 (en) Communication method and communication apparatus
CN118476251A (en) Configuration of provisioning parameters for joining devices to a network
CN114079915A (en) Method, system and device for determining user plane security algorithm
WO2022027364A1 (en) Access authentication method for bluetooth device, electronic device, and storage medium
WO2022061668A1 (en) Bluetooth device access authentication method, and electronic device and storage medium
EP4322579A1 (en) Communication method and apparatus
CN115280803B (en) Multimedia broadcast multicast service authentication method, device, equipment and medium
CN113678127B (en) Access control method, server, access device and storage medium
CN118265031B (en) Information security method, apparatus, communication device and storage medium
CN113285805B (en) Communication method and device
CN114124423B (en) Authentication method, client, server and storage medium
WO2022252658A1 (en) Roaming access method and apparatus
RU2816700C1 (en) Method and device of network connection in real time
WO2023159603A1 (en) Security implementation method and apparatus, terminal device, and network elements

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 20948691

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 20948691

Country of ref document: EP

Kind code of ref document: A1