WO2023116239A1 - 权限确定方法、装置、计算机设备和计算机可读存储介质 - Google Patents

权限确定方法、装置、计算机设备和计算机可读存储介质 Download PDF

Info

Publication number
WO2023116239A1
WO2023116239A1 PCT/CN2022/130533 CN2022130533W WO2023116239A1 WO 2023116239 A1 WO2023116239 A1 WO 2023116239A1 CN 2022130533 W CN2022130533 W CN 2022130533W WO 2023116239 A1 WO2023116239 A1 WO 2023116239A1
Authority
WO
WIPO (PCT)
Prior art keywords
target
digital certificate
challenge
authority
control device
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2022/130533
Other languages
English (en)
French (fr)
Inventor
李辉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Shenzhen TCL New Technology Co Ltd
Original Assignee
Shenzhen TCL New Technology Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Shenzhen TCL New Technology Co Ltd filed Critical Shenzhen TCL New Technology Co Ltd
Publication of WO2023116239A1 publication Critical patent/WO2023116239A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/44Program or device authentication
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/64Protecting data integrity, e.g. using checksums, certificates or signatures

Definitions

  • the present application relates to the technical field of Internet of Things devices, and in particular to a permission determination method, device, computer equipment, and computer-readable storage medium.
  • IOT Internet of Things
  • IoT devices are generally controlled through their application programs (Application), which results in the need for users to download a new application program for each additional IoT device, which is troublesome.
  • Application Application
  • IoT devices are controlled by other applications, security cannot be guaranteed.
  • Embodiments of the present application provide a permission determination method, apparatus, computer equipment, and computer-readable storage medium, which can also ensure security when other application programs are used to control IoT devices.
  • a permission determination method applied to a control device comprising:
  • the target digital certificate includes a certificate obtained by the certification authority after authenticating the target server with the authentication private key
  • a permission determination method applied to an Internet of Things device, comprising:
  • the above target digital certificate is a certificate obtained by the certification authority after authenticating the target server with the certification private key;
  • the content of the target digital certificate is obtained, and the first challenge information is returned to the control device, so that the control device sends the first challenge information to the target server, and the first challenge information is used to indicate the above-mentioned
  • the target server generates a first challenge value, and returns the first challenge value to the control device;
  • the control authority of the target application program on the control device to the Internet of Things device is determined.
  • a permission determination method, applied to a target server comprising:
  • the target digital certificate is used to instruct the IoT device to perform verification, and when the verification passes, obtain the target The content of the digital certificate, and return the first challenge information to the above-mentioned control device, the above-mentioned target digital certificate includes the certificate obtained by the certification authority after using the authentication private key to authenticate the above-mentioned target server;
  • an embodiment of the present application provides an apparatus for determining authority, which is applied to a control device, including:
  • the first receiving module is used to receive the target digital certificate sent by the target server, and the above target digital certificate includes a certificate obtained by the certification authority after authenticating the above target server with an authentication private key;
  • the first sending module is configured to send the above-mentioned target digital certificate to the Internet of Things device, so that the above-mentioned Internet of Things device uses the built-in authentication public key to verify the above-mentioned target digital certificate, and obtain the above-mentioned target digital certificate when the verification is passed the content of the certificate;
  • the second receiving module is configured to receive the first challenge information returned by the IoT device based on the verification of the target digital certificate
  • the second sending module is configured to send the above-mentioned first challenge information to the above-mentioned target server, so that the above-mentioned target server generates a first challenge value based on the above-mentioned first challenge information;
  • the third receiving module is configured to receive the above-mentioned first challenge value sent by the above-mentioned target server, and send the above-mentioned first challenge value to the above-mentioned IoT device, so as to determine the above-mentioned control based on the above-mentioned first challenge value and the content of the above-mentioned target digital certificate
  • the control authority of the target application on the device to the aforementioned IoT devices.
  • an embodiment of the present application provides an apparatus for determining authority, which is applied to Internet of Things devices, including:
  • the fourth receiving module is used to receive the target digital certificate sent by the control device, and the above target digital certificate is a certificate obtained by the certification authority after authenticating the target server with the certification private key;
  • the first verification module is used to verify the above-mentioned target digital certificate by using the built-in authentication public key
  • the third sending module is configured to obtain the content of the target digital certificate when the verification is passed, and send the first challenge information to the control device, so that the control device sends the first challenge information to the target server, and the first challenge information is sent to the target server.
  • the challenge information is used to instruct the target server to generate a first challenge value, and return the first challenge value to the control device;
  • a fifth receiving module configured to receive the first challenge value sent by the control device
  • a determination module configured to determine the control authority of the target application program on the control device to the IoT device based on the first challenge value and the content of the target digital certificate.
  • an embodiment of the present application provides an apparatus for determining authority, which is applied to a target server, including:
  • the fourth sending module is configured to send the target digital certificate to the control device, so that the control device sends the target digital certificate to the Internet of Things device, and the target digital certificate is used to instruct the Internet of Things device to perform verification, and the When the verification is passed, obtain the content of the above-mentioned target digital certificate, and return the first challenge information to the above-mentioned control device, and the above-mentioned target digital certificate includes the certificate obtained after the certification authority authenticates the above-mentioned target server with the authentication private key;
  • a sixth receiving module configured to receive the above-mentioned first challenge information sent by the above-mentioned control device
  • a generating module configured to generate a first challenge value based on the first challenge information
  • the fifth sending module is configured to send the above-mentioned first challenge value to the above-mentioned control device, so that the above-mentioned control device sends the above-mentioned first challenge value to the above-mentioned Internet of Things device, and the above-mentioned first challenge value and the content of the above-mentioned target digital certificate are used
  • the control authority of the target application program on the control device to the above-mentioned Internet of Things device is determined on the above-mentioned Internet of Things device.
  • the embodiment of the present application also provides a computer device, including a processor and a memory, the memory stores a computer program, and the processor is configured to run the computer program in the memory to implement the permission determination method provided in the embodiment of the present application.
  • an embodiment of the present application also provides a computer-readable storage medium, the above-mentioned computer-readable storage medium stores a computer program, and the above-mentioned computer program is suitable for being loaded by a processor to execute any one of the permissions provided by the embodiments of the present application. Identify the steps in the method.
  • the target digital certificate sent by the target server is received first, and the target digital certificate includes the certificate obtained by the certification authority after authenticating the target server with the authentication private key. Then send the target digital certificate to the IoT device, so that the IoT device uses the built-in authentication public key to verify the target digital certificate, and obtain the content of the target digital certificate when the verification is passed. Next, receiving the first challenge information returned by the IoT device based on the verification of the target digital certificate. Then, the first challenge information is sent to the target server, so that the target server generates a first challenge value based on the first challenge information.
  • the target server since the target server and the target application program belong to the same merchant, the target server trusts the target application program.
  • the Internet of Things device passes the verification of the target digital certificate using the authentication public key, it means that the target digital certificate is a certificate certified by the certification authority.
  • the IoT device can trust the content of the target digital certificate, so that it can be determined whether the target server can be trusted according to the content of the target digital certificate and the first challenge value sent by the target server, so as to determine whether The target application program can be trusted, so that even if the target application program on the control device is not the application program corresponding to the IoT device, security can be guaranteed when the IoT device is controlled through the target application program on the control device.
  • FIG. 1 is a schematic flowchart of a method for determining authority provided in an embodiment of the present application
  • FIG. 2 is a schematic flowchart of another permission determination method provided by the embodiment of the present application.
  • FIG. 3 is a schematic flowchart of another permission determination method provided by the embodiment of the present application.
  • FIG. 4 is an interactive schematic diagram of another permission determination method provided by the embodiment of the present application.
  • FIG. 5 is a schematic structural diagram of a device for determining authority provided in an embodiment of the present application.
  • FIG. 6 is a schematic structural diagram of another device for determining authority provided by an embodiment of the present application.
  • Fig. 7 is a schematic structural diagram of another device for determining authority provided by an embodiment of the present application.
  • Fig. 8 is a schematic structural diagram of a computer device provided by an embodiment of the present application.
  • Embodiments of the present application provide a permission determination method, device, computer equipment, and computer-readable storage medium.
  • the authority determination device may be integrated in a computer device, and the computer device may be a server, a control device, or an Internet of Things device.
  • the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, and can also provide cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication , middleware service, domain name service, security service, network acceleration service (Content Delivery Network, CDN), and cloud servers for basic cloud computing services such as big data and artificial intelligence platforms.
  • cloud databases cloud computing, cloud functions, cloud storage, network services, cloud communication , middleware service, domain name service, security service, network acceleration service (Content Delivery Network, CDN), and cloud servers for basic cloud computing services such as big data and artificial intelligence platforms.
  • the control device may be, but not limited to, a smart phone, a tablet computer, a notebook computer, and a desktop computer.
  • IoT devices refer to devices that can communicate with other devices through the network, for example, smart air conditioners, smart speakers and other devices.
  • the server, the control device, and the IoT device may be connected directly or indirectly through wired or wireless communication, which is not limited in this application.
  • the process of controlling the IoT device may be: sending a control command to the IoT device through an application program corresponding to the IoT device on the control device, and the IoT device executes the operation corresponding to the control command.
  • the authority of the application program corresponding to the Internet of Things device will be verified.
  • the verification process can be as follows: download the application program corresponding to the IoT device on the control device, store the private key carried by the application program, set the public key corresponding to the private key on the IoT device, and determine the ID of the control device through the public key. safety.
  • the stored private key on the control device is easy to be cracked.
  • the control device without authority can also control the IoT device according to the cracked private key, resulting in insecurity.
  • the user wants to control the IoT device through other applications on the control device, since the other application does not carry the private key (the other application does not belong to the same merchant as the IoT device, the merchant of the IoT device cannot share the private key set on other application programs), so that the authority of other application programs on the control device cannot be verified, so that there is a security problem. Therefore, in the related art, it is not yet possible to control the IoT device through other applications.
  • the embodiment of the present application provides a method for determining authority.
  • the target digital certificate sent by the target server is first received. certificate obtained afterwards. Then send the target digital certificate to the IoT device, so that the IoT device uses the built-in authentication public key to verify the target digital certificate, and obtain the content of the target digital certificate when the verification is passed.
  • receiving the first challenge information returned by the IoT device based on the verification of the target digital certificate.
  • the first challenge information is sent to the target server, so that the target server generates a first challenge value based on the first challenge information.
  • the target server since the target server and the target application program belong to the same merchant, the target server trusts the target application program.
  • the Internet of Things device passes the verification of the target digital certificate using the authentication public key, it means that the target digital certificate is a certificate certified by the certification authority.
  • the IoT device can trust the content of the target digital certificate, so that it can be determined whether the target server can be trusted according to the content of the target digital certificate and the first challenge value sent by the target server, so as to determine whether The target application program can be trusted, so that even if the target application program on the control device is not the application program corresponding to the IoT device, security can be guaranteed when the IoT device is controlled through the target application program on the control device.
  • S101 Receive a target digital certificate sent by a target server, where the target digital certificate includes a certificate obtained by an authentication authority after authenticating the target server by using an authentication private key.
  • the certification body refers to an e-commerce certification center (Certificate Authority, CA). Since the authentication structure is a trusted third party, when the authentication structure authenticates the target server, it means that the certification body trusts the target server, and the IoT device can trust the target server.
  • CA e-commerce certification center
  • the target digital certificate refers to a string of numbers that can indicate the identity information of the target server.
  • the target server can obtain the target digital certificate after being authenticated by the certification authority.
  • the controlling device may receive the target digital certificate through the target application program on the controlling device.
  • the target application refers to the application that actually controls the IoT device.
  • the target application can be an application developed by the merchant of the IoT device, that is, the application corresponding to the IoT device, or an application developed by other merchants (because when the target application When the program is an application program corresponding to an Internet of Things device, applying the permission determination method provided by the embodiment of the present application can also provide security for controlling the Internet of Things device. Therefore, the target application program can also be an application program corresponding to an Internet of Things device).
  • control device may implement information interaction with the target server and the Internet of Things device through the target application program.
  • the target digital certificate may be sent to the IoT device through the target application program
  • the first challenge information may be received through the target application program and sent to the target server through the target application program.
  • the target server may be an initial server produced by a merchant of the IoT device, and at this time the target application program is an application program corresponding to the IoT device.
  • the target server can also be a server of other merchants (other than the merchant that produced the IoT device), and in this case, the target application is other applications on the control device (other applications refer to those installed on the control device) applications other than those corresponding to IoT devices).
  • the IoT device is a device produced by A merchant
  • the application program corresponding to the IoT device is the A application program.
  • Merchant B has developed an application program B
  • the target server may be the server of merchant B
  • the target application program may be the application program B.
  • the user of the control device wants to control the IoT device through the target application program on the control device
  • the user can operate the target application program on the control device, so that the target application program of the control device generates a permission verification request and verifies the permission
  • the request is sent to the target server, and the target server sends the target digital certificate to the control device based on the permission verification request, and the control device receives the target digital certificate.
  • the authority verification request may be automatically generated when the user completes the installation of the target application, and the authority verification request is sent to the target server, and the target server then sends the target digital certificate to the control device based on the authority verification request, and the control device receives to the target digital certificate.
  • the time for the control device to receive the target digital certificate can be set by the user according to the actual situation, which is not limited in this application.
  • S102 Send the target digital certificate to the Internet of Things device, so that the Internet of Things device uses the built-in authentication public key to verify the target digital certificate, and obtain the content of the target digital certificate when the verification is passed.
  • the target application is another application on the control device
  • the target server corresponding to the other application is the server of another merchant
  • the merchant that produces the IoT device cannot store the private key of the IoT device on the target server. Therefore, you can first let the certification authority trusted by the IoT device use the certification private key to authenticate the target server, and then set the certification public key of the certification authority on the IoT device.
  • control device obtains the target digital certificate, it sends the target digital certificate to the IoT device, so that the IoT device uses the built-in authentication public key to verify the target digital certificate. If the verification is passed, it means that the target digital certificate is a certificate certified by the certification authority, which means that the IoT device can trust the content of the target digital certificate.
  • the content of the target digital certificate may include, but not limited to, the identity information of the target server, the information of the certification authority, and the first public key of the target server.
  • the IoT device After the IoT device passes the verification of the target digital certificate, it returns the first challenge information to the control device, and the control device thus receives the first challenge information.
  • the first challenge information may be a string of random character strings.
  • the Internet of Things device may not return the first challenge information to the control device after the verification of the target digital certificate is passed.
  • the control device can send the challenge information acquisition request together with the target digital certificate to the IoT device.
  • the control device may first send the target digital certificate to the IoT device, and then send the challenge information acquisition request to the IoT device.
  • the IoT device may generate the first challenge information and return the first challenge information when the target digital certificate is verified and passed. Or, the IoT device may first generate the first challenge information, and then return the first challenge information when the target digital certificate is verified and passed. As for the time when the IoT device generates the first challenge information, the user can choose according to the actual situation, which is not limited in this application.
  • the control device After receiving the first challenge information, the control device sends the first challenge information to the target server, so that the target server generates a first challenge value based on the first challenge information.
  • the target server may use the first private key of the target server to sign the first challenge information, so as to obtain the first challenge value.
  • the target server may use a preset encryption algorithm to encrypt the first challenge information, so as to obtain the first challenge value.
  • the content of the target digital certificate includes a decryption algorithm corresponding to a preset encryption algorithm.
  • the target server can trust the target application program. Therefore, after the target server receives the first challenge information, the target application program may not be verified.
  • the target server may also verify the authority of the control device, that is, verify the authority of the target application program of the control device. After the verification is passed, the target server generates a first challenge value based on the first challenge information.
  • the user can choose according to the actual situation.
  • the token and the first challenge information can be sent to the target server through the target application program. After the target server receives the token, it will compare the token with the token stored in itself. If they are the same, the verification of the target application program is passed.
  • both the control device and the target server can generate random numbers according to preset rules, and then the control device encrypts the random numbers with the stored public key, and sends the encrypted random numbers together with the first challenge information through the target application program to the target server.
  • the target server uses the stored private key to decrypt the random number, and compares the decrypted random number with the random number generated according to the preset rules. If the random numbers are the same, the verification of the target application program is passed.
  • S105 Receive the first challenge value sent by the target server, and send the first challenge value to the IoT device, so as to determine the control of the target application program on the control device to the IoT device based on the first challenge value and the content of the target digital certificate permission.
  • control device After the control device receives the first challenge value sent by the target server, it sends the first challenge value to the IoT device, so that the IoT device determines the target application on the control device based on the content of the first challenge value and the target digital certificate. Control permissions for networked devices.
  • the process of determining the control authority of the target application program on the control device to the IoT device based on the first challenge value and the content of the target digital certificate may be:
  • the Internet of Things device trusts the content of the target digital certificate
  • the Internet of Things device uses the content of the target digital certificate to verify the first challenge value and passes the verification
  • the first challenge information obtained when the verification is passed is the same as the first challenge information sent by the Internet of Things device.
  • the challenge information is the same, it means that the IoT device can trust the target server, and the target server trusts the target application program, so at this time, the IoT device can mark the target application program as an application program with control authority over the IoT device.
  • the target application program is marked as an application program that does not have control authority for the IoT device.
  • the target server uses the first private key of the target server to sign the first challenge information to obtain the first challenge value and the content of the target digital certificate includes the first public key of the target server
  • the content of the target digital certificate is used
  • the process of verifying the first challenge value may be: verifying the first challenge value by using the first public key.
  • the target server uses a preset encryption algorithm to encrypt the first challenge information to obtain the first challenge value and the content of the target digital certificate includes a decryption algorithm corresponding to the preset encryption algorithm
  • use the content of the target digital certificate to The process of verifying the first challenge value may be: using a decryption algorithm to decrypt the first challenge value.
  • the embodiment of the present application provides a method for determining authority.
  • the target digital certificate sent by the target server is first received.
  • the target digital certificate includes the certificate obtained by the certification authority after authenticating the target server with the authentication private key.
  • send the target digital certificate to the IoT device so that the IoT device uses the built-in authentication public key to verify the target digital certificate, and obtain the content of the target digital certificate when the verification is passed.
  • receiving the first challenge information returned by the IoT device based on the verification of the target digital certificate.
  • the first challenge information is sent to the target server, so that the target server generates a first challenge value based on the first challenge information.
  • the target server since the target server and the target application program belong to the same merchant, the target server trusts the target application program.
  • the Internet of Things device passes the verification of the target digital certificate using the authentication public key, it means that the target digital certificate is a certificate certified by the certification authority.
  • the IoT device can trust the content of the target digital certificate, so that it can be determined whether the target server can be trusted according to the content of the target digital certificate and the first challenge value sent by the target server, so as to determine whether The target application program can be trusted, so that even if the target application program on the control device is not the application program corresponding to the IoT device, security can be guaranteed when the IoT device is controlled through the target application program on the control device.
  • the target digital certificate includes a first digital certificate
  • the first digital certificate may be a certificate obtained after the certification authority authenticates the first public key of the target server by using the certification private key.
  • send the target digital certificate to the IoT device so that the IoT device uses the built-in authentication public key to verify the target digital certificate, and when the verification passes, obtain the content of the target digital certificate, including:
  • receiving the first challenge value sent by the target server, and sending the first challenge value to the IoT device, so as to determine the control authority of the target application program on the control device to the IoT device based on the content of the first challenge value and the target digital certificate, include:
  • the target application on the device is marked as an application with control rights over the IoT device.
  • the certification authority uses the certification private key to sign the first public key of the target server to obtain the first digital certificate.
  • the Internet of Things device verifies the first digital certificate with the authentication public key, if the verification is passed, the first public key can be obtained, and it indicates that the Internet of Things device can trust the first public key.
  • the IoT device uses the first public key to verify the first challenge value obtained after signing with the first private key. If the verification passes, it means that the IoT device can trust the target server, and the target server trusts the target application. Therefore, the IoT device can trust the target application, that is, mark the target application as an application that has control authority over the IoT device.
  • the first digital certificate may also be marked as a certificate with authority.
  • sending the target digital certificate to the IoT device includes:
  • the control device first sends a certificate acquisition request to the IoT device. After receiving the certificate acquisition request, the IoT device obtains the second digital certificate returned based on the certificate acquisition request. Then the control device receives the second digital certificate, and the second digital certificate is a certificate obtained after the certification authority signs the second public key of the Internet of Things device with the certification private key.
  • control device verifies the second digital certificate by using the built-in authentication public key, and obtains the second public key of the IoT device when the verification is passed.
  • the control device regenerates the second challenge information, and sends the second challenge information to the IoT device, so that the IoT device generates a second challenge value based on the second challenge information.
  • control device receives the second challenge value, and verifies the second challenge value according to the second public key.
  • verification passes, it means that the IoT device is trustworthy, and then the target digital certificate is sent to the IoT device.
  • the control device may also implement information interaction with the IoT device through the target application program.
  • the control device can also verify the device information of the IoT device.
  • the device information includes, but is not limited to, the merchant ID of the IoT device, the device ID of the IoT device, and the serial number of the IoT device.
  • a process for the IoT device to generate the second challenge value based on the second challenge information may be: the IoT device signs the second challenge information with a second private key to obtain the second challenge value.
  • the control device trusts the certification authority.
  • the authentication public key is built into the Internet of Things device, and the authentication public key is used to verify the second digital certificate signed by the authentication private key. If the verification is passed, the second public key can be obtained, and the second digital certificate is explained
  • the certificate certified by the certification authority means that the control device can trust the second public key.
  • the control device passes the verification of the second challenge value using the second public key, it means that the control device can trust the IoT device, that is, it means that the target application program on the control device can trust the IoT device.
  • the process of establishing a connection between the control device and the IoT device may be: receiving the network information to be distributed broadcast by the IoT device. Establish a connection with the IoT device based on the network information to be distributed. Send the target digital certificate to the IoT device based on the connection.
  • the IoT device can broadcast the network information to be configured through Bluetooth, or the IoT device can also broadcast the network information to be configured through the soft wireless access point (SoftAP).
  • SoftAP soft wireless access point
  • the network information to be distributed includes, but is not limited to, the merchant logo of the IoT device, the device ID of the IoT device, the serial number of the IoT device, and the media access control address (Media Access Control Address, MAC), etc.
  • the control device After receiving the information of the network to be distributed, the control device displays the information of the network to be distributed, so that the user can know the information of the network to be distributed.
  • the user selects the displayed network information to be distributed, and the control device establishes a connection with the IoT device corresponding to the network information to be distributed in response to the user's selection operation.
  • Subsequent information interaction between the control device and the IoT device can be carried out through this connection.
  • the target digital certificate is sent to the IoT device through the connection, and for example, the first challenge information sent by the IoT device is received through the connection.
  • the user may also be prompted to input the identification code of the IoT device (Personal Identification Number, PIN)
  • the control device After the control device establishes a connection with the IoT device through the SoftAP, the control device cannot use the network, that is, the control device is offline at this time, that is, the control device cannot send the first challenge information to the target server. Therefore, after the control device receives the first challenge information, or passes the verification of the second challenge value, the control device can connect to the router, and identify the router's service set (Service Set Identifier, SSID) and password are sent to the IoT device, and the IoT device connects to the router based on the service set ID and password. Then the control device sends the first challenge information to the target server through the router, receives the first challenge value sent by the target server through the router, and sends the first challenge value to the IoT device through the router.
  • SSID Service Set Identifier
  • control device can send control commands to the IoT device through the target application based on the router, so that the IoT device executes and controls the command corresponding operation.
  • control device establishes a Bluetooth connection with the IoT device
  • control device sends a control command to the IoT device through the target application program based on the Bluetooth connection, so that the IoT device performs an operation corresponding to the control command.
  • the process of the Internet of Things device performing the operation corresponding to the control instruction may be: the Internet of Things device first checks the mark of the target application program carried in the control command, if the target application program has been marked as an application program with control authority, then IoT devices can perform operations corresponding to control instructions.
  • control device can send the first digital certificate and the control command to the IoT device based on the router or the Bluetooth connection. After receiving the first digital certificate, the IoT device has already verified the first digital certificate. When the first digital certificate is received, the operation corresponding to the control instruction can be executed.
  • the control device can connect to the router and identify the service set of the router (Service Set Identifier, SSID) and password are sent to the IoT device, and the IoT device connects to the router based on the service set ID and password.
  • the control device and the IoT device can establish a Bluetooth connection.
  • the control device controls the IoT devices based on the router or bluetooth connection.
  • the process of controlling the IoT device by the control device may be: sending a control command to the IoT device through a target application program. After the IoT device receives it, look at the markup of the target application. If the target application program is marked as an application program with control authority, the IoT device will execute the operation corresponding to the control instruction.
  • the process for the control device to control the Internet of Things device can also be: when the control device passes the verification of the authority of the Internet of Things device, the control device can pass the control authority information (Access Control List, ACL) to the IoT device. If the IoT device has not verified the target application on the control device, it will mark the control authority information as untrusted. If the IoT device verifies the target application When passed, the control authority information is marked as trusted and stored.
  • ACL Access Control List
  • control device can send the control instruction and the control authority information to the IoT device.
  • the IoT device After receiving the control instruction and control authority information, the IoT device compares the received control authority information with the stored control authority information, and if the received control authority information is the same as the stored control authority information, execute the operation corresponding to the control instruction .
  • the certification body refers to an e-commerce certification center (Certificate Authority, CA). Since the authentication structure is a trusted third party, when the authentication structure authenticates the target server, it means that the certification body trusts the target server, and the IoT device can trust the target server.
  • CA e-commerce certification center
  • the target digital certificate refers to a string of numbers that can indicate the identity information of the target server.
  • the target server can obtain the target digital certificate after being authenticated by the certification authority. Then the target server sends the target digital certificate to the control device.
  • the controlling device may receive the target digital certificate through the target application program on the controlling device.
  • the target application refers to the application that actually controls the IoT device.
  • the target application can be an application developed by the merchant of the IoT device, that is, the application corresponding to the IoT device, or an application developed by other merchants (because when the target application When the program is an application program corresponding to an Internet of Things device, applying the permission determination method provided by the embodiment of the present application can also provide security for controlling the Internet of Things device. Therefore, the target application program can also be an application program corresponding to an Internet of Things device).
  • the target server may be an initial server produced by a merchant of the IoT device, and at this time the target application program is an application program corresponding to the IoT device.
  • the target server can also be a server of other merchants (other than the merchant that produced the IoT device), and in this case, the target application is other applications on the control device (other applications refer to those installed on the control device) applications other than those corresponding to IoT devices).
  • the IoT device is a device produced by A merchant
  • the application program corresponding to the IoT device is the A application program.
  • Merchant B has developed an application program B
  • the target server may be the server of merchant B
  • the target application program may be the application program B.
  • the user of the control device wants to control the IoT device through the target application program on the control device
  • the user can operate the target application program on the control device, so that the control device sends the target digital certificate to the IoT device, and the IoT device thereby Received target digital certificate.
  • the IoT device After receiving the target digital certificate, the IoT device uses the built-in authentication public key to verify the target digital certificate.
  • the target digital certificate is a certificate certified by the certification authority, which means that the IoT device can trust the content of the target digital certificate. Then, the first challenge information is sent to the control device, and the control device then sends the first challenge information to the target server.
  • the target server may use the first private key of the target server to sign the first challenge information, so as to obtain the first challenge value.
  • the target server may use a preset encryption algorithm to encrypt the first challenge information, so as to obtain the first challenge value.
  • the content of the target digital certificate includes a decryption algorithm corresponding to a preset encryption algorithm.
  • the content of the target digital certificate may include, but not limited to, the identity information of the target server, the information of the certification authority, and the first public key of the target server.
  • the first challenge information may be a string of random character strings.
  • the IoT device may generate the first challenge information and return the first challenge information when the target digital certificate is verified and passed. Or, the IoT device may first generate the first challenge information, and then return the first challenge information when the target digital certificate is verified and passed. As for the time when the IoT device generates the first challenge information, the user can choose according to the actual situation, which is not limited in this application.
  • the control device After the target server sends the first challenge value to the control device, the control device sends the first challenge value to the IoT device, and the IoT device receives the first challenge value.
  • the Internet of Things device trusts the content of the target digital certificate
  • the content of the target digital certificate is used to verify the first challenge value and the verification passes
  • the first challenge information obtained when the verification is passed is the same as the first challenge information sent by the Internet of Things device.
  • the IoT device can trust the target server, and the target server trusts the target application program, so at this time, the IoT device can mark the target application program as an application program with control authority over the IoT device.
  • the target digital certificate may also be marked as a certificate with authority.
  • the target application program is marked as an application program that does not have control authority for the IoT device.
  • the target server uses the first private key of the target server to sign the first challenge information to obtain the first challenge value and the content of the target digital certificate includes the first public key of the target server
  • the content of the target digital certificate is used
  • the process of verifying the first challenge value may be: verifying the first challenge value by using the first public key.
  • the target server uses a preset encryption algorithm to encrypt the first challenge information to obtain the first challenge value and the content of the target digital certificate includes a decryption algorithm corresponding to the preset encryption algorithm
  • use the content of the target digital certificate to The process of verifying the first challenge value may be: using a decryption algorithm to decrypt the first challenge value.
  • the Internet of Things device first receives the target digital certificate sent by the control device, and the target digital certificate is a certificate obtained after the certification authority authenticates the target server with the certification private key. Then, the IoT device uses the built-in authentication public key to verify the target digital certificate. When the verification is passed, the IoT device obtains the content of the target digital certificate, and returns the first challenge information to the control device, so that the control device sends the first challenge information to the target server, and the first challenge information is used to instruct the target server to generate a first challenge value, and return the first challenge value to the control device. The IoT device receives the first challenge value sent by the control device, and finally determines the control authority of the target application program on the control device to the IoT device based on the first challenge value and the content of the target digital certificate.
  • the target server since the target server and the target application program belong to the same merchant, the target server trusts the target application program.
  • the Internet of Things device passes the verification of the target digital certificate using the authentication public key, it means that the target digital certificate is a certificate certified by the certification authority.
  • the IoT device can trust the content of the target digital certificate, so that it can be determined whether the target server can be trusted according to the content of the target digital certificate and the first challenge value sent by the target server, so as to determine whether The target application program can be trusted, so that even if the target application program on the control device is not the application program corresponding to the IoT device, security can be guaranteed when the IoT device is controlled through the target application program on the control device.
  • S301 Send the target digital certificate to the control device, so that the control device sends the target digital certificate to the IoT device.
  • the target digital certificate is used to instruct the IoT device to perform verification, and obtain the target digital certificate when the verification is passed. content, and return the first challenge information to the control device, and the target digital certificate includes the certificate obtained by the certification authority after using the certification private key to authenticate the target server.
  • the certification body refers to an e-commerce certification center (Certificate Authority, CA). Since the authentication structure is a trusted third party, when the authentication structure authenticates the target server, it means that the certification body trusts the target server, and the IoT device can trust the target server.
  • CA e-commerce certification center
  • the target digital certificate refers to a string of numbers that can indicate the identity information of the target server.
  • the target server can obtain the target digital certificate after being authenticated by the certification authority. Then the target server sends the target digital certificate to the control device.
  • the controlling device may receive the target digital certificate through the target application program on the controlling device.
  • the target application refers to the application that actually controls the IoT device.
  • the target application can be an application developed by the merchant of the IoT device, that is, the application corresponding to the IoT device, or an application developed by other merchants (because when the target application When the program is an application program corresponding to an Internet of Things device, applying the permission determination method provided by the embodiment of the present application can also provide security for controlling the Internet of Things device. Therefore, the target application program can also be an application program corresponding to an Internet of Things device).
  • the target server may be an initial server produced by a merchant of the IoT device, and at this time the target application program is an application program corresponding to the IoT device.
  • the target server can also be a server of other merchants (other than the merchant that produced the IoT device), and in this case, the target application is other applications on the control device (other applications refer to those installed on the control device) applications other than those corresponding to IoT devices).
  • the IoT device is a device produced by A merchant
  • the application program corresponding to the IoT device is the A application program.
  • Merchant B has developed an application program B
  • the target server may be the server of merchant B
  • the target application program may be the application program B.
  • the user of the control device wants to control the IoT device through the target application program on the control device
  • the user can operate the target application program on the control device, so that the target application program of the control device generates a permission verification request and verifies the permission
  • the request is sent to the target server, and the target server sends the target digital certificate to the control device based on the authority verification request.
  • the authority verification request can also be automatically generated when the user finishes installing the target application program, and the authority verification request is sent to the target server, and the target server then sends the target digital certificate to the control device based on the authority verification request.
  • the time for the target server to send the target digital certificate can be set by the user according to the actual situation, which is not limited in this application.
  • the IoT device After receiving the target digital certificate, the IoT device uses the built-in authentication public key to verify the target digital certificate. If the verification is passed, it means that the target digital certificate is a certificate certified by the certification authority, which means that the IoT device can trust the content of the target digital certificate. Then, the first challenge information is returned to the control device, so that the control device receives the first challenge information.
  • the first challenge information may be a string of random character strings.
  • the IoT device may generate the first challenge information and return the first challenge information when the target digital certificate is verified and passed. Or, the IoT device may first generate the first challenge information, and then return the first challenge information when the target digital certificate is verified and passed. As for the time when the IoT device generates the first challenge information, the user can choose according to the actual situation, which is not limited in this application.
  • the content of the target digital certificate may include, but not limited to, the identity information of the target server, the information of the certification authority, and the first public key of the target server.
  • S302. Receive first challenge information sent by the control device.
  • the control device After receiving the first challenge information, the control device sends the first challenge information to the target server, and the target server thus receives the first challenge information.
  • the process of generating the first challenge value based on the first challenge information may be as follows: the target server may use the first private key of the target server to sign the first challenge information, so as to obtain the first challenge value.
  • the target server may use a preset encryption algorithm to encrypt the first challenge information, so as to obtain the first challenge value.
  • the content of the target digital certificate includes a decryption algorithm corresponding to a preset encryption algorithm.
  • the target server can trust the target application program. Therefore, after the target server receives the first challenge information, the target application program may not be verified.
  • the target server may also verify the authority of the control device, that is, verify the authority of the target application program of the control device. After the verification is passed, the target server generates a first challenge value based on the first challenge information.
  • the user can choose according to the actual situation.
  • the token and the first challenge information can be sent to the target server through the target application program. After the target server receives the token, it will compare the token with the token stored in itself. If they are the same, the verification of the target application program is passed.
  • both the control device and the target server can generate random numbers according to preset rules, and then the control device encrypts the random numbers with the stored public key, and sends the encrypted random numbers together with the first challenge information through the target application program to the target server.
  • the target server uses the stored private key to decrypt the random number, and compares the decrypted random number with the random number generated according to the preset rules. If the random numbers are the same, the verification of the target application program is passed.
  • S304 Send the first challenge value to the control device, so that the control device sends the first challenge value to the IoT device, and the first challenge value and the content of the target digital certificate are used by the IoT device to determine the target application program on the control device Control authority over IoT devices.
  • the process for the Internet of Things device to determine the control authority of the target application program on the control device to the Internet of Things device based on the first challenge value and the content of the target digital certificate may be as follows:
  • the Internet of Things device trusts the content of the target digital certificate
  • the content of the target digital certificate is used to verify the first challenge value and the verification passes
  • the first challenge information obtained when the verification is passed is the same as the first challenge information sent by the Internet of Things device.
  • the IoT device can trust the target server, and the target server trusts the target application program, so at this time, the IoT device can mark the target application program as an application program with control authority over the IoT device.
  • the target digital certificate may also be marked as a certificate with authority.
  • the IoT device When the verification of the first challenge value using the content of the target digital certificate fails, it means that the IoT device cannot trust the target server, and the IoT device marks the target application as not having control authority over the IoT device application.
  • the target server uses the first private key of the target server to sign the first challenge information to obtain the first challenge value and the content of the target digital certificate includes the first public key of the target server
  • the content of the target digital certificate is used
  • the process of verifying the first challenge value may be: verifying the first challenge value by using the first public key.
  • the target server uses a preset encryption algorithm to encrypt the first challenge information to obtain the first challenge value and the content of the target digital certificate includes a decryption algorithm corresponding to the preset encryption algorithm
  • use the content of the target digital certificate to The process of verifying the first challenge value may be: using a decryption algorithm to decrypt the first challenge value.
  • the embodiment of the present application provides a method for determining authority.
  • the target server first sends the target digital certificate to the control device, so that the control device sends the target digital certificate to the IoT device.
  • the certificate is used to instruct the Internet of Things device to perform verification, and when the verification is passed, obtain the content of the target digital certificate, and return the first challenge information to the control device. certificate obtained.
  • the target server receives the first challenge information sent by the control device.
  • the target server generates a first challenge value based on the first challenge information.
  • the target server sends the first challenge value to the control device, so that the control device sends the first challenge value to the IoT device, and the content of the first challenge value and the target digital certificate is used by the IoT device to determine the target application on the control device The control authority of the program to the IoT device.
  • the target server since the target server and the target application program belong to the same merchant, the target server trusts the target application program.
  • the Internet of Things device passes the verification of the target digital certificate using the authentication public key, it means that the target digital certificate is a certificate certified by the certification authority.
  • the IoT device can trust the content of the target digital certificate, so that it can be determined whether the target server can be trusted according to the content of the target digital certificate and the first challenge value sent by the target server, so as to determine whether The target application program can be trusted, so that even if the target application program on the control device is not the application program corresponding to the IoT device, security can be guaranteed when the IoT device is controlled through the target application program on the control device.
  • the permission determination method includes:
  • the target server sends the first digital certificate to the control device, and the first digital certificate is a certificate obtained after the certification authority authenticates the first public key of the target server with the authentication private key.
  • the Internet of Things device broadcasts the information of the network to be distributed, and the control device establishes a connection with the Internet of Things device according to the information of the network to be distributed after receiving the information of the network to be distributed.
  • the control device sends a certificate acquisition request to the IoT device through the target application.
  • the Internet of Things device returns a second digital certificate to the control device based on the certificate acquisition request, and the second digital certificate is a certificate obtained by signing the second public key of the Internet of Things device with the certification private key by the certification authority.
  • the control device uses the built-in authentication public key to verify the second digital certificate. When the verification is passed, it obtains the second public key of the IoT device, generates a second challenge information, and passes the second challenge information to the target application program. sent to IoT devices.
  • the IoT device signs the second challenge information with the second private key to obtain a second challenge value, and sends the second challenge value to the control device.
  • the control device verifies the second challenge value according to the second public key. When the verification is passed, a connection is established with the router, and the service set ID and password of the connected router are sent to the IoT device.
  • the control device After the IoT device is connected to the router, the control device sends control commands to the IoT device through the target application program based on the router. At this point, the IoT device has not verified the permissions of the target application, so it responds with an error and sends an error message to the control device.
  • the control device After receiving the error information, the control device sends the first digital certificate and challenge information acquisition request to the IoT device through the target application program.
  • the Internet of Things device uses the built-in authentication public key to verify the first digital certificate, obtains the first public key of the target server when the verification is passed, and returns the first challenge information to the control device based on the challenge information acquisition request.
  • the control device sends the first challenge information to the target server.
  • the target server uses the first private key to sign the first challenge information, obtains the first challenge value, and sends the first challenge value to the control device.
  • the control device sends the first challenge value to the IoT device.
  • the IoT device uses the first public key to verify the first challenge value.
  • the verification first challenge information is obtained, and if the verified first challenge information is compared with the sent first challenge information, the first digital certificate is marked as a certificate with control authority.
  • the control device sends the control instruction and the first digital certificate to the IoT device through the target application program. Since the first digital certificate is a certificate with control authority, the IoT device executes the operation corresponding to the control instruction.
  • an embodiment of the present application also provides a permission determination device, which is applied to a control device.
  • the permission determination device may include:
  • the first receiving module 501 is configured to receive the target digital certificate sent by the target server, and the target digital certificate includes a certificate obtained by the certification authority after authenticating the target server by using the certification private key.
  • the first sending module 502 is configured to send the target digital certificate to the Internet of Things device, so that the Internet of Things device uses the built-in authentication public key to verify the target digital certificate, and when the verification is passed, obtain the content of the target digital certificate .
  • the second receiving module 503 is configured to receive the first challenge information returned by the Internet of Things device based on the verification of the target digital certificate.
  • the second sending module 504 is configured to send the first challenge information to the target server, so that the target server generates a first challenge value based on the first challenge information.
  • the third receiving module 505 is configured to receive the first challenge value sent by the target server, and send the first challenge value to the IoT device, so as to determine the target application program on the control device based on the first challenge value and the content of the target digital certificate Control authority over IoT devices.
  • the target digital certificate includes a first digital certificate
  • the first digital certificate is a certificate obtained after the certification authority authenticates the first public key of the target server by using the certification private key.
  • the first sending module 502 is specifically configured to execute:
  • the second receiving module 503 is specifically configured to execute:
  • the second sending module 504 is specifically configured to execute:
  • the third receiving module 505 is specifically configured to execute:
  • the first sending module 502 is specifically configured to execute:
  • the second digital certificate is a certificate obtained after the certification authority signs the second public key of the Internet of Things device with the authentication private key;
  • the target digital certificate is sent to the IoT device.
  • the first sending module 502 is specifically configured to execute:
  • the authority determination device also includes:
  • the instruction sending module is configured to send a control instruction to the Internet of Things device through the target application program, so that the Internet of Things device performs an operation corresponding to the control instruction.
  • each of the above modules can be implemented as an independent entity, or can be combined arbitrarily as the same or several entities.
  • the specific implementation methods and corresponding beneficial effects of the above modules please refer to the previous method embodiments. I won't repeat them here.
  • an embodiment of the present application also provides a permission determination device, which is applied to an Internet of Things device.
  • the permission determination device may include:
  • the fourth receiving module 601 is configured to receive the target digital certificate sent by the control device, and the target digital certificate is a certificate obtained after the certification authority authenticates the target server with the certification private key.
  • the first verification module 602 is configured to verify the target digital certificate by using the built-in authentication public key.
  • the third sending module 603 is configured to obtain the content of the target digital certificate when the verification is passed, and send the first challenge information to the control device, so that the control device sends the first challenge information to the target server, and the first challenge information uses Then instruct the target server to generate a first challenge value, and return the first challenge value to the control device.
  • the fifth receiving module 604 is configured to receive the first challenge value sent by the control device.
  • a determination module 605 configured to determine the control authority of the target application program on the control device to the IoT device based on the first challenge value and the content of the target digital certificate.
  • each of the above modules can be implemented as an independent entity, or can be combined arbitrarily as the same or several entities.
  • each of the above modules and the corresponding beneficial effects please refer to the previous method embodiments. I won't repeat them here.
  • an embodiment of the present application also provides a permission determination device, which is applied to a target server.
  • the permission determination device may include:
  • the fourth sending module 701 is configured to send the target digital certificate to the control device, so that the control device sends the target digital certificate to the IoT device, the target digital certificate is used to instruct the IoT device to perform verification, and when the verification passes , obtain the content of the target digital certificate, and return the first challenge information to the control device, where the target digital certificate includes the certificate obtained by the certification authority after authenticating the target server with the certification private key.
  • the sixth receiving module 702 is configured to receive the first challenge information sent by the control device.
  • a generating module 703, configured to generate a first challenge value based on the first challenge information.
  • the fifth sending module 704 is configured to send the first challenge value to the control device, so that the control device sends the first challenge value to the IoT device, and the content of the first challenge value and the target digital certificate are used to determine and control the IoT device The control permissions of the target application on the device to the IoT device.
  • each of the above modules can be implemented as an independent entity, or can be combined arbitrarily as the same or several entities.
  • each of the above modules and the corresponding beneficial effects please refer to the previous method embodiments. I won't repeat them here.
  • the embodiment of the present application also provides a computer device, as shown in FIG. 8 , which shows a schematic structural diagram of the computer device involved in the embodiment of the present application. Specifically:
  • the computer device may include a processor 801 of one or more processing cores, a memory 802 of one or more computer-readable storage media, a power supply 803, an input unit 804 and other components.
  • a processor 801 of one or more processing cores may include a processor 801 of one or more processing cores, a memory 802 of one or more computer-readable storage media, a power supply 803, an input unit 804 and other components.
  • FIG. 8 does not constitute a limitation on the computer device, and may include more or less components than shown in the figure, or combine some components, or arrange different components. in:
  • the processor 801 is the control center of the computer equipment. It uses various interfaces and lines to connect various parts of the entire computer equipment. By running or executing the computer programs and/or modules stored in the memory 802, and calling the Data, perform various functions of computer equipment and process data, so as to monitor the computer equipment as a whole.
  • the processor 801 may include one or more processing cores; preferably, the processor 801 may integrate an application processor and a modem processor, wherein the application processor mainly processes operating systems, user interfaces, and application programs, etc. , the modem processor mainly handles wireless communications. It can be understood that the foregoing modem processor may not be integrated into the processor 801 .
  • the memory 802 can be used to store computer programs and modules, and the processor 801 executes various functional applications and data processing by running the computer programs and modules stored in the memory 802 .
  • the memory 802 may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, a computer program required by at least one function (such as a sound playback function, an image playback function, etc.); Data created by the use of computer equipment, etc.
  • the memory 802 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one magnetic disk storage device, flash memory device, or other volatile solid-state storage devices.
  • the memory 802 may further include a memory controller to provide the processor 801 with access to the memory 802 .
  • the computer device also includes a power supply 803 for supplying power to each component.
  • the power supply 803 can be logically connected to the processor 801 through the power management system, so that functions such as charging, discharging, and power consumption management can be realized through the power management system.
  • the power supply 803 may also include one or more DC or AC power supplies, recharging systems, power failure detection circuits, power converters or inverters, power status indicators and other arbitrary components.
  • the computer device can also include an input unit 804, which can be used to receive input numbers or character information, and generate keyboard, mouse, joystick, optical or trackball signal input related to user settings and function control.
  • an input unit 804 can be used to receive input numbers or character information, and generate keyboard, mouse, joystick, optical or trackball signal input related to user settings and function control.
  • the computer device may also include a display unit, etc., which will not be repeated here.
  • the processor 801 in the computer device loads the executable file corresponding to the process of one or more computer programs into the memory 802 according to the following instructions, and the processor 801 executes the executable file stored in the The computer program in memory 802, thereby realizes various functions, such as:
  • the target digital certificate sent by the target server includes the certificate obtained by the certification authority after authenticating the target server with the authentication private key;
  • an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and the computer program can be loaded by a processor to execute the steps in any permission determination method provided in the embodiments of the present application. .
  • the computer-readable storage medium may include: read-only memory (ROM, Read Only Memory), random access memory (RAM, Random Access Memory), disk or CD, etc.
  • a computer program product or computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium.
  • the processor of the computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the above permission determination method.

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Storage Device Security (AREA)

Abstract

本申请实施例公开了一种权限确定方法、装置、计算机设备和计算机可读存储介质;在本申请实施例中,可以根据目标数字证书的内容和目标服务器发送的第一挑战值确定是否可以信任目标服务器,从而确定是否可以信任目标应用程序,进而使得即使控制设备上的目标应用程序不是物联网设备对应的应用程序,通过控制设备上的目标应用程序控制物联网设备时也可以保证安全性。

Description

权限确定方法、装置、计算机设备和计算机可读存储介质
本申请要求申请日为2021年12月23日、申请号为202111590467.2、发明名称为“权限确定方法、装置、计算机设备和计算机可读存储介质”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。
技术领域
本申请涉及物联网设备技术领域,具体涉及一种权限确定方法、装置、计算机设备和计算机可读存储介质。
背景技术
随着科学技术的发展,物联网(Internet of Things,IOT)设备的应用越来越广泛。
目前,为了保证安全,一般是通过物联网设备的应用程序(Application)控制物联网设备,导致每增加一个物联网设备,用户需下载一个新的应用程序,比较麻烦。而如果通过其他应用程序控制物联网设备,无法保证安全性。
技术问题
通过其他应用程序控制物联网设备,无法保证安全性。
技术解决方案
本申请实施例提供一种权限确定方法、装置、计算机设备和计算机可读存储介质,当通过其他应用程序控制物联网设备时也可以保证安全性。
一种权限确定方法,应用于控制设备,包括:
接收目标服务器发送的目标数字证书,上述目标数字证书包括认证机构采用认证私钥对上述目标服务器认证后得到的证书;
将上述目标数字证书发送至物联网设备,以使上述物联网设备采用内置的认证公钥对上述目标数字证书进行校验,并在校验通过时,取得上述目标数字证书的内容;
接收上述物联网设备基于对上述目标数字证书校验通过后返回的第一挑战信息;
将上述第一挑战信息发送至上述目标服务器,以使上述目标服务器基于上述第一挑战信息生成第一挑战值;
接收上述目标服务器发送的上述第一挑战值,并将上述第一挑战值发送至上述物联网设备,以基于上述第一挑战值和上述目标数字证书的内容确定上述控制设备上的目标应用程序对上述物联网设备的控制权限。
一种权限确定方法,应用于物联网设备,包括:
接收控制设备发送的目标数字证书,上述目标数字证书为认证机构采用认证私钥对目标服务器认证后得到的证书;
采用内置的认证公钥对上述目标数字证书进行校验;
当校验通过时,取得上述目标数字证书的内容,并返回第一挑战信息至上述控制设备,以使上述控制设备将第一挑战信息发送至上述目标服务器,上述第一挑战信息用于指示上述目标服务器生成第一挑战值,并将上述第一挑战值返回至上述控制设备;
接收上述控制设备发送的上述第一挑战值;
基于上述第一挑战值和上述目标数字证书的内容确定上述控制设备上的目标应用程序对上述物联网设备的控制权限。
一种权限确定方法,应用于目标服务器,包括:
将目标数字证书发送至控制设备,以使得上述控制设备将上述目标数字证书发送至物联网设备,上述目标数字证书用于指示上述物联网设备进行校验,并在校验通过时,取得上述目标数字证书的内容,并返回第一挑战信息至上述控制设备,上述目标数字证书包括认证机构采用认证私钥对上述目标服务器认证后得到的证书;
接收上述控制设备发送的上述第一挑战信息;
基于上述第一挑战信息进生成第一挑战值;
将上述第一挑战值发送至上述控制设备,以使得上述控制设备将上述第一挑战值发送至上述物联网设备,上述第一挑战值和上述目标数字证书的内容用于上述物联网设备确定上述控制设备上的目标应用程序对上述物联网设备的控制权限。
相应地,本申请实施例提供一种权限确定装置,应用于控制设备,包括:
第一接收模块,用于接收目标服务器发送的目标数字证书,上述目标数字证书包括认证机构采用认证私钥对上述目标服务器认证后得到的证书;
第一发送模块,用于将上述目标数字证书发送至物联网设备,以使上述物联网设备采用内置的认证公钥对上述目标数字证书进行校验,并在校验通过时,取得上述目标数字证书的内容;
第二接收模块,用于接收上述物联网设备基于对上述目标数字证书校验通过后返回的第一挑战信息;
第二发送模块,用于将上述第一挑战信息发送至上述目标服务器,以使上述目标服务器基于上述第一挑战信息生成第一挑战值;
第三接收模块,用于接收上述目标服务器发送的上述第一挑战值,并将上述第一挑战值发送至上述物联网设备,以基于上述第一挑战值和上述目标数字证书的内容确定上述控制设备上的目标应用程序对上述物联网设备的控制权限。
相应地,本申请实施例提供一种权限确定装置,应用于物联网设备,包括:
第四接收模块,用于接收控制设备发送的目标数字证书,上述目标数字证书为认证机构采用认证私钥对目标服务器认证后得到的证书;
第一校验模块,用于采用内置的认证公钥对上述目标数字证书进行校验;
第三发送模块,用于当校验通过时,取得上述目标数字证书的内容,并发送第一挑战信息至上述控制设备,以使上述控制设备将第一挑战信息发送至上述目标服务器,上述第一挑战信息用于指示上述目标服务器生成第一挑战值,并将上述第一挑战值返回至上述控制设备;
第五接收模块,用于接收上述控制设备发送的第一挑战值;
确定模块,用于基于上述第一挑战值和上述目标数字证书的内容确定上述控制设备上的目标应用程序对上述物联网设备的控制权限。
相应地,本申请实施例提供一种权限确定装置,应用于目标服务器,包括:
第四发送模块,用于将目标数字证书发送至控制设备,以使得上述控制设备将上述目标数字证书发送至物联网设备,上述目标数字证书用于指示上述物联网设备进行校验,并在校验通过时,取得上述目标数字证书的内容,并返回第一挑战信息至上述控制设备,上述目标数字证书包括认证机构采用认证私钥对上述目标服务器认证后得到的证书;
第六接收模块,用于接收上述控制设备发送的上述第一挑战信息;
生成模块,用于基于上述第一挑战信息进生成第一挑战值;
第五发送模块,用于将上述第一挑战值发送至上述控制设备,以使得上述控制设备将上述第一挑战值发送至上述物联网设备,上述第一挑战值和上述目标数字证书的内容用于上述物联网设备确定上述控制设备上的目标应用程序对上述物联网设备的控制权限。
此外,本申请实施例还提供一种计算机设备,包括处理器和存储器,上述存储器存储有计算机程序,上述处理器用于运行上述存储器内的计算机程序实现本申请实施例提供的权限确定方法。
此外,本申请实施例还提供一种计算机可读存储介质,上述计算机可读存储介质存储有计算机程序,上述计算机程序适于处理器进行加载,以执行本申请实施例所提供的任一种权限确定方法中的步骤。
有益效果
在本申请的实施例中,先接收目标服务器发送的目标数字证书,目标数字证书包括认证机构采用认证私钥对目标服务器认证后得到的证书。然后将目标数字证书发送至物联网设备,以使物联网设备采用内置的认证公钥对目标数字证书进行校验,并在校验通过时,取得目标数字证书的内容。接着,接收物联网设备基于对目标数字证书校验通过后返回的第一挑战信息。再将第一挑战信息发送至目标服务器,以使目标服务器基于第一挑战信息生成第一挑战值。最后接收目标服务器发送的上述第一挑战值,并将第一挑战值发送至物联网设备,以基于第一挑战值和目标数字证书的内容确定控制设备的目标应用程序对物联网设备的控制权限。
即在本申请实施例中,由于目标服务器和目标应用程序是属于同一个商家的,因此,目标服务器信任目标应用程序。当物联网设备采用认证公钥对目标数字证书的校验通过时,说明该目标数字证书为认证机构认证过的证书。因为认证机构是物联网设备信任的机构,所以物联网设备可以信任目标数字证书的内容,以便可以根据目标数字证书的内容和目标服务器发送的第一挑战值确定是否可以信任目标服务器,从而确定是否可以信任目标应用程序,进而使得即使控制设备上的目标应用程序不是物联网设备对应的应用程序,通过控制设备上的目标应用程序控制物联网设备时也可以保证安全性。
附图说明
为了更清楚地说明本申请实施例中的技术方案,下面将对实施例描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本申请的一些实施例,对于本领域技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。
图1是本申请实施例提供的权限确定方法的流程示意图;
图2是本申请实施例提供的另一种权限确定方法的流程示意图;
图3是本申请实施例提供的另一种权限确定方法的流程示意图;
图4是本申请实施例提供的另一种权限确定方法的交互示意图;
图5是本申请实施例提供的权限确定装置的结构示意图;
图6是本申请实施例提供的另一种权限确定装置的结构示意图;
图7是本申请实施例提供的另一种权限确定装置的结构示意图;
图8是本申请实施例提供的计算机设备的结构示意图。
本发明的实施方式
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域技术人员在没有作出创造性劳动前提下所获得的所有其他实施例,都属于本申请保护的范围。
本申请实施例提供一种权限确定方法、装置、计算机设备和计算机可读存储介质。其中,该权限确定装置可以集成在计算机设备中,该计算机设备可以是服务器,也可以是控制设备,也可以是物联网设备。
其中,服务器可以是独立的物理服务器,也可以是多个物理服务器构成的服务器集群或者分布式系统,还可以是提供云服务、云数据库、云计算、云函数、云存储、网络服务、云通信、中间件服务、域名服务、安全服务、网络加速服务(Content Delivery Network,CDN)、以及大数据和人工智能平台等基础云计算服务的云服务器。
控制设备可以是智能手机、平板电脑、笔记本电脑以及台式计算机等,但并不局限于此。
物联网设备指可以与其他设备进行网络通信的设备,比如,可以是智能空调、智能音箱等设备。
服务器、控制设备以及物联网设备可以通过有线或无线通信方式进行直接或间接地连接,本申请在此不做限制。
以下分别进行详细说明。需要说明的是,以下实施例的描述顺序不作为对实施例优选顺序的限定。
相关技术中,对物联网设备进行控制的过程可以为:通过控制设备上的物联网设备对应的应用程序发送控制指令至物联网设备,物联网设备再执行控制指令对应的操作。
为了保证安全性,在通过控制设备上的物联网设备对应的应用程序控制物联网设备之前,会对物联网设备对应的应用程序的权限进行校验。校验的过程可以为:在控制设备上下载物联网设备对应的应用程序,将应用程序携带的私钥进行存储,在物联网设备上设置私钥对应的公钥,通过公钥确定控制设备的安全性。
然而,在控制设备上的存储的私钥容易被破解,当被破解时,没有权限的控制设备也可根据破解得到的私钥对物联网设备进行控制,从而导致不安全。
此外,如果用户想通过控制设备上的其他应用程序控制物联网设备,由于其他应用程序没有携带私钥(其他应用程序与物联网设备不属于同一个商家,所以物联网设备的商家不能将私钥设置在其他应用程序上),使得不能对控制设备上的其他应用程序的权限进行校验,从而使得存在安全性的问题。因此,相关技术中,还不能通过其他应用程序控制物联网设备。
为了解决上述的安全性的问题,本申请实施例提供了一种权限确定方法,在该方法中,先接收目标服务器发送的目标数字证书,目标数字证书包括认证机构采用认证私钥对目标服务器认证后得到的证书。然后将目标数字证书发送至物联网设备,以使物联网设备采用内置的认证公钥对目标数字证书进行校验,并在校验通过时,取得目标数字证书的内容。接着,接收物联网设备基于对目标数字证书校验通过后返回的第一挑战信息。再将第一挑战信息发送至目标服务器,以使目标服务器基于第一挑战信息生成第一挑战值。最后接收目标服务器发送的第一挑战值,并将第一挑战值发送至物联网设备,以基于第一挑战值和目标数字证书的内容确定控制设备上的目标应用程序对物联网设备的控制权限。
即在本申请实施例中,由于目标服务器和目标应用程序是属于同一个商家的,因此,目标服务器信任目标应用程序。当物联网设备采用认证公钥对目标数字证书的校验通过时,说明该目标数字证书为认证机构认证过的证书。因为认证机构是物联网设备信任的机构,所以物联网设备可以信任目标数字证书的内容,以便可以根据目标数字证书的内容和目标服务器发送的第一挑战值确定是否可以信任目标服务器,从而确定是否可以信任目标应用程序,进而使得即使控制设备上的目标应用程序不是物联网设备对应的应用程序,通过控制设备上的目标应用程序控制物联网设备时也可以保证安全性。
下面对本申请实施例提供的权限确定方法进行详细的描述。如图1所示,该权限确定方法的具体流程如下:
S101、接收目标服务器发送的目标数字证书,目标数字证书包括认证机构采用认证私钥对目标服务器认证后得到的证书。
其中,认证机构指电子商务认证中心(Certificate Authority,CA)。由于认证结构是受信任的第三方,因此,当认证结构对目标服务器进行认证后,说明认证机构信任目标服务器,则物联网设备可以信任目标服务器。
目标数字证书指一串能够表明目标服务器身份信息的数字。目标服务器先在认证机构上进行认证后,可以得到目标数字证书。
控制设备可以通过控制设备上的目标应用程序接收目标数字证书。目标应用程序指实际控制物联网设备的应用程序,目标应用程序可以为物联网设备的商家研发的应用程序,即物联网设备对应的应用程序,也可以其他商家研发的应用程序(由于当目标应用程序为物联网设备对应的应用程序时,应用本申请实施例提供的权限确定方法也可以提供控制物联网设备的安全性。因此,目标应用程序也可以为物联网设备对应的应用程序)。
应理解,在本申请的方法实施例中,控制设备可以通过目标应用程序实现与目标服务器和物联网设备之间的信息交互。比如,可以通过目标应用程序将目标数字证书发送至物联网设备,又比如,可以通过目标应用程序接收第一挑战信息并通过目标应用程序将第一挑战信息发送至目标服务器。
目标服务器可以为物联网设备的商家生产的初始服务器,则此时目标应用程序为物联网设备对应的应用程序。
或者,目标服务器也可以为其他商家(除了生产该物联网设备的商家之外的商家)的服务器,此时,目标应用程序为控制设备上的其他应用程序(其他应用程序指控制设备上已安装的除了物联网设备对应的应用程序之外的应用程序)。
比如,物联网设备为A商家生产的设备,物联网设备对应的应用程序为A应用程序。B商家研发了B应用程序,则目标服务器可以为B商家的服务器,目标应用程序可以为B应用程序。
当控制设备的用户想通过控制设备上的目标应用程序控制物联网设备时,用户可以对控制设备上的目标应用程序进行操作,使得控制设备的目标应用程序生成权限验证请求,并将该权限验证请求发送至目标服务器,目标服务器再基于该权限验证请求将目标数字证书发送至控制设备,控制设备从而接收到目标数字证书。
或者,也可以在用户安装完成目标应用程序时自动生成权限验证请求,并将该权限验证请求发送至目标服务器,目标服务器再基于该权限验证请求将目标数字证书发送至控制设备,控制设备从而接收到目标数字证书。
对于控制设备接收目标数字证书的时间,用户可以根据实际情况进行设置,本申请在此不做限定。
S102、将目标数字证书发送至物联网设备,以使物联网设备采用内置的认证公钥对目标数字证书进行校验,并在校验通过时,取得目标数字证书的内容。
当目标应用程序为控制设备上的其他应用程序时,由于其他应用程序对应的目标服务器为其他商家的服务器,因此,生产物联网设备的商家无法将物联网设备的私钥存储在目标服务器上。所以,可以先让物联网设备信任的认证机构采用认证私钥对目标服务器进行认证,然后在物联网设备上设置认证机构的认证公钥。
接着,控制设备在获取到目标数字证书后,再将该目标数字证书发送至物联网设备,使得物联网设备采用内置的认证公钥对目标数字证书进行校验。如果校验通过,说明该目标数字证书是认证机构认证过的证书,即说明物联网设备可以信任该目标数字证书的内容。
目标数字证书的内容可以包括但不限于目标服务器的身份信息、认证机构的信息以及目标服务器的第一公钥等信息。
S103、接收物联网设备基于对目标数字证书校验通过后返回的第一挑战信息。
物联网设备在对目标数字证书校验通过后,将第一挑战信息返回至控制设备,控制设备从而接收到第一挑战信息。其中,第一挑战信息可以为一串随机字符串。
应理解,物联网设备在对目标数字证书校验通过后,也可以不将第一挑战信息返回至控制设备,当接收到控制设备发送的挑战信息获取请求时,如果对目标数字证书校验通过,再将第一挑战信息返回至控制设备。控制设备可以将挑战信息获取请求和目标数字证书一起发送至物联网设备。或者,控制设备也可以先将目标数字证书发送至物联网设备,然后再将挑战信息获取请求发送至物联网设备。
物联网设备可以在对目标数字证书校验通过时生成该第一挑战信息并返回该第一挑战信息。或在,物联网设备也可以先生成第一挑战信息,然后在对目标数字证书校验通过时返回该第一挑战信息。对于物联网设备生成第一挑战信息的时间,用户可以根据实际情况进行选择,本申请在此不做限定。
S104、将第一挑战信息发送至目标服务器,以使目标服务器基于第一挑战信息生成第一挑战值。
控制设备接收到第一挑战信息后,将第一挑战信息发送至目标服务器,使得目标服务器基于第一挑战信息生成第一挑战值。
可选地,目标服务器可以是采用目标服务器的第一私钥对第一挑战信息进行签名,从而得到第一挑战值。
或者,目标服务器可以采用预设的加密算法对第一挑战信息进行加密,从而得到第一挑战值。此时,目标数字证书的内容包括预设的加密算法对应的解密算法。
需要说明的是,由于目标应用程序与目标服务器是属于同一商家的,因此,目标服务器可以信任该目标应用程序。因此,当目标服务器接收到第一挑战信息之后,可以不对目标应用程序进行校验。
或者,为了进一步保证安全,目标服务器也可以校验控制设备的权限,即校验控制设备的目标应用程序的权限。当校验通过后,目标服务器再基于第一挑战信息生成第一挑战值。
对于目标服务器校验目标应用程序的权限的方法,用户可以根据实际情况进行选择。比如,可以通过目标应用程序将令牌和第一挑战信息一起发送至目标服务器,目标服务器接收到后,将令牌与本身存储的令牌进行比对,如果该令牌与本身存储的令牌相同,则对目标应用程序的校验通过。
又比如,控制设备和目标服务器均可以根据预设规则生成随机数,然后控制设备采用存储的公钥对随机数进行加密,并通过目标应用程序将加密后的随机数和第一挑战信息一起发送至目标服务器。目标服务器接收到后,采用存储的私钥对随机数进行解密,并将解密后的随机数与根据预设规则生成的随机数进行比对,如果解密后的随机数与根据预设规则生成的随机数相同,则对目标应用程序的校验通过。本申请在此不做具体限定。
S105、接收目标服务器发送的第一挑战值,并将第一挑战值发送至物联网设备,以基于第一挑战值和目标数字证书的内容确定控制设备上的目标应用程序对物联网设备的控制权限。
控制设备接收到目标服务器发送的第一挑战值之后,将第一挑战值发送至物联网设备,使得物联网设备基于第一挑战值和目标数字证书的内容确定控制设备上的目标应用程序对物联网设备的控制权限。
其中,基于第一挑战值和目标数字证书的内容确定控制设备上的目标应用程序对物联网设备的控制权限的过程可以为:
因为物联网设备信任目标数字证书的内容,所以当物联网设备采用目标数字证书的内容对第一挑战值的校验通过时且校验通过时得到的第一挑战信息与物联网设备发送的第一挑战信息相同时,说明物联网设备可以信任目标服务器,而目标服务器信任目标应用程序,所以,此时物联网设备可以将该目标应用程序标记为具备对物联网设备的控制权限的应用程序。
当采用目标数字证书的内容对第一挑战值的校验不通过时,说明物联网设备不可以信任目标服务器,则将该目标应用程序标记为不具备对物联网设备的控制权限的应用程序。
可选地,当目标服务器采用目标服务器的第一私钥对第一挑战信息进行签名,得到第一挑战值且目标数字证书的内容包括目标服务器的第一公钥时,采用目标数字证书的内容对第一挑战值进行校验的过程可以为:采用第一公钥对第一挑战值进行校验。
又或者,当目标服务器采用预设的加密算法对第一挑战信息进行加密,得到第一挑战值且目标数字证书的内容包括预设的加密算法对应的解密算法时,采用目标数字证书的内容对第一挑战值进行校验的过程可以为:采用解密算法对第一挑战值进行解密。
由以上可知,本申请实施例提供了一种权限确定方法,在该方法中,先接收目标服务器发送的目标数字证书,目标数字证书包括认证机构采用认证私钥对目标服务器认证后得到的证书。然后将目标数字证书发送至物联网设备,以使物联网设备采用内置的认证公钥对目标数字证书进行校验,并在校验通过时,取得目标数字证书的内容。接着,接收物联网设备基于对目标数字证书校验通过后返回的第一挑战信息。再将第一挑战信息发送至目标服务器,以使目标服务器基于第一挑战信息生成第一挑战值。最后接收目标服务器发送的第一挑战值,并将第一挑战值发送至物联网设备,以基于第一挑战值和目标数字证书的内容确定控制设备上的目标应用程序对物联网设备的控制权限。
即在本申请实施例中,由于目标服务器和目标应用程序是属于同一个商家的,因此,目标服务器信任目标应用程序。当物联网设备采用认证公钥对目标数字证书的校验通过时,说明该目标数字证书为认证机构认证过的证书。因为认证机构是物联网设备信任的机构,所以物联网设备可以信任目标数字证书的内容,以便可以根据目标数字证书的内容和目标服务器发送的第一挑战值确定是否可以信任目标服务器,从而确定是否可以信任目标应用程序,进而使得即使控制设备上的目标应用程序不是物联网设备对应的应用程序,通过控制设备上的目标应用程序控制物联网设备时也可以保证安全性。
在一些实施例中,目标数字证书包括第一数字证书,第一数字证书可以为认证机构采用认证私钥对目标服务器的第一公钥认证后得到的证书。
相应地,将目标数字证书发送至物联网设备,以使物联网设备采用内置的认证公钥对目标数字证书进行校验,并在校验通过时,取得目标数字证书的内容,包括:
将第一数字证书发送至物联网设备,以使物联网设备采用内置的认证公钥对第一数字证书进行校验,并在校验通过时,取得目标服务器的第一公钥。
接收物联网设备基于对目标数字证书校验通过后返回的第一挑战信息,包括:
接收物联网设备基于对第一数字证书校验通过后返回的第一挑战信息。
将第一挑战信息发送至所述目标服务器,以使目标服务器基于第一挑战信息生成第一挑战值,包括:
将第一挑战信息发送至目标服务器,以使目标服务器采用目标服务器的第一私钥对第一挑战信息进行签名,得到第一挑战值。
接收目标服务器发送的第一挑战值,并将第一挑战值发送至物联网设备,以基于第一挑战值和目标数字证书的内容确定控制设备上的目标应用程序对物联网设备的控制权限,包括:
接收目标服务器发送的第一挑战值,并将第一挑战值发送至物联网设备,以使物联网设备采用第一公钥对第一挑战值进行校验,并在校验通过时,将控制设备上的目标应用程序标记为具备对物联网设备的控制权限的应用程序。
在本实施例中,认证机构采用认证私钥对目标服务器的第一公钥进行签名,得到第一数字证书。物联网设备采用认证公钥对第一数字证书进行校验后,如果校验通过,则可以得到第一公钥,并且说明物联网设备可以信任第一公钥。然后物联网设备再采用第一公钥对采用第一私钥签名后得到的第一挑战值进行校验,如果校验通过,说明物联网设备可以信任目标服务器,而目标服务器信任目标应用程序,所以物联网设备可以信任目标应用程序,即将目标应用程序标记为具备对物联网设备的控制权限的应用程序。
需要说明的是,当物联网设备采用第一公钥对第一挑战值校验通过时,也可以将第一数字证书标为为具备权限的证书。
虽然物联网设备校验了控制设备的目标应用程序的权限,但是,目标应用程序还没校验物联网设备的权限。因此,在另一些实施例中,将目标数字证书发送至物联网设备,包括:
控制设备先向物联网设备发送证书获取请求。物联网设备收到证书获取请求后,基于证书获取请求返回的第二数字证书。然后控制设备接收第二数字证书,第二数字证书为认证机构采用认证私钥对物联网设备的第二公钥进行签名后得到的证书。
接着,控制设备采用内置的认证公钥对第二数字证书进行校验,在校验通过时,取得物联网设备的第二公钥。
控制设备再生成第二挑战信息,并将第二挑战信息发送至物联网设备,以使物联网设备基于第二挑战信息生成第二挑战值。
最后,控制设备接收第二挑战值,并根据第二公钥对第二挑战值进行校验。当校验通过时,说明该物联网设备是可以信任的,则将目标数字证书发送至物联网设备。
应理解,在目标应用程对物联网设备的权限的校验过程中,控制设备也可以通过目标应用程序实现与物联网设备的信息交互。控制设备在对第二挑战值校验的同时,还可以校验物联网设备的设备信息。设备信息包括但不限于物联网设备的商家标识、物联网设备的设备标识以及物联网设备的序列号等。
物联网设备基于第二挑战信息生成第二挑战值的过程可以为:物联网设备采用第二私钥对第二挑战信息进行签名,得到第二挑战值。
在本实施例中,控制设备信任认证机构。在物联网设备中内置认证公钥,并采用认证公钥对采用认证私钥签名后的第二数字证书进行校验,如果校验通过,则可以得到第二公钥,并说明第二数字证书为认证机构认证过的证书,即说明控制设备可以信任第二公钥。当控制设备采用第二公钥对第二挑战值的校验通过时,说明控制设备可以信任物联网设备,即说明控制设备上的目标应用程序可以信任物联网设备。
控制设备在与物联网设备进行信息交互之前,控制设备需先与物联网设备建立连接。控制设备与物联网设备建立连接的过程可以为:接收物联网设备广播的待配网信息。根据待配网信息与物联网设备建立连接。基于连接将目标数字证书发送至物联网设备。
物联网设备可以通过蓝牙广播待配网信息,或者,物联网设备也通过软无线接入点(SoftAP)广播待配网信息。
待配网信息包括但不限于物联网设备的商家标识、物联网设备的设备标识,物联网设备的序列号以及媒体存取控制位址(Media Access Control Address,MAC)等。
控制设备接收到待配网信息之后,将待配网信息进行显示,以便用户可以了解到该待配网信息。用户对显示的待配网信息进行选择,控制设备响应于用户的选择操作,与待配网信息对应的物联网设备建立连接。后续控制设备与物联网设备之间的信息交互,可以通过该连接进行。比如,通过该连接将目标数字证书发送至物联网设备,又比如,通过该连接接收物联网设备发送的第一挑战信息。
需要说明的是,在控制设备与物联网设备建立连接的过程中,为了保证安全性,还可以提示用户输入物联网设备的识别码(Personal Identification Number,PIN)
当控制设备通过SoftAP与物联网设备建立连接后,控制设备无法使用网络,即此时控制设备属于离线状态,即控制设备无法将第一挑战信息发送至目标服务器。因此,当控制设备可以在接收到第一挑战信息后,或者在对第二挑战值的校验通过后,控制设备可以连接至路由器,并将路由器的服务集标识(Service Set Identifier,SSID)和密码发送至物联网设备,物联网设备基于该服务集标识和密码连接至路由器。然后控制设备再通过路由器将第一挑战信息发送至目标服务器,通过路由器接收目标服务器发送的第一挑战值,以及通过路由器将第一挑战值发送至物联网设备。
此外,在将目标应用程序标记为具备对物联网设备的控制权限的应用程序之后,控制设备可以基于该路由器,通过目标应用程序发送控制指令至物联网设备,以使物联网设备执行与控制指令对应的操作。
或者,如果控制设备与物联网设备建立的是蓝牙连接,则控制设备基于蓝牙连接,通过目标应用程序发送控制指令至物联网设备,以使物联网设备执行与控制指令对应的操作。
其中,物联网设备执行与控制指令对应的操作的过程可以为:物联网设备先查看控制指令中携带的目标应用程序的标记,如果该目标应用程序已经被标记为具备控制权限的应用程序,则物联网设备可以执行与控制指令对应的操作。
或者,控制设备可以基于该路由器或蓝牙连接,将第一数字证书和控制指令一起发送至物联网设备,物联网设备接收到之后,由于之前已经对第一数字证书进行校验,因此,当接收到第一数字证书时可以执行控制指令对应的操作。
在另一些实施例中,在将控制设备上的目标应用程序标记为具备对物联网设备的控制权限的应用程序之后,控制设备可以连接到路由器,并将路由器的服务集标识(Service Set Identifier,SSID)和密码发送至物联网设备,物联网设备基于该服务集标识和密码连接至路由器。或者,控制设备和物联网设备可以建立蓝牙连接。最后控制设备基于路由器或蓝牙连接控制物联网设备。
其中,控制设备控制物联网设备的过程可以为:通过目标应用程序将控制指令发送至物联网设备。物联网设备接收后,查看目标应用程序的标记。如果目标应用程序的标记为具备控制权限的应用程序,物联网设备则执行控制指令对应的操作。
或者,控制设备控制物联网设备的过程也可以为:当控制设备对物联网设备的权限的校验通过时,控制设备可以通过目标应用程序将控制权限信息(Access Control List,ACL)发送至物联网设备中,物联网设备如果还没校验控制设备上的目标应用程序,则将该控制权限信息标记为不信任,如果物联网设备对目标应用程序的校验通过时,则将控制权限信息标记为信任并进行存储。
然后控制设备可以将控制指令和控制权限信息一起发送至物联网设备。物联网设备在接收到控制指令和控制权限信息后,将接收的控制权限信息与存储的控制权限信息比对,如果接收的控制权限信息与存储的控制权限信息相同,则执行控制指令对应的操作。
下面对本申请实施例提供的另一种权限确定方法进行详细的描述。如图2所示,该权限确定方法的具体流程如下:
S201、接收控制设备发送的目标数字证书,目标数字证书为认证机构采用认证私钥对目标服务器认证后得到的证书。
其中,认证机构指电子商务认证中心(Certificate Authority,CA)。由于认证结构是受信任的第三方,因此,当认证结构对目标服务器进行认证后,说明认证机构信任目标服务器,则物联网设备可以信任目标服务器。
目标数字证书指一串能够表明目标服务器身份信息的数字。目标服务器先在认证机构上进行认证后,可以得到目标数字证书。然后目标服务器再将目标数字证书发送给控制设备。
控制设备可以通过控制设备上的目标应用程序接收目标数字证书。目标应用程序指实际控制物联网设备的应用程序,目标应用程序可以为物联网设备的商家研发的应用程序,即物联网设备对应的应用程序,也可以其他商家研发的应用程序(由于当目标应用程序为物联网设备对应的应用程序时,应用本申请实施例提供的权限确定方法也可以提供控制物联网设备的安全性。因此,目标应用程序也可以为物联网设备对应的应用程序)。
目标服务器可以为物联网设备的商家生产的初始服务器,则此时目标应用程序为物联网设备对应的应用程序。
或者,目标服务器也可以为其他商家(除了生产该物联网设备的商家之外的商家)的服务器,此时,目标应用程序为控制设备上的其他应用程序(其他应用程序指控制设备上已安装的除了物联网设备对应的应用程序之外的应用程序)。
比如,物联网设备为A商家生产的设备,物联网设备对应的应用程序为A应用程序。B商家研发了B应用程序,则目标服务器可以为B商家的服务器,目标应用程序可以为B应用程序。
当控制设备的用户想通过控制设备上的目标应用程序控制物联网设备时,用户可以对控制设备上的目标应用程序进行操作,使得控制设备将目标数字证书发送至物联网设备,物联网设备从而接收到目标数字证书。
S202、采用内置的认证公钥对目标数字证书进行校验。
物联网设备在接收到目标数字证书之后,采用内置的认证公钥对目标数字证书进行校验。
S203、当校验通过时,取得目标数字证书的内容,并返回第一挑战信息至控制设备,以使控制设备将第一挑战信息发送至目标服务器,第一挑战信息用于指示目标服务器生成第一挑战值,并将第一挑战值返回至控制设备。
如果校验通过,说明该目标数字证书是认证机构认证过的证书,即说明物联网设备可以信任该目标数字证书的内容。则将第一挑战信息发送至控制设备,控制设备再将第一挑战信息发送至目标服务器。
目标服务器接收到第一挑战信息后,可以采用目标服务器的第一私钥对第一挑战信息进行签名,从而得到第一挑战值。
或者,目标服务器可以采用预设的加密算法对第一挑战信息进行加密,从而得到第一挑战值。此时,目标数字证书的内容包括预设的加密算法对应的解密算法。
目标数字证书的内容可以包括但不限于目标服务器的身份信息、认证机构的信息以及目标服务器的第一公钥等信息。第一挑战信息可以为一串随机字符串。
物联网设备可以在对目标数字证书校验通过时生成该第一挑战信息并返回该第一挑战信息。或在,物联网设备也可以先生成第一挑战信息,然后在对目标数字证书校验通过时返回该第一挑战信息。对于物联网设备生成第一挑战信息的时间,用户可以根据实际情况进行选择,本申请在此不做限定。
S204、接收控制设备发送的第一挑战值。
目标服务器将第一挑战值发送至控制设备之后,控制设备再将第一条挑战值发送给物联网设备,物联网设备从而接收到第一挑战值。
S205、基于第一挑战值和目标数字证书的内容确定控制设备上的目标应用程序对物联网设备的控制权限。
因为物联网设备信任目标数字证书的内容,所以当采用目标数字证书的内容对第一挑战值的校验通过且校验通过时得到的第一挑战信息与物联网设备发送的第一挑战信息相同时,说明物联网设备可以信任目标服务器,而目标服务器信任目标应用程序,所以,此时物联网设备可以将该目标应用程序标记为具备对物联网设备的控制权限的应用程序。
需要说明的是,当校验通过时,也可以将目标数字证书标为为具备权限的证书。
当采用目标数字证书的内容对第一挑战值的校验不通过时,说明物联网设备不可以信任目标服务器,则将该目标应用程序标记为不具备对物联网设备的控制权限的应用程序。
可选地,当目标服务器采用目标服务器的第一私钥对第一挑战信息进行签名,得到第一挑战值且目标数字证书的内容包括目标服务器的第一公钥时,采用目标数字证书的内容对第一挑战值进行校验的过程可以为:采用第一公钥对第一挑战值进行校验。
又或者,当目标服务器采用预设的加密算法对第一挑战信息进行加密,得到第一挑战值且目标数字证书的内容包括预设的加密算法对应的解密算法时,采用目标数字证书的内容对第一挑战值进行校验的过程可以为:采用解密算法对第一挑战值进行解密。
在本实施例中,物联网设备先接收控制设备发送的目标数字证书,目标数字证书为认证机构采用认证私钥对目标服务器认证后得到的证书。然后,物联网设备采用内置的认证公钥对目标数字证书进行校验。当校验通过时,物联网设备取得目标数字证书的内容,并返回第一挑战信息至控制设备,以使控制设备将第一挑战信息发送至目标服务器,第一挑战信息用于指示目标服务器生成第一挑战值,并将第一挑战值返回至控制设备。物联网设备接收控制设备发送的第一挑战值,最后基于第一挑战值和目标数字证书的内容确定控制设备上的目标应用程序对物联网设备的控制权限。
即在本实施例中,由于目标服务器和目标应用程序是属于同一个商家的,因此,目标服务器信任目标应用程序。当物联网设备采用认证公钥对目标数字证书的校验通过时,说明该目标数字证书为认证机构认证过的证书。因为认证机构是物联网设备信任的机构,所以物联网设备可以信任目标数字证书的内容,以便可以根据目标数字证书的内容和目标服务器发送的第一挑战值确定是否可以信任目标服务器,从而确定是否可以信任目标应用程序,进而使得即使控制设备上的目标应用程序不是物联网设备对应的应用程序,通过控制设备上的目标应用程序控制物联网设备时也可以保证安全性。
本实施例中的其他实现过程以及对应的有益效果,可以参照上述的方法实施例,本实施在此不再赘述。
下面对本申请实施例提供的另一种权限确定方法进行详细的描述。如图3所示,该权限确定方法的具体流程如下:
S301、将目标数字证书发送至控制设备,以使得控制设备通将目标数字证书发送至物联网设备,目标数字证书用于指示物联网设备进行校验,并在校验通过时,取得目标数字证书的内容,并返回第一挑战信息至控制设备,目标数字证书包括认证机构采用认证私钥对目标服务器认证后得到的证书。
其中,认证机构指电子商务认证中心(Certificate Authority,CA)。由于认证结构是受信任的第三方,因此,当认证结构对目标服务器进行认证后,说明认证机构信任目标服务器,则物联网设备可以信任目标服务器。
目标数字证书指一串能够表明目标服务器身份信息的数字。目标服务器先在认证机构上进行认证后,可以得到目标数字证书。然后目标服务器再将目标数字证书发送至控制设备。
控制设备可以通过控制设备上的目标应用程序接收目标数字证书。目标应用程序指实际控制物联网设备的应用程序,目标应用程序可以为物联网设备的商家研发的应用程序,即物联网设备对应的应用程序,也可以其他商家研发的应用程序(由于当目标应用程序为物联网设备对应的应用程序时,应用本申请实施例提供的权限确定方法也可以提供控制物联网设备的安全性。因此,目标应用程序也可以为物联网设备对应的应用程序)。
目标服务器可以为物联网设备的商家生产的初始服务器,则此时目标应用程序为物联网设备对应的应用程序。
或者,目标服务器也可以为其他商家(除了生产该物联网设备的商家之外的商家)的服务器,此时,目标应用程序为控制设备上的其他应用程序(其他应用程序指控制设备上已安装的除了物联网设备对应的应用程序之外的应用程序)。
比如,物联网设备为A商家生产的设备,物联网设备对应的应用程序为A应用程序。B商家研发了B应用程序,则目标服务器可以为B商家的服务器,目标应用程序可以为B应用程序。
当控制设备的用户想通过控制设备上的目标应用程序控制物联网设备时,用户可以对控制设备上的目标应用程序进行操作,使得控制设备的目标应用程序生成权限验证请求,并将该权限验证请求发送至目标服务器,目标服务器再基于该权限验证请求将目标数字证书发送至控制设备。
或者,也可以在用户安装完成目标应用程序时自动生成权限验证请求,并将该权限验证请求发送至目标服务器,目标服务器再基于该权限验证请求将目标数字证书发送至控制设备。
对于目标服务器发送目标数字证书的时间,用户可以根据实际情况进行设置,本申请在此不做限定。
物联网设备在接收到目标数字证书之后,采用内置的认证公钥对目标数字证书进行校验。如果校验通过,说明该目标数字证书是认证机构认证过的证书,即说明物联网设备可以信任该目标数字证书的内容。则将第一挑战信息返回至控制设备,控制设备从而接收到第一挑战信息。其中,第一挑战信息可以为一串随机字符串。
物联网设备可以在对目标数字证书校验通过时生成该第一挑战信息并返回该第一挑战信息。或在,物联网设备也可以先生成第一挑战信息,然后在对目标数字证书校验通过时返回该第一挑战信息。对于物联网设备生成第一挑战信息的时间,用户可以根据实际情况进行选择,本申请在此不做限定。
目标数字证书的内容可以包括但不限于目标服务器的身份信息、认证机构的信息以及目标服务器的第一公钥等信息。
S302、接收控制设备发送的第一挑战信息。
控制设备在接收到第一挑战信息之后,将第一挑战信息发送至目标服务器,目标服务器从而接收到第一挑战信息。
S303、基于第一挑战信息进生成第一挑战值。
基于第一挑战信息进生成第一挑战值的过程可以为:目标服务器可以是采用目标服务器的第一私钥对第一挑战信息进行签名,从而得到第一挑战值。
或者,目标服务器可以采用预设的加密算法对第一挑战信息进行加密,从而得到第一挑战值。此时,目标数字证书的内容包括预设的加密算法对应的解密算法。
需要说明的是,由于目标应用程序与目标服务器是属于同一商家的,因此,目标服务器可以信任该目标应用程序。因此,当目标服务器接收到第一挑战信息之后,可以不对目标应用程序进行校验。
或者,为了进一步保证安全,目标服务器也可以校验控制设备的权限,即校验控制设备的目标应用程序的权限。当校验通过后,目标服务器再基于第一挑战信息生成第一挑战值。
对于目标服务器校验目标应用程序的权限的方法,用户可以根据实际情况进行选择。比如,可以通过目标应用程序将令牌和第一挑战信息一起发送至目标服务器,目标服务器接收到后,将令牌与本身存储的令牌进行比对,如果该令牌与本身存储的令牌相同,则对目标应用程序的校验通过。
又比如,控制设备和目标服务器均可以根据预设规则生成随机数,然后控制设备采用存储的公钥对随机数进行加密,并通过目标应用程序将加密后的随机数和第一挑战信息一起发送至目标服务器。目标服务器接收到后,采用存储的私钥对随机数进行解密,并将解密后的随机数与根据预设规则生成的随机数进行比对,如果解密后的随机数与根据预设规则生成的随机数相同,则对目标应用程序的校验通过。本申请在此不做具体限定。
S304、将第一挑战值发送至控制设备,以使得控制设备将第一挑战值发送至物联网设备,第一挑战值和目标数字证书的内容用于物联网设备确定控制设备上的目标应用程序对物联网设备的控制权限。
物联网设备基于第一挑战值和目标数字证书的内容确定控制设备上的目标应用程序对物联网设备的控制权限的过程可以为:
因为物联网设备信任目标数字证书的内容,所以当采用目标数字证书的内容对第一挑战值的校验通过且校验通过时得到的第一挑战信息与物联网设备发送的第一挑战信息相同时,说明物联网设备可以信任目标服务器,而目标服务器信任目标应用程序,所以,此时物联网设备可以将该目标应用程序标记为具备对物联网设备的控制权限的应用程序。
需要说明的是,当校验通过时,也可以将目标数字证书标为为具备权限的证书。
当采用目标数字证书的内容对第一挑战值的校验不通过时,说明物联网设备不可以信任目标服务器,则物联网设备将该目标应用程序标记为不具备对物联网设备的控制权限的应用程序。
可选地,当目标服务器采用目标服务器的第一私钥对第一挑战信息进行签名,得到第一挑战值且目标数字证书的内容包括目标服务器的第一公钥时,采用目标数字证书的内容对第一挑战值进行校验的过程可以为:采用第一公钥对第一挑战值进行校验。
又或者,当目标服务器采用预设的加密算法对第一挑战信息进行加密,得到第一挑战值且目标数字证书的内容包括预设的加密算法对应的解密算法时,采用目标数字证书的内容对第一挑战值进行校验的过程可以为:采用解密算法对第一挑战值进行解密。
由以上可知,本申请实施例提供了一种权限确定方法,在该方法中,目标服务器先将目标数字证书发送至控制设备,以使得控制设备通将目标数字证书发送至物联网设备,目标数字证书用于指示物联网设备进行校验,并在校验通过时,取得目标数字证书的内容,并返回第一挑战信息至控制设备,目标数字证书包括认证机构采用认证私钥对目标服务器认证后得到的证书。然后,目标服务器接收控制设备发送的第一挑战信息。接着,目标服务器基于第一挑战信息进生成第一挑战值。最后目标服务器将第一挑战值发送至控制设备,以使得控制设备将第一挑战值发送至物联网设备,第一挑战值和目标数字证书的内容用于物联网设备确定控制设备上的目标应用程序对物联网设备的控制权限。
即在本申请实施例中,由于目标服务器和目标应用程序是属于同一个商家的,因此,目标服务器信任目标应用程序。当物联网设备采用认证公钥对目标数字证书的校验通过时,说明该目标数字证书为认证机构认证过的证书。因为认证机构是物联网设备信任的机构,所以物联网设备可以信任目标数字证书的内容,以便可以根据目标数字证书的内容和目标服务器发送的第一挑战值确定是否可以信任目标服务器,从而确定是否可以信任目标应用程序,进而使得即使控制设备上的目标应用程序不是物联网设备对应的应用程序,通过控制设备上的目标应用程序控制物联网设备时也可以保证安全性。
本实施例中的其他实现过程以及对应的有益效果,可以参照上述的方法实施例,本实施在此不再赘述。
下面描述本申请提供的另一种权限的确定方法。参照图4,该权限确定方法包括:
目标服务器将第一数字证书发送至控制设备,第一数字证书为认证机构采用认证私钥对目标服务器的第一公钥认证后得到的证书。物联网设备广播待配网信息,控制设备接收到待配网信息之后,根据待配网信息与物联网设备建立连接。
控制设备通过目标应用程序向物联网设备发送证书获取请求。物联网设备基于证书获取请求返回第二数字证书至控制设备,第二数字证书为认证机构采用认证私钥对物联网设备的第二公钥进行签名后得到的证书。
控制设备采用内置的认证公钥对第二数字证书进行校验,在校验通过时,取得物联网设备的第二公钥,并生成第二挑战信息,并通过目标应用程序将第二挑战信息发送至物联网设备。
物联网设备采用第二私钥对第二挑战信息进行签名,得到第二挑战值,并将第二挑战值发送至控制设备。控制设备根据第二公钥对第二挑战值进行校验。当校验通过时,与路由器建立连接,并将连接的路由器的服务集标识和密码发送至物联网设备。
物联网设备连接到该路由器后,控制设备基于该路由器,通过目标应用程序发送控制指令至物联网设备。此时,物联网设备还未校验目标应用程序的权限,因此,响应出现错误并将错误信息发送至控制设备。
控制设备接收到错误信息后,通过目标应用程序将第一数字证书和挑战信息获取请求发送至物联网设备。物联网设备采用内置的认证公钥对第一数字证书进行校验,在校验通过时,取得目标服务器的第一公钥,并基于挑战信息获取请求返回第一挑战信息至控制设备。
控制设备将第一挑战信息发送至目标服务器。目标服务器采用第一私钥对第一挑战信息进行签名,得到第一挑战值,并将第一挑战值发送至控制设备。控制设备将第一挑战值发送至物联网设备。
物联网设备采用第一公钥对第一挑战值进行校验。校验通过时,取得校验第一挑战信息,如果校验的第一挑战信息与发送的第一挑战信息进行比对,则将第一数字证书标记为具备控制权限的证书。
控制设备通过目标应用程序发送控制指令和第一数字证书至物联网设备。由于第一数字证书为具备控制权限的证书,因此,物联网设备执行控制指令对应的操作。
本实施例中的名词的含义与上述权限确定方法中相同,具体实现细节可以参考上述方法实施例中的说明。
为了更好地实施以上方法,本申请实施例还提供一种权限确定装置,该权限确定装置应用于控制设备中,例如,如图5所示,该权限确定装置可以包括:
第一接收模块501,用于接收目标服务器发送的目标数字证书,目标数字证书包括认证机构采用认证私钥对目标服务器认证后得到的证书。
第一发送模块502,用于将目标数字证书发送至物联网设备,以使物联网设备采用内置的认证公钥对目标数字证书进行校验,并在校验通过时,取得目标数字证书的内容。
第二接收模块503,用于接收物联网设备基于对目标数字证书校验通过后返回的第一挑战信息。
第二发送模块504,用于将第一挑战信息发送至目标服务器,以使目标服务器基于第一挑战信息生成第一挑战值。
第三接收模块505,用于接收目标服务器发送的第一挑战值,并将第一挑战值发送至物联网设备,以基于第一挑战值和目标数字证书的内容确定控制设备上的目标应用程序对物联网设备的控制权限。
可选地,目标数字证书包括第一数字证书,第一数字证书为认证机构采用认证私钥对目标服务器的第一公钥认证后得到的证书。
相应地,第一发送模块502具体用于执行:
将第一数字证书发送至物联网设备,以使物联网设备采用内置的认证公钥对第一数字证书进行校验,并在校验通过时,取得目标服务器的第一公钥。
第二接收模块503具体用于执行:
接收物联网设备基于对第一数字证书校验通过后返回的第一挑战信息。
第二发送模块504具体用于执行:
将第一挑战信息发送至目标服务器,以使目标服务器采用目标服务器的第一私钥对第一挑战信息进行签名,得到第一挑战值。
第三接收模块505具体用于执行:
接收目标服务器发送的第一挑战值,并将第一挑战值发送至物联网设备,以使物联网设备采用第一公钥对第一挑战值进行校验,并在校验通过时,将目标应用程序标记为具备对物联网设备的控制权限的应用程序。
可选地,第一发送模块502具体用于执行:
向物联网设备发送证书获取请求;
接收物联网设备基于证书获取请求返回的第二数字证书,第二数字证书为认证机构采用认证私钥对物联网设备的第二公钥进行签名后得到的证书;
采用内置的认证公钥对第二数字证书进行校验,在校验通过时,取得物联网设备的第二公钥;
生成第二挑战信息,并将第二挑战信息发送至物联网设备,以使物联网设备基于第二挑战信息生成第二挑战值;
接收第二挑战值,并根据第二公钥对第二挑战值进行校验;
当校验通过时,将目标数字证书发送至物联网设备。
可选地,第一发送模块502具体用于执行:
接收物联网设备广播的待配网信息;
根据待配网信息与物联网设备建立连接;
基于连接将目标数字证书发送至物联网设备。
可选地,权限确定装置还包括:
指令发送模块,用于通过目标应用程序发送控制指令至物联网设备,以使物联网设备执行与控制指令对应的操作。
具体实施时,以上各个模块可以作为独立的实体来实现,也可以进行任意组合,作为同一或若干个实体来实现,以上各个模块的具体实施方法以及对应的有益效果可参见前面的方法实施例,在此不再赘述。
为了更好地实施以上方法,本申请实施例还提供一种权限确定装置,该权限确定装置应用于物联网设备中,例如,如图6所示,该权限确定装置可以包括:
第四接收模块601,用于接收控制设备发送的目标数字证书,目标数字证书为认证机构采用认证私钥对目标服务器认证后得到的证书。
第一校验模块602,用于采用内置的认证公钥对目标数字证书进行校验。
第三发送模块603,用于当校验通过时,取得目标数字证书的内容,并发送第一挑战信息至控制设备,以使控制设备将第一挑战信息发送至目标服务器,第一挑战信息用于指示目标服务器生成第一挑战值,并将第一挑战值返回至控制设备。
第五接收模块604,用于接收控制设备发送的第一挑战值。
确定模块605,用于基于第一挑战值和目标数字证书的内容确定控制设备上的目标应用程序对物联网设备的控制权限。
具体实施时,以上各个模块可以作为独立的实体来实现,也可以进行任意组合,作为同一或若干个实体来实现,以上各个模块的具体实施方式以及对应的有益效果可参见前面的方法实施例,在此不再赘述。
为了更好地实施以上方法,本申请实施例还提供一种权限确定装置,该权限确定装置应用于目标服务器中,例如,如图7所示,该权限确定装置可以包括:
第四发送模块701,用于将目标数字证书发送至控制设备,以使得控制设备将目标数字证书发送至物联网设备,目标数字证书用于指示物联网设备进行校验,并在校验通过时,取得目标数字证书的内容,并返回第一挑战信息至控制设备,目标数字证书包括认证机构采用认证私钥对目标服务器认证后得到的证书。
第六接收模块702,用于接收控制设备发送的第一挑战信息。
生成模块703,用于基于第一挑战信息进生成第一挑战值。
第五发送模块704,用于将第一挑战值发送至控制设备,以使得控制设备将第一挑战值发送至物联网设备,第一挑战值和目标数字证书的内容用于物联网设备确定控制设备上的目标应用程序对物联网设备的控制权限。
具体实施时,以上各个模块可以作为独立的实体来实现,也可以进行任意组合,作为同一或若干个实体来实现,以上各个模块的具体实施方式以及对应的有益效果可参见前面的方法实施例,在此不再赘述。
本申请实施例还提供一种计算机设备,如图8所示,其示出了本申请实施例所涉及的计算机设备的结构示意图,具体来讲:
该计算机设备可以包括一个或者一个以上处理核心的处理器801、一个或一个以上计算机可读存储介质的存储器802、电源803和输入单元804等部件。本领域技术人员可以理解,图8中示出的计算机设备结构并不构成对计算机设备的限定,可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置。其中:
处理器801是该计算机设备的控制中心,利用各种接口和线路连接整个计算机设备的各个部分,通过运行或执行存储在存储器802内的计算机程序和/或模块,以及调用存储在存储器802内的数据,执行计算机设备的各种功能和处理数据,从而对计算机设备进行整体监控。可选的,处理器801可包括一个或多个处理核心;优选的,处理器801可集成应用处理器和调制解调处理器,其中,应用处理器主要处理操作系统、用户界面和应用程序等,调制解调处理器主要处理无线通信。可以理解的是,上述调制解调处理器也可以不集成到处理器801中。
存储器802可用于存储计算机程序以及模块,处理器801通过运行存储在存储器802的计算机程序以及模块,从而执行各种功能应用以及数据处理。存储器802可主要包括存储程序区和存储数据区,其中,存储程序区可存储操作系统、至少一个功能所需的计算机程序(比如声音播放功能、图像播放功能等)等;存储数据区可存储根据计算机设备的使用所创建的数据等。此外,存储器802可以包括高速随机存取存储器,还可以包括非易失性存储器,例如至少一个磁盘存储器件、闪存器件、或其他易失性固态存储器件。相应地,存储器802还可以包括存储器控制器,以提供处理器801对存储器802的访问。
计算机设备还包括给各个部件供电的电源803,优选的,电源803可以通过电源管理系统与处理器801逻辑相连,从而通过电源管理系统实现管理充电、放电、以及功耗管理等功能。电源803还可以包括一个或一个以上的直流或交流电源、再充电系统、电源故障检测电路、电源转换器或者逆变器、电源状态指示器等任意组件。
该计算机设备还可包括输入单元804,该输入单元804可用于接收输入的数字或字符信息,以及产生与用户设置以及功能控制有关的键盘、鼠标、操作杆、光学或者轨迹球信号输入。
尽管未示出,计算机设备还可以包括显示单元等,在此不再赘述。具体在本实施例中,计算机设备中的处理器801会按照如下的指令,将一个或一个以上的计算机程序的进程对应的可执行文件加载到存储器802中,并由处理器801来运行存储在存储器802中的计算机程序,从而实现各种功能,比如:
接收目标服务器发送的目标数字证书,目标数字证书包括认证机构采用认证私钥对目标服务器认证后得到的证书;
将目标数字证书发送至物联网设备,以使物联网设备采用内置的认证公钥对目标数字证书进行校验,并在校验通过时,取得目标数字证书的内容;
接收物联网设备基于对目标数字证书校验通过后返回的第一挑战信息;
将第一挑战信息发送至目标服务器,以使目标服务器基于第一挑战信息生成第一挑战值;
接收目标服务器发送的第一挑战值,并将第一挑战值发送至物联网设备,以基于第一挑战值和目标数字证书的内容确定控制设备上的目标应用程序对物联网设备的控制权限。
以上各个操作的具体实施以及对应的有益效果可参见前面的实施例,在此不作赘述。
本领域普通技术人员可以理解,上述实施例的各种方法中的全部或部分步骤可以通过计算机程序来完成,或通过计算机程序控制相关的硬件来完成,该计算机程序可以存储于一计算机可读存储介质中,并由处理器进行加载和执行。
为此,本申请实施例提供一种计算机可读存储介质,其中存储有计算机程序,该计算机程序能够被处理器进行加载,以执行本申请实施例所提供的任一种权限确定方法中的步骤。
以上各个操作的具体实施以及对应的有益效果可参见前面的实施例,在此不再赘述。
其中,该计算机可读存储介质可以包括:只读存储器(ROM,Read Only Memory)、随机存取记忆体(RAM,Random Access Memory)、磁盘或光盘等。
由于该计算机可读存储介质中所存储的计算机程序,可以执行本申请实施例所提供的任一种权限确定方法中的步骤,因此,可以实现本申请实施例所提供的任一种权限确定方法所能实现的有益效果,详见前面的实施例,在此不再赘述。
其中,根据本申请的一个方面,提供了一种计算机程序产品或计算机程序,该计算机程序产品或计算机程序包括计算机指令,该计算机指令存储在计算机可读存储介质中。计算机设备的处理器从计算机可读存储介质读取该计算机指令,处理器执行该计算机指令,使得该计算机设备执行上述权限确定方法。
以上对本申请实施例所提供的一种权限确定方法、装置、计算机设备和计算机可读存储介质进行了详细介绍,本文中应用了具体个例对本申请的原理及实施方式进行了阐述,以上实施例的说明只是用于帮助理解本申请的方法及其核心思想;同时,对于本领域的技术人员,依据本申请的思想,在具体实施方式及应用范围上均会有改变之处,综上所述,本说明书内容不应理解为对本申请的限制。

Claims (20)

  1. 一种权限确定方法,其中,应用于控制设备,包括:
    接收目标服务器发送的目标数字证书,所述目标数字证书包括认证机构采用认证私钥对所述目标服务器认证后得到的证书;
    将所述目标数字证书发送至物联网设备,以使所述物联网设备采用内置的认证公钥对所述目标数字证书进行校验,并在校验通过时,取得所述目标数字证书的内容;
    接收所述物联网设备基于对所述目标数字证书校验通过后返回的第一挑战信息;
    将所述第一挑战信息发送至所述目标服务器,以使所述目标服务器基于所述第一挑战信息生成第一挑战值;
    接收所述目标服务器发送的所述第一挑战值,并将所述第一挑战值发送至所述物联网设备,以基于所述第一挑战值和所述目标数字证书的内容确定所述控制设备上的目标应用程序对所述物联网设备的控制权限。
  2. 根据权利要求1所述的权限确定方法,其中,所述目标数字证书包括第一数字证书,所述第一数字证书为认证机构采用认证私钥对所述目标服务器的第一公钥认证后得到的证书;
    相应地,所述将所述目标数字证书发送至物联网设备,以使所述物联网设备采用内置的认证公钥对所述目标数字证书进行校验,并在校验通过时,取得所述目标数字证书的内容,包括:
    将所述第一数字证书发送至物联网设备,以使所述物联网设备采用内置的认证公钥对所述第一数字证书进行校验,并在校验通过时,取得所述目标服务器的所述第一公钥;
    所述接收所述物联网设备基于对所述目标数字证书校验通过后返回的第一挑战信息,包括:
    接收所述物联网设备基于对所述第一数字证书校验通过后返回的第一挑战信息;
    所述将所述第一挑战信息发送至所述目标服务器,以使所述目标服务器基于所述第一挑战信息生成第一挑战值,包括:
    将所述第一挑战信息发送至所述目标服务器,以使所述目标服务器采用所述目标服务器的第一私钥对所述第一挑战信息进行签名,得到第一挑战值;
    所述接收所述目标服务器发送的所述第一挑战值,并将所述第一挑战值发送至所述物联网设备,以基于所述第一挑战值和所述目标数字证书的内容确定所述控制设备上的目标应用程序对所述物联网设备的控制权限,包括:
    接收所述目标服务器发送的所述第一挑战值,并将所述第一挑战值发送至所述物联网设备,以使所述物联网设备采用所述第一公钥对所述第一挑战值进行校验,并在校验通过时,将所述目标应用程序标记为具备对所述物联网设备的控制权限的应用程序。
  3. 根据权利要求1所述的权限确定方法,其中,所述将所述目标数字证书发送至物联网设备,包括:
    向所述物联网设备发送证书获取请求;
    接收所述物联网设备基于所述证书获取请求返回的第二数字证书,所述第二数字证书为所述认证机构采用所述认证私钥对所述物联网设备的第二公钥进行签名后得到的证书;
    采用内置的认证公钥对所述第二数字证书进行校验,在校验通过时,取得所述物联网设备的第二公钥;
    生成第二挑战信息,并将所述第二挑战信息发送至所述物联网设备,以使所述物联网设备基于第二挑战信息生成第二挑战值;
    接收所述第二挑战值,并根据所述第二公钥对所述第二挑战值进行校验;
    当校验通过时,将所述目标数字证书发送至所述物联网设备。
  4. 根据权利要求1所述的权限确定方法,其中,所述将所述目标数字证书发送至物联网设备,包括:
    接收所述物联网设备广播的待配网信息;
    根据所述待配网信息与所述物联网设备建立连接;
    基于所述连接将所述目标数字证书发送至物联网设备。
  5. 根据权利要求2所述的权限确定方法,其中,在所述接收所述目标服务器发送的所述第一挑战值,并将所述第一挑战值发送至所述物联网设备,以使所述物联网设备采用所述第一公钥对所述第一挑战值进行校验,并在校验通过时,将所述目标应用程序标记为具备对所述物联网设备的控制权限的应用程序之后,还包括:
    通过所述目标应用程序发送控制指令至所述物联网设备,以使所述物联网设备执行与所述控制指令对应的操作。
  6. 根据权利要求1所述的权限确定方法,其中,所述将所述第一挑战信息发送至所述目标服务器,以使所述目标服务器基于所述第一挑战信息生成第一挑战值,包括:
    根据预设规则生成随机数,并对所述随机数进行加密,得到加密后的随机数;
    将所述加密后的随机数和所述第一挑战信息发送至所述目标服务器,以使所述目标服务器在对所述加密后的随机数的校验通过时,基于所述第一挑战信息生成第一挑战值。
  7. 根据权利要求1所述的权限确定方法,其中,所述将所述第一挑战信息发送至所述目标服务器,以使所述目标服务器基于所述第一挑战信息生成第一挑战值,包括:
    获取令牌;
    将所述令牌和所述第一挑战信息发送至所述目标服务器,以使所述目标服务器将所述令牌与存储的令牌进行比对,若所述令牌与所述存储的令牌相同,则基于所述第一挑战信息生成第一挑战值。
  8. 根据权利要求1所述的权限确定方法,其中,在所述接收所述目标服务器发送的所述第一挑战值,并将所述第一挑战值发送至所述物联网设备,以使所述物联网设备采用所述第一公钥对所述第一挑战值进行校验,并在校验通过时,将所述目标应用程序标记为具备对所述物联网设备的控制权限的应用程序之后,还包括:
    发送所述所述控制设备的控制权限信息至所述物联网设备,以使若所述控制设备上的目标应用程序具备对所述物联网设备的控制权限,所述物联网设备则将所述控制权限信息进行存储;
    通过所述目标应用程序发送控制指令和所述控制权限信息至所述物联网设备,以使若所述控制权限信息与存储的控制权限信息相同,所述物联网设备则执行所述控制指令对应的操作。
  9. 一种权限确定方法,其中,应用于物联网设备,包括:
    接收控制设备发送的目标数字证书,所述目标数字证书为认证机构采用认证私钥对目标服务器认证后得到的证书;
    采用内置的认证公钥对所述目标数字证书进行校验;
    当校验通过时,取得所述目标数字证书的内容,并返回第一挑战信息至所述控制设备,以使所述控制设备将第一挑战信息发送至所述目标服务器,所述第一挑战信息用于指示所述目标服务器生成第一挑战值,并将所述第一挑战值返回至所述控制设备;
    接收所述控制设备发送的所述第一挑战值;
    基于所述第一挑战值和所述目标数字证书的内容确定所述控制设备上的目标应用程序对所述物联网设备的控制权限。
  10. 根据权利要求9所述的权限确定方法,其中,所述基于所述第一挑战值和所述目标数字证书的内容确定所述控制设备上的目标应用程序对所述物联网设备的控制权限,包括:
    采用所述目标数字证书的内容对所述第一挑战值进行校验;
    若对所述第一挑战值的校验通过时得到的第一挑战信息与所述物联网设备发送的第一挑战信息相同,则将所述目标应用程序标记为具备对所述物联网设备的控制权限的应用程序。
  11. 根据权利要求10所述的权限确定方法,其中,在将所述目标应用程序标记为具备对所述物联网设备的控制权限的应用程序之后,还包括:
    获取所述控制设备通过所述目标应用程序发生的控制指令;
    若所述目标应用程序为标记的应用程序,则执行所述控制指令对应的操作。
  12. 根据权利要求9所述的权限确定方法,其中,在基于所述第一挑战值和所述目标数字证书的内容确定所述控制设备上的目标应用程序对所述物联网设备的控制权限之后,包括:
    获取所述控制设备发送的控制权限信息;
    若所述控制设备上的目标应用程序具备对所述物联网设备的控制权限,则将所述控制权限信息进行存储;
    获取所述控制设备通过所述目标应用程序发送的控制指令和所述控制权限信息;
    若所述控制权限信息与存储的控制权限信息相同,则执行所述控制指令对应的操作。
  13. 一种权限确定方法,其中,应用于目标服务器,包括:
    将目标数字证书发送至控制设备,以使得所述控制设备将所述目标数字证书发送至物联网设备,所述目标数字证书用于指示所述物联网设备进行校验,并在校验通过时,取得所述目标数字证书的内容,并返回第一挑战信息至所述控制设备,所述目标数字证书包括认证机构采用认证私钥对所述目标服务器认证后得到的证书;
    接收所述控制设备发送的所述第一挑战信息;
    基于所述第一挑战信息进生成第一挑战值;
    将所述第一挑战值发送至所述控制设备,以使得所述控制设备将所述第一挑战值发送至所述物联网设备,所述第一挑战值和所述目标数字证书的内容用于所述物联网设备确定所述控制设备上的目标应用程序对所述物联网设备的控制权限。
  14. 根据权利要求13所述的权限确定方法,其中,所述接收所述控制设备发送的所述第一挑战信息,基于所述第一挑战信息进生成第一挑战值,包括:
    接收所述控制设备发送的所述第一挑战信息和加密后的随机数;
    对所述加密后的随机数进行解密,得到解密后的随机数;
    若所述解密后的随机数与根据预设规则生成的随机数相同,则基于所述第一挑战信息进生成第一挑战值。
  15. 根据权利要求13所述的权限确定方法,其中,所述目标数字证书包括第一数字证书,在将目标数字证书发送至控制设备之前,还包括:
    将所述目标服务器的第一公钥发送至所述认证机构,以使所述认证机构采用认证私钥对所述第一公钥进行认证,得到第一数字证书;
    接收所述认证机构返回的第一数字证书。
  16. 一种权限确定装置,其中,应用于控制设备,包括:
    第一接收模块,用于接收目标服务器发送的目标数字证书,所述目标数字证书包括认证机构采用认证私钥对所述目标服务器认证后得到的证书;
    第一发送模块,用于将所述目标数字证书发送至物联网设备,以使所述物联网设备采用内置的认证公钥对所述目标数字证书进行校验,并在校验通过时,取得所述目标数字证书的内容;
    第二接收模块,用于接收所述物联网设备基于对所述目标数字证书校验通过后返回的第一挑战信息;
    第二发送模块,用于将所述第一挑战信息发送至所述目标服务器,以使所述目标服务器基于所述第一挑战信息生成第一挑战值;
    第三接收模块,用于接收所述目标服务器发送的所述第一挑战值,并将所述第一挑战值发送至所述物联网设备,以基于所述第一挑战值和所述目标数字证书的内容确定所述控制设备上的目标应用程序对所述物联网设备的控制权限。
  17. 一种权限确定装置,其中,应用于物联网设备,包括:
    第四接收模块,用于接收控制设备发送的目标数字证书,所述目标数字证书为认证机构采用认证私钥对目标服务器认证后得到的证书;
    第一校验模块,用于采用内置的认证公钥对所述目标数字证书进行校验;
    第三发送模块,用于当校验通过时,取得所述目标数字证书的内容,并发送第一挑战信息至所述控制设备,以使所述控制设备将第一挑战信息发送至所述目标服务器,所述第一挑战信息用于指示所述目标服务器生成第一挑战值,并将所述第一挑战值返回至所述控制设备;
    第五接收模块,用于接收所述控制设备发送的第一挑战值;
    确定模块,用于基于所述第一挑战值和所述目标数字证书的内容确定所述控制设备上的目标应用程序对所述物联网设备的控制权限。
  18. 一种权限确定装置,其中,应用于目标服务器,包括:
    第四发送模块,用于将目标数字证书发送至控制设备,以使得所述控制设备将所述目标数字证书发送至物联网设备,所述目标数字证书用于指示所述物联网设备进行校验,并在校验通过时,取得所述目标数字证书的内容,并返回第一挑战信息至所述控制设备,所述目标数字证书包括认证机构采用认证私钥对所述目标服务器认证后得到的证书;
    第六接收模块,用于接收所述控制设备发送的所述第一挑战信息;
    生成模块,用于基于所述第一挑战信息进生成第一挑战值;
    第五发送模块,用于将所述第一挑战值发送至所述控制设备,以使得所述控制设备将所述第一挑战值发送至所述物联网设备,所述第一挑战值和所述目标数字证书的内容用于所述物联网设备确定所述控制设备上的目标应用程序对所述物联网设备的控制权限。
  19. 一种计算机设备,其中,包括处理器和存储器,所述存储器存储有计算机程序,所述处理器用于运行所述存储器内的计算机程序,以执行权利要求1至8任一项所述的权限确定方法、权利要求9-12任一项所述的权限确定方法或权利要求13-15任一项所述的权限确定方法。
  20. 一种计算机可读存储介质,其中,所述计算机可读存储介质存储有计算机程序,所述计算机程序适于处理器进行加载,以执行权利要求1至8任一项所述的权限确定方法、权利要求9-12任一项所述的权限确定方法或权利要求13-15任一项所述的权限确定方法。
PCT/CN2022/130533 2021-12-23 2022-11-08 权限确定方法、装置、计算机设备和计算机可读存储介质 Ceased WO2023116239A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202111590467.2A CN114329534A (zh) 2021-12-23 2021-12-23 权限确定方法、装置、计算机设备和计算机可读存储介质
CN202111590467.2 2021-12-23

Publications (1)

Publication Number Publication Date
WO2023116239A1 true WO2023116239A1 (zh) 2023-06-29

Family

ID=81054967

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2022/130533 Ceased WO2023116239A1 (zh) 2021-12-23 2022-11-08 权限确定方法、装置、计算机设备和计算机可读存储介质

Country Status (2)

Country Link
CN (1) CN114329534A (zh)
WO (1) WO2023116239A1 (zh)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114329534A (zh) * 2021-12-23 2022-04-12 深圳Tcl新技术有限公司 权限确定方法、装置、计算机设备和计算机可读存储介质

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105245552A (zh) * 2015-11-18 2016-01-13 北京京东世纪贸易有限公司 实现安全控制授权的智能设备、终端设备及方法
JP2017175226A (ja) * 2016-03-18 2017-09-28 株式会社インテック 公開鍵証明書を発行するためのプログラム、方法およびシステム
CN108366063A (zh) * 2018-02-11 2018-08-03 广东美的厨房电器制造有限公司 智能设备的数据通信方法、装置及其设备
CN108667780A (zh) * 2017-03-31 2018-10-16 华为技术有限公司 一种身份认证的方法、系统及服务器和终端
CN110690966A (zh) * 2019-11-08 2020-01-14 北京金茂绿建科技有限公司 终端与业务服务器连接的方法、系统、设备及存储介质
CN114329534A (zh) * 2021-12-23 2022-04-12 深圳Tcl新技术有限公司 权限确定方法、装置、计算机设备和计算机可读存储介质

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109600223B (zh) * 2017-09-30 2021-05-14 腾讯科技(深圳)有限公司 验证方法、激活方法、装置、设备及存储介质
CN109831311B (zh) * 2019-03-21 2022-04-01 深圳市网心科技有限公司 一种服务器验证方法、系统、用户终端及可读存储介质
CN114329424A (zh) * 2021-12-23 2022-04-12 深圳Tcl新技术有限公司 权限确定方法、装置、计算机设备和计算机可读存储介质

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105245552A (zh) * 2015-11-18 2016-01-13 北京京东世纪贸易有限公司 实现安全控制授权的智能设备、终端设备及方法
JP2017175226A (ja) * 2016-03-18 2017-09-28 株式会社インテック 公開鍵証明書を発行するためのプログラム、方法およびシステム
CN108667780A (zh) * 2017-03-31 2018-10-16 华为技术有限公司 一种身份认证的方法、系统及服务器和终端
CN108366063A (zh) * 2018-02-11 2018-08-03 广东美的厨房电器制造有限公司 智能设备的数据通信方法、装置及其设备
CN110690966A (zh) * 2019-11-08 2020-01-14 北京金茂绿建科技有限公司 终端与业务服务器连接的方法、系统、设备及存储介质
CN114329534A (zh) * 2021-12-23 2022-04-12 深圳Tcl新技术有限公司 权限确定方法、装置、计算机设备和计算机可读存储介质

Also Published As

Publication number Publication date
CN114329534A (zh) 2022-04-12

Similar Documents

Publication Publication Date Title
US12010248B2 (en) Systems and methods for providing authentication to a plurality of devices
US12095747B2 (en) Cryptographic proxy service
US10911226B2 (en) Application specific certificate management
US9467430B2 (en) Device, method, and system for secure trust anchor provisioning and protection using tamper-resistant hardware
US8918641B2 (en) Dynamic platform reconfiguration by multi-tenant service providers
CN116458117A (zh) 安全数字签名
CN115277168B (zh) 一种访问服务器的方法以及装置、系统
CN110770695A (zh) 物联网(iot)设备管理
US10270757B2 (en) Managing exchanges of sensitive data
KR20140127303A (ko) 다중 팩터 인증 기관
CN106464739B (zh) 用于保护与增强的媒体平台的通信的方法和系统
CN114329424A (zh) 权限确定方法、装置、计算机设备和计算机可读存储介质
WO2023116239A1 (zh) 权限确定方法、装置、计算机设备和计算机可读存储介质
US20260025284A1 (en) Enclave architecture
CN116263817A (zh) 一种数据访问控制方法及相关系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 22909556

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 22909556

Country of ref document: EP

Kind code of ref document: A1