IP Library Granted Patent US 11,392,685
Granted Patent B2
US 11,392,685 · App. 17/368,382 · Granted Jul 19, 2022

Device authentication method and apparatus

Inventors: Jianfen Peng (Shenzhen, CN); Zhipeng Guo (Shenzhen, CN)
Assignee: HUAWEI TECHNOLOGIES CO., LTD.
G06F21/44H04W12/069G06F2221/2129
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,392,685
App. No.
17/368,382
Granted
Jul 19, 2022
Kind
B2
Abstract

This application relates to an apparatus and a non-transitory computer readable medium applying to the internet of vehicles. Embodiments of this application implement a distributed authentication process, which including sending information used to indicate a to-be-authenticated device to the to-be-authenticated device. Compared with a centralized authentication mechanism, the authentication manner in the embodiments of this application reduces load of a device because one intermediate node does not need to perform authentication on a plurality of nodes. If the to-be-authenticated device fails to be authenticated, because the authentication is an authentication process related to a first service, the determined execution policy is an execution policy related to the first service, and the determined execution policy better meets a service requirement.

Claims (56)

1. A device authentication method, comprising:

receiving, by a second device, first information for requesting an authentication of a first service for a first device, wherein the first information includes an identity of the first service and the identity of the first service indicates the second device;

performing, by the second device, in response to the first information, the authentication on the first device having a function related to the first service;

determining, by the second device when the authentication fails, a first execution policy based on the first service, wherein the first execution policy comprises stopping using the function, or using the function and generating an alert; and

executing, by the second device, the first execution policy, or indicating, by the second device, the first execution policy to the first device for the first device to execute the first execution policy;

wherein the performing the authentication on the first device, comprises:

receiving, information of a first certificate from the first device, wherein the first certificate is a device certificate of the first device;

verifying, based on another certificate of the first device, whether the first certificate is correct;

generating, the first random number when the first certificate is correct;

sending, the first random number to the first device; and

receiving, from the first device, the first signature that is generated based on the first random number;

performing, the authentication on the first device based on the first signature, the first random number, and an identifier of the first device.

2. The method according to claim 1 , wherein the information of the first certificate does not comprise subject attribute information of the first certificate.

3. The method according to claim 1 , wherein the information of the first certificate comprises one or any combination of the following information:

version information of the first certificate;

signer information of the first certificate;

subject information of the first certificate;

validity information of the first certificate; or

signature information of the first certificate.

4. A communications apparatus, comprising:

a processor; and

a memory, wherein the memory is configured to store program instructions, and the processor coupled to the memory is configured to execute the instructions to:

receive, first information for requesting an authentication of a first service for a first device, wherein the first information includes an identity of the first service and the identity of the first service indicates a second device;

perform, in response to the first information, the authentication on the first device having a function related to the first service;

determine, when the authentication fails, a first execution policy based on the first service, wherein the first execution policy comprises stopping using the function, or using the function and generating an alert; and

execute, the first execution policy, or indicate, the first execution policy to the first device for the first device to execute the first execution policy;

wherein the perform the authentication on the first device, comprises:

receive, information of a first certificate from the first device, wherein the first certificate is a device certificate of the first device;

verify, based on another certificate of the first device, whether the first certificate is correct;

generate, the first random number when the first certificate is correct;

send, the first random number to the first device; and

receive, from the first device, the first signature that is generated based on the first random number;

perform, the authentication on the first device based on the first signature, the first random number, and an identifier of the first device.

5. The apparatus according to claim 4 , wherein the processor is further configured to execute the instructions to:

receive, from the first device, the identifier of the first device.

6. The apparatus according to claim 4 , wherein the information of the first certificate does not comprise subject attribute information of the first certificate.

7. The apparatus according to claim 4 , wherein the information of the first certificate comprises one or any combination of the following information:

version information of the first certificate;

signer information of the first certificate;

subject information of the first certificate;

validity information of the first certificate; or

signature information of the first certificate.

8. A communications system, comprising:

a first device; and

a second device communicating with the first device, wherein the second device is configured to

receive, first information for requesting an authentication of a first service for the first device, wherein the first information includes an identity of the first service and the identity of the first service indicates the second device;

perform, in response to the first information, the authentication on the first device having a function related to the first service;

determine, when the authentication fails, a first execution policy based on the first service, wherein the first execution policy comprises stopping using the function, or using the function and generating an alert; and

executing, the first execution policy, or indicating, by the second device, the first execution policy to the first device for the first device to execute the first execution policy;

wherein the perform the authentication on the first device, comprises:

receive, information of a first certificate from the first device, wherein the first certificate is a device certificate of the first device;

verify, based on another certificate of the first device, whether the first certificate is correct;

generate, the first random number when the first certificate is correct;

send, the first random number to the first device; and

receive, from the first device, the first signature that is generated based on the first random number;

perform, the authentication on the first device based on the first signature, the first random number, and an identifier of the first device.

Assignments (3)
CHANGE OF NAME Recorded May 1, 2026
From: SHENZHEN YINWANG INTELLIGENT TECHNOLOGIES CO., LTD.
To: YINWANG INTELLIGENT TECHNOLOGIES CO., LTD.
Reel/Frame 075316/0074 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 12, 2024
From: HUAWEI TECHNOLOGIES CO., LTD.
To: SHENZHEN YINWANG INTELLIGENT TECHNOLOGIES CO., LTD.
Reel/Frame 069335/0922 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2021
From: PENG, JIANFEN; GUO, ZHIPENG
To: HUAWEI TECHNOLOGIES CO., LTD.
Reel/Frame 057468/0190 →
Priority Claims (1)
CN 201910886787.9 · Sep 19, 2019 · national
Continuity (2)
Continuation PCTCN2020092176 · May 25, 2020
Related Publication 20210334353A1 · Oct 28, 2021
Cited By (1)
US 12,372,638