IP Library Granted Patent US 12,488,084
Granted Patent B2
US 12,488,084 · App. 18/280,213 · Granted Dec 2, 2025

Device authentication method and system, IoT device and authentication server

Inventor: Haitao Zheng (Beijing, CN)
Assignee: Beijing BOE Technology Development Co., Ltd.
G06F21/44
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,488,084
App. No.
18/280,213
Granted
Dec 2, 2025
Kind
B2
Abstract

The present disclosure relates to a device authentication method and system, an IoT device, and an authentication server. The method includes: obtaining random data; obtaining public input parameters including the random data, and generating an authentication proof based on a preset proof parameter and the public input parameters; sending the authentication proof to an authentication server, such that the authentication server verifies the authentication proof based on a preset verification parameter to obtain an authentication result; obtaining the authentication result returned by the authentication server. This embodiment can use authentication proof without the need to use device key information for authentication, improving authentication security. Moreover, the authentication server is unable to restore device key information based on the authentication proof, further avoiding leakage of the device key information and improving information security.

Claims (21)

1 . A device authentication method, applied to an Internet of Things IoT device, and the method comprising:

obtaining random data;

obtaining public input parameters comprising the random data, and generating an authentication proof based on a preset proof parameter and the public input parameters;

sending the authentication proof to an authentication server, such that the authentication server verifies the authentication proof based on a preset verification parameter to obtain an authentication result;

obtaining the authentication result returned by the authentication server.

2 . The method according to claim 1 , wherein obtaining random data comprises:

generating first random data and sending the first random data to the authentication server such that the authentication server encrypts the first random data through a preset encryption algorithm to generate encrypted data, and sending the encrypted data to the IoT device;

obtaining the encrypted data and decrypting the encrypted data through a preset decryption algorithm to obtain second random data;

when the second random data is consistent with the first random data, taking the second random data as the obtained random data; otherwise, determining that no random data has been received.

3 . The method according to claim 1 , wherein obtaining public input parameters including the random data, and generating an authentication proof based on a preset proof parameter and the public input parameters comprises:

obtaining a device number and a device certificate of the IoT device;

taking the device number, the device certificate and the random data as the public input parameters, and inputting the public input parameters into a preset zero-knowledge proof circuit to obtain a solution vector of the zero-knowledge proof circuit;

inputting the solution vector and the proof parameter into a preset zero-knowledge proof algorithm to obtain an authentication proof output by the zero-knowledge proof algorithm.

4 . The method according to claim 1 , wherein the method further comprises a step of obtaining the preset proof parameter, comprising:

sending to a build server a build request comprising device key information, such that the build server generates a device certificate and a proof parameter corresponding to the device certificate based on the device key information; the device key information comprising a device number, a key, and a device type;

obtaining the proof parameter sent by the build server to obtain the preset proof parameter.

5 . An Internet of Things IoT device comprising:

a processor;

a memory for storing computer programs executable by the processor;

wherein the processor is configured to execute computer programs in the memory to implement the method according to claim 1 .

6 . A non-transitory computer-readable storage medium, wherein when an executable computer program in the storage medium is executed by a processor, the method according to claim 1 can be implemented.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 11, 2025
From: BOE TECHNOLOGY GROUP CO., LTD.
To: BEIJING BOE TECHNOLOGY DEVELOPMENT CO., LTD.
Reel/Frame 072855/0052 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 2, 2023
From: ZHENG, HAITAO
To: BOE TECHNOLOGY GROUP CO., LTD.
Reel/Frame 064781/0643 →
Priority Claims (1)
CN 202111387516.2 · Nov 22, 2021 · national
Continuity (1)
Related Publication 20240143727A1 · May 2, 2024
References Cited (20)
US 20080178008A1 · Takahashi et al. · 2008 [cited by applicant]
US 20160269374A1 · Smith · 2016 [cited by applicant]
US 20190156019A1 · Chen · 2019 [cited by applicant]
US 20210152545A1 · Park · 2021 [cited by examiner]
US 20210297255A1 · Wan et al. · 2021 [cited by applicant]
US 20220393884A1 · Panchamia · 2022 [cited by examiner]
CN 109614820A · 2019 [cited by applicant]
CN 110071906A · 2019 [cited by applicant]
CN 110324151A · 2019 [cited by applicant]
CN 111211908A · 2020 [cited by applicant]
CN 112260995A · 2021 [cited by applicant]
CN 112436940A · 2021 [cited by applicant]
CN 112565265A · 2021 [cited by applicant]
CN 113890768A · 2022 [cited by applicant]
EP 4027675B1 · 2025 [cited by examiner]
KR 20080031622A · 2008 [cited by applicant]
KR 20140052605A · 2014 [cited by applicant]
CN2021113875162 first office action. [cited by applicant]
PCT/CN2022/120073 international search report. [cited by applicant]
PCT/CN2022/120073 Written Opinion. [cited by applicant]