All Products
Search
Document Center

Device Authentication

Last Updated: Jan 26, 2019

There are two ways of device authentication:

  • Unique-certificate-per-device:
    Burning a unique certificate (ProductKey, DeviceName and DeviceSecret) into each device.

  • Unique-certificate-per-product:
    Burning a same certificate (ProductKey, Product Secret) into all of the devices of a product, this method requires less mocifications to production line. Each device needs to have its own unique identifier and pre-upload it to the Alibaba Cloud IoT Platform, the platform will decide if it can accept a connection from a device based on its identifier.

Invoking IOT_Ioctl() to configure the authentication method:

  1. /* Choose Login Method */
  2. int dynamic_register = 1; /* 0: Do not use unique-certificate-per-product, 1: use unique-certificate-per-product */
  3. IOT_Ioctl(IOTX_IOCTL_SET_DYNAMIC_REGISTER, (void *)&dynamic_register);

Implement unique-certificate-per-device authentication

You need to invoke IOT_Ioctl to set the authentication mode:

  1. // for demo only
  2. /* Set the authentication mode */
  3. int dynamic_register = 0;
  4. IOT_Ioctl(IOTX_IOCTL_SET_DYNAMIC_REGISTER, (void *)&dynamic_register);

Implement unique-certificate-per-product authentication

unique-certificate-per-product just means the content (ProductKey, ProductSecret) burned into the devices of a product are same, it will use a process called dynamic-registration to obtain the DeviceSecret from IoT platform by using the unique identifier of a device, the unique identifier of the device can be its SN, MAC address, and this unique identifier will be treated as DeviceName.

After SDK obtains a device’s DeviceSecret from IoT platform, it will invoke HAL_SetDeviceSecret() to save the DeviceSecret, the device must keep this value in the Flash. DeviceSecret can’t be erased after a device got it through the dynamic-registation process, because the IoT platform will refuse to provide the DeviceSeret if the device has got its DeviceSecret.

If you want to use unique-certificate-per-product, simply call the following interfaces to enable the dynamic registration function.

  1. /* Turn on the dynamic registration function */
  2. int dynamic_register = 1; /* 1: Use unique-certificate-per-product */
  3. IOT_Ioctl(IOTX_IOCTL_SET_DYNAMIC_REGISTER, (void *)&dynamic_register);

Example of unique-certificate-per-product authentication for Basic-Edition products

Visit Alibaba Clout IoT Platform, select the product and enable “Dynamic-Registration”:

basic-dyn-reg

Now create a new device under this product:

addDev

Open the Link Kit SDK, replace code like this:

  1. #include "iot_import.h"
  2. #include "iot_export.h"
  3. #include "app_entry.h"
  4. // To replace the values of PRODUCT_KEY, PRODUCT_SECRET, DEVICE_NAME
  5. #define PRODUCT_KEY "a1MZxOdcBnO"
  6. #define PRODUCT_SECRET "h4I4dneEFp7EImTv"
  7. #define DEVICE_NAME "Example_dyn1"
  8. //And comment the DEVICE_SECRET
  9. //#define DEVICE_SECRET "t9GmMf2jb3LgWfXBaZD2r3aJrfVWBv56"
  10. ...
  11. ...
  12. int main(int argc, char **argv)
  13. {
  14. IOT_OpenLog("mqtt");
  15. IOT_SetLogLevel(IOT_LOG_DEBUG);
  16. user_argc = argc;
  17. user_argv = argv;
  18. HAL_SetProductKey(PRODUCT_KEY);
  19. HAL_SetProductSecret(PRODUCT_SECRET);
  20. HAL_SetDeviceName(DEVICE_NAME);
  21. // Comment the setting to DeviceSecret, because we will get it from the IoT platform dynamically
  22. /* HAL_SetDeviceSecret(DEVICE_SECRET); */
  23. /* Choose Login Server */
  24. int domain_type = IOTX_CLOUD_DOMAIN_SH;
  25. IOT_Ioctl(IOTX_IOCTL_SET_DOMAIN, (void *)&domain_type);
  26. /* Enable Dynamic registration */
  27. int dynamic_register = 1;
  28. IOT_Ioctl(IOTX_IOCTL_SET_DYNAMIC_REGISTER, (void *)&dynamic_register);
  29. mqtt_client();
  30. IOT_DumpMemoryStats(IOT_LOG_DEBUG);
  31. IOT_CloseLog();
  32. EXAMPLE_TRACE("out of sample!") ;
  33. return 0;
  34. }

After you compile the code, execute the sample program, the output will be like:

  1. $./output/release/bin/mqtt-example
  2. [inf] IOT_SetupConnInfo(114): DeviceSecret KV does not exist, Now We Need Dynamic Register...
  3. [inf] _calc_dynreg_sign(61): Random Key: 7y4Jg5xdKCy9W2i
  4. [inf] _calc_dynreg_sign(75): Sign: d3b560d5be0c9c19749470e85d912b65685fa4b20edcbd179ccfe98fcca23d5e
  5. [inf] httpclient_common(794): host: 'iot-auth.cn-shanghai.aliyuncs.com', port: 443
  6. ...
  7. ...
  8. ...
  9. [inf] _fetch_dynreg_http_resp(110): Http Response Payload: {"code":200,"data":{"deviceName":"Example_dyn1","deviceSecret":"KGQQFFlGinIipW9Xn7xQ5U6d6MokPZD4","productKey":"a1ExpAkj9Hi"},"message":"success"}
  10. [inf] _fetch_dynreg_http_resp(127): Dynamic Register Code: 200
  11. [inf] _fetch_dynreg_http_resp(148): Dynamic Register Device Secret: KGQQFFlGinIipW9Xn7xQ5U6d6MokPZD4
  12. [inf] iotx_device_info_init(39): device_info created successfully!
  13. ...
  14. [dbg] iotx_device_info_set(49): start to set device info!
  15. [dbg] iotx_device_info_set(63): device_info set successfully!
  16. [inf] guider_print_dev_guider_info(279): ....................................................
  17. [inf] guider_print_dev_guider_info(280): ProductKey : a1ExpAkj9Hi
  18. [inf] guider_print_dev_guider_info(281): DeviceName : Example_dyn1
  19. [inf] guider_print_dev_guider_info(282): DeviceID : a1ExpAkj9Hi.Example_dyn1
  20. [inf] guider_print_dev_guider_info(284): ....................................................
  21. [inf] guider_print_dev_guider_info(285): PartnerID Buf : ,partner_id=example.demo.partner-id
  22. [inf] guider_print_dev_guider_info(286): ModuleID Buf : ,module_id=example.demo.module-id
  23. [inf] guider_print_dev_guider_info(287): Guider URL :
  24. [inf] guider_print_dev_guider_info(289): Guider SecMode : 2 (TLS + Direct)
  25. [inf] guider_print_dev_guider_info(291): Guider Timestamp : 2524608000000
  26. [inf] guider_print_dev_guider_info(292): ....................................................
  27. [inf] guider_print_dev_guider_info(298): ....................................................
  28. [inf] guider_print_conn_info(256): -----------------------------------------
  29. ...
  30. ...
  31. [inf] iotx_mc_connect(2502): mqtt connect success!

The preceding execution output indicates that the device has acquired the DeviceSecret using dynamic-registration.

  1. (Device Secret): "KGQQFFlGinIipW9Xn7xQ5U6d6MokPZD4"

The SDK automatically calls HAL_Kv_Set to make it persistent, and SDK will get it from the Flash for the next time when the device connectes to the IoT Platform. If the user attempts to use the unique-certificate-per-product function on the same device for a second time, the cloud will return the following error:

  1. [inf] _fetch_dynreg_http_resp(110): Http Response Payload: {"code":6289,"message":"device is already active"}

Support the Alibaba Cloud Link Platform for Smart Living

When networking is activated for overseas devices on the Alibaba Cloud Link Platform for Smart Living, they will be uniformly connected to the activation center in Singapore. The platform will automatically assign the devices to the nearest data nodes. For example, devices activated in the United States will automatically connect to the servers in the United States.

The SDK can support the Alibaba Cloud Link Platform for Smart Living mode by performing the following two configurations:

  1. Change the FEATURE_MQTT_DIRECT of make.setting to n, which enables the https authentication mode
  2. Configure the Singapore site as the connection site:
  1. /* Choose Login Server */
  2. int domain_type = IOTX_CLOUD_REGION_SINGAPORE;
  3. IOT_Ioctl(IOTX_IOCTL_SET_REGION, (void *)&domain_type);