Authentication patterns for China-made IoT devices
Most Chinese surveillance/IoT devices share a small set of auth models. Knowing them saves hours of trial-and-error.
1. HTTP Digest (most common)
Hikvision ISAPI and Dahua CGI both use Digest auth over HTTP/HTTPS. The client sends an empty request, receives a 401 with a WWW-Authenticate challenge (nonce, realm), then re-sends with a hashed response.
# curl handles the handshake for you
curl --digest -u admin:PASSWORD "http://192.168.1.64/ISAPI/System/deviceInfo"
2. Session token
Dahua's CGI often requires a session: call global.login to obtain a token, then append session=<token> to later requests. SDKs manage this internally.
3. SDK binary protocol
The Hikvision Device Network SDK (port 8000) and Dahua NetSDK (port 37777) use a proprietary TCP protocol behind a login call — no HTTP Digest involved.
4. ONVIF
For cross-vendor clients, ONVIF (WS-Security with a derived key) is the portable option. Both vendors support ONVIF profiles S/G.
Always activate the device and set a strong
adminpassword first — integration is blocked until activation.