Authentication patterns for China-made IoT devices

Most Chinese surveillance/IoT devices share a small set of auth models. Knowing them saves hours of trial-and-error.

1. HTTP Digest (most common)

Hikvision ISAPI and Dahua CGI both use Digest auth over HTTP/HTTPS. The client sends an empty request, receives a 401 with a WWW-Authenticate challenge (nonce, realm), then re-sends with a hashed response.

# curl handles the handshake for you
curl --digest -u admin:PASSWORD "http://192.168.1.64/ISAPI/System/deviceInfo"

2. Session token

Dahua's CGI often requires a session: call global.login to obtain a token, then append session=<token> to later requests. SDKs manage this internally.

3. SDK binary protocol

The Hikvision Device Network SDK (port 8000) and Dahua NetSDK (port 37777) use a proprietary TCP protocol behind a login call — no HTTP Digest involved.

4. ONVIF

For cross-vendor clients, ONVIF (WS-Security with a derived key) is the portable option. Both vendors support ONVIF profiles S/G.

Always activate the device and set a strong admin password first — integration is blocked until activation.