快速入门:使用适用于 Azure IoT 中心设备预配服务的 Java 设备 SDK 创建和预配模拟的 TPM 设备Quickstart: Create and provision a simulated TPM device using Java device SDK for Azure IoT Hub Device Provisioning Service

在本快速入门中,我们在 Windows 计算机上创建一台模拟 IoT 设备。In this quickstart, you create a simulated IoT device on a Windows computer. 此模拟设备包含用作硬件安全模块 (HSM) 的 TPM 模拟器。The simulated device includes a TPM simulator as a Hardware Security Module (HSM). 我们使用设备预配服务 (DPS) 的单个注册,通过设备示例 Java 代码将此模拟设备连接到 IoT 中心。You use device sample Java code to connect this simulated device with your IoT hub using an individual enrollment with the Device Provisioning Service (DPS).

先决条件Prerequisites

备注

初始的设备孪生状态配置仅在 IoT 中心的标准层中提供。The initial device twin state configuration is available only in the standard tier of IoT Hub. 有关基本和标准 IoT 中心层的详细信息,请参阅如何选择合适的 IoT 中心层For more information about the basic and standard IoT Hub tiers, see How to choose the right IoT Hub tier.

准备环境Prepare the environment

  1. 确保已在计算机上安装 Java SE 开发工具包 8Make sure you have Java SE Development Kit 8 installed on your machine.

  2. 下载并安装 MavenDownload and install Maven.

  3. 确保在计算机上安装 git 并将其添加到可供命令窗口访问的环境变量。Make sure git is installed on your machine and is added to the environment variables accessible to the command window. 请参阅软件自由保护组织提供的 Git 客户端工具,了解要安装的最新版 git 工具,其中包括 Git Bash,这是一个命令行应用,可以用来与本地 Git 存储库交互。See Software Freedom Conservancy's Git client tools for the latest version of git tools to install, which includes the Git Bash, the command-line app that you can use to interact with your local Git repository.

  4. 打开命令提示符。Open a command prompt. 为设备模拟代码示例克隆 GitHub 存储库。Clone the GitHub repo for device simulation code sample.

    git clone https://github.com/Azure/azure-iot-sdk-java.git --recursive
    
  5. 运行 TPM 模拟器作为模拟设备的 HSMRun the TPM simulator to be the HSM for the simulated device. 单击“允许访问”,以便更改“Windows 防火墙”设置。 Click Allow access to allow changes to Windows Firewall settings. 该模拟器通过套接字在端口 2321 和 2322 上进行侦听。It listens over a socket on ports 2321 and 2322. 请勿关闭此窗口;本快速入门指南自始至终都需让该模拟器保持运行状态。Do not close this window; you need to keep this simulator running until the end of this quickstart guide.

    .\azure-iot-sdk-java\provisioning\provisioning-tools\tpm-simulator\Simulator.exe
    

    TPM 模拟器

  6. 在单独的命令提示符处导航到根文件夹,然后生成示例依赖项。In a separate command prompt, navigate to the root folder and build the sample dependencies.

    cd azure-iot-sdk-java
    mvn install -DskipTests=true
    
  7. 导航到示例文件夹。Navigate to the sample folder.

    cd provisioning/provisioning-samples/provisioning-tpm-sample
    
  8. 登录到 Azure 门户,选择左侧菜单上的“所有资源”按钮,打开设备预配服务 。Sign in to the Azure portal, select the All resources button on the left-hand menu and open your Device Provisioning service. 记下“ID 范围”和“预配服务全局终结点”。 Note your ID Scope and Provisioning Service Global Endpoint.

    设备预配服务信息

  9. 编辑 src/main/java/samples/com/microsoft/azure/sdk/iot/ProvisioningTpmSample.java,使之包括“ID 范围”和“预配服务全局终结点”,如前所述。 Edit src/main/java/samples/com/microsoft/azure/sdk/iot/ProvisioningTpmSample.java to include your ID Scope and Provisioning Service Global Endpoint as noted before.

    private static final String idScope = "[Your ID scope here]";
    private static final String globalEndpoint = "[Your Provisioning Service Global Endpoint here]";
    private static final ProvisioningDeviceClientTransportProtocol PROVISIONING_DEVICE_CLIENT_TRANSPORT_PROTOCOL = ProvisioningDeviceClientTransportProtocol.HTTPS;
    

    保存文件。Save the file.

  10. 使用以下命令生成项目,导航到目标文件夹,然后执行创建的 .jar 文件。Use the following commands to build the project, navigate to the target folder, and execute the created .jar file. version 占位符替换为你的 Java 版本的占位符。Replace the version placeholder with your version of Java.

    mvn clean install
    cd target
    java -jar ./provisioning-tpm-sample-{version}-with-deps.jar
    
  11. 程序开始运行。The program begins running. 记下用于下一部分的“认可密钥”和“注册 ID”,让程序保持运行 。Note the Endorsement key and Registration ID for the next section and leave the program running.

    Java TPM 设备程序

创建设备注册项Create a device enrollment entry

Azure IoT 设备预配服务支持两类注册:The Azure IoT Device Provisioning Service supports two types of enrollments:

本文演示单个注册。This article demonstrates individual enrollments.

  1. 登录到 Azure 门户,选择左侧菜单上的“所有资源”按钮,打开设备预配服务 。Sign in to the Azure portal, select the All resources button on the left-hand menu and open your Device Provisioning service.

  2. 在“设备预配服务”菜单中,选择“管理注册” 。From the Device Provisioning Service menu, select Manage enrollments. 选择“个人注册”选项卡,然后选择顶部的“添加个人注册”按钮 。Select Individual Enrollments tab and select the Add individual enrollment button at the top.

  3. 在“添加注册”面板中,输入以下信息 :In the Add Enrollment panel, enter the following information:

    • 选择“TPM” 作为标识证明机制Select TPM as the identity attestation Mechanism.

    • 使用你之前记下的值输入 TPM 设备的“注册 ID”和“认可密钥” 。Enter the Registration ID and Endorsement key for your TPM device from the values you noted previously.

    • 选择与预配服务链接的 IoT 中心。Select an IoT hub linked with your provisioning service.

    • (可选)可以提供以下信息:Optionally, you may provide the following information:

      • 输入唯一“设备 ID” 。Enter a unique Device ID. 为设备命名时,请确保避免使用敏感数据。Make sure to avoid sensitive data while naming your device. 如果选择不提供此项,则系统将改用注册 ID 来标识设备。If you choose not to provide one, the registration ID will be used to identify the device instead.
      • 使用设备所需的初始配置更新“初始设备孪生状态” 。Update the Initial device twin state with the desired initial configuration for the device.
    • 完成后,按“保存”按钮 。Once complete, press the Save button.

      在门户边栏选项卡中输入设备注册信息

    成功注册以后,设备的“注册 ID”显示在“单个注册”选项卡下的列表中。 On successful enrollment, the Registration ID of your device appears in the list under the Individual Enrollments tab.

模拟设备Simulate the device

  1. 在计算机上运行 Java 示例代码的命令窗口中按 Enter,继续运行应用程序 。On the command window running the Java sample code on your machine, press Enter to continue running the application. 请注意相关消息,这些消息模拟设备启动后连接到设备预配服务以获取 IoT 中心信息的情况。Notice the messages that simulate the device booting and connecting to the Device Provisioning Service to get your IoT hub information.

    最终的 Java TPM 设备程序

  2. 将模拟设备成功预配到与预配服务链接的 IoT 中心以后,设备 ID 会显示在该中心的“IoT 设备”边栏选项卡上 。On successful provisioning of your simulated device to the IoT hub linked with your provisioning service, the device ID appears on the hub's IoT devices blade.

    设备注册到 IoT 中心

    如果从设备的注册项中的默认值更改了“初始设备孪生状态” ,则它会从中心拉取所需的孪生状态,并执行相应的操作。If you changed the initial device twin state from the default value in the enrollment entry for your device, it can pull the desired twin state from the hub and act accordingly. 有关详细信息,请参阅了解并在 IoT 中心内使用设备孪生For more information, see Understand and use device twins in IoT Hub.

清理资源Clean up resources

如果打算继续使用和探索设备客户端示例,请勿清理在本快速入门中创建的资源。If you plan to continue working on and exploring the device client sample, do not clean up the resources created in this quickstart. 如果不打算继续学习,请按以下步骤删除本快速入门中创建的所有资源。If you do not plan to continue, use the following steps to delete all resources created by this quickstart.

  1. 关闭计算机上的设备客户端示例输出窗口。Close the device client sample output window on your machine.
  2. 关闭计算机上的 TPM 模拟器窗口。Close the TPM simulator window on your machine.
  3. 在 Azure 门户的左侧菜单中选择“所有资源”,然后选择设备预配服务 。From the left-hand menu in the Azure portal, select All resources and then select your Device Provisioning service. 打开服务的“管理注册”边栏选项卡,然后选择“单个注册”选项卡 。选中在本快速入门中注册的设备的“注册 ID”旁边的复选框,然后按窗格顶部的“删除”按钮 。Open the Manage Enrollments blade for your service, and then select the Individual Enrollments tab. Select the check box next to the REGISTRATION ID of the device you enrolled in this quickstart, and press the Delete button at the top of the pane.
  4. 在 Azure 门户的左侧菜单中选择“所有资源”,然后选择 IoT 中心 。From the left-hand menu in the Azure portal, select All resources and then select your IoT hub. 打开中心的“IoT 设备”边栏选项卡,选中在本快速入门中注册的设备的“设备 ID”旁边的复选框,然后按窗格顶部的“删除”按钮 。Open the IoT devices blade for your hub, select the check box next to the DEVICE ID of the device you registered in this quickstart, and then press the Delete button at the top of the pane.

后续步骤Next steps

在本快速入门中,你已在计算机上创建 TPM 模拟设备,并已使用 IoT 中心设备预配服务将其预配到 IoT 中心。In this quickstart, you’ve created a TPM simulated device on your machine and provisioned it to your IoT hub using the IoT Hub Device Provisioning Service. 若要了解如何以编程方式注册 TPM 设备,请继续阅读快速入门中关于 TPM 设备的编程注册内容。To learn how to enroll your TPM device programmatically, continue to the quickstart for programmatic enrollment of a TPM device.