Iot device control method and apparatus
Patent Information
- Application Number
- CN202210253751.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-15
- Publication Date
- 2026-09-04
- Estimated Expiration
- 2042-03-15
AI Technical Summary
[0003]假如平台A提供给平台B的平台级认证凭据泄露,则会使厂商B从厂商A购买的所有设备都被恶意攻击的风险,无法最小化泄露带来的物联网设备安全风险
[0036] The IoT device control method according to embodiments of the present invention, by combining OAuth 2.0 and on-device operation confirmation mechanisms, solves the cumbersome authorization process required by users when using cross-platform IoT devices, while also addressing manufacturers' needs for independent user systems and personalized interactive experiences, and ensuring the security of cross-platform IoT device control. Furthermore, by obtaining data from all devices registered on the second cloud platform at once using an access token, and selecting the target device to be controlled from the device list, it avoids repeatedly fetching device data, thereby reducing communication costs and interaction time.
Smart Images

Figure CN116800803B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of mobile communication technology, and more particularly to a method and apparatus for controlling Internet of Things (IoT) devices. Background Technology
[0002] Currently, if manufacturer A sells IoT devices to manufacturer B, and manufacturer A's platform A needs to authorize the IoT devices connected to platform A to manufacturer B's platform B, the following solution is typically used: manufacturer A pre-registers the devices sold to manufacturer B on platform A, and then manufacturer B's platform B directly controls them. The main disadvantages are:
[0003] If the platform-level authentication credentials provided by platform A to platform B are leaked, all devices purchased by manufacturer B from manufacturer A will be at risk of being maliciously attacked, and the security risks of IoT devices caused by the leak cannot be minimized. Summary of the Invention
[0004] This invention aims to at least solve one of the technical problems existing in the prior art. To this end, this invention proposes an IoT device control method. According to an embodiment of this invention, the IoT device control method generates device operation credentials only after a user performs a corresponding operation on the device. The device can only be controlled based on these operation credentials, meaning the operation credentials prove that the user initiating the operation is present at the device. This determines that malicious attacks and the initiation of control over a large number of devices require the attacker to be physically present at the device, increasing the difficulty of attacks and improving the security of cross-platform control of IoT devices.
[0005] This invention also proposes a method for controlling Internet of Things (IoT) devices.
[0006] An Internet of Things (IoT) device control method according to a first aspect of the present invention includes:
[0007] The first cloud platform receives information from the second cloud platform indicating that the target device has entered the target state; the information is used to instruct a specified operation to be performed on the target device.
[0008] The first cloud platform receives the operation credentials of the target device generated by the second cloud platform; the operation credentials are generated when the second cloud platform confirms that the specified operation has been completed.
[0009] The first cloud platform sends a control command to the second cloud platform to control the target device based on the access token and the operation credentials;
[0010] The target device is a device registered on the second cloud platform;
[0011] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0012] According to the IoT device control method of the present invention, the device operation credentials are generated only after the user performs the corresponding operation on the device. The device can only be controlled based on the operation credentials. That is, the operation credentials can prove that the user who initiated the operation is next to the device. This means that to maliciously attack and initiate the control of a large number of devices, the attacker needs to come to the device to operate, which increases the difficulty of the attack and improves the security of cross-platform control of IoT devices.
[0013] According to an embodiment of the present invention, before the first cloud platform receives information from the second cloud platform that the target device has entered the target state, the method further includes:
[0014] The first cloud platform sends a control request to the second cloud platform;
[0015] The control request is used to instruct the second cloud platform to control the target device to enter the target state.
[0016] According to the IoT device control method of the present invention, a control request is sent from a first cloud platform to a second cloud platform. After receiving the control request, the second cloud platform controls the target device to enter a verifiable target state, thereby ensuring the security of cross-platform device control.
[0017] According to one embodiment of the present invention, before the first cloud platform sends a control request to the second cloud platform, the method further includes:
[0018] The first cloud platform initiates an OAuth2.0 request to the second cloud platform; the OAuth2.0 request is used by the second cloud platform to generate the access token and send it to the first cloud platform.
[0019] The first cloud platform receives the access token sent by the second cloud platform;
[0020] The first cloud platform obtains the list of devices associated with the second cloud platform based on the access token and the acquisition request, and determines the target device based on the device list.
[0021] The IoT device control method according to embodiments of the present invention, by combining OAuth 2.0 and on-device operation confirmation mechanisms, solves the cumbersome authorization process required by users when using cross-platform IoT devices, while also addressing manufacturers' needs for independent user systems and personalized interactive experiences, and ensuring the security of cross-platform IoT device control. Furthermore, by obtaining data from all devices registered on the second cloud platform at once using an access token, and selecting the target device to be controlled from the device list, it avoids repeatedly fetching device data, thereby reducing communication costs and interaction time.
[0022] An Internet of Things (IoT) device control method according to a second aspect of the present invention includes:
[0023] The second cloud platform sends information about the target device entering the target state to the first cloud platform; the information is used to instruct the target device to perform a specified operation.
[0024] The second cloud platform confirms the completion of the specified operation, generates the operation credentials for the target device, and sends them to the first cloud platform;
[0025] The second cloud platform receives control instructions sent by the first cloud platform based on the access token and the operation credentials, and controls the target device according to the control instructions;
[0026] The target device is a device registered on the second cloud platform;
[0027] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0028] According to the IoT device control method of the present invention, the device operation credentials are generated only after the user performs the corresponding operation on the device. The device can only be controlled based on the operation credentials. That is, the operation credentials can prove that the user who initiated the operation is next to the device. This means that to maliciously attack and initiate the control of a large number of devices, the attacker needs to come to the device to operate, which increases the difficulty of the attack and improves the security of cross-platform control of IoT devices.
[0029] According to one embodiment of the present invention, before the second cloud platform sends the information that the target device has entered the target state to the first cloud platform, the method further includes:
[0030] The second cloud platform receives the control request sent by the first cloud platform and controls the target device to enter the target state according to the control request.
[0031] According to the IoT device control method of the present invention, after receiving a control request sent by a first cloud platform through a second cloud platform, the target device is controlled to enter a verifiable target state, thereby ensuring the security of cross-platform device control.
[0032] According to an embodiment of the present invention, before the second cloud platform receives the control request sent by the first cloud platform, the process includes:
[0033] The second cloud platform receives the OAuth 2.0 request sent by the first cloud platform;
[0034] The second cloud platform generates an access token based on the OAuth2.0 request and sends it to the first cloud platform;
[0035] The second cloud platform sends a list of devices associated with the second cloud platform to the first cloud platform based on the access token and acquisition request sent by the first cloud platform; the device list is used by the first cloud platform to determine the target device.
[0036] The IoT device control method according to embodiments of the present invention, by combining OAuth 2.0 and on-device operation confirmation mechanisms, solves the cumbersome authorization process required by users when using cross-platform IoT devices, while also addressing manufacturers' needs for independent user systems and personalized interactive experiences, and ensuring the security of cross-platform IoT device control. Furthermore, by obtaining data from all devices registered on the second cloud platform at once using an access token, and selecting the target device to be controlled from the device list, it avoids repeatedly fetching device data, thereby reducing communication costs and interaction time.
[0037] According to one embodiment of the present invention, after the second cloud platform receives the control instruction sent by the first cloud platform based on the access token and the operation credential, it further includes:
[0038] The second cloud platform verifies the timeliness of the operation credentials;
[0039] If the operation credentials are valid, the second cloud platform controls the target device according to the control instructions.
[0040] According to the IoT device control method of the present invention, by verifying the timeliness of the operation credentials, users do not need to perform a specified operation on the device every time they use the same target device within a preset time period. This ensures the security of cross-platform device control, avoids operational complexity, and improves the user experience.
[0041] An Internet of Things (IoT) device control apparatus according to a third aspect of the present invention includes:
[0042] The first receiving module is used by the first cloud platform to receive information from the second cloud platform that the target device has entered the target state; the information is used to instruct a specified operation to be performed on the target device.
[0043] The second receiving module is used for the first cloud platform to receive the operation credentials of the target device generated by the second cloud platform; the operation credentials are generated when the second cloud platform confirms that the specified operation has been completed.
[0044] The first sending module is used by the first cloud platform to send control instructions for controlling the target device to the second cloud platform based on the access token and the operation credentials;
[0045] The target device is a device registered on the second cloud platform;
[0046] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0047] According to the IoT device control device of the present invention, the device operation credentials are generated only after the user performs the corresponding operation on the device. The device can only be controlled based on the operation credentials. That is, the operation credentials can prove that the user who initiated the operation is next to the device. This means that to maliciously attack and initiate the control of a large number of devices, the attacker needs to come to the device to operate, which increases the difficulty of the attack and improves the security of cross-platform control of IoT devices.
[0048] An Internet of Things (IoT) device control apparatus according to a fourth aspect of the present invention includes:
[0049] The second sending module is used by the second cloud platform to send information about the target device entering the target state to the first cloud platform; the information is used to instruct a specified operation to be performed on the target device.
[0050] The generation module is used to generate the operation credentials of the target device and send them to the first cloud platform after the second cloud platform confirms the completion of the specified operation.
[0051] The control module is used for the second cloud platform to receive control instructions sent by the first cloud platform based on the access token and the operation credentials, and to control the target device according to the control instructions;
[0052] The target device is a device registered on the second cloud platform;
[0053] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0054] According to the IoT device control device of the present invention, the device operation credentials are generated only after the user performs the corresponding operation on the device. The device can only be controlled based on the operation credentials. That is, the operation credentials can prove that the user who initiated the operation is next to the device. This means that to maliciously attack and initiate the control of a large number of devices, the attacker needs to come to the device to operate, which increases the difficulty of the attack and improves the security of cross-platform control of IoT devices.
[0055] An electronic device according to a fifth aspect of the present invention includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of any of the above-described Internet of Things device control methods.
[0056] According to a sixth aspect of the present invention, a non-transitory computer-readable storage medium is provided thereon storing a computer program that, when executed by a processor, implements the steps of any of the above-described Internet of Things device control methods.
[0057] The above-described one or more technical solutions in the embodiments of the present invention have at least one of the following technical effects:
[0058] By generating device operation credentials only after a user performs a corresponding operation on the device, and then controlling the device based on these credentials, the operation credentials prove that the user initiating the operation is near the device. This means that to maliciously attack and control a large number of devices, the attacker needs to be near the device to perform the operation, which increases the difficulty of the attack and improves the security of cross-platform control of IoT devices.
[0059] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description
[0060] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0061] Figure 1 This is one of the flowcharts illustrating the IoT device control method provided in this embodiment of the invention;
[0062] Figure 2 This is a second schematic flowchart of the IoT device control method provided in this embodiment of the invention;
[0063] Figure 3 This is a flowchart illustrating the IoT device control method provided in the embodiments of the present invention;
[0064] Figure 4 This is one of the structural schematic diagrams of the IoT device control device provided in the embodiments of the present invention;
[0065] Figure 5 This is a second schematic diagram of the structure of the IoT device control device provided in the embodiment of the present invention;
[0066] Figure 6 This is a schematic diagram of the structure of the electronic device provided in an embodiment of the present invention. Detailed Implementation
[0067] The embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples. The following examples are for illustrative purposes only and should not be construed as limiting the scope of the invention.
[0068] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., refer to specific features, structures, materials, or characteristics described in connection with that embodiment or example, which are included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.
[0069] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0070] Figure 1 This is one of the flowcharts illustrating the IoT device control method provided in this embodiment of the invention, referred to... Figure 1 The IoT device control method provided in this embodiment of the invention includes the following steps:
[0071] Step 110: The first cloud platform receives information from the second cloud platform that the target device has entered the target state; the information is used to instruct on a specified operation to be performed on the target device.
[0072] Step 120: The first cloud platform receives the operation credentials for the target device generated by the second cloud platform; the operation credentials are generated when the second cloud platform confirms that the specified operation has been completed.
[0073] Step 130: The first cloud platform sends control commands to the second cloud platform to control the target device based on the access token and operation credentials;
[0074] The target device is a device registered on the second cloud platform;
[0075] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0076] The execution entity of the IoT device control method provided in this embodiment of the invention can be a first cloud platform. The following describes the technical solution of the invention in detail using the execution of the IoT device control method provided in this embodiment of the invention on a first cloud platform as an example. The first cloud platform and the second cloud platform are respectively connected to different smart devices. Different smart devices refer to smart devices of different models or manufactured by different manufacturers, not specifically different types of smart devices. The smart devices connected to the first cloud platform can be interactive devices, such as smart speakers, smart wearable devices, etc. The smart devices connected to the second cloud platform can be smart home appliances, such as air conditioners, refrigerators, rice cookers, washing machines, or water heaters, etc., which will not be listed here.
[0077] Optionally, in step 110, the first cloud platform receives information from the second cloud platform that the target device has entered the target state; the information is used to instruct a specified operation to be performed on the target device.
[0078] The target device is a device registered on the second cloud platform, and the target device can communicate with the second cloud platform. The target device can be an air conditioner, refrigerator, rice cooker, washing machine, or water heater, etc., manufactured by the same manufacturer. The target state refers to the target device entering a verifiable state, that is, the state in which the user can perform specified operations on the target device.
[0079] After the second cloud platform controls the target device to enter a verifiable state, it sends this information to the first cloud platform. Upon receiving this information, the first cloud platform informs the user that the target device has entered a verifiable state and instructs the user to perform a specified operation on the device. Once the target device enters a verifiable state, it can prompt the user to perform a confirmation operation through sound, light, or an interface (e.g., pressing a button on the device or interface). Alternatively, the first cloud platform's interactive terminal can display the target device's interface to the user, thus instructing them to perform a confirmation operation.
[0080] In step 120, the first cloud platform receives the operation credentials of the target device generated by the second cloud platform; the operation credentials are generated when the second cloud platform confirms that the specified operation has been completed.
[0081] After the target device receives user confirmation of the operation, it reports the confirmed operation through the communication channel established with the second cloud platform. Upon receiving the reported event from the target device, the second cloud platform confirms that the target user has completed the specified operation on the target device and generates and stores an operation credential unique to the first cloud platform. It then sends this operation credential to the first cloud platform, which records and stores it upon receipt.
[0082] Understandably, operation credentials can possess a certain degree of complexity, randomness, and timeliness. For example, an operation credential can be a randomly generated string that at least meets the following conditions: includes uppercase and lowercase letters, and has a sufficiently long string length. Furthermore, since the operation credential is only generated when the user operates on the device, it proves that the user initiating the operation is near the device. This means that to maliciously attack and gain control of a large number of devices, the attacker needs to be physically present at the devices, which increases the difficulty of the attack and enhances security to some extent.
[0083] In step 130, the first cloud platform sends control commands to the second cloud platform for controlling the target device based on the access token and operation credentials.
[0084] The target user initiates a control operation on the target device through the interactive terminal of the first cloud platform. After the interactive terminal of the first cloud platform sends the corresponding operation request to the first cloud platform, the first cloud platform carries the pre-acquired access token and the device's operation credentials to the second cloud platform to request control of the IoT device. The second cloud platform will verify the legality of the access token and operation credentials carried by the first cloud platform. After the verification is successful, the second cloud platform will issue control commands through the communication channel established with the IoT device, thereby completing the entire authorization and control process.
[0085] The IoT device control method provided in this embodiment of the invention generates device operation credentials only after the user performs a corresponding operation on the device. The device can only be controlled based on the device operation credentials. That is, the operation credentials can prove that the user who initiated the operation is next to the device. This means that to maliciously attack and initiate control of a large number of devices, the attacker needs to come to the device to operate, which increases the difficulty of the attack and improves the security of cross-platform control of IoT devices.
[0086] In one embodiment, before the first cloud platform receives information from the second cloud platform that the target device has entered the target state, the method further includes:
[0087] The first cloud platform sends a control request to the second cloud platform;
[0088] The control request is used to instruct the second cloud platform to control the target device to enter the target state.
[0089] Optionally, the first cloud platform first sends a control request to the second cloud platform. After receiving the control request, the second cloud platform records the triggering behavior of the first cloud platform and the target device, and controls the target device to enter a verifiable state according to the control request.
[0090] The IoT device control method provided in this embodiment of the invention sends a control request from a first cloud platform to a second cloud platform. After receiving the control request, the second cloud platform controls the target device to enter a verifiable target state, thus ensuring the security of cross-platform device control.
[0091] In one embodiment, before the first cloud platform sends a control request to the second cloud platform, the method further includes:
[0092] The first cloud platform initiates an OAuth 2.0 request to the second cloud platform; the OAuth 2.0 request is used by the second cloud platform to generate an access token and send it to the first cloud platform.
[0093] The first cloud platform receives the access token sent by the second cloud platform;
[0094] The first cloud platform obtains the list of devices associated with the second cloud platform based on the access token and the acquisition request, and then determines the target device based on the device list.
[0095] Optionally, the first cloud platform initiates an OAuth2.0 request to the second cloud platform. That is, the first cloud platform completes the authorization process with the second cloud platform according to the OAuth2.0 client credentials protocol specification. The second cloud platform generates an access token based on the OAuth2.0 request and sends it to the first cloud platform.
[0096] OAuth 2.0 is an authorization mechanism used to authorize third-party applications to access user data. The authorization code method involves the third-party application first requesting an authorization code, and then using that code to obtain a token. This method offers relatively high security. The authorization code is transmitted through the front-end, while the token is stored on the back-end, and all communication with the resource server is completed on the back-end. This separation of front-end and back-end prevents token leakage.
[0097] Access tokens are a security concept in the Windows operating system. When a user logs in, the system creates an access token containing the SID returned by the login process and a list of privileges assigned to the user and their security groups by local security policies. All processes running as that user have a copy of this token. The system uses the token to control which secure objects a user can access and their ability to perform related system operations.
[0098] After receiving the access token, the first cloud platform uses it to retrieve the device list associated with the second cloud platform in batches. This device list comprises all devices connected to the second cloud platform. The first cloud platform initiates a request to the second cloud platform using the access token. Upon recognizing the access token, the second cloud platform responds to the request by sending the device list back to the first cloud platform, ensuring the security of cross-platform control of IoT devices.
[0099] The first cloud platform can process data according to its own business logic and display relevant devices to users through its interactive terminal. This allows it to determine at once which devices are registered on the second cloud platform, i.e., which devices can be controlled through the second cloud platform.
[0100] The IoT device control method provided in this invention, by combining OAuth 2.0 and on-device operation confirmation mechanisms, solves the cumbersome authorization process required by users when using cross-platform IoT devices. It also addresses manufacturers' needs for independent user systems and personalized interactive experiences, while ensuring security for cross-platform IoT device control. Furthermore, by using an access token to retrieve data from all devices registered on a second cloud platform at once, and selecting the target device from the device list, it avoids repeatedly fetching device data, thereby reducing communication costs and interaction time.
[0101] Figure 2 This is a second flowchart illustrating the IoT device control method provided in an embodiment of the present invention, referring to... Figure 2 The IoT device control method provided in this embodiment of the invention includes the following steps:
[0102] Step 210: The second cloud platform sends the information that the target device has entered the target state to the first cloud platform; the information is used to instruct on the specified operation to be performed on the target device.
[0103] Step 220: The second cloud platform confirms the completion of the specified operation, generates the operation credentials for the target device, and sends them to the first cloud platform;
[0104] Step 230: The second cloud platform receives the control command sent by the first cloud platform based on the access token and operation credentials, and controls the target device according to the control command;
[0105] The target device is a device registered on the second cloud platform;
[0106] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0107] The execution entity of the IoT device control method provided in this embodiment of the invention can be a second cloud platform. The following describes the technical solution of the invention in detail using the execution of the IoT device control method provided in this embodiment of the invention on a second cloud platform as an example. The smart devices connected to the second cloud platform can be smart home appliances, such as air conditioners, refrigerators, rice cookers, washing machines, or water heaters, etc., which will not be listed here. The smart devices connected to the first cloud platform can be voice interaction devices, such as speakers, smart wearable devices, etc. The first cloud platform and the second cloud platform connect to different smart devices respectively. Different smart devices refer to smart devices of different models or manufactured by different manufacturers, not specifically different types of smart devices.
[0108] Optionally, in step 210, the second cloud platform sends information about the target device entering the target state to the first cloud platform; the information is used to instruct on a specified operation to be performed on the target device.
[0109] The target device is a device registered on the second cloud platform, and the target device can communicate with the second cloud platform. The target device can be an air conditioner, refrigerator, rice cooker, washing machine, or water heater, etc., manufactured by the same manufacturer. The target state refers to the target device entering a verifiable state, that is, the state in which the user can perform specified operations on the target device.
[0110] After the second cloud platform controls the target device to enter a verifiable state, it sends this information to the first cloud platform. Upon receiving this information, the first cloud platform informs the user that the target device has entered a verifiable state and instructs the user to perform a specified operation on the device. Once the target device enters a verifiable state, it can prompt the user to perform a confirmation operation through sound, light, or an interface (e.g., pressing a button on the device or interface). Alternatively, the first cloud platform's interactive terminal can display the target device's interface to the user, thus instructing them to perform a confirmation operation.
[0111] In step 220, the second cloud platform confirms the completion of the specified operation, generates the operation credentials for the target device, and sends them to the first cloud platform.
[0112] After the target device receives user confirmation of the operation, it reports the confirmed operation through the communication channel established with the second cloud platform. Upon receiving the reported event from the target device, the second cloud platform confirms that the target user has completed the specified operation on the target device and generates and stores an operation credential unique to the first cloud platform. It then sends this operation credential to the first cloud platform, which records and stores it upon receipt.
[0113] Understandably, operation credentials can possess a certain degree of complexity, randomness, and timeliness. For example, an operation credential can be a randomly generated string that at least meets the following conditions: includes uppercase and lowercase letters, and has a sufficiently long string length. Furthermore, since the operation credential is only generated when the user operates on the device, it proves that the user initiating the operation is near the device. This means that to maliciously attack and gain control of a large number of devices, the attacker needs to be physically present at the devices, which increases the difficulty of the attack and enhances security to some extent.
[0114] In step 230, the second cloud platform receives control instructions sent by the first cloud platform based on the access token and operation credentials, and controls the target device according to the control instructions.
[0115] The target user initiates a control operation on the target device through the interactive terminal of the first cloud platform. After the interactive terminal of the first cloud platform sends the corresponding operation request to the first cloud platform, the first cloud platform carries the pre-acquired access token and the device's operation credentials to the second cloud platform to request control of the IoT device. The second cloud platform will verify the legality of the access token and operation credentials carried by the first cloud platform. After the verification is successful, the second cloud platform will issue control commands through the communication channel established with the IoT device, thereby completing the entire authorization and control process.
[0116] The IoT device control method provided in this embodiment of the invention generates device operation credentials only after the user performs a corresponding operation on the device. The device can only be controlled based on the device operation credentials. That is, the operation credentials can prove that the user who initiated the operation is next to the device. This means that to maliciously attack and initiate control of a large number of devices, the attacker needs to come to the device to operate, which increases the difficulty of the attack and improves the security of cross-platform control of IoT devices.
[0117] In one embodiment, before the second cloud platform sends the information about the target device entering the target state to the first cloud platform, the method further includes:
[0118] The second cloud platform receives the control request sent by the first cloud platform and controls the target device to enter the target state according to the control request.
[0119] Optionally, the first cloud platform first sends a control request to the second cloud platform. After receiving the control request, the second cloud platform records the triggering behavior of the first cloud platform and the target device, and controls the target device to enter a verifiable state according to the control request.
[0120] The IoT device control method provided in this embodiment of the invention controls the target device to enter a verifiable target state after receiving a control request sent by the first cloud platform through the second cloud platform, thereby ensuring the security of cross-platform device control.
[0121] In one embodiment, before the second cloud platform receives the control request sent by the first cloud platform, the method further includes:
[0122] The second cloud platform receives the OAuth 2.0 request sent by the first cloud platform;
[0123] The second cloud platform generates an access token based on the OAuth 2.0 request and sends it to the first cloud platform;
[0124] Based on the access token and acquisition request sent by the first cloud platform, the second cloud platform sends a list of devices associated with the second cloud platform to the first cloud platform; the device list is used by the first cloud platform to identify the target device.
[0125] Optionally, the first cloud platform initiates an OAuth2.0 request to the second cloud platform. That is, the first cloud platform completes the authorization process with the second cloud platform according to the OAuth2.0 client credentials protocol specification. The second cloud platform generates an access token based on the OAuth2.0 request and sends it to the first cloud platform.
[0126] OAuth 2.0 is an authorization mechanism used to authorize third-party applications to access user data. The authorization code method involves the third-party application first requesting an authorization code, and then using that code to obtain a token. This method offers relatively high security. The authorization code is transmitted through the front-end, while the token is stored on the back-end, and all communication with the resource server is completed on the back-end. This separation of front-end and back-end prevents token leakage.
[0127] Access tokens are a security concept in the Windows operating system. When a user logs in, the system creates an access token containing the SID returned by the login process and a list of privileges assigned to the user and their security groups by local security policies. All processes running as that user have a copy of this token. The system uses the token to control which secure objects a user can access and their ability to perform related system operations.
[0128] After receiving the access token, the first cloud platform uses it to retrieve the device list associated with the second cloud platform in batches. This device list comprises all devices connected to the second cloud platform. Upon receiving the retrieval request and access token from the first cloud platform, the second cloud platform recognizes the access token and responds to the first cloud platform's request by sending the device list back to it. This ensures the security of cross-platform control of IoT devices.
[0129] The first cloud platform can process data according to its own business logic and display relevant devices to users through its interactive terminal. This allows it to determine at once which devices are registered on the second cloud platform, i.e., which devices can be controlled through the second cloud platform.
[0130] The IoT device control method provided in this invention, by combining OAuth 2.0 and on-device operation confirmation mechanisms, solves the cumbersome authorization process required by users when using cross-platform IoT devices. It also addresses manufacturers' needs for independent user systems and personalized interactive experiences, while ensuring security for cross-platform IoT device control. Furthermore, by using an access token to retrieve data from all devices registered on a second cloud platform at once, and selecting the target device from the device list, it avoids repeatedly fetching device data, thereby reducing communication costs and interaction time.
[0131] In one embodiment, after the second cloud platform receives the control command sent by the first cloud platform based on the access token and operation credentials, it further includes:
[0132] The second cloud platform verifies the validity of operation credentials;
[0133] If the operation credentials are valid, the second cloud platform controls the target device according to the control instructions.
[0134] Optionally, the operation credentials are time-limited and valid only within a preset period; they are not permanently valid after being generated once. The validity period of the operation credentials can be one month, two months, or three months, and the specific validity period can be set according to needs, without limitation here. If the second cloud platform verifies that the operation credentials are valid, the second cloud platform controls the target device according to the control commands.
[0135] For example, if the validity period of the operation credential is one month, when a user controls the target device for the first time across platforms, the operation credential generated after performing a specified operation on the device will be valid for one month. This means that if a user controls the same target device within a month, they do not need to perform the specified operation on the device each time, improving the user experience.
[0136] According to the IoT device control method of the present invention, by verifying the timeliness of the operation credentials, users do not need to perform a specified operation on the device every time they use the same target device within a preset time period. This ensures the security of cross-platform device control, avoids operational complexity, and improves the user experience.
[0137] Figure 3 This is a flowchart illustrating the IoT device control method provided in an embodiment of the present invention. (Refer to...) Figure 3 The IoT device control method provided in this embodiment of the invention has the following specific interaction process:
[0138] Step 1: Vendor B's cloud platform B completes the authorization process with platform A according to the OAuth 2.0 client credentials protocol specification and obtains the access token;
[0139] Step 2: Vendor B's cloud platform B, carrying an access token, obtains the complete device list from Vendor A's cloud platform A in batches, processes it according to its own business logic, and displays the relevant devices to Vendor B's users through Vendor B's interactive terminal.
[0140] Step 3: Manufacturer B's user requests temporary operation credentials for the IoT device through Manufacturer B's interactive terminal and transmits the request to Manufacturer B's cloud platform B. The cloud platform B then carries the access token to Manufacturer A's cloud platform A to initiate an instruction to put the IoT device into a verifiable state.
[0141] After receiving the request, cloud platform A first stores the record of cloud platform B triggering the IoT device to enter the verifiable state, and then sends a control command to the device to enter the verifiable state through the communication channel established with the IoT device.
[0142] Once an IoT device enters a verifiable state, it prompts the user to perform a verification operation through sound, light, or interface (e.g., pressing a button on the device or a button on the interface). Alternatively, it can display the operation interface of the relevant IoT device to the user through the manufacturer B's interactive terminal, thereby instructing the user to complete the device verification operation.
[0143] Step 4: After a user confirms an operation on Manufacturer A's IoT device, the device will report the confirmed operation through the communication channel established with Cloud Platform A. Upon receiving the report from the IoT device, Cloud Platform A will verify the trigger record between the device and Cloud Platform B. If the verification is successful, Cloud Platform A will generate and store a temporary operation credential unique to Cloud Platform B for the device. Cloud Platform A will then send the operation credential back to Cloud Platform B, which will record and store it upon receipt.
[0144] Step 5: Manufacturer B user initiates control operations on the IoT device through Manufacturer B's interactive terminal. After Manufacturer B's interactive terminal sends the corresponding operation request to Cloud Platform B, it sends an access token and temporary device operation credentials to Cloud Platform A to request control of the IoT device. Cloud Platform A then verifies the legality of the access token and temporary device credentials sent by Cloud Platform B. After successful verification, it issues control commands through the communication channel established with the IoT device, thereby completing the entire authorization and control process.
[0145] The following explanation uses a specific scenario as an example. For instance, equipment manufacturer A sells a large number of smart devices to real estate developer B. Equipment manufacturer A's installation engineers will install these devices and connect them to the network via equipment manufacturer A's cloud platform A.
[0146] If real estate developer B later wishes to build its own application terminals and allows users to use these terminals under its own name, then real estate developer B's cloud platform B will complete the authorization process with device manufacturer A's cloud platform A through OAuth 2.0 client credentials. It will then retrieve this device information and provide it to the user.
[0147] When a user needs to operate the device, real estate developer B's cloud platform B requests device manufacturer A's cloud platform A to put the device into a verifiable state. At this point, the user is prompted to operate the device through the device or real estate developer B's own application terminal interface. In this way, by confirming the operation on the device and reporting the confirmed operation instruction to device manufacturer A's cloud platform A, cloud platform A can issue device operation credentials to real estate developer B's cloud platform B.
[0148] Next, when a user initiates device control through the real estate manufacturer B's application terminal and cloud platform B, they will have the credentials to operate the device. Since the user needs to be physically present to operate the device for the first time during this interaction, this mitigates the risk of large-scale malicious control of devices due to attacks on the real estate manufacturer B's application terminal or cloud platform, thus improving the security of the entire interaction process in cross-platform control of IoT devices.
[0149] The IoT device control method provided by this invention solves the cumbersome authorization process that users need to perform when using cross-platform IoT devices by combining OAuth 2.0 and the on-device operation confirmation mechanism. At the same time, it solves the manufacturer's need for an independent user system and personalized interactive experience, and meets the security requirements for cross-platform control of IoT devices, thereby significantly reducing manufacturer costs and improving user experience.
[0150] Figure 4 This is one of the structural schematic diagrams of an IoT device control device provided in an embodiment of the present invention. (Refer to...) Figure 4 The IoT device control device provided by the present invention includes:
[0151] The first receiving module 410 is used by the first cloud platform to receive information from the second cloud platform that the target device has entered the target state; the information is used to instruct a specified operation to be performed on the target device.
[0152] The second receiving module 420 is used by the first cloud platform to receive the operation credentials of the target device generated by the second cloud platform; the operation credentials are generated when the second cloud platform confirms that the specified operation has been completed.
[0153] The first sending module 430 is used by the first cloud platform to send control commands for controlling the target device to the second cloud platform based on the access token and operation credentials;
[0154] The target device is a device registered on the second cloud platform;
[0155] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0156] The IoT device control device provided in this embodiment of the invention generates device operation credentials only after the user performs a corresponding operation on the device. The device can only be controlled based on the device operation credentials. That is, the operation credentials can prove that the user who initiated the operation is next to the device. This means that to maliciously attack and initiate control of a large number of devices, the attacker needs to come to the device to operate, which increases the difficulty of the attack and improves the security of cross-platform control of IoT devices.
[0157] In one embodiment, before the first cloud platform receives information from the second cloud platform that the target device has entered the target state, the method further includes:
[0158] The first cloud platform sends a control request to the second cloud platform;
[0159] The control request is used to instruct the second cloud platform to control the target device to enter the target state.
[0160] In one embodiment, before the first cloud platform sends a control request to the second cloud platform, the method further includes:
[0161] The first cloud platform initiates an OAuth 2.0 request to the second cloud platform; the OAuth 2.0 request is used by the second cloud platform to generate an access token and send it to the first cloud platform.
[0162] The first cloud platform receives the access token sent by the second cloud platform;
[0163] The first cloud platform obtains the list of devices associated with the second cloud platform based on the access token and the acquisition request, and then determines the target device based on the device list.
[0164] Figure 5 This is a second structural schematic diagram of the IoT device control device provided in an embodiment of the present invention. (Refer to...) Figure 5 The IoT device control device provided by the present invention includes:
[0165] The second sending module 510 is used by the second cloud platform to send information about the target device entering the target state to the first cloud platform; the information is used to instruct a specified operation to be performed on the target device.
[0166] The generation module 520 is used by the second cloud platform to confirm the completion of the specified operation, generate the operation credentials of the target device, and send them to the first cloud platform;
[0167] The control module 530 is used for the second cloud platform to receive control commands sent by the first cloud platform based on the access token and operation credentials, and to control the target device according to the control commands;
[0168] The target device is a device registered on the second cloud platform;
[0169] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0170] The IoT device control device provided in this embodiment of the invention generates device operation credentials only after the user performs a corresponding operation on the device. The device can only be controlled based on the device operation credentials. That is, the operation credentials can prove that the user who initiated the operation is next to the device. This means that to maliciously attack and initiate control of a large number of devices, the attacker needs to come to the device to operate, which increases the difficulty of the attack and improves the security of cross-platform control of IoT devices.
[0171] In one embodiment, before the second cloud platform sends the information about the target device entering the target state to the first cloud platform, the method further includes:
[0172] The second cloud platform receives the control request sent by the first cloud platform and controls the target device to enter the target state according to the control request.
[0173] In one embodiment, before the second cloud platform receives the control request sent by the first cloud platform, the method further includes:
[0174] The second cloud platform receives the OAuth 2.0 request sent by the first cloud platform;
[0175] The second cloud platform generates an access token based on the OAuth 2.0 request and sends it to the first cloud platform;
[0176] Based on the access token and acquisition request sent by the first cloud platform, the second cloud platform sends a list of devices associated with the second cloud platform to the first cloud platform; the device list is used by the first cloud platform to identify the target device.
[0177] In one embodiment, after the second cloud platform receives the control command sent by the first cloud platform based on the access token and operation credentials, it further includes:
[0178] The second cloud platform verifies the validity of operation credentials;
[0179] If the operation credentials are valid, the second cloud platform controls the target device according to the control instructions.
[0180] Figure 6 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 6 As shown, the electronic device may include a processor 610, a communications interface 620, a memory 630, and a communication bus 640, wherein the processor 610, the communications interface 620, and the memory 630 communicate with each other via the communication bus 640. The processor 610 can call logical instructions in the memory 630 to execute the following methods:
[0181] The first cloud platform receives information from the second cloud platform indicating that the target device has entered the target state; the information is used to instruct on a specified operation to be performed on the target device.
[0182] The first cloud platform receives the operation credentials of the target device generated by the second cloud platform; the operation credentials are generated when the second cloud platform confirms that the specified operation has been completed.
[0183] The first cloud platform sends control commands to the second cloud platform to control the target device based on the access token and operation credentials;
[0184] The target device is a device registered on the second cloud platform;
[0185] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0186] or
[0187] The second cloud platform sends information about the target device entering the target state to the first cloud platform; the information is used to instruct on the specified operation to be performed on the target device.
[0188] The second cloud platform confirms the completion of the specified operation, generates the operation credentials for the target device, and sends them to the first cloud platform;
[0189] The second cloud platform receives control commands sent by the first cloud platform based on access tokens and operation credentials, and controls the target device according to the control commands;
[0190] The target device is a device registered on the second cloud platform;
[0191] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0192] Furthermore, the logical instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0193] Furthermore, this invention discloses a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, and when these instructions are executed by a computer, the computer can execute the IoT device control methods provided in the above-described method embodiments, such as including:
[0194] The first cloud platform receives information from the second cloud platform indicating that the target device has entered the target state; the information is used to instruct on a specified operation to be performed on the target device.
[0195] The first cloud platform receives the operation credentials of the target device generated by the second cloud platform; the operation credentials are generated when the second cloud platform confirms that the specified operation has been completed.
[0196] The first cloud platform sends control commands to the second cloud platform to control the target device based on the access token and operation credentials;
[0197] The target device is a device registered on the second cloud platform;
[0198] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0199] or
[0200] The second cloud platform sends information about the target device entering the target state to the first cloud platform; the information is used to instruct on the specified operation to be performed on the target device.
[0201] The second cloud platform confirms the completion of the specified operation, generates the operation credentials for the target device, and sends them to the first cloud platform;
[0202] The second cloud platform receives control commands sent by the first cloud platform based on access tokens and operation credentials, and controls the target device according to the control commands;
[0203] The target device is a device registered on the second cloud platform;
[0204] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0205] On the other hand, embodiments of the present invention also provide a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, is implemented to perform the IoT device control methods provided in the above embodiments, including, for example:
[0206] The first cloud platform receives information from the second cloud platform indicating that the target device has entered the target state; the information is used to instruct on a specified operation to be performed on the target device.
[0207] The first cloud platform receives the operation credentials of the target device generated by the second cloud platform; the operation credentials are generated when the second cloud platform confirms that the specified operation has been completed.
[0208] The first cloud platform sends control commands to the second cloud platform to control the target device based on the access token and operation credentials;
[0209] The target device is a device registered on the second cloud platform;
[0210] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0211] or
[0212] The second cloud platform sends information about the target device entering the target state to the first cloud platform; the information is used to instruct on the specified operation to be performed on the target device.
[0213] The second cloud platform confirms the completion of the specified operation, generates the operation credentials for the target device, and sends them to the first cloud platform;
[0214] The second cloud platform receives control commands sent by the first cloud platform based on access tokens and operation credentials, and controls the target device according to the control commands;
[0215] The target device is a device registered on the second cloud platform;
[0216] The access token was obtained in advance by the first cloud platform from the second cloud platform.
[0217] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0218] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0219] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
[0220] The above embodiments are for illustrative purposes only and are not intended to limit the scope of the invention. Although the invention has been described in detail with reference to the embodiments, those skilled in the art should understand that various combinations, modifications, or equivalent substitutions of the technical solutions of the invention do not depart from the spirit and scope of the invention and should be covered within the scope of the claims of the invention.
Claims
1. A method for controlling an Internet of Things (IoT) device, characterized in that, include: The first cloud platform receives information from the second cloud platform that the target device has entered the target state; The information is used to instruct the specified operation to be performed on the target device; The first cloud platform receives the operation credentials of the target device generated by the second cloud platform; the operation credentials are generated when the second cloud platform confirms that the specified operation has been completed. The first cloud platform sends a control command to the second cloud platform to control the target device based on the access token and the operation credentials; The target device is a device registered on the second cloud platform; The access token was obtained in advance by the first cloud platform from the second cloud platform.
2. The IoT device control method according to claim 1, characterized in that, Before the first cloud platform receives the information from the second cloud platform that the target device has entered the target state, it also includes: The first cloud platform sends a control request to the second cloud platform; The control request is used to instruct the second cloud platform to control the target device to enter the target state.
3. The IoT device control method according to claim 2, characterized in that, Before the first cloud platform sends a control request to the second cloud platform, the process also includes: The first cloud platform initiates an OAuth2.0 request to the second cloud platform; the OAuth2.0 request is used by the second cloud platform to generate the access token and send it to the first cloud platform. The first cloud platform receives the access token sent by the second cloud platform; The first cloud platform obtains the list of devices associated with the second cloud platform based on the access token and the acquisition request, and determines the target device based on the device list.
4. A method for controlling an Internet of Things (IoT) device, characterized in that, include: The second cloud platform sends the information about the target device entering the target state to the first cloud platform; The information is used to instruct the specified operation to be performed on the target device; The second cloud platform confirms the completion of the specified operation, generates the operation credentials for the target device, and sends them to the first cloud platform; The second cloud platform receives control instructions sent by the first cloud platform based on the access token and the operation credentials, and controls the target device according to the control instructions; The target device is a device registered on the second cloud platform; The access token was obtained in advance by the first cloud platform from the second cloud platform.
5. The IoT device control method according to claim 4, characterized in that, Before the second cloud platform sends the information about the target device entering the target state to the first cloud platform, it also includes: The second cloud platform receives the control request sent by the first cloud platform and controls the target device to enter the target state according to the control request.
6. The IoT device control method according to claim 5, characterized in that, Before the second cloud platform receives the control request sent by the first cloud platform, the process also includes: The second cloud platform receives the OAuth 2.0 request sent by the first cloud platform; The second cloud platform generates an access token based on the OAuth2.0 request and sends it to the first cloud platform; The second cloud platform sends a list of devices associated with the second cloud platform to the first cloud platform based on the access token and acquisition request sent by the first cloud platform; the device list is used by the first cloud platform to determine the target device.
7. The IoT device control method according to any one of claims 4-6, characterized in that, After the second cloud platform receives the control command sent by the first cloud platform based on the access token and the operation credentials, it further includes: The second cloud platform verifies the timeliness of the operation credentials; If the operation credentials are valid, the second cloud platform controls the target device according to the control instructions.
8. An Internet of Things (IoT) device control device, characterized in that, include: The first receiving module is used for the first cloud platform to receive information from the second cloud platform that the target device has entered the target state. The information is used to instruct the specified operation to be performed on the target device; The second receiving module is used for the first cloud platform to receive the operation credentials of the target device generated by the second cloud platform; the operation credentials are generated when the second cloud platform confirms that the specified operation has been completed. The first sending module is used by the first cloud platform to send control instructions for controlling the target device to the second cloud platform based on the access token and the operation credentials; The target device is a device registered on the second cloud platform; The access token was obtained in advance by the first cloud platform from the second cloud platform.
9. A control device for an Internet of Things (IoT) device, characterized in that, include: The second sending module is used by the second cloud platform to send the information of the target device entering the target state to the first cloud platform. The information is used to instruct the specified operation to be performed on the target device; The generation module is used to generate the operation credentials of the target device and send them to the first cloud platform after the second cloud platform confirms the completion of the specified operation. The control module is used for the second cloud platform to receive control instructions sent by the first cloud platform based on the access token and the operation credentials, and to control the target device according to the control instructions; The target device is a device registered on the second cloud platform; The access token was obtained in advance by the first cloud platform from the second cloud platform.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the Internet of Things device control method as described in any one of claims 1 to 7.
11. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the Internet of Things device control method as described in any one of claims 1 to 7.
12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the steps of the Internet of Things device control method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Wireless network configuration method, apparatus and system
CN107046483A
Communication method for device, device and storage medium
CN113273161A