Device Control Method, Electronic Device and Storage Medium Based on Internet of Things Platform

Through the opening of the service tool for application layer services on the Internet of Things platform, the problems of high threshold and low efficiency of application development of IoT device manufacturers are solved, and efficient management of IoT devices and effective management of application layer services are achieved.

CN115580641BActive Publication Date: 2025-06-27TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110761712.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-06
Publication Date
2025-06-27
Estimated Expiration
2041-07-06

AI Technical Summary

Technical Problem

The existing technology faces high development threshold, low efficiency and time-consuming problems when applying manufacturers of IoT devices, which affect the effective control of IoT devices.

Method used

Through the service tools corresponding to the application layer service of the Internet of Things platform, IoT devices can easily and effectively access application layer services and realize device management and control. The specific method includes establishing a communication connection with the device through an Internet of Things platform, receiving application requests in the device, establishing a session, and calling application layer services during the session to respond to the request.

Benefits of technology

It reduces the difficulty of developing IoT applications, improves the efficiency and effectiveness of device management and control, and realizes effective control on the application layer of the IoT platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115580641B_ABST
    Figure CN115580641B_ABST
Patent Text Reader

Abstract

The present application provides a device control method, an Internet of Things platform, a device, an electronic device, and a computer-readable storage medium based on an Internet of Things platform; the method includes: establishing a communication connection with an Internet of Things device through the Internet of Things platform, and receiving an application request initiated by an Internet of Things application in the Internet of Things device based on the communication connection; wherein, the Internet of Things application deploys service tools corresponding to at least part of the application layer services in the Internet of Things platform, and the service tools are used to generate the application request; establishing a session based on the application request; during the duration of the session, invoking at least part of the application layer services in the Internet of Things platform to respond to the application request. Through the present application, the implementation difficulty of device control can be reduced, and the efficiency and effectiveness of device control can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to Internet of Things technology, and in particular to a device control method, an Internet of Things platform, a device, an electronic device, and a computer-readable storage medium based on the Internet of Things platform. Background Art

[0002] The Internet of Things (IoT) is the "Internet of everything connected", which is an extension and expansion of the Internet. It is a huge network formed by combining various IoT devices with the network, so as to achieve interconnection and communication with IoT devices at any time and any place.

[0003] In order to control IoT devices, in the solutions provided by related technologies, usually, a manufacturer (referring to the manufacturer of IoT devices) develops its own manufacturer application based on the request routing and distribution capabilities provided by the Internet of Things platform, and deploys the manufacturer application in the IoT device, so as to connect the IoT device to the Internet of Things platform. However, in the process of developing the manufacturer application, problems such as high development threshold, low efficiency, and long time consumption are faced, which is not conducive to the effective control of IoT devices. Summary of the Invention

[0004] Embodiments of the present application provide a device control method, a device, an electronic device, and a computer-readable storage medium based on the Internet of Things platform, which can open the service tools corresponding to the application layer services of the Internet of Things platform for IoT devices to conveniently and effectively access the application layer services, thereby improving the efficiency and effectiveness of device control.

[0005] The technical solution of the embodiments of the present application is implemented as follows:

[0006] Embodiments of the present application provide a device control method based on the Internet of Things platform, including:

[0007] Establish a communication connection with an IoT device through the Internet of Things platform, and receive an application request initiated by an IoT application in the IoT device based on the communication connection;

[0008] Wherein, the IoT application deploys service tools corresponding to at least part of the application layer services in the Internet of Things platform, and the service tools are used to generate the application request;

[0009] Establish a session based on the application request;

[0010] During the duration of the session, call at least part of the application layer services in the Internet of Things platform to respond to the application request.

[0011] Embodiments of the present application provide an Internet of Things platform, including a device layer and an application layer;

[0012] The device layer is used to establish a communication connection with the Internet of Things (IoT) device and receive an application request initiated by an IoT application in the IoT device based on the communication connection;

[0013] Among them, at least part of the service tools corresponding to the application layer services in the IoT platform are deployed in the IoT application, and the service tools are used to generate the application request;

[0014] The application layer is used to:

[0015] Establish a session based on the application request;

[0016] During the duration of the session, call at least part of the application layer services in the IoT platform to respond to the application request.

[0017] An embodiment of the present application provides a device control device based on an IoT platform, including:

[0018] A connection module is used to establish a communication connection with an IoT device through the IoT platform and receive an application request initiated by an IoT application in the IoT device based on the communication connection;

[0019] Among them, at least part of the service tools corresponding to the application layer services in the IoT platform are deployed in the IoT application, and the service tools are used to generate the application request;

[0020] A session establishment module is used to establish a session based on the application request;

[0021] A session response module is used to call at least part of the application layer services in the IoT platform to respond to the application request during the duration of the session.

[0022] An embodiment of the present application provides an electronic device, including:

[0023] A memory is used to store executable instructions;

[0024] A processor, when executing the executable instructions stored in the memory, implements the device control method based on the IoT platform provided by the embodiment of the present application.

[0025] An embodiment of the present application provides a computer-readable storage medium, storing executable instructions, which are used to cause a processor to implement the device control method based on the IoT platform provided by the embodiment of the present application when executed.

[0026] The embodiment of the present application has the following beneficial effects:

[0027] In the embodiments of the present application, by opening service tools corresponding to at least part of the application layer services of the Internet of Things platform, Internet of Things devices can conveniently and effectively access the at least part of the application layer services through Internet of Things applications deployed with the service tools. For the Internet of Things platform, effective management and control on the application layer can be achieved through sessions. At the same time, the embodiments of the present application can also reduce the development difficulty of Internet of Things applications and improve the efficiency of device management and control. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 is a schematic structural diagram of a device management and control system based on an Internet of Things platform provided by an embodiment of the present application;

[0029] Figure 2 is a schematic structural diagram of a terminal device provided by an embodiment of the present application;

[0030] Figure 3A is a schematic flow diagram of a device management and control method based on an Internet of Things platform provided by an embodiment of the present application;

[0031] Figure 3B is a schematic flow diagram of a device management and control method based on an Internet of Things platform provided by an embodiment of the present application;

[0032] Figure 3C is a schematic flow diagram of a device management and control method based on an Internet of Things platform provided by an embodiment of the present application;

[0033] Figure 3D is a schematic flow diagram of active management and control at the device level provided by an embodiment of the present application;

[0034] Figure 3E is a schematic flow diagram of a device management and control method based on an Internet of Things platform provided by an embodiment of the present application;

[0035] Figure 3F is a schematic flow diagram of a device management and control method based on an Internet of Things platform provided by an embodiment of the present application;

[0036] Figure 4 is a schematic diagram of an Internet of Things platform provided by an embodiment of the present application;

[0037] Figure 5 is a schematic diagram of a session hierarchical architecture provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0038] In order to make the objectives, technical solutions, and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be construed as limiting the present application. All other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present application.

[0039] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments. It will be understood, however, that "some embodiments" may be the same subset or a different subset of all possible embodiments, and may be combined with each other without conflict.

[0040] In the following description, the terms "first", "second", and "third" are used only to distinguish similar objects and do not represent a specific order for the objects. It will be understood that "first", "second", and "third" may, where permitted, be interchanged in a specific order or sequence so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In the following description, the term "plurality" means at least two.

[0041] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this application belongs. The terms used herein are for the purpose of describing embodiments of the present application only and are not intended to limit the present application.

[0042] Before further elaborating on the embodiments of the present application, the nouns and terms involved in the embodiments of the present application are described, and the nouns and terms involved in the embodiments of the present application are subject to the following explanations.

[0043] 1) Internet of Things (IoT) platform: Used to provide secure and reliable connection and communication capabilities for IoT devices. On the one hand, the IoT platform can receive data sent by IoT devices; on the other hand, the IoT platform can also send data to IoT devices. In the embodiments of the present application, the IoT platform may include a decoupled device layer and application layer. Among them, the device layer is used to provide device layer services, and the application layer is used to provide application layer services. The device layer and the application layer can be respectively used to implement device management and control at different levels.

[0044] 2) IoT application: Refers to an application program running on an IoT device. The application program is deployed (or integrated) with service tools corresponding to at least part of the application layer services in the IoT platform, and is used to trigger the invocation of the at least part of the application layer services. Among them, the service tool refers to a toolkit for developing an application program for the at least part of the application layer services, also known as a Software Development Kit (SDK).

[0045] 3) IoT account: Refers to an account that can be used in the IoT platform. In the embodiments of the present application, the IoT account can include two types. The first type is the account held by the user of the IoT device (such as the user who uses a payment device for payment), and the second type is the account held by the manufacturer (or manufacturer user) who manufactures / maintains the IoT device.

[0046] 4) Session: Generally refers to the communication process between the IoT platform and IoT devices and related to application requests. The purpose of the session is to complete the response to the application request.

[0047] 5) Platform as a Service (PaaS): Refers to providing a complete software R & D and deployment platform, including application design, application development, application testing, and application hosting, as a service to users (such as developers). For example, PaaS provides a framework for developers on which they can create custom applications.

[0048] 6) Software as a Service (SaaS): Also known as cloud application service, it refers to delivering application programs or components of application programs (such as service tools) to users over the network. In this way, users can directly run the application programs or components of the application programs on the device to use the corresponding services. In the embodiments of the present application, the IoT platform belongs to the SaaS platform.

[0049] The embodiments of the present application provide a device control method, an IoT platform, a device, an electronic device, and a computer-readable storage medium based on the IoT platform, which can reduce the implementation difficulty of device control and improve the efficiency and effectiveness of device control. The following describes the exemplary applications of the electronic devices provided in the embodiments of the present application. The electronic devices provided in the embodiments of the present application can be implemented as various types of terminal devices or as servers.

[0050] See Figure 1 , Figure 1 is a schematic diagram of the architecture of the device control system 100 based on the IoT platform provided in the embodiments of the present application. The terminal device 400 is connected to the server 200 through the network 300-1, and the server 200 is connected to the IoT device 500 ( Figure 1 taking a payment device as an example in ). Among them, the network 300-1 can be a wide area network, a local area network, or a combination of the two, and the same applies to the network 300-2.

[0051] In some embodiments, taking the electronic device as a terminal device as an example, the device management and control method based on the Internet of Things platform provided by the embodiments of the present application can be implemented by the terminal device. For example, the terminal device 400 can be used as the underlying support device of the Internet of Things platform to support the operation of the Internet of Things platform; alternatively, the terminal device 400 can be different from the Internet of Things platform and implement device management and control by sending instructions to the Internet of Things platform. For the sake of easy understanding, the latter situation will be used for illustrative examples. During the operation of the Internet of Things platform, the terminal device 400 can send instructions to the Internet of Things platform to enable the Internet of Things platform to perform the following processing: establish a communication connection with the Internet of Things device and receive an application request initiated by the Internet of Things application in the Internet of Things device based on the communication connection; establish a session based on the application request; during the duration of the session, call at least some of the application layer services in the Internet of Things platform to respond to the application request. The Internet of Things platform can send the call result obtained by calling at least some of the application layer services to the terminal device 400 so that the user of the terminal device 400 can know.

[0052] In some embodiments, taking the electronic device as a server as an example, the device management and control method based on the Internet of Things platform provided by the embodiments of the present application can also be implemented by the server. For example, the server 200 can be used as the underlying support device of the Internet of Things platform to support the operation of the Internet of Things platform, where the operation of the Internet of Things platform can depend on multiple servers. Figure 1 Only one server is taken as an example for illustration. The server 200 can establish a communication connection with the Internet of Things device and receive an application request initiated by the Internet of Things application in the Internet of Things device based on the communication connection; establish a session based on the application request; during the duration of the session, call at least some of the application layer services in the Internet of Things platform (that is, at least some of the application layer services provided by the server 200) to respond to the application request.

[0053] In some embodiments, the terminal device 400 or the server 200 can implement the device management and control method based on the Internet of Things platform provided by the embodiments of the present application by running a computer program. For example, the computer program can be a native program or software module in the operating system; it can be a local (Native) application (APP, Application), that is, a program that needs to be installed in the operating system to run; it can also be a small program, that is, a program that only needs to be downloaded to the browser environment to run; it can also be a small program that can be embedded in any APP. In short, the above computer program can be any form of application program, module or plug-in.

[0054] In some embodiments, the server 200 may be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms. Among them, the cloud service may be a device control service based on the Internet of Things platform for the terminal device 400 to call. The terminal device 400 may be a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart TV, a smart watch, etc., but is not limited thereto. The terminal device and the server may be directly or indirectly connected through wired or wireless communication methods, which are not limited in the embodiments of the present application.

[0055] Taking the electronic device provided in the embodiments of the present application as an example of the terminal device, it can be understood that for the case where the electronic device is a server, Figure 2 Some parts in the structure shown (such as the user interface, the presentation module, and the input processing module) may be missing. Refer to Figure 2 , Figure 2 is a schematic structural diagram of the terminal device 400 provided in the embodiments of the present application. Figure 2 The terminal device 400 shown includes at least one processor 410, a memory 450, at least one network interface 420, and a user interface 430. Each component in the terminal device 400 is coupled together through a bus system 440. It can be understood that the bus system 440 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 440 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clear illustration, in Figure 2 all kinds of buses are labeled as the bus system 440.

[0056] The processor 410 may be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a Digital Signal Processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or any conventional processor, etc.

[0057] The user interface 430 includes one or more output devices 431 that enable the presentation of media content, including one or more speakers and / or one or more visual display screens. The user interface 430 also includes one or more input devices 432, including user interface components that facilitate user input, such as a keyboard, a mouse, a microphone, a touch screen display, a camera, and other input buttons and controls.

[0058] The memory 450 can be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state memory, hard disk drives, optical disc drives, etc. The memory 450 optionally includes one or more storage devices that are physically remote from the processor 410.

[0059] The memory 450 includes volatile memory, non-volatile memory, or both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), and the volatile memory can be random access memory (RAM). The memory 450 described in the embodiments of the present application is intended to include any suitable type of memory.

[0060] In some embodiments, the memory 450 is capable of storing data to support various operations. Examples of such data include programs, modules, and data structures, or subsets or supersets thereof, which are illustratively described below.

[0061] The operating system 451 includes system programs for handling various basic system services and performing hardware-related tasks, such as the framework layer, core library layer, driver layer, etc., for implementing various basic services and handling hardware-based tasks;

[0062] The network communication module 452 is used to reach other electronic devices via one or more (wired or wireless) network interfaces 420. Exemplary network interfaces 420 include: Bluetooth, Wi-Fi (Wireless Fidelity), and USB (Universal Serial Bus), etc.;

[0063] The presentation module 453 is used to enable the presentation of information (such as a user interface for operating peripheral devices and displaying content and information) via one or more output devices 431 associated with the user interface 430 (such as a display screen, speaker, etc.).

[0064] The input processing module 454 is used to detect and translate one or more user inputs or interactions from one of one or more input devices 432.

[0065] In some embodiments, the device control device based on the Internet of Things platform provided by the embodiments of the present application can be implemented in software. Figure 2The device control device 455 based on the Internet of Things platform stored in the memory 450 is shown, which can be software in the form of programs and plugins, etc., and includes the following software modules: a connection module 4551, a session establishment module 4552, and a session response module 4553. These modules are logical, so they can be combined arbitrarily or further split according to the functions implemented. The functions of each module will be described below.

[0066] The device control method based on the Internet of Things platform provided in the embodiments of the present application will be described in combination with the exemplary applications and implementations of the electronic device provided in the embodiments of the present application.

[0067] See Figure 3A , Figure 3A is a schematic flowchart of the device control method based on the Internet of Things platform provided in the embodiments of the present application, and will be described in combination with Figure 3A the steps shown.

[0068] In step 101, a communication connection is established with the Internet of Things device through the Internet of Things platform, and an application request initiated by the Internet of Things application in the Internet of Things device is received based on the communication connection; wherein, the Internet of Things application deploys service tools corresponding to at least part of the application layer services in the Internet of Things platform, and the service tools are used to generate application requests.

[0069] Here, the Internet of Things application is deployed (or installed) in the Internet of Things device, and the Internet of Things application deploys (or integrates, embeds) service tools corresponding to at least part of the application layer services in the Internet of Things platform, such as SDKs corresponding to at least part of the application layer services. During the operation of the Internet of Things device, application requests for at least part of the application layer services can be generated through the service tools. Among them, the application requests can be generated when the Internet of Things device receives a trigger operation from a user (such as a using user), or can be automatically generated. The embodiments of the present application do not limit the application layer services provided by the Internet of Things platform. For example, it can include at least one of communication services, payment services, Q&A services, and login services.

[0070] In order to achieve device control at the application level, a communication connection can be established with the Internet of Things device through the Internet of Things platform, and an application request initiated by the Internet of Things application in the Internet of Things device is received based on the communication connection. It should be noted that in the case where the Internet of Things platform includes a decoupled device layer and application layer, a communication connection can be established with the Internet of Things device through the device layer, and an application request initiated by the Internet of Things application in the Internet of Things device is received based on the communication connection.

[0071] It should be noted that for the service tools corresponding to at least some of the application layer services deployed in the Internet of Things applications, the service tools may include the invocation logic for the at least some of the application layer services. For example, it restricts the types of data that the application request should include (such as the device identifier of the Internet of Things device, the application identifier of the Internet of Things application, and the account identifier of the Internet of Things account), and for another example, it restricts sending the application request to the Internet of Things platform through a specific interface. In this way, it can ensure that the invocation process can be carried out accurately and efficiently. Of course, the service tools may also include the development environment and operating environment configured to achieve the invocation. In this way, it can help reduce the development work of the Internet of Things applications.

[0072] In the embodiments of the present application, the service tools may be manually configured by relevant personnel (such as the back-end personnel of the Internet of Things platform), or may be automatically generated based on the principle of artificial intelligence. For example, the operation process (such as the data processing process) of at least some of the application layer services may be analyzed by artificial intelligence, and the service tools for the at least some of the application layer services may be generated according to the analysis results to support the subsequent operation process based on the service tools.

[0073] In some embodiments, before step 101, it further includes: performing any one of the following processes: sending the service tool to the Internet of Things account of the Internet of Things platform, so that the Internet of Things account deploys the service tool into the Internet of Things application, and deploys the Internet of Things application with the deployed service tool to the Internet of Things device; deploying the service tool into the Internet of Things application, and sending the Internet of Things application with the deployed service tool to the Internet of Things account, so that the Internet of Things account deploys the Internet of Things application with the deployed service tool to the Internet of Things device; deploying the Internet of Things application with the deployed service tool to the Internet of Things device maintained by the Internet of Things account.

[0074] In the embodiments of the present application, at least some of the service tools corresponding to the application layer services in the Internet of Things platform may be opened, so as to realize the deployment of the Internet of Things application in the Internet of Things device. As an example, the following three methods are provided and will be described separately.

[0075] 1) Sending the service tool to the Internet of Things account of the Internet of Things platform. In this way, the user holding the Internet of Things account can deploy the service tool into the created Internet of Things application, and deploy the Internet of Things application with the deployed service tool to the Internet of Things device. For example, controlling the Internet of Things device to download and install the Internet of Things application with the deployed service tool. Compared with the method of developing the Internet of Things application from scratch, this method can reduce the development difficulty of the Internet of Things application, so as to perform convenient and effective device management and control. Among them, the Internet of Things account here may refer to the Internet of Things account held by the manufacturer (or manufacturer user) who manufactures / maintains the Internet of Things device.

[0076] 2) Deploy the service tool to the Internet of Things (IoT) application and send the IoT application with the deployed service tool to the IoT account. In this way, the user holding the IoT account can directly deploy the IoT application with the deployed service tool to the IoT device without developing the IoT application. This method can directly provide a ready-made IoT application to the IoT account, thus saving the development steps and is suitable for manufacturer users who lack development capabilities or development time.

[0077] 3) Deploy the service tool to the IoT application and deploy the IoT application with the deployed service tool to the IoT device maintained by the IoT account. This method provides a complete solution and is suitable for manufacturer users who lack device deployment capabilities or deployment time.

[0078] Through the above methods, the flexibility of deployment can be improved, and any of the above methods can be selected according to the user requirements in the actual application scenario.

[0079] In some embodiments, when receiving an application request initiated by the IoT application in the IoT device based on a communication connection, it further includes: receiving the signature result sent by the IoT device based on the communication connection; performing signature verification processing on the signature result according to the verification key corresponding to the IoT device to obtain a signature verification result; when the signature verification result is successful, determining to respond to the application request.

[0080] Here, the IoT platform stores the verification key corresponding to the IoT device. After establishing a communication connection with the IoT device through the IoT platform, it can receive the signature result sent by the IoT device based on the communication connection and perform signature verification processing on the signature result according to the stored verification key to obtain a signature verification result. When the obtained signature verification result is successful, it is determined to respond to the application request; when the obtained signature verification result is failed, it is determined not to respond to the application request. Responding to the application request here can refer to establishing a session based on the application request and invoking at least part of the application layer services in the IoT platform during the duration of the session; it can also refer to invoking at least part of the application layer services in the IoT platform during the duration of the session on the basis of an established session based on the application request. When it is determined not to respond to the application request, an error prompt can be sent to the IoT device based on the communication connection.

[0081] For example, when each Internet of Things (IoT) device leaves the factory, the manufacturer generates an asymmetric key pair corresponding to the IoT device. The asymmetric key pair includes a public key and a private key. The manufacturer can send the public key to the IoT platform for storage as a verification key, and at the same time perform signature processing based on the private key to obtain a signature result, and burn the signature result into the IoT device. In this way, after the IoT device establishes a communication connection with the IoT platform, it sends the burned signature result to the IoT platform based on the communication connection, so that the IoT platform performs signature verification processing (i.e., cloud signature verification) on the received signature result through the stored public key to determine whether the IoT device is legal. The embodiments of the present application do not limit the algorithm used to generate the asymmetric key pair. For example, it can be the RSA algorithm or the Elliptic Curve Cryptography (ECC) algorithm, etc.

[0082] It should be noted that in the case where the IoT platform includes a decoupled device layer and application layer, the device layer can receive the signature result sent by the IoT device based on the communication connection, perform signature verification processing on the signature result according to the verification key pair corresponding to the IoT device to obtain a signature verification result, and determine to respond to the application request when the signature verification result is successful. This process can be regarded as the device authentication service provided by the device layer, that is, a kind of device layer service.

[0083] Through the above method, the legality and security of the communication process between the IoT platform and the IoT device can be ensured.

[0084] In step 102, establish a session based on the application request.

[0085] When receiving an application request initiated by an IoT application in the IoT device based on the communication connection, establish a session based on the application request. The purpose of this session is to implement the response to the application request. It should be noted that in the case where the IoT platform includes a decoupled device layer and application layer, the device layer or the application layer can establish a session based on the application request.

[0086] In some embodiments, the number of IoT applications in the IoT device includes multiple, and different IoT applications are used to initiate different application requests. The above-mentioned establishment of a session based on the application request can be achieved in the following way: establish sessions based on different application requests respectively; where each session corresponds to one application request.

[0087] In an embodiment of the present application, a plurality of Internet of Things (IoT) applications may be deployed on an IoT device. The application layer services invoked by different IoT applications may be different or partially the same. In this case, each IoT application initiates an application request. When the IoT platform receives each application request, a session based on the application request is established, where each session corresponds to an application request. In this way, it is possible to ensure that the processing of different application requests is isolated from each other, thereby enhancing the security of the processing process.

[0088] In step 103, during the duration of the session, at least some of the application layer services in the IoT platform are invoked to respond to the application request.

[0089] During the duration of the session, at least some of the application layer services in the IoT platform (referring to at least some of the application layer services requested by the application request) are invoked to respond to the application request. When the response to the application request is completed, the session can be closed to save communication resources.

[0090] It should be noted that in the case where the IoT platform includes a decoupled device layer and application layer, at least some of the application layer services in the IoT platform can be invoked by the application layer to respond to the application request.

[0091] In some embodiments, after step 103, it further includes: receiving status parameters sent by the IoT device based on a communication connection and storing the status parameters in the device shadow corresponding to the IoT device in the IoT platform; where the status parameters are used to represent the invocation results of at least some of the application layer services; in response to a parameter acquisition operation of the IoT account of the IoT platform on the device shadow, sending the status parameters in the device shadow to the IoT account; in response to a parameter update operation of the IoT account on the device shadow, invoking at least some of the application layer services in the IoT platform to perform an update process on the status parameters in the device shadow; where the updated status parameters are used to be synchronized to the IoT device.

[0092] In the embodiments of the present application, the Internet of Things platform can provide a device shadow service (such as provided by the device layer). The device shadow can be in the form of a document (such as a JSON document) for storing the status parameters of Internet of Things devices. For example, after invoking at least some of the application layer services in the Internet of Things platform, the status parameters sent by the Internet of Things device can be received based on the communication connection (the status parameters can be sent periodically by the Internet of Things device), and the status parameters are stored in the device shadow corresponding to the Internet of Things device in the Internet of Things platform, where the device shadow is used to store the latest status parameters. The status parameters generally refer to the parameters generated during the operation of the Internet of Things device and can be used to reflect the invocation results of at least some of the application layer services, such as whether the invocation is successful. For example, when at least some of the application layer services are invoked successfully, a specific value in the status parameters of the Internet of Things device is updated from A to B. If the obtained value is B, it proves that the invocation is successful; if the obtained value is still A, it proves that the invocation fails.

[0093] When the Internet of Things platform receives a parameter acquisition operation for the device shadow from the Internet of Things account, the status parameters in the device shadow are sent to the Internet of Things account. In this way, when the communication connection between the Internet of Things platform and the Internet of Things device is unstable (such as unstable network), accurate status parameters can be sent to the Internet of Things account, facilitating the user holding the Internet of Things account to understand the invocation situation of at least some of the application layer services.

[0094] When the user holding the Internet of Things account is not satisfied with the invocation result represented by the status parameters, a parameter update operation for the device shadow can be sent to the Internet of Things platform through the Internet of Things account. When the Internet of Things platform receives this parameter update operation, at least some of the application layer services in the Internet of Things platform are re-invoked according to the application request (such as through the application layer) to update the status parameters in the device shadow during the invocation process. The updated status parameters in the device shadow are used to be synchronized to the Internet of Things device, that is, used to notify the Internet of Things device to apply the updated status parameters. In this way, the success rate of invoking at least some of the application layer services can be improved.

[0095] It should be noted that the Internet of Things platform can only respond to the parameter acquisition operation and parameter update operation initiated by specific Internet of Things accounts (such as the authorized Internet of Things accounts corresponding to the Internet of Things devices) to ensure security.

[0096] Such as Figure 3A As shown, by opening the service tools corresponding to at least some of the application layer services in the embodiments of the present application, the development difficulty of Internet of Things applications can be reduced, thereby improving the efficiency and effectiveness of device management and control.

[0097] In some embodiments, refer to Figure 3B , Figure 3BIt is a schematic flowchart of a device control method based on an Internet of Things platform provided by an embodiment of the present application. Based on Figure 3A After step 101, in step 201, the request information in the application request may further be subjected to a permission verification process to obtain a permission verification result; wherein, the request information is used to represent at least one of an Internet of Things device, an Internet of Things application, at least some application layer services, and an Internet of Things account of the Internet of Things platform.

[0098] Here, the Internet of Things platform may perform a permission verification process on the information carried in the application request (for the sake of distinction, hereinafter referred to as request information) to obtain a permission verification result, and the permission verification result is used to indicate whether the application request is eligible to invoke at least some application layer services. The permission verification process may be implemented through the application layer of the Internet of Things platform.

[0099] Among them, the request information is used to represent at least one of an Internet of Things device, an Internet of Things application, at least some application layer services, and an Internet of Things account (such as the account held by the user using the Internet of Things device) of the Internet of Things platform.

[0100] In some embodiments, the above-mentioned permission verification process for the request information in the application request to obtain a permission verification result may be implemented in the following manner: perform at least one of the following processes: when the request information is used to represent an Internet of Things device and an Internet of Things application, query the authorized Internet of Things applications corresponding to the Internet of Things device, perform an application matching process on the Internet of Things application and the authorized Internet of Things applications, and determine the permission verification result according to the obtained application matching result; when the request information is used to represent an Internet of Things application and at least some application layer services, query the authorized application layer services corresponding to the Internet of Things application, perform a service matching process on at least some application layer services and the authorized application layer services, and determine the permission verification result according to the obtained service matching result; when the request information is used to represent an Internet of Things device and an Internet of Things account, query the authorized Internet of Things accounts corresponding to the Internet of Things device, perform an account matching process on the Internet of Things account and the authorized Internet of Things accounts, and determine the permission verification result according to the obtained account matching result.

[0101] Here, several example ways of the permission verification process are provided.

[0102] 1) When the request information is used to represent an Internet of Things (IoT) device and an IoT application, query the IoT applications that the IoT device is authorized to run (i.e., the IoT applications that are allowed to run) in the IoT platform, and perform an application matching process between the IoT application represented by the request information and the authorized IoT applications. Determine the permission verification result based on the obtained application matching result. Among them, the authorized IoT applications corresponding to each IoT device can be freely set according to the actual application scenario, and each IoT device can correspond to one or more authorized IoT applications. The application matching process can be to match the application identifier of the IoT application in the request information with the application identifiers of the authorized IoT applications. When the application identifier of the IoT application in the request information is the same as the application identifier of any one of the authorized IoT applications, determine that the application matching result is successful; when the application identifier of the IoT application in the request information is different from the application identifiers of all the authorized IoT applications, determine that the application matching result is failed. It should be noted that this method can be regarded as the application authentication service provided by the application layer of the IoT platform, that is, to verify whether the IoT device is eligible to run the IoT application.

[0103] 2) When the request information is used to represent an IoT application and the application layer services to be invoked (i.e., at least some application layer services), query the authorized application layer services that the IoT application is authorized to call (i.e., the application layer services that are allowed to be called) in the IoT platform, and perform a service matching process between the application layer services represented by the request information and the authorized application layer services. Determine the permission verification result based on the obtained service matching result. Similarly, the authorized application layer services corresponding to each IoT application can be freely set according to the actual application scenario, and each IoT application can correspond to one or more authorized application layer services. The service matching process can be to match the service identifier of the application layer service in the request information with the service identifiers of the authorized application layer services. When the service identifier of the application layer service in the request information is the same as the service identifier of any one of the authorized application layer services, determine that the service matching result is successful; when the service identifier of the application layer service in the request information is different from the service identifiers of all the authorized application layer services, determine that the service matching result is failed. It should be noted that this method can be regarded as the service authentication service provided by the application layer of the IoT platform, that is, to verify whether the IoT application is eligible to call the application layer services.

[0104] 3) When the request information is used to represent an IoT device and an IoT account (i.e., the account held by the user who is using the IoT device), query the authorized IoT accounts corresponding to the IoT device in the IoT platform (i.e., the accounts authorized to use the IoT device), and perform account matching processing on the IoT account represented by the request information and the authorized IoT accounts. Determine the permission verification result based on the obtained account matching result. Similarly, the authorized IoT accounts corresponding to each IoT device can be freely set according to the actual application scenario, and each IoT device can correspond to one or more authorized IoT accounts. The account matching processing can be to match the account identifier (such as the account name, or including both the account name and the account password) of the IoT account in the request information with the account identifiers of the authorized IoT accounts. When the account identifier of the IoT account in the request information is the same as the account identifier of any one of the authorized IoT accounts, determine that the account matching result is successful; when the account identifier of the IoT account in the request information is different from the account identifiers of all the authorized IoT accounts, determine that the account matching result is failed. It should be noted that this method can be regarded as the account authentication service provided by the application layer of the IoT platform, that is, to verify whether the IoT account is eligible to use the IoT device.

[0105] Any one of the above three methods can be selected for application, and the obtained matching result (such as the application matching result, the service matching result, or the account matching result) is directly used as the permission verification result. Or, the above three methods can also be combined for application, and the permission verification result is comprehensively determined according to the matching results obtained by each combined method. For example, in the case of combining the above method (1) and method (2), when both the application matching result and the service matching result are successful, determine that the permission verification result is successful; when at least one of the application matching result and the service matching result is failed, determine that the permission verification result is failed. In this way, the flexibility and accuracy of the permission verification processing can be improved.

[0106] In step 202, when the permission verification result is successful, determine to respond to the application request.

[0107] When the permission verification result is successful, determine to respond to the application request; when the permission verification result is failed, determine not to respond to the application request. Responding to the application request here can refer to establishing a session based on the application request and invoking at least some of the application layer services in the IoT platform during the duration of the session; it can also refer to invoking at least some of the application layer services in the IoT platform during the duration of the session on the basis of an established session based on the application request. Among them, when determining not to respond to the application request, an error prompt can be sent to the IoT device based on the communication connection.

[0108] Such as Figure 3BAs shown, the embodiment of the present application can determine whether the application request is legal through permission verification processing, thereby improving the security of device management.

[0109] In some embodiments, see Figure 3C , Figure 3C is a flow chart of a device management and control method based on an Internet of Things platform provided in an embodiment of the present application, Figure 3A The illustrated step 103 may be implemented by at least one of steps 401 to 404 , which will be described in conjunction with each step.

[0110] In step 401, when at least part of the application layer services include communication services, multimedia communication between the IoT device and the communication object is performed during the duration of the session; wherein the communication object includes an IoT account of the IoT platform and at least one of the IoT devices that are different from the IoT devices.

[0111] Here, when the application layer service requested by the application request includes a communication service, multimedia communication is performed between the IoT device and a communication object (which may be the communication object specified by the application request), wherein the communication object includes an IoT account of the IoT platform and at least one of the IoT devices that is different from the IoT device that initiates the application request.

[0112] The multimedia communication here refers to a communication process for transmitting multimedia data. The multimedia data may include at least one of text (or message), image, video and audio, but is not limited thereto.

[0113] In some embodiments, the above-mentioned multimedia communication between the IoT device and the communication object during the duration of the session can be achieved in the following way: at least one of the following processing is performed during the duration of the session: sending the first multimedia data in the application request to the communication object; obtaining the second multimedia data sent by the communication object, and sending the second multimedia data to the IoT device based on the communication connection.

[0114] In the embodiments of the present application, the multimedia communication can be one-way. For example, the multimedia data in the application request (named as the first multimedia data for easy distinction) is sent to the communication object. For example, the Internet of Things device needs to report the collected data to the communication object for real-time data detection by the communication object; or, the multimedia data sent by the communication object (named as the second multimedia data for easy distinction) is obtained and sent to the Internet of Things device based on the communication connection. For example, the Internet of Things device needs to pull data from the communication object to ensure normal subsequent operation. The multimedia communication can also be two-way, that is, it can support the transmission of the above-mentioned first multimedia data and second multimedia data simultaneously. Through the above method, the flexibility of multimedia communication can be improved, and it is applicable to various communication scenarios.

[0115] In step 402, when at least part of the application layer services include payment services, the payment information in the application request is matched with the set payment information during the duration of the session, and the payment operation is performed when the obtained payment information matching result is successful.

[0116] Here, when the application layer service requested by the application request includes a payment service, the payment information in the application request is matched with the set payment information (i.e., the payment information eligible to perform the payment operation). The payment information here can include at least one of a password, a fingerprint, and a face image, but is not limited thereto.

[0117] When the payment information in the application request is the same as the set payment information, it can be determined that the payment information matching result is successful; when the payment information in the application request is different from the set payment information, it can be determined that the payment information matching result is failed, which is applicable to the scenario where the payment information is a password.

[0118] Or, when the similarity between the payment information in the application request and the set payment information is greater than the similarity threshold, it can be determined that the payment information matching result is successful; when the similarity between the payment information in the application request and the set payment information is less than or equal to the similarity threshold, it can be determined that the payment information matching result is failed, which is applicable to the scenario where the payment information is a fingerprint and / or a face image.

[0119] When the obtained payment information matching result is successful, the payment operation is performed; when the obtained payment information matching result is failed, the execution of the payment operation is prohibited. The embodiments of the present application do not limit the execution manner of the payment operation. For example, it can be to deduct the balance of a specified account (including but not limited to the Internet of Things account).

[0120] In step 403, when at least some of the application layer services include a question-and-answer service, during the duration of the session, the question in the application request is processed for answering to obtain an answer, and the answer is sent to the Internet of Things device based on the communication connection.

[0121] Here, when the application layer service requested by the application request includes a question-and-answer service, the question in the application request is processed for answering to obtain an answer. The embodiments of the present application do not limit the manner of answering processing. For example, it can be implemented through an Artificial Intelligence (AI) model, such as a Transformer model. After obtaining the answer through the answering processing, the answer is sent to the Internet of Things device based on the communication connection, thereby completing the complete question-and-answer process.

[0122] In step 404, when at least some of the application layer services include a login service, during the duration of the session, the login information in the application request is matched with the set login information for login information matching processing, and when the obtained login information matching result is successful, the login state of the Internet of Things application is entered.

[0123] Here, when the application layer service requested by the application request includes a login service, the login information in the application request is matched with the set login information (i.e., the login information with the permission to enter the login state) for login information matching processing, and when the obtained login information matching result is successful, it is determined to enter the login state of the Internet of Things application. Among them, the login information may include an account name and an account password, but is not limited thereto. When the login information in the application request is the same as the set login information, it is determined that the login information matching result is successful; when the login information in the application request is different from the set login information, it is determined that the login information matching result is failed. Of course, the manner of login information matching processing is not limited thereto.

[0124] Compared with the non-login state, the login state can support the use of more functions in the Internet of Things application. For example, the user can request to call more application layer services.

[0125] Such as Figure 3C shown, the embodiments of the present application provide various examples of application layer services, which can improve the flexibility of invocation and are applicable to different application scenarios.

[0126] In some embodiments, referring to Figure 3D , Figure 3D is a schematic flowchart of the active control at the device level provided by the embodiments of the present application, which can be executed between any steps shown in Figure 3A , and will be described in conjunction with each step shown in Figure 3D .

[0127] In step 301, in response to the management and control operation of the IoT account of the IoT platform on the IoT device, the authorized IoT account corresponding to the IoT device is queried.

[0128] In the embodiments of the present application, in addition to supporting application-level device control, device-level device control can also be supported. For example, when receiving a control operation of an IoT account on an IoT device, the authorized IoT account corresponding to the IoT device is queried. The authorized IoT account here refers to an IoT account that has the right to perform device-level device control on the IoT device, such as an IoT account held by the manufacturer of the IoT device. The number of authorized IoT accounts can be one or more.

[0129] In step 302, the IoT account is matched with the authorized IoT account to obtain an account matching result.

[0130] For example, when the account ID of the IoT account that initiates the management and control operation is the same as the account ID of any authorized IoT account, the account matching result is determined to be a successful match; when the account ID of the IoT account that initiates the management and control operation is different from the account IDs of all authorized IoT accounts, the account matching result is determined to be a failed match.

[0131] It is worth noting that the above steps 301 and 302 can be implemented by the application layer of the Internet of Things platform.

[0132] In step 303, when the account matching result is successful, a management and control operation for the IoT device is performed.

[0133] For example, when the account matching result is successful, the control operation for the IoT device is performed; when the account matching result is failed, the control operation for the IoT device is prohibited. The control operation here refers to the control operation at the device level, which can be implemented by the device layer of the IoT platform.

[0134] In some embodiments, the above-mentioned execution of management and control operations on IoT devices can be achieved by performing at least one of the following processing: disabling or unbanning IoT devices in the IoT platform; disconnecting the communication connection between the IoT platform and the IoT device; obtaining the status parameters of the IoT device; and sending control instructions to the IoT device based on the communication connection, so that the IoT device executes the received control instructions.

[0135] Here, several example ways to perform control operations are provided.

[0136] 1) Disable / unlock an IoT device in the IoT platform. For example, disabling an IoT device may mean prohibiting the establishment of a communication connection with the IoT device until it is unlocked; disabling an IoT device may also mean prohibiting the sending of data to the IoT device through the IoT platform, but the IoT platform can obtain data from the IoT device.

[0137] 2) Disconnect the communication connection between the IoT platform and the IoT device.

[0138] 3) Obtain the status parameters of the IoT device. For example, the status parameters sent by the IoT device can be received based on the established communication connection, or the status parameters can be read from the device shadow (corresponding to the IoT device) of the IoT platform.

[0139] 4) Send a control instruction to the IoT device based on the communication connection so that the IoT device executes the received control instruction. Among them, the control instruction can be in the form of a device model or other forms, which is not limited. The device model is the digital representation of an entity in the physical space (such as a sensor, a vehicle-mounted device, a building, a factory, etc.) in the cloud.

[0140] Through the above methods, the flexibility of device management and control at the device level can be improved, which is suitable for diverse requirements.

[0141] Such as Figure 3D As shown, through the account matching process in the embodiments of the present application, the security of device management and control at the device level can be improved, and illegal accounts can be effectively prevented from performing illegal management and control on IoT devices.

[0142] In some embodiments, referring to Figure 3E , Figure 3E is a schematic flowchart of a device management and control method based on an IoT platform provided by the embodiments of the present application. After step 101 shown in Figure 3A , in step 501, the device identifier of the IoT device and the application identifier of the IoT application in the application request can be combined to obtain the session identifier of the session.

[0143] In the embodiments of the present application, multiple IoT applications may be deployed in an IoT device. Therefore, in order to achieve mutual isolation between multiple IoT applications, when receiving an application request initiated by an IoT application in the IoT device based on the communication connection, the device identifier of the IoT device and the application identifier of the IoT application carried in the application request can be combined (for example, concatenated) to obtain the session identifier of the session.

[0144] For example, when the Internet of Things device is a payment device, a payment application and a mini-program application are deployed in the payment device. Among them, the payment application is used to trigger a payment operation, and the mini-program application is used to query preferential information such as coupons and memberships. During the process of a user using the payment device for payment, the payment device will run the payment application and the mini-program application simultaneously, and the running payment application and mini-program application will initiate application requests respectively. For the Internet of Things platform, when receiving the application requests corresponding to the payment application and the mini-program application respectively, it generates a session identifier of "device identifier of the payment device + application identifier of the payment application" and a session identifier of "device identifier of the payment device + application identifier of the mini-program application". Different session identifiers correspond to different sessions, so that the application requests corresponding to the payment application and the mini-program application can be separately responded to. In this case, each session identifier includes the device identifier of an Internet of Things device and the application identifier of an Internet of Things application.

[0145] In Figure 3E In, after step 101 shown in Figure 3A it is also possible to perform combined processing on the device identifier of the Internet of Things device, the application identifier of the Internet of Things application, and the account identifier of the Internet of Things account in the application request in step 502 to obtain the session identifier of the session.

[0146] In the embodiments of the present application, a user may also use different Internet of Things applications in different Internet of Things devices at the same time. For example, in a vehicle-mounted scenario, when the user is using the vehicle-mounted navigation application in the vehicle-mounted navigation device for vehicle navigation, the user is also using the intelligent Q&A application in the vehicle-mounted audio device for AI Q&A. In response to this, combined processing can be performed on the device identifier of the Internet of Things device, the application identifier of the Internet of Things application, and the account identifier of the Internet of Things account (referring to the account held by the user using the Internet of Things device) in the application request to obtain the session identifier of the session. For example, the form of the session identifier can be "device identifier of the Internet of Things device + application identifier of the Internet of Things application + account identifier of the Internet of Things account", that is, each session identifier includes the device identifier of an Internet of Things device, the application identifier of an Internet of Things application, and the account identifier of an Internet of Things account.

[0147] It should be noted that steps 501 and 502 can be implemented by the device layer or the application layer of the Internet of Things platform.

[0148] As Figure 3E shown, the embodiments of the present application provide two forms of session identifiers, which can effectively isolate identities, data, and ability permissions, and ensure that application requests can be safely and smoothly responded to.

[0149] In some embodiments, referring to Figure 3F , Figure 3FIt is a schematic flowchart of a device control method based on an Internet of Things platform provided by an embodiment of the present application. Figure 3A Step 101 shown can be updated to step 601. In step 601, at least part of the device layer services in the Internet of Things platform are called through the device layer to establish a communication connection with the Internet of Things device, and an application request initiated by the Internet of Things application in the Internet of Things device is received based on the communication connection; wherein, at least part of the service tools corresponding to the application layer services in the Internet of Things platform are deployed in the Internet of Things application, and the service tools are used to generate the application request.

[0150] In an embodiment of the present application, the Internet of Things platform may include a decoupled device layer and an application layer. Among them, the device layer is used to provide device layer services, and the application layer is used to provide application layer services.

[0151] For the Internet of Things device, at least part of the device layer services in the Internet of Things platform can be called through the device layer to establish a communication connection with the Internet of Things device, and an application request initiated by the Internet of Things application in the Internet of Things device is received based on the communication connection. Among them, the service tools corresponding to the at least part of the device layer services can be deployed in the Internet of Things device to trigger the call of the at least part of the device layer services.

[0152] In Figure 3F medium, Figure 3A Step 102 shown can be updated to step 602. In step 602, a session based on the application request is established through the application layer.

[0153] Here, a session based on the application request can be established through the application layer.

[0154] In Figure 3F medium, Figure 3A Step 103 shown can be updated to step 603. In step 603, during the duration of the session, at least part of the application layer services in the Internet of Things platform are called through the application layer to respond to the application request.

[0155] Here, during the duration of the session, at least part of the application layer services in the Internet of Things platform are called through the application layer to respond to the application request. The call process of at least part of the application layer services can refer to the above example.

[0156] Such as Figure 3F shown, the embodiment of the present application realizes a SAAS platform through a decoupled device layer and application layer, which can improve the orderliness and effectiveness of device control.

[0157] Next, the exemplary application of the embodiments of the present application in an actual application scenario will be described. First, the solution provided by the related art will be introduced. In the solution provided by the related art, the design purpose of the Internet of Things platform is to provide access capabilities for applications in the manufacturer's Internet of Things devices and to achieve efficient communication between the Internet of Things devices and the manufacturer's background. Essentially, this solution is actually implemented on the premise of deploying a single application developed by the manufacturer for a single Internet of Things device. Therefore, the solution provided by the related art has at least the following problems: 1) An Internet of Things device has only one device identifier. In the solution provided by the related art, only the device identifier is used to identify the identity, which will result in the inability to achieve account-level isolation in aspects such as data storage, capability permission control, and logic function development, and there are security problems such as data leakage and insufficient permission granularity; 2) The solution provided by the related art focuses on providing the IoT basic capabilities of the Internet of Things devices for the manufacturer (such as the ability to establish a communication connection with the Internet of Things device), that is, the Internet of Things platform belongs to the PaaS platform, resulting in the inability to implement the supporting basic capabilities based on application-level users; 3) The manufacturer needs to develop its own manufacturer application based on the request routing and distribution capabilities provided by the Internet of Things platform, facing problems such as high development threshold, low efficiency, and long duration, and unable to achieve convenient and effective device management.

[0158] In response to this, the embodiments of the present application provide an Internet of Things platform that decouples the device layer and the application layer. This Internet of Things platform is a SAAS platform and can implement multi-level capabilities (or services) from the operating system to the solution. For manufacturers, they can choose which levels of capabilities to use according to their own development capabilities and / or requirements. As an example, a schematic diagram as Figure 4 shown will be used to separately illustrate each level of the Internet of Things platform.

[0159] 1) Operating system layer. Here, highly encapsulated SDKs for multiple operating systems such as Android, Linux, iOS, and Windows are provided. Manufacturers can select the SDK corresponding to the operating system they need to use and embed it into the Internet of Things device, so that the Internet of Things device can efficiently and conveniently access the Internet of Things platform.

[0160] 2) Device layer. The device layer services provided by the device layer may include device management and control services and message management services. Among them, the device management and control services may include device management services and device control services. The device management services such as device banning (disabling), device offline (i.e., disconnecting the communication connection between the IoT platform and the IoT device), and device networking (i.e., establishing the communication connection between the IoT platform and the IoT device), etc. The device control services such as controlling the IoT device through control instructions (such as the device model or other forms of instructions); The message management services such as message routing (such as forwarding the messages received from the IoT device to a specific IoT account) and request transfer (such as forwarding the requests received from the IoT device to a specific application layer service), etc. It should be noted that the device layer services in the embodiments of the present application may run continuously or start running when triggered (such as triggered by a specific IoT account).

[0161] As an example, the device layer services provided by the embodiments of the present application will be described in conjunction with Figure 4 : ① Lifecycle: Used to store a series of changes of the IoT device after leaving the factory, such as whether it is activated (i.e., whether the signature verification result is successful), whether it is banned, etc.; ② Device status: Used to represent the status parameters of the device. For example, when the IoT device is an air conditioner, the status parameter may be the temperature of the air conditioner; ③ Device authentication: For example, for each IoT device, a corresponding asymmetric key pair including a public key and a private key may be generated (such as generated by the manufacturer). The public key is used to store in the IoT platform, and the private key is used to sign to obtain a signature result. This signature result is used to burn into the IoT device. In this way, the signature verification process (i.e., cloud signature verification) can be performed on the signature result sent by the IoT device according to the public key in the IoT platform to determine whether the IoT device is legal, so as to determine whether to activate the IoT device; ④ Remote control: By sending control instructions to the IoT device, the remote control of the IoT device can be realized; ⑤ Log service: Used to store the logs generated during the operation of the IoT device; ⑥ Over-The-Air (OTA): Remotely manage the data in the IoT device through OTA technology, such as upgrading the version of the IoT application in the IoT device; ⑦ Data protection: Protect various data related to the IoT device; ⑧ Device shadow: Used to store the status parameters of the IoT device to respond to the parameter acquisition operation of the IoT account; At the same time, it also supports the update process of the status parameters in the device shadow, and the updated status parameters are used to synchronize to the IoT device.

[0162] 3) Application layer. The application layer is used to provide application layer services that support the operation of IoT applications. It will be described in conjunction with Figure 4Describe the application layer services provided in the embodiments of the present application: ① Application authentication: used to restrict which Internet of Things (IoT) applications an IoT device can run (corresponding to the authorized IoT applications in the above text). For example, a certain IoT application can only run on an IoT device that has been activated and permitted to be deployed by a user (or IoT account). ② Service authentication: used to restrict which application layer services an IoT application can run (or integrate with) (corresponding to the authorized application layer services in the above text). ③ User binding: binds a user (or IoT account) to an IoT device, enabling the user to perform control operations on the IoT device, such as turning on, turning off, and obtaining status parameters. The IoT account bound to the IoT device corresponds to the authorized IoT account in the above text. ④ Application login: For example, perform a login information matching process on the login information (such as including an account and password) carried in the application request sent by the IoT device and the set login information, and enter the login state of the IoT application when the obtained login information matching result is successful, that is, determine that the login is successful. ⑤ Message communication: Supports message communication between an IoT device and a communication object, where the communication object includes at least one of an IoT account on the IoT platform and an IoT device different from the IoT device. ⑥ Audio and video call: Supports audio and video calls between an IoT device and a communication object. ⑦ Third-party push notification: A third party (such as a manufacturer) can send a specific notification (such as multimedia data) to the IoT device through a specific IoT account (such as the authorized IoT account in the above text). ⑧ Instant messaging: Supports instant messaging between an IoT device and a communication object.

[0163] It should be noted that for the operating system layer, device layer, and application layer, corresponding capabilities (or services) can be provided through the encapsulated SDK, that is, by embedding the SDK in the IoT device, so that the IoT device can use the corresponding capabilities in the IoT platform.

[0164] In the embodiments of the present application, a ready-made IoT application can also be directly provided. The IoT application is deployed (such as integrated) with the SDK corresponding to at least part of the application layer services. IoT applications include device control applications, applet hardware framework applications, in-vehicle instant messaging applications, AI Q&A applications, payment applications, smart home applications, etc. In this way, the manufacturer does not need to perform additional development and can directly deploy (such as download and install) the IoT application on the IoT device. In addition, for manufacturers without device manufacturing capabilities, a complete solution can also be provided, that is, an IoT device deployed with an IoT application (the IoT application is deployed with the SDK corresponding to at least part of the application layer services), and the manufacturer can directly use it.

[0165] It should be noted that for an IoT application integrated with an SDK corresponding to an application layer service, multiple IoT applications can be deployed on the same IoT device, so that the IoT device can call multiple application layer services in the IoT platform.

[0166] In addition, in the solution provided by the related technology, the capabilities related to the application layer account are not provided, and there is no problem of multiple sessions of the device account in the corresponding single-device single-application mode. In the embodiments of the present application, multiple IoT applications may be deployed on the IoT device at the same time. In view of this, a new ID can be generated in the way of two-dimensional combination of device_id (i.e., device identifier) + app_id (i.e., application identifier) as the session ID (i.e., session identifier) to identify the identity of an IoT device on an IoT application. Since the app_id factor is included in the session ID, the session IDs corresponding to different IoT applications in the same IoT device are different. Based on this, isolation of device data and capability permissions between different applications on the same device can be realized. For example, two IoT applications are deployed on a face recognition payment device, one of which is a face recognition payment application for triggering payment operations, and the other is a mini-program application for querying coupons, membership information, etc. Through the above method, these two IoT applications can each generate a session, so as to achieve isolation while ensuring the smooth operation of these two IoT applications.

[0167] At the same time, for ordinary applications that are not IoT (such as mobile phone applications), there is no need to use different applications of multiple devices with the same account. In the embodiments of the present application, on the basis of providing the basic capabilities of IoT-based accounts and supporting applications, the same IoT account may be used simultaneously on multiple devices and multiple applications. In view of this, the embodiments of the present application provide a schematic diagram of the session hierarchical architecture as Figure 5 shown, as Figure 5 shown, device_id + app_id + user_id (i.e., account identifier) can be used as the session ID. Since the session ID includes three factors, flexible combination of three layers of device, application, and account can be realized, ensuring that each instance has a corresponding session and greatly improving the expansion ability of the session.

[0168] The embodiments of the present application can at least achieve the following technical effects: 1) Provide a multi-level capability architecture from the operating system to the solution to realize the SAAS platform of IoT; 2) Realize the isolation of identity, data, and capability permissions between different applications on the same device by creating independent IDs for the identities of the same IoT device on different IoT applications; 3) Realize the ability to simultaneously log in the same IoT account (or user account) on different devices and different applications through the session hierarchical architecture of device, application, and account.

[0169] Next, the exemplary structure of the device control device 455 provided in the embodiments of the present application implemented as a software module based on the Internet of Things platform will be further described. In some embodiments, as Figure 2 shown, the software module in the device control device 455 based on the Internet of Things platform stored in the memory 450 may include: a connection module 4551, configured to establish a communication connection with an Internet of Things device through the Internet of Things platform, and receive an application request initiated by an Internet of Things application in the Internet of Things device based on the communication connection; wherein, the Internet of Things application deploys service tools corresponding to at least part of the application layer services in the Internet of Things platform, and the service tools are used to generate application requests; a session establishment module 4552, configured to establish a session based on the application request; a session response module 4553, configured to call at least part of the application layer services in the Internet of Things platform during the duration of the session to respond to the application request.

[0170] In some embodiments, the device control device 455 based on the Internet of Things platform further includes a permission module, configured to: perform a permission verification process on the request information in the application request to obtain a permission verification result; when the permission verification result is successful, determine to respond to the application request; wherein, the request information is used to represent at least one of an Internet of Things device, an Internet of Things application, at least part of the application layer services, and an Internet of Things account of the Internet of Things platform.

[0171] In some embodiments, the permission module is further configured to: perform at least one of the following processes: when the request information is used to represent an Internet of Things device and an Internet of Things application, query the authorized Internet of Things applications corresponding to the Internet of Things device, perform an application matching process on the Internet of Things application and the authorized Internet of Things applications, and determine the permission verification result according to the obtained application matching result; when the request information is used to represent an Internet of Things application and at least part of the application layer services, query the authorized application layer services corresponding to the Internet of Things application, perform a service matching process on at least part of the application layer services and the authorized application layer services, and determine the permission verification result according to the obtained service matching result; when the request information is used to represent an Internet of Things device and an Internet of Things account, query the authorized Internet of Things accounts corresponding to the Internet of Things device, perform an account matching process on the Internet of Things account and the authorized Internet of Things accounts, and determine the permission verification result according to the obtained account matching result.

[0172] In some embodiments, the session response module 4553 is further configured to perform at least one of the following processes: when at least part of the application layer services include communication services, perform multimedia communication between the IoT device and the communication object; wherein the communication object includes at least one of the IoT account of the IoT platform and an IoT device different from the IoT device; when at least part of the application layer services include payment services, perform payment information matching processing on the payment information in the application request and the set payment information, and perform a payment operation when the obtained payment information matching result is successful; when at least part of the application layer services include Q&A services, perform response processing on the question in the application request to obtain an answer, and send the answer to the IoT device based on the communication connection; when at least part of the application layer services include login services, perform login information matching processing on the login information in the application request and the set login information, and determine to enter the login state of the IoT application when the obtained login information matching result is successful.

[0173] In some embodiments, the session response module 4553 is further configured to perform at least one of the following processes: send the first multimedia data in the application request to the communication object; obtain the second multimedia data sent by the communication object, and send the second multimedia data to the IoT device based on the communication connection.

[0174] In some embodiments, the device management device 455 based on the IoT platform further includes a management module, configured to: in response to the management operation of the IoT account of the IoT platform on the IoT device, query the authorized IoT account corresponding to the IoT device; perform account matching processing on the IoT account and the authorized IoT account to obtain an account matching result; when the account matching result is successful, perform the management operation on the IoT device.

[0175] In some embodiments, the management module is further configured to perform at least one of the following processes: disable or lift the ban on the IoT device in the IoT platform; disconnect the communication connection between the IoT platform and the IoT device; obtain the status parameters of the IoT device; send a control instruction to the IoT device based on the communication connection so that the IoT device executes the received control instruction.

[0176] In some embodiments, the session establishment module 4552 is further configured to perform any one of the following processes: perform combination processing on the device identifier of the IoT device and the application identifier of the IoT application in the application request to obtain a session identifier of the session; perform combination processing on the device identifier of the IoT device, the application identifier of the IoT application, and the account identifier of the IoT account in the application request to obtain a session identifier of the session; wherein the session identifier is used to distinguish different sessions.

[0177] In some embodiments, the Internet of Things (IoT) platform includes a device layer and an application layer; the connection module 4551 is further configured to call at least some of the device layer services in the IoT platform through the device layer to establish a communication connection with the IoT device; the session response module 4553 is further configured to call at least some of the application layer services in the IoT platform through the application layer.

[0178] In some embodiments, the device management and control device 455 based on the IoT platform further includes a deployment module, configured to: perform any one of the following processes: send a service tool to an IoT account of the IoT platform, so that the IoT account deploys the service tool to an IoT application, and deploy the IoT application with the deployed service tool to an IoT device; deploy the service tool to the IoT application, and send the IoT application with the deployed service tool to the IoT account, so that the IoT account deploys the IoT application with the deployed service tool to the IoT device; deploy the IoT application with the deployed service tool to the IoT device maintained by the IoT account.

[0179] In some embodiments, the device management and control device 455 based on the IoT platform further includes a signature verification module, configured to: receive a signature result sent by the IoT device based on the communication connection; perform a signature verification process on the signature result according to a verification key corresponding to the IoT device to obtain a signature verification result; when the signature verification result is successful, determine to respond to the application request.

[0180] In some embodiments, the device management and control device 455 based on the IoT platform further includes a synchronization module, configured to: receive status parameters sent by the IoT device based on the communication connection, and store the status parameters in a device shadow corresponding to the IoT device in the IoT platform; wherein, the status parameters are used to represent the call results of at least some of the application layer services; in response to a parameter acquisition operation of an IoT account of the IoT platform on the device shadow, send the status parameters in the device shadow to the IoT account; in response to a parameter update operation of the IoT account on the device shadow, call at least some of the application layer services in the IoT platform to update the status parameters in the device shadow; wherein, the updated status parameters are used to be synchronized to the IoT device.

[0181] An embodiment of the present application provides a computer program product or a computer program, which includes computer instructions (i.e., executable instructions), and the computer instructions are stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes the above-mentioned device management and control method based on the IoT platform in the embodiments of the present application.

[0182] An embodiment of the present application provides a computer-readable storage medium storing executable instructions that, when executed by a processor, cause the processor to execute the method provided by the embodiment of the present application. For example, as Figure 3A , Figure 3B , Figure 3C , Figure 3E and Figure 3F shown in the device control method based on the Internet of Things platform.

[0183] In some embodiments, the computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, flash memory, magnetic surface memory, optical disc, or CD-ROM; or may be various devices including one or any combination of the above memories.

[0184] In some embodiments, the executable instructions may be in the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including being deployed as an independent program or being deployed as a module, component, subroutine, or other unit suitable for use in a computing environment.

[0185] As an example, the executable instructions may or may not correspond to a file in the file system, may be stored as part of a file that stores other programs or data. For example, they may be stored in one or more scripts in a HyperText Markup Language (HTML) document, stored in a single file dedicated to the program being discussed, or stored in multiple cooperating files (e.g., files that store one or more modules, subroutines, or portions of code).

[0186] As an example, the executable instructions may be deployed to be executed on one electronic device, or on multiple electronic devices located at one location, or on multiple electronic devices distributed at multiple locations and interconnected by a communication network.

[0187] The above are only embodiments of the present application and are not intended to limit the protection scope of the present application. Any modifications, equivalent replacements, and improvements made within the spirit and scope of the present application are included in the protection scope of the present application.

Claims

1. A device control method based on the Internet of Things platform, characterized in that, The method includes: Establishing a communication connection with an Internet of Things (IoT) device through an IoT platform, and receiving an application request initiated by an IoT application in the IoT device based on the communication connection; Wherein, at least part of the service tools corresponding to the application layer services in the IoT platform are deployed in the IoT application, and the service tools are used to generate the application request; Establishing a session based on the application request and performing any one of the following processes: Performing a combined process on the device identifier of the IoT device and the application identifier of the IoT application in the application request to obtain a session identifier of the session; Performing a combined process on the device identifier of the IoT device, the application identifier of the IoT application, and the account identifier of an IoT account in the application request to obtain a session identifier of the session, where the IoT account is an account held by a user using the IoT device, and the session identifier is used to distinguish different sessions; During the duration of the session, invoking at least part of the application layer services in the IoT platform to respond to the application request.

2. The method according to claim 1, characterized in that, The method further includes: Performing a permission verification process on the request information in the application request to obtain a permission verification result; When the permission verification result is successful, determining to respond to the application request; Wherein, the request information is used to represent at least one of the IoT device, the IoT application, at least part of the application layer services, and the IoT account of the IoT platform.

3. The method according to claim 2, characterized in that, The performing a permission verification process on the request information in the application request to obtain a permission verification result includes: Performing at least one of the following processes: When the request information is used to represent the IoT device and the IoT application, querying the authorized IoT applications corresponding to the IoT device, performing an application matching process between the IoT application and the authorized IoT applications, and determining the permission verification result according to the obtained application matching result; When the request information is used to represent the IoT application and at least part of the application layer services, querying the authorized application layer services corresponding to the IoT application, performing a service matching process between at least part of the application layer services and the authorized application layer services, and determining the permission verification result according to the obtained service matching result; When the request information is used to represent the IoT device and the IoT account, querying the authorized IoT accounts corresponding to the IoT device, performing an account matching process between the IoT account and the authorized IoT accounts, and determining the permission verification result according to the obtained account matching result.

4. The method according to claim 1, characterized in that The invoking at least part of the application layer services in the IoT platform includes: Performing at least one of the following processes: When at least part of the application layer services includes a communication service, performing multimedia communication between the IoT device and a communication object; wherein, the communication object includes at least one of the IoT account of the IoT platform and an IoT device different from the IoT device; When at least part of the application layer services include payment services, perform payment information matching processing on the payment information in the application request and the set payment information, and perform a payment operation when the obtained payment information matching result is successful; When at least part of the application layer services include Q&A services, perform response processing on the question in the application request to obtain an answer, and send the answer to the IoT device based on the communication connection; When at least part of the application layer services include login services, perform login information matching processing on the login information in the application request and the set login information, and determine to enter the login state of the IoT application when the obtained login information matching result is successful.

5. The method according to claim 4, wherein The performing of multimedia communication between the IoT device and the communication object includes: Performing at least one of the following processes: Sending the first multimedia data in the application request to the communication object; Obtaining the second multimedia data sent by the communication object, and sending the second multimedia data to the IoT device based on the communication connection.

6. The method according to claim 1, characterized in that The method further includes: In response to a management and control operation of the IoT account of the IoT platform for the IoT device, query the authorized IoT account corresponding to the IoT device; Perform account matching processing on the IoT account and the authorized IoT account to obtain an account matching result; When the account matching result is successful, perform the management and control operation for the IoT device.

7. The method according to claim 6, characterized in that, The performing of the management and control operation for the IoT device includes: Performing at least one of the following processes: Disable or lift the ban on the IoT device in the IoT platform; Disconnect the communication connection between the IoT platform and the IoT device; Obtain the status parameters of the IoT device; Send a control instruction to the IoT device based on the communication connection so that the IoT device executes the received control instruction.

8. The method according to claim 1, characterized in that The number of IoT applications in the IoT device includes multiple, and different IoT applications are used to initiate different application requests; The establishing of a session based on the application request includes: Respectively establish sessions based on different application requests; wherein, each session corresponds to one application request.

9. The method according to any one of claims 1 to 8, characterized in that The IoT platform includes a device layer and an application layer; the establishing of a communication connection with the IoT device through the IoT platform includes: Calling at least part of the device layer services in the IoT platform through the device layer to establish a communication connection with the IoT device; The calling of at least part of the application layer services in the IoT platform includes: Calling at least part of the application layer services in the IoT platform through the application layer.

10. The method according to any one of claims 1 to 8, characterized in that, The method further includes: Performing any one of the following processes: Sending the service tool to the IoT account of the IoT platform so that the IoT account deploys the service tool to the IoT application, and deploying the IoT application with the service tool to the IoT device; Deploy the service tool to the Internet of Things (IoT) application, and send the IoT application with the deployed service tool to the IoT account, so that the IoT account deploys the IoT application with the deployed service tool to the IoT device; Deploy the IoT application with the deployed service tool to the IoT device maintained by the IoT account.

11. The method according to any one of claims 1 to 8, characterized in that, The method further includes: Receive the signature result sent by the IoT device based on the communication connection; Perform signature verification processing on the signature result according to the verification key corresponding to the IoT device to obtain a signature verification result; When the signature verification result is successful, determine to respond to the application request.

12. The method according to any one of claims 1 to 8, characterized in that, The method further includes: Receive the status parameter sent by the IoT device based on the communication connection, and store the status parameter in the device shadow corresponding to the IoT device in the IoT platform; wherein, the status parameter is used to represent the call result of at least part of the application layer services; In response to the parameter acquisition operation of the IoT account of the IoT platform for the device shadow, send the status parameter in the device shadow to the IoT account; In response to the parameter update operation of the IoT account for the device shadow, call at least part of the application layer services in the IoT platform to update the status parameter in the device shadow; wherein, the updated status parameter is used to be synchronized to the IoT device.

13. An electronic device, characterized in that, It includes: A memory for storing executable instructions; A processor, when executing the executable instructions stored in the memory, implements the device control method based on the IoT platform according to any one of claims 1 to 12.

14. A computer-readable storage medium, characterized in that, Stores executable instructions, which are used to implement the device control method based on the IoT platform according to any one of claims 1 to 12 when being executed by a processor.

15. A computer program product, comprising computer-executable instructions, characterized in that, When the computer executable instructions are executed by a processor, the device control method based on the IoT platform according to any one of claims 1 to 12 is implemented.

Citation Information

Patent Citations

  • Service processing method in micro-service framework and related equipment

    CN109995713A