Method for building an intelligent Internet of Things system based on peer-to-peer network and related equipment
By deploying host gateways and peer-to-peer network servers in the IoT system and establishing communication connections between terminals and host gateways, the stability and security issues caused by cloud dependence are solved, and the security of data storage and system stability are achieved.
Patent Information
- Application Number
- CN202211369822.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-03
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2042-11-03
AI Technical Summary
Existing IoT systems are highly dependent on cloud data centers, resulting in poor stability and low privacy and security. When the cloud crashes or loses connection, system functions are unavailable and user data is easily leaked.
An intelligent Internet of Things system based on a peer-to-peer network is adopted. By deploying a host gateway and a peer-to-peer network server, the terminal device is connected to the host gateway, and the peer-to-peer network server is used to register the node information of the host gateway and the legal control terminal, establish a communication connection between the terminal and the host gateway, and store the data in the host gateway to realize the control and management of the terminal device.
It improves the stability and security of the IoT system, avoids the impact of cloud downtime, ensures the security and privacy of data storage, and further enhances the security of the system through permission management and key distribution.
Smart Images

Figure CN115665167B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet of Things, and in particular to a method for building an intelligent Internet of Things system based on a peer-to-peer network and related equipment. Background Art
[0002] Currently, IoT systems all use cloud data centers as data storage and transfer centers. Control commands from control terminals also need to be identified and forwarded through the cloud data centers to achieve control of all IoT devices. However, this approach relies heavily on cloud data centers. In the event of cloud downtime or loss of connectivity, all or some of the IoT devices within the system become unavailable, resulting in poor system stability. Furthermore, because existing IoT systems typically store user data in cloud data centers, there is a risk of privacy leaks, resulting in low privacy security for IoT systems. Summary of the Invention
[0003] In view of the above, it is necessary to propose a method for building an intelligent IoT system based on a peer-to-peer network and related equipment to avoid the impact of the cloud on the IoT system and improve the security and stability of the IoT system. The related equipment includes an intelligent IoT system based on a peer-to-peer network, electronic equipment, and storage media.
[0004] In a first aspect, an embodiment of the present invention provides a method for building an intelligent Internet of Things system based on a peer-to-peer network, the method comprising:
[0005] Deploy a host gateway and a peer-to-peer network server, connect the host gateway to a first router, and connect all terminal devices within a preset range to the host gateway, wherein the first router is used to map the intranet address of the host gateway to a first external network address;
[0006] Connect all legitimate control terminals to a second router and bind them to a host ID to obtain a binding result, wherein the legitimate control terminal is a control terminal with access permission to the host gateway, and the host ID is a unique identifier of the host gateway. The second router is used to map the intranet address of each legitimate control terminal to a second external network address, and the second external network address corresponds one-to-one with the legitimate control terminal;
[0007] Sending the host ID and the first external network address to the peer-to-peer network server to register the host node corresponding to the host gateway, and sending the second external network address and terminal ID of any legitimate control terminal to the peer-to-peer network server to register the control node corresponding to each legitimate control terminal, where the terminal ID is a unique identifier of the legitimate control terminal;
[0008] Based on the binding result, the host node and the control node establish communication connections between all legal control terminals and the host gateway to complete the construction of the Internet of Things system.
[0009] The above-mentioned method for building an intelligent IoT system based on a peer-to-peer network can connect all terminal devices within a preset range to the IoT system and control the terminal devices. First, a host gateway is deployed as a data storage center to replace the cloud. The node information of the host gateway and all legal control terminals is registered with the peer-to-peer network server to establish a communication connection between all legal control terminals and the host gateway. Then, all terminal devices within the preset range are controlled, completing the construction of the IoT system. The above-mentioned intelligent IoT system based on a peer-to-peer network stores all data in the host gateway, and the host gateway is used independently within the preset range, avoiding interference from external factors such as cloud downtime, and improving the stability and security of the IoT system. At the same time, the control terminal is managed through the root account for permission management and key distribution, further improving the security of the IoT system.
[0010] In some embodiments, the host gateway includes at least a data storage device, which is used to store all data information in the Internet of Things system; and the host gateway supports a communication protocol of a peer-to-peer network.
[0011] In some embodiments, the terminal device includes a sub-gateway and / or at least one Internet of Things device, and connecting all terminal devices within a preset range to the host gateway includes:
[0012] Assign a device ID and device IP to each terminal device, where the device ID is the unique identifier of the terminal device and the device IP is the intranet IP used to establish a communication connection between the terminal device and the host gateway;
[0013] The terminal device is assigned a device ID and a device IP and stored in the host gateway.
[0014] In some embodiments, the host node includes a correspondence between a host ID and the first external network address, and the first external network address includes at least the external network IP of the first route;
[0015] The control node corresponds to the legitimate control terminal in a one-to-one manner, and the control node includes a correspondence between the terminal ID of the corresponding legitimate control terminal and a second external network address, wherein the second external network address includes at least the external network IP and external network port number of the second route;
[0016] The host node and all control nodes are stored in the peer-to-peer network server.
[0017] In some embodiments, establishing communication connections between all legal control terminals and the host gateway based on the binding result, the host node, and the control node includes:
[0018] For each of the legal control terminals, query the host node based on the host ID in the binding result to obtain the first external network address;
[0019] Sending the connection request of the legitimate control terminal from the second external network address of the legitimate control terminal to the first route corresponding to the first external network address, and writing the second external network address into the first route;
[0020] In response to a connection request from the legitimate control terminal, the peer-to-peer network server controls the host gateway to query all control nodes based on the terminal ID of the legitimate control terminal to obtain a second external network address corresponding to the legitimate control terminal;
[0021] Sending the connection request of the host gateway from the first external network address to the second route corresponding to the second external network address of the legal control terminal;
[0022] After the first external network address is written into the second route, a communication connection is established between the legal control terminal and the host gateway.
[0023] In some embodiments, before connecting all legitimate control terminals to the second router and binding them to the host ID to obtain a binding result, the method further includes: creating a root account of the host gateway, and obtaining at least one legitimate control terminal and key information of the legitimate control terminal based on the root account, specifically including:
[0024] Bind at least one root user to the root account and send authentication requests from any control terminal to the root user;
[0025] The root account reminds the root user to perform authentication approval to obtain the authentication result of each root user, the authentication result including legal and illegal;
[0026] Counting the proportion of legitimate authentication results to all root users, and when the proportion is not less than a preset proportion, treating the control terminal as a legitimate control terminal;
[0027] Assign the same or different key information to different legal control terminals.
[0028] In some embodiments, after establishing communication connections between all legal control terminals and the host gateway based on the binding result, the host node and the control node, the method further includes:
[0029] Performing an encryption operation on the control instruction of the target legitimate control terminal based on the key information to obtain a control instruction ciphertext, wherein the target legitimate control terminal is any one of all legitimate control terminals;
[0030] Transmitting the control instruction ciphertext to the host gateway via the communication connection between the control node of the target legitimate control terminal and the host node;
[0031] After receiving the control instruction, the host gateway decrypts the control instruction ciphertext based on the key information to obtain the control instruction of the target legitimate control terminal, wherein the control instruction includes a target device ID and an operation instruction, wherein the target device ID is the device ID of the target device, and the target device is all terminal devices corresponding to the control instruction;
[0032] The operation instruction is sent from the host gateway to the target device based on the target device IP corresponding to the target device ID.
[0033] In a second aspect, an embodiment of the present invention further provides a peer-to-peer network-based intelligent Internet of Things system, the system comprising a host gateway, a peer-to-peer network server, a device management module, a terminal management module, a registration module, and a communication connection module:
[0034] The device management module is used to connect the host gateway to a first router and connect all terminal devices within a preset range to the host gateway, and the first router is used to map the intranet address of the host gateway to a first external network address;
[0035] The terminal management module is used to connect all legitimate control terminals to the second route and bind them to the host ID to obtain a binding result. The legitimate control terminal is a control terminal with access permission to the host gateway. The host ID is a unique identifier of the host gateway. The second route is used to map the intranet address of each legitimate control terminal to a second external network address. The second external network address has a one-to-one correspondence with the legitimate control terminal.
[0036] The registration module is used to send the host ID and the first external network address to the peer-to-peer network server to register the host node corresponding to the host gateway, and send the second external network address and terminal ID of any legal control terminal to the peer-to-peer network server to register the control node corresponding to each legal control terminal, wherein the terminal ID is a unique identifier of the legal control terminal;
[0037] The communication connection module is used to establish communication connections between all legal control terminals and the host gateway based on the binding result, the host node and the control node, thereby completing the construction of the Internet of Things system.
[0038] In a third aspect, an embodiment of the present invention further provides an electronic device, comprising: a memory storing computer-readable instructions; and a processor executing the computer-readable instructions stored in the memory to implement the method for building an intelligent Internet of Things system based on a peer-to-peer network as described above.
[0039] In a fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium, on which computer-readable instructions are stored. When the computer-readable instructions are executed by a processor, the method for building an intelligent Internet of Things system based on a peer-to-peer network as described above is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 This is a flowchart of a preferred embodiment of the method for building an intelligent Internet of Things system based on a peer-to-peer network provided in an embodiment of the present application.
[0041] Figure 2 This is a schematic diagram of the architecture of a preferred embodiment of a peer-to-peer network-based intelligent Internet of Things system provided in an embodiment of the present application.
[0042] Figure 3 It is a structural diagram of an electronic device of a preferred embodiment of the method for building an intelligent Internet of Things system based on a peer-to-peer network provided in an embodiment of the present application. DETAILED DESCRIPTION
[0043] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0044] like Figure 1 As shown, Figure 1 This is a flowchart of a method for building a peer-to-peer network-based intelligent Internet of Things system provided by some embodiments of the present application. Depending on different needs, the order of the steps in the flowchart can be changed, and some steps can be omitted.
[0045] S101. Deploy a host gateway and a peer network server, connect the host gateway to a first router, and connect all terminal devices within a preset range to the host gateway, where the first router is used to map the intranet address of the host gateway to a first extranet address.
[0046] In some optional embodiments, the host gateway includes at least a data storage device, which is used to store all data information in the peer-to-peer network-based intelligent Internet of Things system; and the host gateway supports the communication protocol of the peer-to-peer network and can transmit information in the peer-to-peer network.
[0047] In some optional embodiments, the host gateway is connected to a first router, wherein the first router has a Network Address Translation (NAT) function and is configured to map the intranet address of the host gateway to a first external network address, wherein the first external network address includes at least the external network IP address of the first router. After the intranet address of the host gateway is mapped to the first external network address, the host gateway can access the external network through the first external network address.
[0048] In some optional embodiments, the external IP of the first route may adopt the IPV4 protocol or the IPV6 protocol. When the external IP of the first route adopts the IPV4 protocol, the external IP of the first route is a dynamic external IP; when the external IP of the first route adopts the IPV6 protocol, the external IP of the first route is a dynamic external IP or a fixed external IP.
[0049] In some optional embodiments, the intranet address of the host gateway can be the intranet IP of the host gateway, or can be a combination of the intranet IP and the intranet port number of the host gateway, which is not limited in the embodiments of the present application. If the intranet address of the host gateway is the intranet IP of the host gateway, then the first external network address is the external network IP of the first route; if the intranet address of the host gateway is a combination of the intranet IP and the intranet port number, then the first external network address is a combination of the external network IP and the external port number of the first route.
[0050] It should be noted that the external IP refers to a non-reserved IP address connected to the external network. One external IP can correspond to multiple external ports. A terminal can access the external network through any external port corresponding to the external IP only when it obtains the external IP; and the internal IP is an IP address allocated and used within the local area network. One internal IP can also correspond to multiple internal ports. A terminal can communicate with other terminals in the same local area network through any internal port corresponding to the internal IP only when it obtains the internal IP.
[0051] In some optional embodiments, the preset range can be a household, or a business or organization, which is not limited in the present embodiment. The terminal device includes a sub-gateway and / or at least one IoT device, wherein at least one IoT device is connected to a sub-gateway.
[0052] In order to facilitate the management and control of IoT devices within the preset range, IoT devices with the same attributes can be connected to the same sub-gateway. For example, IoT devices within the same range can be connected to the same sub-gateway, or IoT devices with the same control logic can be connected to the same sub-gateway. For example, the preset range is set to home, and a sub-gateway is deployed in each room. Then, all IoT devices in a room are connected to the sub-gateway corresponding to the room, and the sub-network is connected to the host gateway, thereby connecting all IoT devices under the sub-network to the host gateway. In addition, IoT devices can also be directly connected to the host gateway. Then, all sub-gateways and all IoT sub-devices constitute all terminal devices in the home, and all terminal devices are connected to the host gateway.
[0053] In some optional embodiments, connecting all terminal devices within a preset range to the host gateway includes:
[0054] Assign a device ID and device IP to each terminal device, where the device ID is the unique identifier of the terminal device and the device IP is the intranet IP used to establish a communication connection between the terminal device and the host gateway;
[0055] The terminal device is assigned a device ID and a device IP and stored in the host gateway.
[0056] Among them, the device IP is an intranet IP, which can be a fixed static IP or a randomly changing dynamic IP, and the embodiment of this application does not limit it.
[0057] In some optional embodiments, after the terminal device is connected to the host gateway, the terminal device and the host gateway form a device local area network. A communication connection can then be established between any terminal device and the host gateway based on the device IP address and the intranet address of the host gateway. It should be noted that communication connections are established between all terminal devices and the host gateway within the device local area network, while only the host gateway can access the external network via the first route.
[0058] In this way, all terminal devices within the preset range are connected to the host gateway, and a device ID and a device IP are assigned to each terminal device, and a communication connection is established between the host gateway and all terminal devices. The host gateway is connected to the external network through the first route.
[0059] S102. Connect all legal control terminals to the second route and bind them with the host ID to obtain a binding result. The legal control terminal is a control terminal with access rights to the host gateway. The host ID is a unique identifier of the host gateway. The second route is used to map the intranet address of each legal control terminal to a second external network address. The second external network address corresponds one-to-one to the legal control terminal.
[0060] Preferably, the MAC address of the host gateway is used as the host ID, wherein the MAC address is a unique code assigned by the manufacturer to the network hardware.
[0061] In some optional embodiments, before connecting all legitimate control terminals to the second router and binding them to the host ID to obtain a binding result, the method further includes: creating a root account of the host gateway, and obtaining at least one legitimate control terminal and key information of the legitimate control terminal based on the root account, specifically including:
[0062] Bind at least one root user to the root account and send authentication requests from any control terminal to the root user;
[0063] The root account reminds the root user to perform authentication approval to obtain authentication results of each root user, the authentication results including legal and illegal;
[0064] Counting the proportion of legitimate authentication results to all root users, and when the proportion is not less than a preset proportion, treating the control terminal as a legitimate control terminal;
[0065] Assign the same or different key information to different legal control terminals.
[0066] Among them, the control terminal is a terminal device with a preset APP installed, and the preset APP can transmit messages with the root account; the authentication request at least includes the identity information of the control terminal, and the identity information is the registered user information of the preset APP; the value of the preset ratio is 0.5.
[0067] After obtaining a legal control terminal, key information is allocated to the legal control terminal with the help of a key generator. The key information of different legal control terminals can be the same or different, and the key information of each legal control terminal is stored in the host gateway.
[0068] In other optional embodiments, before any control terminal sends an authentication request to the root account, it is also necessary to complete a preset questionnaire, and use the answer results of the preset questionnaire and the identity information of the control terminal as authentication information to assist the root user in performing authentication approval and obtaining authentication results.
[0069] In some optional embodiments, all legitimate control terminals are connected to a second router. The second router also has a Network Address Translation (NAT) function, which is used to map the intranet address of each legitimate control terminal to a second external network address. The second external network address corresponding to different legitimate control terminals is different, wherein the second external network address at least includes the external network IP address and external network port number of the second router. After the intranet address of any legitimate control terminal is mapped to the second external network address, the legitimate control terminal can access the external network through the second external network address.
[0070] In some optional embodiments, the external IP of the second route can adopt the IPV4 protocol or the IPV6 protocol. When the external IP of the second route adopts the IPV4 protocol, the external IP of the second route is a dynamic external IP; when the external IP of the second route adopts the IPV6 protocol, the external IP of the second route is a dynamic external IP or a fixed external IP.
[0071] In some optional embodiments, the intranet address of the legitimate control terminal can be the intranet IP address of the legitimate control terminal, or a combination of the intranet IP address and the intranet port number of the legitimate control terminal, which is not limited in this embodiment of the present application. All legitimate control terminals are connected to the second router to form a terminal local area network. Each legitimate control terminal in the terminal local area network can access the external network through the corresponding second external network address. The intranet IP addresses of different legitimate control terminals are different.
[0072] It should be noted that the second route corresponds to an external IP and multiple external ports, and the external port number is the unique identifier of the external port; the second route maps the intranet addresses of different control terminals to the same external IP and different external ports, thereby obtaining different second external addresses. For example, assuming that the intranet IP and intranet port number of the legitimate control terminal 1 are 192.168.1.2 and 1010 respectively, and the intranet IP and intranet port number of the legitimate control terminal 2 are 192.168.1.1 and 2010 respectively; then the intranet addresses of control terminal 1 and control terminal 2 are: 192.168.1.2:1010 and 192.168.1.1:2010 respectively, and the external network IP of the second route is 166.111.80.200. The second route maps control terminal 1 and control terminal 2 to two different external network ports 80 and 90 respectively, then the second external network addresses corresponding to control terminal 1 and control terminal 2 are: 166.111.80.200:80 and 166.111.80.200:90 respectively.
[0073] In some optional embodiments, since the legal control terminal and the host gateway are in two different local area networks, the legal control terminal cannot directly establish a communication connection with the host gateway. In order to subsequently establish a communication connection between the legal control terminal and the host gateway, it is necessary to bind all legal control terminals to the host ID to obtain a binding result, and store the binding result in each legal control terminal.
[0074] In this way, all legal control terminals are obtained and connected to the second route, and a second external network address is assigned to each legal control terminal so that the legal control terminal can access the external network. At the same time, each legal control terminal is bound to the host ID of the host gateway for subsequent establishment of a communication connection between the legal control terminal and the host gateway.
[0075] S103. Send the host ID and the first external network address to the peer network server to register the host node corresponding to the host gateway, and send the second external network address and terminal ID of any legal control terminal to the peer network server to register the control node corresponding to each legal control terminal, where the terminal ID is a unique identifier of the legal control terminal.
[0076] In an optional embodiment, the host ID and the first external network address are sent to the peer-to-peer network server, and the correspondence between the host ID and the first external network address is used as node information to register the host node corresponding to the host gateway.
[0077] In an optional embodiment, the second external network address and terminal ID of each legitimate control terminal are sent to the peer-to-peer network server, and the correspondence between the terminal ID and the second external network address is used as node information to register the control node corresponding to the legitimate control terminal, and the control node corresponds one-to-one with the legitimate control terminal. The terminal ID is a unique identifier of the legitimate control terminal, and preferably, the MAC address of the legitimate control terminal is used as the terminal ID of the legitimate control terminal.
[0078] The host node and the control node of each legal control terminal are stored in the peer-to-peer network server.
[0079] In this way, after completing the registration process of the host gateway and each legal control terminal in the peer-to-peer network server and obtaining the host node and the control node, the host gateway and each legal control terminal can obtain the permission to access the peer-to-peer network server.
[0080] S104: Based on the binding result, the host node and the control node establish communication connections between all legal control terminals and the host gateway to complete the construction of the Internet of Things system.
[0081] In some optional embodiments, the binding result is stored in each legal control terminal, and the host ID of the host gateway to which the legal control terminal needs to connect can be obtained based on the binding result.
[0082] In some optional embodiments, establishing communication connections between all legal control terminals and the host gateway based on the binding result, the host node, and the control node includes:
[0083] For each of the legal control terminals, query the host node based on the host ID in the binding result to obtain the first external network address;
[0084] Sending the connection request of the legitimate control terminal from the second external network address of the legitimate control terminal to the first route corresponding to the first external network address, and writing the second external network address into the first route;
[0085] In response to a connection request from the legitimate control terminal, the peer-to-peer network server controls the host gateway to query all control nodes based on the terminal ID of the legitimate control terminal to obtain a second external network address corresponding to the legitimate control terminal;
[0086] Sending the connection request of the host gateway from the first external network address to the second route corresponding to the second external network address of the legal control terminal;
[0087] After the first external network address is written into the second route, a communication connection is established between the legal control terminal and the host gateway.
[0088] In this optional embodiment, after the connection request from the legitimate control terminal is sent from the second external network address of the legitimate control terminal to the first route corresponding to the first external network address, since the first route receives the request from the second external network address of the legitimate control terminal for the first time, the second external network address is unfamiliar to the first route, and the connection request is rejected by the first route, and the second external network address is written to the first route. Then, in response to the connection request from the legitimate control terminal, the peer-to-peer network controls the host gateway to send a connection request to the legitimate control terminal, sending the host gateway's connection request from the first external network address to the second route corresponding to the second external network address of the legitimate control terminal. Since the second route receives the request from the first external network address for the first time, the first external network address is unfamiliar to the second route, and the connection request is rejected by the second route, and the first external network address is written to the second route. At this point, the first external network address is stored in the second route, and the first route stores the second external network address of the legitimate control terminal, thereby establishing a communication connection between the host gateway and the legitimate control terminal.
[0089] In some optional embodiments, the legitimate control terminals are traversed to establish a communication connection between each legitimate control terminal and the host gateway.
[0090] In some optional embodiments, after establishing communication connections between all legal control terminals and the host gateway based on the binding result, the host node and the control node, the method further includes:
[0091] Performing an encryption operation on the control instruction of the target legitimate control terminal based on the key information to obtain a control instruction ciphertext, wherein the target legitimate control terminal is any one of all legitimate control terminals;
[0092] Transmitting the control instruction ciphertext to the host gateway via the communication connection between the control node of the target legitimate control terminal and the host node;
[0093] After receiving the control instruction, the host gateway decrypts the control instruction ciphertext based on the key information to obtain the control instruction of the target legitimate control terminal, wherein the control instruction includes a target device ID and an operation instruction, wherein the target device ID is the device ID of the target device, and the target device is all terminal devices corresponding to the control instruction;
[0094] The operation instruction is sent from the host gateway to the target device based on the target device IP corresponding to the target device ID.
[0095] The encryption operation is symmetric encryption, meaning that the encryption and decryption processes use the same key information. The operation instructions are used to control the target device to perform corresponding operations, and include at least one of a control instruction, a query instruction, a network configuration instruction, and a parameter setting instruction. The control instruction is used to control the movement of the target device, the query instruction is used to query the real-time status of the target device, the network configuration instruction is used to control the target device to connect to or disconnect from the host gateway, and the parameter setting instruction is used to adjust the parameters of the target device.
[0096] In other optional embodiments, the encryption operation may also be asymmetric encryption, where asymmetric encryption means that the key information used in the encryption process and the decryption process are different. When the encryption operation is asymmetric encryption, the key information corresponding to a legitimate control terminal includes two different keys, and the two different keys are used for the encryption process and the decryption process, respectively.
[0097] In some optional embodiments, the target device is at least one of an Internet of Things device and an Internet of Things sub-device, and the target device performs a corresponding operation after receiving the operation instruction.
[0098] This completes the construction of a peer-to-peer intelligent IoT system. In this IoT system, any legitimate control terminal directly establishes a communication connection with the host gateway to control all terminal devices within a preset range. All data is stored in the host gateway, and the host gateway is used independently within the preset range. This avoids interference from external factors such as cloud downtime and information leakage, and improves the stability and security of the IoT system.
[0099] The above-mentioned method for building an intelligent IoT system based on a peer-to-peer network can connect all terminal devices within a preset range to the IoT system and control the terminal devices. First, a host gateway is deployed as a data storage center to replace the cloud. The node information of the host gateway and all legal control terminals is registered with the peer-to-peer network server to establish a communication connection between all legal control terminals and the host gateway. Then, all terminal devices within the preset range are controlled, completing the construction of the IoT system. The above-mentioned intelligent IoT system based on a peer-to-peer network stores all data in the host gateway, and the host gateway is used independently within the preset range, avoiding interference from external factors such as cloud downtime, and improving the stability and security of the IoT system. At the same time, the control terminal is managed through the root account for permission management and key distribution, further improving the security of the IoT system.
[0100] To facilitate understanding, first combine Figure 2 The present invention introduces a peer-to-peer network-based intelligent Internet of Things system 100 provided in an embodiment of the present application.
[0101] Figure 2 FIG is a schematic diagram of the architecture of the intelligent Internet of Things system 100 based on a peer-to-peer network. Figure 2 As shown, a peer-to-peer network-based intelligent IoT system 100 deploys a host gateway as a data storage center and uses a peer-to-peer network server to establish communication connections between all authorized control terminals and the host gateway to achieve control of IoT devices. This eliminates the influence of the cloud on the IoT system and improves the security and stability of the IoT system. The peer-to-peer network-based intelligent IoT system 100 includes a host gateway 10, a peer-to-peer network server 20, a device management module 30, a terminal management module 40, a registration module 50, and a communication connection module 60.
[0102] The host gateway 10 includes at least a data storage device, which is used to store all data information in the peer-to-peer network-based intelligent Internet of Things system; and the host gateway 10 supports the communication protocol of the peer-to-peer network and can transmit information in the peer-to-peer network.
[0103] The device management module 30 is used to connect the host gateway 10 to a first router and connect all terminal devices within a preset range to the host gateway 10. The first router is used to map the intranet address of the host gateway 10 to a first external network address.
[0104] In some optional embodiments, the host gateway 10 is connected to a first router, and the first router has a network address translation (NAT) function, which is used to map the intranet address of the host gateway 10 to a first external network address, wherein the first external network address at least includes the external network IP of the first router. After the intranet address of the host gateway 10 is mapped to the first external network address, the host gateway 10 can access the external network through the first external network address. The intranet address and the first external network address of the host gateway 10 are specifically mentioned above and will not be repeated here.
[0105] In some optional embodiments, the preset range can be a household, or a business or organization, which is not limited in the present embodiment. The terminal device includes a sub-gateway and / or at least one IoT device, wherein at least one IoT device is connected to a sub-gateway.
[0106] In some optional embodiments, connecting all terminal devices within a preset range to the host gateway 10 includes:
[0107] Assign a device ID and a device IP to each terminal device, where the device ID is a unique identifier of the terminal device and the device IP is an intranet IP used to establish a communication connection between the terminal device and the host gateway 10;
[0108] The terminal device is assigned a device ID and a device IP and stored in the host gateway 10 .
[0109] Among them, the device IP is an intranet IP, which can be a fixed static IP or a randomly changing dynamic IP, and the embodiment of this application does not limit it.
[0110] In some optional embodiments, after the terminal device is connected to the host gateway 10, the terminal device and the host gateway 10 form a device local area network. Based on the device IP and the intranet address of the host gateway 10, a communication connection can be established between any terminal device and the host gateway 10. It should be noted that a communication connection is established between all terminal devices and the host gateway 10, and the host gateway 10 can access the external network through the first routing connection.
[0111] In this way, all terminal devices within the preset range are connected to the host gateway 10, and a device ID and device IP are assigned to each terminal device, establishing a communication connection between the host gateway 10 and all terminal devices, and the host gateway 10 is connected to the external network through the first route.
[0112] The terminal management module 40 is used to connect all legal control terminals to the second route and bind them to the host ID to obtain a binding result. The legal control terminal is a control terminal with access permission to the host gateway 10. The host ID is a unique identifier of the host gateway 10. The second route is used to map the intranet address of each legal control terminal to a second external network address. The second external network address corresponds one-to-one to the legal control terminal.
[0113] In some optional embodiments, the MAC address of the host gateway 10 is used as the host ID, wherein the MAC address is a unique code assigned by the manufacturer to the network hardware; before connecting all legitimate control terminals to the second router and binding them with the host ID to obtain a binding result, the method further includes: creating a root account of the host gateway 10, and obtaining at least one legitimate control terminal and key information of the legitimate control terminal based on the root account, specifically including:
[0114] Bind at least one root user to the root account and send authentication requests from any control terminal to the root user;
[0115] The root account reminds the root user to perform authentication approval to obtain the authentication result of each root user, the authentication result including legal and illegal;
[0116] Counting the proportion of legitimate authentication results to all root users, and when the proportion is not less than a preset proportion, treating the control terminal as a legitimate control terminal;
[0117] Assign the same or different key information to different legal control terminals.
[0118] Among them, the control terminal is a terminal device with a preset APP installed, and the authentication request includes at least the identity information of the control terminal, and the identity information is the registered user information of the preset APP; the value of the preset ratio is 0.5, please refer to the above for details, which will not be repeated here.
[0119] In some optional embodiments, all legal control terminals are connected to a second router, which also has a Network Address Translation (NAT) function for mapping the intranet address of each legal control terminal to a second external network address, and the second external network addresses corresponding to different legal control terminals are different, wherein the second external network address at least includes the external network IP and external network port number of the second router. After the intranet address of any legal control terminal is mapped to the second external network address, the legal control terminal can access the external network through the second external network address. The specific details of the intranet address and the second external network address of the legal control terminal are mentioned above and will not be repeated here.
[0120] In this way, all legal control terminals are obtained and connected to the second route, and a second external network address is assigned to each legal control terminal so that the legal control terminal can access the external network. At the same time, each legal control terminal is bound to the host ID of the host gateway 10 for subsequent establishment of a communication connection between the legal control terminal and the host gateway 10.
[0121] The registration module 50 is used to send the host ID and the first external network address to the peer network server 20 to register the host node corresponding to the host gateway 10, and send the second external network address and terminal ID of any legal control terminal to the peer network server 20 to register the control node corresponding to each legal control terminal, where the terminal ID is a unique identifier of the legal control terminal.
[0122] In some optional embodiments, in an optional embodiment, the host ID and the first external network address are sent to the peer network server 20, and the correspondence between the host ID and the first external network address is used as node information to register the host node corresponding to the host gateway 10.
[0123] In an optional embodiment, the second external network address and terminal ID of each legitimate control terminal are sent to the peer-to-peer network server 20. The correspondence between the terminal ID and the second external network address is used as node information to register the control node corresponding to the legitimate control terminal. The control node corresponds one-to-one with the legitimate control terminal. The terminal ID is a unique identifier of the legitimate control terminal. Preferably, the MAC address of the legitimate control terminal is used as the terminal ID of the legitimate control terminal. The host node and the control node of each legitimate control terminal are stored in the peer-to-peer network server 20.
[0124] In this way, after completing the registration process of the host gateway 10 and each legitimate control terminal in the peer network server 20 and obtaining the host node and control node, the host gateway 10 and each legitimate control terminal can obtain the permission to access the peer network server 20.
[0125] The communication connection module 60 is used to establish communication connections between all legal control terminals and the host gateway 10 based on the binding result, the host node and the control node, thereby completing the construction of the Internet of Things system.
[0126] In some optional embodiments, establishing communication connections between all legitimate control terminals and the host gateway 10 based on the binding result, the host node, and the control node includes:
[0127] For each of the legal control terminals, query the host node based on the host ID in the binding result to obtain the first external network address;
[0128] Sending the connection request of the legitimate control terminal from the second external network address of the legitimate control terminal to the first route corresponding to the first external network address, and writing the second external network address into the first route;
[0129] In response to the connection request of the legitimate control terminal, the peer-to-peer network server 20 controls the host gateway 10 to query all control nodes based on the terminal ID of the legitimate control terminal to obtain the second external network address of the legitimate control terminal;
[0130] Sending the connection request of the host gateway 10 from the first external network address to the second route corresponding to the second external network address of the legitimate control terminal;
[0131] After the first external network address is written into the second route, a communication connection is established between the legal control terminal and the host gateway 10 .
[0132] In some optional embodiments, after establishing communication connections between all legitimate control terminals and the host gateway 10 based on the binding result, the host node and the control node, the method further includes:
[0133] Performing an encryption operation on the control instruction of the target legitimate control terminal based on the key information to obtain a control instruction ciphertext, wherein the target legitimate control terminal is any one of all legitimate control terminals;
[0134] Transmitting the control instruction ciphertext to the host gateway 10 through the communication connection between the control node of the target legitimate control terminal and the host node;
[0135] After receiving the control instruction, the host gateway 10 decrypts the control instruction ciphertext based on the key information to obtain the control instruction of the target legitimate control terminal, wherein the control instruction includes a target device ID and an operation instruction. The target device ID is the device ID of the target device, and the target device is all terminal devices corresponding to the control instruction.
[0136] The operation instruction is sent from the host gateway 10 to the target device based on the target device IP corresponding to the target device ID.
[0137] In some optional embodiments, the target device is at least one of an Internet of Things device and an Internet of Things sub-device, and the target device performs a corresponding operation after receiving the operation instruction.
[0138] The above-mentioned intelligent Internet of Things system based on the peer-to-peer network stores all data in the host gateway 10, and the host gateway 10 is used alone within a preset range, avoiding interference from external factors such as cloud downtime, and improving the stability and security of the Internet of Things system; at the same time, the control terminal is managed through the root account and keys are distributed, further improving the security of the Internet of Things system.
[0139] See Figure 3 , is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Electronic device 1 includes memory 12 and processor 13. Memory 12 is used to store computer-readable instructions, and processor 13 is used to execute the computer-readable instructions stored in the memory to implement the method for establishing a peer-to-peer network-based intelligent Internet of Things system described in any of the above embodiments.
[0140] In an optional embodiment, the electronic device 1 further includes a bus, a computer program stored in the memory 12 and executable on the processor 13, such as a program for building a smart Internet of Things system based on a peer-to-peer network.
[0141] Figure 3Only the electronic device 1 having the memory 12 and the processor 13 is shown. It can be understood by those skilled in the art that Figure 3 The structure shown does not constitute a limitation on the electronic device 1 , and the electronic device 1 may include fewer or more components than shown in the figure, or combine certain components, or arrange the components differently.
[0142] Combine Figure 1 The memory 12 in the electronic device 1 stores a plurality of computer-readable instructions to implement a method for building an intelligent Internet of Things system based on a peer-to-peer network, and the processor 13 can execute the plurality of instructions to implement:
[0143] Deploy a host gateway and a peer-to-peer network server, connect the host gateway to a first router, and connect all terminal devices within a preset range to the host gateway, wherein the first router is used to map the intranet address of the host gateway to a first external network address;
[0144] Connect all legitimate control terminals to a second router and bind them to a host ID to obtain a binding result, wherein the legitimate control terminal is a control terminal with access permission to the host gateway, and the host ID is a unique identifier of the host gateway. The second router is used to map the intranet address of each legitimate control terminal to a second external network address, and the second external network address corresponds one-to-one with the legitimate control terminal;
[0145] Sending the host ID and the first external network address to the peer-to-peer network server to register the host node corresponding to the host gateway, and sending the second external network address and terminal ID of any legitimate control terminal to the peer-to-peer network server to register the control node corresponding to each legitimate control terminal, where the terminal ID is a unique identifier of the legitimate control terminal;
[0146] Based on the binding result, the host node and the control node establish communication connections between all legal control terminals and the host gateway to complete the construction of the Internet of Things system.
[0147] Specifically, the specific implementation method of the processor 13 for the above instructions can refer to Figure 1 The description of the relevant steps in the corresponding embodiments will not be repeated here.
[0148] Those skilled in the art will understand that the schematic diagram is merely an example of the electronic device 1 and does not constitute a limitation on the electronic device 1. The electronic device 1 may have a bus structure or a star structure. The electronic device 1 may also include more or less other hardware or software than shown in the figure, or a different arrangement of components. For example, the electronic device 1 may also include input and output devices, network access devices, etc.
[0149] It should be noted that the electronic device 1 is only an example, and other existing or future electronic products that are suitable for this application should also be included in the scope of protection of this application and incorporated herein by reference.
[0150] Among them, the memory 12 includes at least one type of readable storage medium, and the readable storage medium can be non-volatile or volatile. The readable storage medium includes flash memory, mobile hard disk, multimedia card, card-type memory (for example: SD or DX memory, etc.), magnetic memory, disk, optical disk, etc. In some embodiments, the memory 12 can be an internal storage unit of the electronic device 1, such as a mobile hard disk of the electronic device 1. In other embodiments, the memory 12 can also be an external storage device of the electronic device 1, such as a plug-in mobile hard disk, smart memory card (Smart Media Card, SMC), secure digital (Secure Digital, SD) card, flash card (Flash Card), etc. equipped on the electronic device 1. The memory 12 can not only be used to store application software and various types of data installed on the electronic device 1, such as the code of the program for building a smart Internet of Things system based on a peer-to-peer network, but can also be used to temporarily store data that has been output or is to be output.
[0151] In some embodiments, the processor 13 may be composed of an integrated circuit, such as a single packaged integrated circuit, or a plurality of packaged integrated circuits with the same or different functions, including one or more central processing units (CPUs), microprocessors, digital processing chips, graphics processors, and a combination of various control chips. The processor 13 is the control core (Control Unit) of the electronic device 1. It utilizes various interfaces and circuits to connect the various components of the entire electronic device 1. It executes or executes programs or modules stored in the memory 12 (for example, executing a program for building a smart Internet of Things system based on a peer-to-peer network) and calls data stored in the memory 12 to perform various functions of the electronic device 1 and process data.
[0152] The processor 13 executes the operating system of the electronic device 1 and various installed applications. The processor 13 executes the applications to implement the steps in the above-mentioned embodiments of the method for building a smart Internet of Things system based on a peer-to-peer network, such as Figure 1 Steps shown.
[0153] Exemplarily, the computer program may be divided into one or more modules / units, which are stored in the memory 12 and executed by the processor 13 to complete the present application. The one or more modules / units may be a series of computer-readable instruction segments capable of performing specific functions, which are used to describe the execution process of the computer program in the electronic device 1. For example, the computer program may be divided into a host gateway 10, a peer-to-peer network server 20, a device management module 30, a terminal management module 40, a registration module 50, and a communication connection module 60.
[0154] The above-mentioned integrated unit implemented in the form of a software function module can be stored in a computer-readable storage medium. The above-mentioned software function module is stored in a storage medium and includes a number of instructions for causing a computer device (which can be a personal computer, computer device, or network device, etc.) or a processor to execute the portion of the method for building a peer-to-peer network-based intelligent Internet of Things system described in various embodiments of the present application.
[0155] If the modules / units integrated in the electronic device 1 are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the processes in the above-mentioned embodiment methods, and can also instruct the relevant hardware devices to complete them through a computer program. The computer program can be stored in a computer-readable storage medium, and when the computer program is executed by a processor, it can implement the steps of each of the above-mentioned method embodiments.
[0156] The computer program includes computer program code, which may be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium may include any entity or device capable of carrying the computer program code, a recording medium, a USB flash drive, a mobile hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory, or other memory.
[0157] Furthermore, the computer-readable storage medium may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function, etc.; the data storage area may store data created according to the use of the blockchain node, etc.
[0158] The bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 3 The diagram is represented by only one arrow, but it does not mean that there is only one bus or one type of bus. The bus is configured to implement connection and communication between the memory 12 and at least one processor 13, etc.
[0159] An embodiment of the present application also provides a computer-readable storage medium (not shown), which stores computer-readable instructions. The computer-readable instructions are executed by a processor in an electronic device to implement the method for building a peer-to-peer network-based intelligent Internet of Things system described in any of the above embodiments.
[0160] Furthermore, it is clear that the word "comprising" does not exclude other units or steps, and the singular does not exclude the plural. Multiple units or devices listed in the specification may also be implemented by a single unit or device through software or hardware. Terms such as first and second are used to indicate names and do not imply any particular order.
[0161] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit the present application. Although the present application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present application may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present application.
Claims
1. A method for building an intelligent Internet of Things system based on a peer-to-peer network, characterized in that: The method comprises: Deploy a host gateway and a peer-to-peer network server, connect the host gateway to a first router, and connect all terminal devices within a preset range to the host gateway, wherein the first router is used to map the intranet address of the host gateway to a first external network address; Connect all legitimate control terminals to a second router and bind them to a host ID to obtain a binding result, wherein the legitimate control terminal is a control terminal with access permission to the host gateway, and the host ID is a unique identifier of the host gateway. The second router is used to map the intranet address of each legitimate control terminal to a second external network address, and the second external network address corresponds one-to-one with the legitimate control terminal; Sending the host ID and the first external network address to the peer-to-peer network server to register the host node corresponding to the host gateway, and sending the second external network address and terminal ID of any legitimate control terminal to the peer-to-peer network server to register the control node corresponding to each legitimate control terminal, where the terminal ID is a unique identifier of the legitimate control terminal; Based on the binding result, the host node and the control node establish communication connections between all legal control terminals and the host gateway to complete the construction of the Internet of Things system.
2. The method for building a peer-to-peer network-based intelligent Internet of Things system according to claim 1, wherein: The host gateway includes at least a data storage device, which is used to store all data information in the Internet of Things system; The host gateway supports a communication protocol of a peer-to-peer network.
3. The method for building a peer-to-peer network-based intelligent Internet of Things system according to claim 1, wherein: The terminal device includes a sub-gateway and / or at least one Internet of Things device, and connecting all terminal devices within a preset range to the host gateway includes: Assign a device ID and device IP to each terminal device, where the device ID is the unique identifier of the terminal device and the device IP is the intranet IP used to establish a communication connection between the terminal device and the host gateway; The terminal device is assigned a device ID and a device IP and stored in the host gateway.
4. The method for building a peer-to-peer network-based intelligent Internet of Things system according to claim 1, wherein: The host node includes a correspondence between a host ID and the first external network address, and the first external network address includes at least the external network IP of the first route; The control node corresponds to the legitimate control terminal in a one-to-one manner, and the control node includes a correspondence between the terminal ID of the corresponding legitimate control terminal and a second external network address, wherein the second external network address includes at least the external network IP and external network port number of the second route; The host node and all control nodes are stored in the peer-to-peer network server.
5. The method for building a smart Internet of Things system based on a peer-to-peer network according to claim 1, wherein: The establishing of communication connections between all legal control terminals and the host gateway based on the binding result, the host node, and the control node includes: For each of the legal control terminals, query the host node based on the host ID in the binding result to obtain the first external network address; Sending the connection request of the legitimate control terminal from the second external network address of the legitimate control terminal to the first route corresponding to the first external network address, and writing the second external network address into the first route; In response to a connection request from the legitimate control terminal, the peer-to-peer network server controls the host gateway to query all control nodes based on the terminal ID of the legitimate control terminal to obtain a second external network address corresponding to the legitimate control terminal; Sending the connection request of the host gateway from the first external network address to the second route corresponding to the second external network address of the legal control terminal; After the first external network address is written into the second route, a communication connection is established between the legal control terminal and the host gateway.
6. The method for building a peer-to-peer network-based intelligent Internet of Things system according to claim 1, wherein: Before connecting all legal control terminals to the second router and binding them to the host ID to obtain a binding result, the method further includes: creating a root account of the host gateway, and obtaining at least one legal control terminal and key information of the legal control terminal based on the root account, specifically including: Bind at least one root user to the root account and send authentication requests from any control terminal to the root user; The root account reminds the root user to perform authentication approval to obtain the authentication result of each root user, the authentication result including legal and illegal; Counting the proportion of legitimate authentication results to all root users, and when the proportion is not less than a preset proportion, treating the control terminal as a legitimate control terminal; Assign the same or different key information to different legal control terminals.
7. The method for building a peer-to-peer network-based intelligent Internet of Things system according to claim 6, wherein: After establishing communication connections between all legal control terminals and the host gateway based on the binding result, the host node and the control node, the method further includes: Performing an encryption operation on the control instruction of the target legitimate control terminal based on the key information to obtain a control instruction ciphertext, wherein the target legitimate control terminal is any one of all legitimate control terminals; Transmitting the control instruction ciphertext to the host gateway via the communication connection between the control node of the target legitimate control terminal and the host node; After receiving the control instruction, the host gateway decrypts the control instruction ciphertext based on the key information to obtain the control instruction of the target legitimate control terminal, wherein the control instruction includes a target device ID and an operation instruction, wherein the target device ID is the device ID of the target device, and the target device is all terminal devices corresponding to the control instruction; The operation instruction is sent from the host gateway to the target device based on the target device IP corresponding to the target device ID.
8. An intelligent Internet of Things system based on a peer-to-peer network, characterized in that: The system includes a host gateway, a peer-to-peer network server, a device management module, a terminal management module, a registration module, and a communication connection module: The device management module is used to connect the host gateway to a first router and connect all terminal devices within a preset range to the host gateway, and the first router is used to map the intranet address of the host gateway to a first external network address; The terminal management module is used to connect all legitimate control terminals to the second route and bind them to the host ID to obtain a binding result. The legitimate control terminal is a control terminal with access permission to the host gateway. The host ID is a unique identifier of the host gateway. The second route is used to map the intranet address of each legitimate control terminal to a second external network address. The second external network address has a one-to-one correspondence with the legitimate control terminal. The registration module is used to send the host ID and the first external network address to the peer-to-peer network server to register the host node corresponding to the host gateway, and send the second external network address and terminal ID of any legal control terminal to the peer-to-peer network server to register the control node corresponding to each legal control terminal, wherein the terminal ID is a unique identifier of the legal control terminal; The communication connection module is used to establish communication connections between all legal control terminals and the host gateway based on the binding result, the host node and the control node, thereby completing the construction of the Internet of Things system.
9. An electronic device, characterized in that: The electronic device comprises: a memory storing computer-readable instructions; and A processor executes computer-readable instructions stored in the memory to implement the method for building a peer-to-peer network-based intelligent Internet of Things system according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the method for building a peer-to-peer network-based intelligent Internet of Things system according to any one of claims 1 to 7.
Citation Information
Patent Citations
Intelligent terminal equipment network distribution method and system
CN111092794A
Network address translation method and device and electronic equipment
CN114422472A