An access data management and control terminal based on identity recognition
Patent Information
- Application Number
- CN202211577676.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-05
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2042-12-05
AI Technical Summary
[0005]本发明提供一种基于身份识别的访问数据管控终端,终端解决无法对终端数据信息进行有效的安全管控,无法基于不同身份的设备进行分类管控,影响终端储存的数据安全性的问题
[0040]本发明提供的基于身份识别的访问数据管控终端可以基于访问设备身份识别来进行有效管控,还基于访问身份识别技术,能准确有效的对不同访问设备限特定数据访问资源,提升安全性。
Smart Images

Figure CN115935311B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to an access data management terminal based on identity recognition. Background Technology
[0002] With the increasing application of terminals in various business application systems, terminals have become capable of implementing multiple data processing methods and functions. In some data storage fields, terminals can acquire and store data transmitted from external devices, and provide CRUD operations on the stored data.
[0003] For example, in the field of power monitoring, the terminal can acquire and store power monitoring data. When monitoring personnel or users need to view or modify the data, they use external devices to connect to the terminal for data processing. It can also be used in data display scenarios, where the terminal displays application data information. Before displaying the application data, external devices transmit the corresponding data, which is then stored on the terminal before being displayed. If it is necessary to modify the terminal data, external devices can perform CRUD operations on the data. The terminal can also act as a data communication relay, where the data sender stores data on the terminal, and then the receiving device connects to the terminal to retrieve the corresponding data.
[0004] Thus, the terminal needs to accommodate external devices for connection and data processing based on their different uses. Before connecting to the terminal, external devices need access permissions to be set, allowing only authorized devices to connect and process data. Traditional terminal access control relies on the terminal setting login information for authentication; successful authentication allows data interaction and processing. This method requires external devices to enter a verification account and password each time, causing significant inconvenience. Furthermore, this approach fails to effectively manage terminal data security, lacking the ability to categorize and manage devices based on their identities, thus compromising the security of data stored on the terminal. Summary of the Invention
[0005] This invention provides an access data management terminal based on identity recognition. The terminal solves the problems of ineffective security management of terminal data information and inability to classify and manage devices based on different identities, which affects the security of data stored on the terminal.
[0006] The terminal includes: a data acquisition device, a data processor, a storage device, and a communication module;
[0007] The data acquisition device is used to acquire whitelist information of access and usage terminals;
[0008] The data processor is used to obtain preset whitelist information, classify the whitelist information, and store it in the storage.
[0009] The access device communicates with the data processor through a communication module. The data processor identifies the access device's identity information based on the IMEI and determines whether the access device's identity information is in the whitelist. If it is, data interaction with the access device is realized.
[0010] Preferably, the data processor includes: an access receiving module and a device verification module;
[0011] The access receiving module is used to receive access requests sent by access devices. The access request includes identity information and a sequence number.
[0012] The device verification module is used to verify the identity information and serial number of the accessing device based on the IMEI and by retrieving the grouped whitelist information stored in the storage.
[0013] If the verification is successful, the access device and terminal can interact with each other.
[0014] Preferably, the data processor is also used to determine whether the access device is allowed to access based on the identity information and security level of the access device. When the security level of the access device is higher than the preset level, the access device is allowed to access.
[0015] After access is granted, the obtained user identity information is matched with the user data stored in the storage device to obtain user role information;
[0016] Based on user role information and the security level of the accessing device, determine the access permissions of the accessing device to the terminal data.
[0017] Preferably, the access device includes: a user registration module, a user login module, and a user data upload module;
[0018] The user registration module is used to register the user's identity information with the terminal, and the data processor stores the registered user identity information in the storage.
[0019] The user login module is used to log in and access the terminal, and send access requests and identity information to the data processor;
[0020] The data processor verifies the identity information of the accessing device. After successful verification, it configures the accessing device to view two types of data information based on the received data access request: data information that can be viewed and data information that cannot be viewed at will. It also extracts the keyword information of the data access request to push data information to the accessing device.
[0021] The data processor is also used to match the encryption level of the pushed data information, and select an encryption strategy to encrypt the pushed data information according to the encryption level.
[0022] Preferably, the data processor is also used to verify user information on the data stored in the storage device, set the security level of the data information stored in the storage device, and select different encryption algorithms according to different security levels.
[0023] The terminal also includes an authentication device, which includes fingerprint verification, facial verification, and password verification. The authentication data is stored in a storage device for verification by the data processor.
[0024] Preferably, the data processor is further configured to obtain the identity information of the currently accessing device and extract verification information from the identity information;
[0025] The data processor matches the registration information with the verification information, and the storage device stores the registration information and security status of the access device; the security status includes blacklist information and whitelist information, and the whitelist information corresponds to different security levels.
[0026] The data processor will issue an alarm if it verifies an access terminal in the blacklist.
[0027] Preferably, the data processor is also used to divide related access devices into an access group;
[0028] Obtain the type, parent device, and device attributes of the accessing devices in the access group, and authorize the accessing devices using package authorization and hierarchical authorization methods based on the type, parent device, and device attributes.
[0029] Preferably, the data processor is also used to receive the identity information of the accessing device and perform identity category analysis on the identity information;
[0030] The identity information data is classified and stored according to the identity category, and stored in the storage area pre-allocated in the storage device;
[0031] In response to receiving data information sent by the access device, the data processor categorizes and stores the data information sent by the access device by retrieving the partition status in the storage.
[0032] Preferably, the data processor obtains the initial security level corresponding to the access device and the target security level corresponding to the storage, and determines the relationship between the initial security level and the target security level;
[0033] In this embodiment of the invention, the data processor can determine the security level of each access device based on the security requirements of the access device.
[0034] Preferably, the data processor uses a quad-core processor, 1.3GHz;
[0035] The system also includes: 4GB of RAM; Windows 7 or later operating system;
[0036] The system requires Internet Explorer 6 or later, or Google Chrome as the browser.
[0037] The communication module includes: a USB interface, a WIFI module, a Bluetooth module, and a near-field communication (NFC) module;
[0038] The data processor interacts with the access device via a USB interface, a WIFI module, a Bluetooth module, and a near-field communication (NFC) module.
[0039] As can be seen from the above technical solutions, the present invention has the following advantages:
[0040] The access data management terminal based on identity recognition provided by this invention can effectively manage access based on the identity recognition of access devices. Furthermore, based on access identity recognition technology, it can accurately and effectively restrict specific data access resources for different access devices, thereby improving security.
[0041] This invention provides a clear and concise way to maintain terminal data, protect the security of terminal data, and provide managers with accurate statistical data and scientific decision support.
[0042] This invention allows for the simultaneous use of both bundled authorization and hierarchical authorization when authorizing access devices. Bundled authorization authorizes access terminals with interrelated relationships or similar attributes together. Hierarchical authorization includes multi-level authorization, that is, authorization is based on the access device's permissions. Different access levels are granted different permissions, satisfying various access device authorization methods, improving the flexibility of authorization methods, and effectively enabling access devices to quickly access terminals and process terminal data.
[0043] In the identity-based access data management terminal provided by this invention, the terminal performs hierarchical encryption on the transmitted data, effectively protecting the data and playing a role in data security protection. This invention can also prevent the terminal from being attacked and prevent criminals from stealing data information. Attached Figure Description
[0044] To more clearly illustrate the technical solution of the present invention, the accompanying drawings used in the description will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0045] Figure 1 This is a schematic diagram of an access data management terminal based on identity recognition. Detailed Implementation
[0046] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0047] The identity-based access data management terminal provided by this invention can be implemented in various forms. For example, the terminal described in the embodiments of this invention may include mobile terminals such as mobile phones, smartphones, laptops, digital broadcast receivers, personal digital assistants (PDAs), tablet computers (PADs), portable media players (PMPs), navigation devices, etc., as well as fixed terminals such as digital TVs, desktop computers, etc. Hereinafter, it is assumed that the terminal is a mobile terminal. However, those skilled in the art will understand that, in addition to elements specifically designed for mobile purposes, the construction according to embodiments of this invention can also be applied to fixed-type terminals.
[0048] like Figure 1 As shown, the terminal includes: a data acquisition device, a data processor, a storage device, and a communication module; the terminal may also include an audio / video (A / V) input module, a sensing module, an output module, and a power supply module, etc. However, it should be understood that it is not required to implement all the components shown. More or fewer components may be implemented alternatively. The elements of the mobile terminal will be described in detail below.
[0049] The communication module can be coupled to the terminal internally or externally. The wireless internet access technologies involved in this module can include wireless local area networks (Wi-Fi, WLAN), wireless broadband (Wibro), global microwave interconnection access (WiMAX), high-speed downlink packet access (HSDPA), etc.
[0050] Data acquisition devices can be touch screens, mice, keyboards, etc.
[0051] The data acquisition device is used to acquire whitelist information of access and usage terminals;
[0052] The data processor is used to obtain preset whitelist information, classify the whitelist information, and store it in the storage.
[0053] The access device communicates with the data processor through a communication module. The data processor identifies the access device's identity information based on the IMEI and determines whether the access device's identity information is in the whitelist. If it is, data interaction with the access device is realized.
[0054] The data processor can be implemented using at least one of the following: Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), processor, controller, microcontroller, microprocessor, or electronic unit designed to perform the functions described herein. In some cases, such implementations can be implemented within a controller. For software implementations, implementations such as processes or functions can be implemented with separate software modules that allow the performance of at least one function or operation. The software code can be implemented by a software application (or program) written in any suitable programming language, and the software code can be stored in memory and executed by the controller.
[0055] For example, the terminal includes a quad-core processor (1.3GHz), 4GB of RAM, and a Windows 7 or later operating system. The browser is Internet Explorer 6 or later, or Google Chrome.
[0056] The terminal's hardware may also include a quad-core processor with a clock speed of 1.4GHz; 4G DDR3 memory; a 7-inch or 8-inch high-definition IPS LCD screen that supports five-point touch; support for MicroSD, SIM card, USB interface, serial port and custom expansion port; and Android 5.0 and above system versions.
[0057] The terminal software requires the installation of a system management app, a secure access platform app, and a terminal management app. The system management app pushes commands to control the security of the terminal, the secure access terminal app is used to connect to the intranet using a dedicated VPN tunnel, and the terminal management app provides security control and other functions.
[0058] In one exemplary embodiment, the access device accesses the terminal via USB, Wi-Fi, Bluetooth, NFC, or other methods. Furthermore, policies that prioritize whitelisted devices can be prioritized, significantly improving both security and speed.
[0059] The terminal identifies the device's identity based on the IMEI and determines specific data access for a specific device; the terminal can push data of different security levels to the accessing device to implement whitelist-based access to specific data.
[0060] In one exemplary embodiment, the data processor includes: an access receiving module and a device verification module; the access receiving module is used to receive an access request sent by an access device, the access request including identity information and a sequence number; the terminal pre-builds a trusted execution environment for the terminal through a TPM;
[0061] The device verification module is used to verify the identity information and serial number of the accessing device based on the IMEI and by retrieving the grouped whitelist information stored in the storage.
[0062] If the verification is successful, the access device and terminal can interact with each other.
[0063] This invention not only sets up a whitelist of accessing devices but also involves a blacklist. Specifically, the data processor is also used to obtain the identity information of the currently accessing device and extract the verification information from the identity information.
[0064] Verification information can be displayed in the form of images, text, or characters. Each verification message possesses a unique and detectable data characteristic.
[0065] The data processor matches the registration information with the verification information, and the storage device stores the registration information and security status of the access device; the security status includes blacklist information and whitelist information, and the whitelist information corresponds to different security levels.
[0066] Specifically, the storage device contains registration information and security status of multiple access devices. This invention configures the security status with blacklist and whitelist information; the blacklist indicates dangerous access devices that are not permitted to access the terminal. The data processor searches and matches the extracted verification information in the storage device to obtain the verification information of the access device, solving the problems of time-consuming and inaccurate traditional manual verification and matching. If the data processor verifies an access terminal from the blacklist, it will issue an alarm.
[0067] Regarding the security level of this invention, the data processor is also used to determine whether the access device is allowed to access based on the identity information of the access device and the security level of the access device. When the security level of the access device is higher than the preset level, it is determined that the access device is allowed to access.
[0068] After access is granted, the obtained user identity information is matched with the user data stored in the storage device to obtain user role information; based on the user role information and the security level of the access device, the access permissions of the access device to the terminal data are determined.
[0069] In one exemplary embodiment, the data processor is further configured to verify user information on the data stored in the storage device, set the security level of the data information stored in the storage device, and select different encryption algorithms according to different security levels; the terminal also includes: an identity verification device, which includes fingerprint verification, facial verification, and password verification, and stores verification data in the storage device for verification by the data processor.
[0070] In an embodiment of the present invention, the data processor obtains the initial security level corresponding to the access device and the target security level corresponding to the storage, and determines the level relationship between the initial security level and the target security level;
[0071] In this embodiment of the invention, the data processor can determine the security level of each access device based on the security requirements of the access device.
[0072] Specifically, based on the security requirements of the access devices, multiple access devices are divided into at least two security levels. Access devices with relatively higher security levels have higher security requirements, while access devices with relatively lower security levels have lower security requirements.
[0073] In this embodiment of the invention, the relationship between access devices and their corresponding security levels can be recorded through a security level mapping table.
[0074] The data processor obtains the security level mapping table and, based on the relevant identifiers of the access devices, retrieves the initial security level corresponding to the access devices from the security level mapping table. The relevant identifiers of the access devices can be the name of the access devices, the address of the access devices, the type of the access devices, the parent devices, and device attributes, etc., which can uniquely represent the access devices.
[0075] Based on the initial security level of the accessed device and the target security level of the accessed device, the hierarchical relationship between the initial security level and the target security level can be determined.
[0076] In one exemplary embodiment, the access device includes: a user registration module, a user login module, and a user data upload module;
[0077] The user registration module is used to register the user's identity information with the terminal, and the data processor stores the registered user identity information in the storage.
[0078] The user login module is used to log in and access the terminal, and send access requests and identity information to the data processor;
[0079] The data processor verifies the identity information of the accessing device. After successful verification, it configures the accessing device to view two types of data information based on the received data access request: data information that can be viewed and data information that cannot be viewed at will. It also extracts the keyword information of the data access request to push data information to the accessing device.
[0080] The access device of the present invention includes: a user registration module, a user login module, and a user data upload module;
[0081] The user registration module is used to register the user's identity information with the terminal, and the data processor stores the registered user identity information in the storage.
[0082] The user login module is used to log in and access the terminal, and send access requests and identity information to the data processor;
[0083] The data processor verifies the identity information of the accessing device. After successful verification, it configures the accessing device to view two types of data information based on the received data access request: data information that can be viewed and data information that cannot be viewed at will. It also extracts the keyword information of the data access request to push data information to the accessing device.
[0084] The data processor is also used to match the encryption level of the pushed data information. The encryption levels are divided into low security level, medium security level and high security level. Based on the encryption level, an encryption strategy is selected to encrypt the pushed data information.
[0085] For low security levels, MD5 encryption is used; for medium security levels, DES, 3DES, or AES encryption is used; and for high security levels, asymmetric encryption is used. In the identity-based access data management terminal provided by this invention, the terminal effectively protects the transmitted data, thus playing a role in data security protection. This invention can also prevent the terminal from being attacked and prevent criminals from stealing data information.
[0086] In embodiments of the present invention, the data processor is further configured to divide associated access devices into an access group;
[0087] Obtain the type, parent device, and device attributes of the accessing devices in the access group, and authorize the accessing devices using package authorization and / or hierarchical authorization based on the type, parent device, and device attributes;
[0088] When authorizing access devices, the data processor can employ both package authorization and hierarchical authorization methods simultaneously. Package authorization authorizes access terminals that are interconnected or have the same attributes together. Hierarchical authorization includes multiple levels of authorization, meaning that authorization is based on the permissions of the access devices, with different permissions granted to different access levels.
[0089] In this invention, the type, parent device, and device attributes of the authorized access device can be determined first, and then authorization can be packaged and applied to other associated access devices. After the access device authorization is completed, it is simultaneously added to the associated access devices for unified authorization according to the conditions.
[0090] The data processor is also used to receive the identity information of the accessing device and perform identity category analysis on the identity information;
[0091] The identity information data is classified and stored according to the identity category, and stored in the storage area pre-allocated in the storage device;
[0092] The data processor responds to data sent by the accessing devices by retrieving partition status from the storage and classifying and storing the data according to its category. This improves the efficiency of each accessing device in adding, deleting, modifying, and querying the required data.
[0093] The identity-based access data management terminal provided by this invention can function as a processor or integrated circuit device, such as an integrated circuit chip or chipset. Alternatively or additionally, if implemented in software or firmware, the technology can be implemented at least partially by a computer-readable data storage medium, including instructions that, when executed, cause the processor to perform one or more of the methods described above. For example, the computer-readable data storage medium can store instructions, such as those executed by the processor.
[0094] The identity-based access data management terminal provided by this invention comprises the units and algorithm steps of various examples described in conjunction with the embodiments disclosed herein. It can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0095] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A data access control terminal based on identity recognition, characterized in that, include: Data acquisition device, data processor, storage device, and communication module; The data acquisition device is used to acquire whitelist information of access and usage terminals; The data processor is used to obtain preset whitelist information, classify the whitelist information, and store it in the storage. The access device communicates with the data processor through the communication module. The data processor identifies the access device's identity information based on the IMEI and determines whether the access device's identity information is in the whitelist. If it is, data interaction with the access device is realized. The data processor includes: an access receiving module and a device verification module; The access receiving module is used to receive access requests sent by access devices. The access request includes identity information and a sequence number. The device verification module is used to verify the identity information and serial number of the accessing device based on the IMEI and by retrieving the grouped whitelist information stored in the storage. If the verification is successful, the device and terminal can interact with each other for data. The data processor is also used to group related access devices into access groups; Obtain the type, parent device, and device attributes of the accessing devices in the access group, and authorize the accessing devices using package authorization and hierarchical authorization methods based on the type, parent device, and device attributes.
2. The identity recognition-based access data management terminal according to claim 1, characterized in that, The data processor is also used to determine whether the access device is allowed to access based on the access device's identity information and security level. When the access device's security level is higher than the preset level, the access device is allowed to access. After access is granted, the obtained user identity information is matched with the user data stored in the storage device to obtain user role information; Based on user role information and the security level of the accessing device, determine the access permissions of the accessing device to the terminal data.
3. The identity-based access data management terminal according to claim 1, characterized in that, The access devices include: a user registration module, a user login module, and a user data upload module; The user registration module is used to register the user's identity information with the terminal, and the data processor stores the registered user identity information in the storage. The user login module is used to log in and access the terminal, and send access requests and identity information to the data processor; The data processor verifies the identity information of the accessing device. After successful verification, it configures the accessing device to view two types of data information based on the received data access request: data information that can be viewed and data information that cannot be viewed at will. It also extracts the keyword information of the data access request to push data information to the accessing device. The data processor is also used to match the encryption level of the pushed data information, and select an encryption strategy to encrypt the pushed data information according to the encryption level.
4. The identity recognition-based access data management terminal according to claim 3, characterized in that, The data processor is also used to verify user information in the data stored in the storage device, set the security level of the data information stored in the storage device, and select different encryption algorithms according to different security levels. The terminal also includes an authentication device, which includes fingerprint verification, facial verification, and password verification. The authentication data is stored in a storage device for verification by the data processor.
5. The access data management terminal based on identity recognition according to claim 1, characterized in that, The data processor is also used to obtain the identity information of the currently accessing device and extract the verification information from the identity information; The data processor matches the registration information with the verification information, and the storage contains the registration information and security status of the access device. Security status includes blacklist information and whitelist information, with the whitelist information corresponding to different security levels; The data processor will issue an alarm if it verifies an access terminal in the blacklist.
6. The access data management terminal based on identity recognition according to claim 1, characterized in that, The data processor is also used to receive the identity information of the accessing device and perform identity category analysis on the identity information; The identity information data is classified and stored according to the identity category, and stored in the storage area pre-allocated in the storage device; In response to receiving data information sent by the access device, the data processor categorizes and stores the data information sent by the access device by retrieving the partition status in the storage.
7. The identity recognition-based access data management terminal according to claim 1, characterized in that, The data processor obtains the initial security level corresponding to the access device and the target security level corresponding to the storage, and determines the relationship between the initial security level and the target security level; The data processor determines the security level of each access device based on the security requirements of the access device.
8. The access data management terminal based on identity recognition according to claim 1, characterized in that, The data processor uses a quad-core processor, 1.3GHz; The system also includes: 4GB of RAM; Windows 7 or later operating system; The system requires Internet Explorer 6 or later, or Google Chrome as the browser. The communication module includes: a USB interface, a WIFI module, a Bluetooth module, and a near-field communication (NFC) module; The data processor interacts with the access device via a USB interface, a WIFI module, a Bluetooth module, and a near-field communication (NFC) module.
Citation Information
Patent Citations
Resource access method and device, terminal and storage medium
CN110213215A
Safety protection system and method suitable for power intelligent terminal equipment
CN112511494A