Access Token Processing Method and Device

By introducing multi-level access tokens in the OLA specification, the problem of insufficient access permission control is solved, flexible access control for devices, services and attributes is achieved, and system security is improved.

CN116114219BActive Publication Date: 2025-07-08GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080105407.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-12-25
Publication Date
2025-07-08
Estimated Expiration
2040-12-25

AI Technical Summary

Technical Problem

Existing access tokens cannot achieve finer granular access control in the Smart Home Open Connection Alliance (OLA) specification, resulting in inflexible access control for devices, services, and attributes.

Method used

By introducing multi-level access tokens at account level, device level, service level and attribute level, devices allow them to receive different levels of access tokens for finer granular access control.

Benefits of technology

It realizes flexible access control for devices, services, attributes, etc., and improves the precision of system security and permission management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116114219B_ABST
    Figure CN116114219B_ABST
Patent Text Reader

Abstract

This application relates to a method and device for processing access tokens. Among them, a method for processing access tokens includes: a first device receiving at least one level of access tokens from a second device. Another method for processing access tokens includes: a second device sending at least one level of access tokens to a first device. In the embodiments of this application, through access tokens of different levels, more fine-grained access permissions can be controlled.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communications, and more particularly, to a method and device for processing access tokens. Background Art

[0002] In the Open Link Alliance (OLA) specification, the access control permissions and methods for application terminals have not been specified. A user issues an access token (Token) to a device through a mobile application or through a cloud platform, or the device actively requests an access token from the cloud platform, enabling devices under the user account to access each other. Among them, the cloud platform can also be referred to as the cloud, access cloud, etc. However, the current access token cannot achieve more fine-grained access permission control. Summary of the Invention

[0003] Embodiments of this application provide a method and device for processing access tokens, which can control more fine-grained access permissions.

[0004] An embodiment of this application provides a method for processing an access token, including: a first device receives at least one level of access token from a second device.

[0005] An embodiment of this application provides a method for processing an access token, including: a second device sends at least one level of access token to a first device.

[0006] An embodiment of this application provides a first device, including: a receiving unit, configured to receive at least one level of access token from a second device.

[0007] An embodiment of this application provides a second device, including: a sending unit, configured to send at least one level of access token to a first device.

[0008] An embodiment of this application provides a first device, including a processor and a memory. The memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory, so that the first device executes the above-mentioned access token processing method.

[0009] An embodiment of this application provides a second device, including a processor and a memory. The memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory, so that the second device executes the above-mentioned access token processing method.

[0010] An embodiment of this application provides a chip for implementing the above-mentioned access token processing method.

[0011] Specifically, the chip includes: a processor, configured to call and run a computer program from a memory, so that a device installed with the chip executes the above-mentioned access token processing method.

[0012] An embodiment of the present application provides a computer-readable storage medium for storing a computer program, which, when run on a device, causes the device to execute the above-mentioned access token processing method.

[0013] An embodiment of the present application provides a computer program product including computer program instructions that cause a computer to execute the above-mentioned access token processing method.

[0014] An embodiment of the present application provides a computer program that, when running on a computer, causes the computer to execute the above-mentioned access token processing method.

[0015] In the embodiment of the present application, through access tokens at different levels, more fine-grained access permissions can be controlled. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 is a schematic diagram of the device model of OLA according to an embodiment of the present application.

[0017] Figure 2 is a flowchart of an example of issuing an access token.

[0018] Figure 3 is a schematic flowchart of an access token processing method according to an embodiment of the present application.

[0019] Figure 4 is a schematic flowchart of an access token processing method according to another embodiment of the present application.

[0020] Figure 5 is a flowchart of issuing token example 1 of issuing an access token.

[0021] Figure 6 is a flowchart of issuing token example 2 of issuing an access token.

[0022] Figure 7 is a flowchart of issuing token example 3 of issuing an access token.

[0023] Figure 8 is a flowchart of updating token example 1 of issuing an access token.

[0024] Figure 9 is a flowchart of updating token example 2 of issuing an access token.

[0025] Figure 10 is a flowchart of deleting token example 1 of issuing an access token.

[0026] Figure 11 is a flowchart of deleting token example 2 of issuing an access token.

[0027] Figure 12 It is a schematic block diagram of a first device according to an embodiment of the present application.

[0028] Figure 13 It is a schematic block diagram of a first device according to another embodiment of the present application.

[0029] Figure 14 It is a schematic block diagram of a second device according to an embodiment of the present application.

[0030] Figure 15 It is a schematic block diagram of a second device according to another embodiment of the present application.

[0031] Figure 16 It is a schematic block diagram of a communication device according to an embodiment of the present application.

[0032] Figure 17 It is a schematic block diagram of a chip according to an embodiment of the present application.

[0033] Figure 18 It is a schematic block diagram of a communication system according to an embodiment of the present application. Detailed implementation manners

[0034] Next, the technical solutions in the embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application.

[0035] To facilitate understanding of the technical solutions in the embodiments of the present application, the related technologies in the embodiments of the present application are described below. The following related technologies can be arbitrarily combined with the technical solutions in the embodiments of the present application as optional solutions, and they all fall within the protection scope of the embodiments of the present application.

[0036] Regarding the device model of the Open Link Alliance (OLA):

[0037] According to the draft specification of the smart home OLA, the device model of OLA can be referred to Figure 1 . Among them, the device can include various application terminals, such as smart home devices in the smart home scenario, etc. The application terminal can describe its function set through different service sets. A service can be an independent and meaningful function group, and a service can include attributes, methods, events, etc. Among them, an attribute can be the smallest unit for describing the state and function of the application terminal. A method can be used to implement the specific function of the service, and this type of function generally cannot be completed by reading and writing a single attribute. An event can include specific information actively reported by the application terminal to other devices.

[0038] For example, a device can include the following fields:

[0039] type: Device type, which may include the device name (name), the unique identifier of the device type (deviceUUID), etc.;

[0040] description: The description of the device, used to explain the functions of the device, etc.;

[0041] serviceList: Service list, where each service can identify the service type and whether it is mandatory in this device.

[0042] For another example, a service may include the following fields:

[0043] type: Service type, which may include the service name (name), the unique identifier of the service type (ServiceUUID), etc.;

[0044] description: The description of the service, used to explain the purpose of the service, etc.;

[0045] actionList: Method list, where each method can contain the method type and whether it is mandatory in this service;

[0046] eventList: Event list, where each event can contain the event type and whether it is mandatory in this service;

[0047] propertyList: Property list, where each property can contain the property type and whether it is mandatory in this service.

[0048] For another example, a property may include the following fields:

[0049] type: Property type, which may include the property name (name), the unique identifier of the property type (propertyUUID), etc.;

[0050] dataType: The data type of the property value, such as integer, string, structure, etc.;

[0051] access: The access permission of the property, for example: read (R), write (W), notify (N), and any combination of the three. Generally, properties that support the notify (N) permission need to support the read (R) permission; properties that only support the write (W) permission and do not support the read (R) permission should not support the notify (N) permission;

[0052] For another example, an action may include the following fields:

[0053] type: Method type, which may include the operation name (name), the unique identifier of the operation type (actionUUID), etc.;

[0054] description: Description of the operation, used to explain the purpose of the operation or usage rules, etc.;

[0055] inParameter: List of input parameters, which can be zero or more;

[0056] outParameter: List of output parameters, which can be zero or more.

[0057] For another example, an event can include the following fields:

[0058] type: Event type, which can include event name, unique identifier of the event (eventUUID), etc.; For example, the event type can include, for example: message (general message, such as device online / offline), alert (alarm message, such as refrigerator door not closed), and fault (device fault message, such as compressor not working), etc.;

[0059] outParameter: Zero or more parameters that may be included in the reported event message; The above attributes should support notification;

[0060] description: Description of the event, used to explain the purpose of the event or usage rules, etc.

[0061] Regarding the access token (Token):

[0062] The user issues an access token to the device through the mobile application or through the cloud platform, or the device actively requests an access token from the cloud platform, so that the devices under the user account can access each other. Among them, the cloud platform can also be called the cloud, access cloud, etc. See Figure 2 , an example of the process of issuing a token for access is as follows:

[0063] (1) An example of the process of issuing an access token to the device through the cloud can include:

[0064] S11 and S12. Configure the device to access the network. For example, the user configures the IoT (Internet of Things) device to access the network through the mobile application.

[0065] S13. The device accesses the network for the first time.

[0066] S14. If there is no account-level access token (token) in the access cloud, an account-level token can be generated and saved; if there is an account-level token in the access cloud, directly execute S15 to send the account-level token to the device. Generally, when the device first accesses the network, there is no account-level token in the access cloud, and when the device accesses the network again, there may be an access token in the access cloud.

[0067] S15. The access cloud sends the account-level token to the device.

[0068] (2) An example of the process of sending an access token to the device through a mobile phone can include:

[0069] S21. The mobile phone application requests an account-level token from the access cloud.

[0070] S22. If there is no account-level token in the access cloud, an account-level token can be generated and saved. If there is an account-level token in the access cloud, directly execute S23 to send the account-level token to the mobile phone application.

[0071] S23. The access cloud sends the account-level token to the mobile phone application.

[0072] S24. The mobile phone application sends the account-level token to the device.

[0073] (3) An example of the process of the device actively requesting an access token can include.

[0074] S31. The IoT device detects whether it has an account-level token. If not, execute S32 to request from the access cloud.

[0075] S32. The IoT device requests an account-level token from the access cloud.

[0076] S33. If there is no account-level token in the access cloud, an account-level token can be generated and saved. If there is an account-level token in the access cloud, directly execute S34 to send the account-level token to the device.

[0077] S34. The access cloud sends the account-level token to the device.

[0078] In this example, there is only account-level access control in the access token (Token), and the granularity of access permission control is not fine enough to flexibly perform more fine-grained access control on devices, services, attributes, etc.

[0079] Figure 3 It is a schematic flowchart of an access token processing method 40 according to an embodiment of the present application. This method can optionally be applied to Figure 1The device model shown, but not limited thereto. The method includes at least some of the following content.

[0080] S41. The first device receives at least one level of access token from the second device.

[0081] Optionally, in the embodiments of the present application, the at least one level of access token includes at least one of the following:

[0082] An account-level access token;

[0083] A device-level access token;

[0084] A service-level access token;

[0085] An attribute-level access token.

[0086] Exemplarily, during the process of issuing the token, the first device may receive one or more of an account-level access token, a device-level access token, a service-level access token, and an attribute-level access token issued by the second device. The permission scopes of different levels of access tokens may be different. Based on the required permission scope of the first device, one or more levels of access tokens corresponding to this permission scope may be received from the second device.

[0087] In the embodiments of the present application, the account-level access token may control the account-level access permission, the device-level access token may control the device-level access permission, and the service-level access token may control the service-level access permission; the attribute-level access token may control the attribute-level access permission, and the control granularity is finer, which is beneficial to flexibly perform access control on devices, services, attributes, etc.

[0088] Optionally, in the embodiments of the present application, the account-level access token is used to access at least one of the non-restricted attributes, non-restricted methods, and non-restricted events of the devices under the same account.

[0089] Exemplarily, the permission scope of the account-level access token may include allowing access to at least one of the non-restricted attributes, non-restricted methods, and non-restricted events of all devices under a certain account. In the embodiments of the present application, allowing access to non-restricted attributes may include allowing operations such as reading, writing, adding, deleting, and modifying the non-restricted attributes.

[0090] In an example of a specific permission scope, an account includes Device A and Device B. Device A has restricted services S1, S2 and unrestricted service S3. Among them, S1 has unrestricted attributes C1, C2 and restricted event E0. S2 has restricted attribute C3 and unrestricted attribute C4. S3 has unrestricted method F1 and restricted method F2. Device B has unrestricted service S4 and restricted services S5, S6. Among them, S4 has unrestricted attribute C5. S5 has unrestricted attribute C6 and unrestricted event E1. S6 has unrestricted attribute C7, restricted attribute C8 and restricted method F3.

[0091] If the permission scope of the account-level access token of this account can include allowing access to the unrestricted method F1 of the unrestricted service S3 of Device A, and the unrestricted attribute C5 of the unrestricted service S4 of Device B. In addition, if C5 supports read and write permissions, the permission scope of the account-level access token can also include allowing read and write operations on this C5.

[0092] Optionally, in the embodiments of the present application, the device-level access token is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of the unrestricted services of the same device or multiple devices under the same account.

[0093] Exemplarily, the permission scope of the device-level access token can include allowing access to at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of all unrestricted services of the same device. If all devices under a certain account use the same device-level access token, the permission scope of this device-level access token is equivalent to the permission scope of the account-level access token. Referring to the above example of the permission scope, in a specific example, the permission scope of the device-level access token for Device A can include allowing access to the unrestricted method F1 of the unrestricted service S3 of Device A. The permission scope of the device-level access token for Device B can include allowing access to the unrestricted attribute C5 of the unrestricted service S4 of Device B.

[0094] Optionally, in the embodiments of the present application, the service-level access token includes:

[0095] The service-level access token of the same device;

[0096] The service-level access token across devices.

[0097] Exemplarily, the permission scope of the service-level access token can include allowing access to all unrestricted attributes of one or more restricted services of one or more specified devices.

[0098] Optionally, in the embodiments of the present application,

[0099] A service-level access token for the same device is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service of the same device;

[0100] A service-level access token across devices is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service of multiple devices.

[0101] In a specific example, the scope of permissions of a service-level access token for the same device may include: allowing access to the unrestricted attributes C1 and C2 of the restricted service S1 of device A.

[0102] In a specific example, the scope of permissions of a service-level access token across devices may include: allowing access to the unrestricted attributes C1 and C2 of the restricted service S1 of device A, and the unrestricted attribute C7 of the restricted service S6 of device B.

[0103] Optionally, in the embodiments of the present application, the attribute-level access token includes:

[0104] An attribute-level access token for the same service;

[0105] An attribute-level access token across services;

[0106] An attribute-level access token across devices.

[0107] Exemplarily, the scope of permissions of the attribute-level access token may include allowing access to one or more restricted attributes, restricted methods, or restricted events of one or more restricted services of one or more specified devices. The scope of permissions of the attribute-level access token may also include allowing access to one or more restricted attributes, restricted methods, or restricted events of one or more unrestricted services of one or more specified devices.

[0108] Optionally, in the embodiments of the present application,

[0109] An attribute-level access token for the same service is used to access at least one of the at least one restricted attribute, restricted method, and restricted event of the same service of the same device;

[0110] An attribute-level access token across services is used to access at least one of the at least one restricted attribute, restricted method, and restricted event of multiple services of the same device;

[0111] An attribute-level access token across devices is used to access at least one of the at least one restricted attribute, restricted method, and restricted event of multiple services of multiple devices.

[0112] The same service mentioned above may be the same restricted service or the same unrestricted service.

[0113] The above-mentioned multiple services may include multiple restricted services, may also include multiple unrestricted services, or may include both restricted services and unrestricted services.

[0114] In a specific example, the scope of permissions of an access token at the attribute level of the same service may include: allowing access to the restricted attribute C3 of the restricted service S2 of device A.

[0115] In a specific example, the scope of permissions of an access token at the attribute level of the same service may include: allowing access to the restricted method F2 of the unrestricted service S3 of device A.

[0116] In a specific example, the scope of permissions of an access token at the attribute level across services may include: allowing access to the restricted event E0 of the restricted service S1 of device A, and the restricted attribute C3 of the restricted service S2.

[0117] In a specific example, the scope of permissions of an access token at the attribute level across services may include: allowing access to the restricted event E0 of the restricted service S1 of device A, and the restricted method F2 of the unrestricted service S3.

[0118] In a specific example, the scope of permissions of an access token at the attribute level across devices may include: allowing access to the restricted attribute C3 of the restricted service S2 of device A, and the restricted attribute C8 and the restricted method F3 of the restricted service S6 of device B.

[0119] In a specific example, the scope of permissions of an access token at the attribute level across devices may include: allowing access to the restricted method F2 of the unrestricted service S3 of device A, and the restricted attribute C8 and the restricted method F3 of the restricted service S6 of device B.

[0120] Optionally, in an embodiment of the present application, when the first device receives at least one level of access token from the second device, it further includes: when the first device is a controlled device, the first device receives a device-level access token from the second device; or when the first device is a master device, the first device receives a device-level access token and a list of controlled device identifiers from the second device.

[0121] Exemplarily, if the first device is an IoT device and the second device is a cloud device, the first device may request the cloud device to issue a device-level access token. If the IoT device is a controlled device, the cloud device may issue the device-level access token to the IoT device after generating the device-level access token. If the IoT device is a master device, the cloud device may issue the device-level access token and a list of controlled device identifiers to the IoT device after generating the device-level access token. In the embodiments of the present application, the list of controlled device identifiers may include the identifiers of one or more devices that allow the master device to access based on the received access token.

[0122] Exemplarily, if the first device is an IoT device and the second device is a configuration device, the cloud device issues a device-level access token to the IoT device through the configuration device. Specifically, the first device may request the cloud device to issue a device-level access token. If the IoT device is a controlled device, the cloud device may send the generated device-level access token to the configuration device after generating the device-level access token, and the configuration device issues the device-level access token to the IoT device. If the IoT device is a master device, the cloud device may send the generated device-level access token to the configuration device after generating the device-level access token, and the configuration device issues the device-level access token and a list of controlled device identifiers to the IoT device.

[0123] In the embodiments of the present application, a device with the function of configuring device network access may be referred to as a configuration device. For example, the configuration device may include a mobile phone application, a tablet computer, a smart speaker, etc. with the function of configuring device network access.

[0124] Optionally, in the embodiments of the present application, when the first device receives at least one level of access token from the second device, it further includes: when the first device is a controlled device, the first device receives a service-level access token and a list of service names from the second device; or when the first device is a master device, the first device receives a service-level access token, a list of service names, and a controlled device identifier from the second device.

[0125] Exemplarily, if the first device is an IoT device and the second device is a cloud device, the first device may request the cloud device to issue an access token at the service level. If the IoT device is a controlled device, after generating the access token at the service level, the cloud device may issue the access token at the service level and a list of service names to the IoT device. If the IoT device is a master device, after generating the access token at the service level, the cloud device may issue the access token at the service level, a list of service names, and an identifier of the controlled device to the IoT device. In the embodiments of the present application, the list of service names may include one or more service names that allow the master device to access based on the received access token. In the embodiments of the present application, if it is an access token at the service level of the same device, an identifier of the controlled device is issued together with the access token at the service level and the list of service names. If it is an access token at the service level across devices, multiple identifiers of the controlled devices are issued together with the access token at the service level and the list of service names.

[0126] Exemplarily, if the first device is an IoT device and the second device is a configuration device, the cloud device issues an access token at the service level to the IoT device through the configuration device. Specifically, the first device may request the cloud device to issue an access token at the service level. If the IoT device is a controlled device, after generating the access token at the service level, the cloud device may send it to the configuration device, and the configuration device issues the access token at the service level to the IoT device. If the IoT device is a master device, after generating the access token at the service level, the cloud device may send it to the configuration device, and the configuration device issues the access token at the service level, a list of service names, and an identifier of the controlled device to the IoT device.

[0127] Optionally, in the embodiments of the present application, the first device receiving at least one level of access token from the second device further includes: when the first device is a controlled device, the first device receives an access token at the attribute level, service names, and attribute-related information from the second device; or when the first device is a master device, the first device receives an access token at the service level, service names, attribute-related information, and an identifier of the controlled device from the second device; where the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

[0128] Exemplarily, if the first device is an IoT device and the second device is a cloud device, the first device may request the cloud device to issue an attribute-level access token, service name, and attribute-related information. If the IoT device is a controlled device, after generating the attribute-level access token, the cloud device may issue the attribute-level access token to the IoT device. If the IoT device is a master device, after generating the attribute-level access token, the cloud device may issue the attribute-level access token, a list of service names, and the controlled device identifier, service name, attribute-related information, and the controlled device identifier to the IoT device. In the embodiments of the present application, if it is an attribute-level access token for the same service, a service name is issued together with the attribute-level access token. If it is an attribute-level access token across services, multiple service names are issued together with the attribute-level access token. If it is an attribute-level access token across devices, multiple controlled device identifiers and multiple service names are issued together with the attribute-level access token.

[0129] Exemplarily, if the first device is an IoT device and the second device is a configuration device, the cloud device issues an attribute-level access token to the IoT device through the configuration device. Specifically, the first device may request the cloud device to issue an attribute-level access token, service name, and attribute-related information. If the IoT device is a controlled device, after generating the service-level access token, the cloud device may send it to the configuration device, and the configuration device issues the service-level access token, a list of service names, and the controlled device identifier, service name, attribute-related information, and the controlled device identifier to the IoT device. If the IoT device is a master device, after generating the service-level access token, the cloud device may send it to the configuration device, and the configuration device issues the service-level access token, a list of service names, and the controlled device identifier to the IoT device.

[0130] Optionally, in the embodiments of the present application, in addition to the above-mentioned issuance of tokens by the cloud device or by the configuration device, a device may actively request a token.

[0131] Optionally, in the embodiments of the present application, if the first device actively requests a token, the method further includes: the first device sending a token issuance request to the second device.

[0132] Optionally, in the embodiments of the present application, the token issuance request includes one of the following:

[0133] A list of controlled device identifiers, where the token issuance request is used to request a device-level access token;

[0134] A list of controlled device identifiers and service names, where the token issuance request is used to request a service-level access token;

[0135] The controlled device identifier, service name, and attribute-related information, where the token issuance request is used to request an access token at the attribute level. Among them, the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

[0136] For example, if a first device needs to request an access token at the device level, and the first device is an IoT device and the second device is a cloud device, the IoT device can send a token issuance request including a list of controlled device identifiers to the cloud device.

[0137] Another example, if a first device needs to request an access token at the service level, and the first device is an IoT device and the second device is a cloud device, the IoT device can send a token issuance request including the controlled device identifier and a list of service names to the cloud device.

[0138] Another example, if a first device needs to request an access token at the attribute level, and the first device is an IoT device and the second device is a cloud device, the IoT device can send a token issuance request including the controlled device identifier, service name, and attribute-related information to the cloud device.

[0139] Subsequently, the token directly generated and issued by the cloud device, or the token generated by the cloud device and issued by the configuration device.

[0140] Optionally, in the embodiments of the present application, if a token needs to be updated, the method further includes: the first device receives from the second device the identifier of at least one level of access token that needs to be updated and the content to be updated; the first device updates the access token corresponding to the identifier of at least one level of access token that needs to be updated based on the content to be updated.

[0141] Optionally, the content to be updated may include the validity period, permission scope, etc. of one or more tokens. One or more access tokens can be updated at a time.

[0142] For example, if the first device is an IoT device and the second device is a cloud device, the configuration device sends the identifier of a certain level of access token that needs to be updated and the content to be updated to the cloud device. After the cloud device updates the access token, it can send the identifier of the access token and the content to be updated to the IoT device through the cloud device. After the IoT device receives the identifier of the access token and the content to be updated, it modifies the content to be updated in the access token corresponding to the identifier of the access token locally.

[0143] For another example, if the first device is an IoT device and the second device is a cloud device, the configuration device sends the identifier of a certain level of access token that needs to be updated and the content that needs to be updated to the cloud device. After the cloud device updates the access token, it can send the identifier of the access token and the content that needs to be updated to the configuration device. The configuration device then sends the identifier of the access token and the content that needs to be updated to the IoT device. After receiving the identifier of the access token and the content that needs to be updated, the IoT device modifies the content that needs to be updated in the access token corresponding to the identifier of the access token locally.

[0144] Optionally, in the embodiments of the present application, if a token needs to be deleted, the method further includes:

[0145] The first device receives the identifier of at least one level of access token that needs to be deleted from the second device;

[0146] The first device deletes the corresponding access token based on the identifier of at least one level of access token that needs to be deleted.

[0147] Optionally, in the embodiments of the present application, the second device is a configuration device or a cloud device.

[0148] Optionally, the identifier of at least one level of access token that needs to be deleted can be obtained on the configuration device in response to a user's selection operation. One or more access tokens can be deleted at a time.

[0149] For example, if the first device is an IoT device and the second device is a cloud device, the configuration device sends the identifier of a certain level of access token that needs to be deleted to the cloud device. After the cloud device deletes the access token, it can notify the IoT device of the identifier of the deleted access token.

[0150] For another example, if the first device is an IoT device and the second device is a cloud device, the configuration device sends the identifier of a certain level of access token that needs to be deleted to the cloud device. After the cloud device deletes the access token, it can notify the configuration device of the identifier of the deleted access token. The configuration device then notifies the IoT device of the identifier of the deleted access token.

[0151] Optionally, in the embodiments of the present application, the method further includes at least one of the following sharing methods:

[0152] The first device shares at least one level of access token with the configuration device or the Internet of Things device bound to other accounts on the same platform;

[0153] The first device shares at least one level of access token with the configuration device or the Internet of Things device bound to other accounts on the same platform through the cloud device;

[0154] The first device shares at least one level of access tokens with the configuration devices or Internet of Things devices bound to other accounts on different platforms.

[0155] The first device shares at least one level of access tokens with the configuration devices or Internet of Things devices bound to other accounts on different platforms through the cloud device.

[0156] Exemplarily, if Account 1 and Account 2 are connected to the same cloud platform, the devices under Account 1 can share one or more levels of access tokens with the configuration devices such as mobile applications under Account 2, and can also share one or more levels of access tokens with the IoT devices under Account 2.

[0157] Exemplarily, if Account 1 and Account 2 are connected to the same cloud platform, the first device under Account 1 can share one or more levels of access tokens with the configuration devices such as mobile applications under Account 2 through the cloud platform, and can also share one or more levels of access tokens with the IoT devices under Account 2 through the cloud platform.

[0158] Exemplarily, if Account 1, Device 1-1 under Account 1, Account 2, and Device 2-1 under Account 2 are connected to the same cloud platform, Device 1-1 can share one or more levels of access tokens under Account 1 with Device 2-1 under Account 2.

[0159] Exemplarily, if Account 1, Device 1-1 under Account 1, Account 2, and Device 2-1 under Account 2 are connected to the same cloud platform, Device 1-1 can share one or more levels of access tokens under Account 1 with Device 2-1 under Account 2 through the cloud platform.

[0160] Exemplarily, if Account 1, Device 1-1 under Account 1 are connected to Cloud Platform C-1, Account 2, and Device 2-1 under Account 2 are connected to Cloud Platform C-2, Device 1-1 can share one or more levels of access tokens under Account 1 with Device 2-1 under Account 2.

[0161] Exemplarily, if Account 1, Device 1-1 under Account 1 are connected to Cloud Platform C-1, Account 2, and Device 2-1 under Account 2 are connected to Cloud Platform C-2, Device 1-1 can share one or more levels of access tokens under Account 1 with Device 2-1 under Account 2 through Cloud Platforms C-1 and C-2.

[0162] Figure 4 It is a schematic flowchart of an access token processing method 50 according to an embodiment of the present application. This method can optionally be applied to Figure 1 the device model shown, but is not limited thereto. This method includes at least part of the following content.

[0163] S51. The second device sends at least one level of access tokens to the first device.

[0164] Exemplarily, in the scenario of issuing tokens, the second device can be a cloud device or a configuration device. After generating at least one level of access tokens, the cloud device can directly issue them to the first device or issue them to the first device through the configuration device.

[0165] Optionally, in the embodiments of the present application, the at least one level of access tokens includes at least one of the following:

[0166] Account-level access tokens;

[0167] Device-level access tokens;

[0168] Service-level access tokens;

[0169] Attribute-level access tokens.

[0170] Optionally, in the embodiments of the present application, the service-level access tokens include:

[0171] Service-level access tokens for the same device;

[0172] Cross-device service-level access tokens.

[0173] Optionally, in the embodiments of the present application, the attribute-level access tokens include:

[0174] Attribute-level access tokens for the same service;

[0175] Cross-service attribute-level access tokens;

[0176] Cross-device attribute-level access tokens.

[0177] Optionally, in the embodiments of the present application, the account-level access tokens are used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of the devices under the same account.

[0178] Optionally, in the embodiments of the present application, the device-level access tokens are used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of the same device or multiple devices under the same account.

[0179] Optionally, in the embodiments of the present application,

[0180] The service-level access tokens for the same device are used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service of the same device;

[0181] A service-level access token across devices is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service of multiple devices.

[0182] Optionally, in the embodiments of the present application,

[0183] An attribute-level access token of the same service is used to access at least one of the restricted attributes, restricted methods, and restricted events of the same service of the same device;

[0184] An attribute-level access token across services is used to access at least one of the restricted attributes, restricted methods, and restricted events of multiple services of the same device;

[0185] An attribute-level access token across devices is used to access at least one of the restricted attributes, restricted methods, and restricted events of multiple services of multiple devices.

[0186] Optionally, in the embodiments of the present application, the second device sends at least one level of access token to the first device, including: when the first device is a controlled device, the second device sends a service-level access token and a service name list to the first device; or when the first device is a master device, the second device sends a service-level access token, a service name list, and a controlled device identifier to the first device.

[0187] Optionally, in the embodiments of the present application, the first device receiving at least one level of access token from the second device further includes: when the first device is a controlled device, the second device sends an attribute-level access token, a service name, and attribute-related information to the first device; or when the first device is a master device, the second device sends a service-level access token, a service name, attribute-related information, and a controlled device identifier to the first device; wherein the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

[0188] Optionally, in the embodiments of the present application, the method further includes: the second device receives a token issuance request from the first device.

[0189] Optionally, in the embodiments of the present application, the token issuance request includes one of the following:

[0190] A list of controlled device identifiers, and the token issuance request is used to request a device-level access token;

[0191] A controlled device identifier and a list of service names, and the token issuance request is used to request a service-level access token;

[0192] The controlled device identifier, service name, and attribute-related information, where the token issuance request is used to request an access token at the attribute level, and where the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

[0193] Optionally, in an embodiment of the present application, the method further includes:

[0194] The second device sends the identifier of at least one level of access token that needs to be updated and the content that needs to be updated to the first device.

[0195] Exemplarily, in a scenario of updating a token, the second device can be a cloud device or a configuration device. After the cloud device updates at least one level of access token, it can directly send the identifier of at least one level of access token that needs to be updated and the content that needs to be updated to the first device, or send the identifier of at least one level of access token that needs to be updated and the content that needs to be updated to the first device through the configuration device.

[0196] Optionally, in an embodiment of the present application, the method further includes:

[0197] The second device sends the identifier of at least one level of access token that needs to be deleted to the first device.

[0198] Exemplarily, in a scenario of deleting a token, the second device can be a cloud device or a configuration device. After the cloud device deletes at least one level of access token, it can directly notify the first device of the identifier of at least one level of access token that needs to be deleted, or notify the first device of the identifier of at least one level of access token that needs to be deleted through the configuration device.

[0199] Optionally, in an embodiment of the present application, in scenarios such as issuing a token, updating a token, deleting a token, or sharing a token, the second device can be a cloud device.

[0200] Optionally, in an embodiment of the present application, if the second device is a cloud device, the method further includes at least one of the following sharing methods:

[0201] The cloud device shares at least one level of access token from the first device to a configuration device or an Internet of Things device bound to another account on the same platform as the first device;

[0202] The cloud device shares at least one level of access token from the first device to a configuration device or an Internet of Things device bound to another account on a different platform from the first device.

[0203] Optionally, in the embodiments of the present application, the method further includes:

[0204] The cloud device receives the selected master device identification list and / or slave device identification list from the configuration device;

[0205] The cloud device generates a device-level access token and saves the device-level access token and its corresponding master device identification list and / or slave device identification list.

[0206] Exemplarily, if the first device is an IoT device (including a master device and / or a slave device), and the second device is a cloud device, the user can select the master device and / or the slave device through the configuration device to obtain the selected master device identification list and / or slave device identification list. The configuration device can send the selected master device identification list and / or slave device identification list to the cloud device. After receiving the master device identification list and / or slave device identification list, the cloud device can generate a device-level access token and save the device-level access token and its corresponding master device identification list and / or slave device identification list. Then, the cloud device can directly send the device-level access token to the IoT device or send the device-level access token to the IoT device through the configuration device. Refer to the process of the second device sending a token to the first device (master device and / or slave device) as described above.

[0207] Optionally, in the embodiments of the present application, if the second device is a cloud device, the method further includes: The cloud device receives the selected master device identification list, slave device identification, and service name list from the configuration device; The cloud device generates a service-level access token and saves the service-level access token and its corresponding master device identification list, slave device identification, and service name list.

[0208] Exemplarily, if the first device is an IoT device (including a master device and / or a slave device), and the second device is a cloud device, the user can select the master device, slave device, and services of the slave device, etc. through the configuration device to obtain the selected master device identification list, slave device identification, and service name list. The configuration device can send the selected master device identification list, slave device identification, and service name list to the cloud device. After receiving the master device identification list, slave device identification, and service name list, the cloud device can generate a service-level access token and save the service-level access token and its corresponding master device identification list, slave device identification, and service name list. Then, the cloud device can directly send the service-level access token to the IoT device or send the service-level access token to the IoT device through the configuration device. Refer to the process of the second device sending a service-level access token to the first device (master device and / or slave device) as described above.

[0209] Optionally, in the embodiments of the present application, if the second device is a cloud device, the method further includes:

[0210] The cloud device receives the selected master device identifier list, controlled device identifier, service name, and attribute-related information from the configuration device, where the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names;

[0211] The cloud device generates an attribute-level access token and saves the attribute-level access token and its corresponding master device identifier list, controlled device identifier, service name, and attribute-related information.

[0212] Exemplarily, if the first device is an IoT device (including a master device and / or a controlled device) and the second device is a cloud device, the user can select attributes such as the master device, the controlled device, and the services of the controlled device through the configuration device to obtain the selected master device identifier list, controlled device identifier, service name, and attribute-related information. The configuration device can send the selected master device identifier list, controlled device identifier, service name, and attribute-related information to the cloud device. After receiving the master device identifier list, controlled device identifier, service name, and attribute-related information, the cloud device can generate an attribute-level access token and save the attribute-level access token and its corresponding master device identifier list, controlled device identifier, service name, and attribute-related information. Then, the cloud device can directly send the attribute-level access token to the IoT device or send the attribute-level access token to the IoT device through the configuration device. Refer to the process of the second device sending the attribute-level access token to the first device (master device and / or controlled device) described above.

[0213] Optionally, in the embodiments of the present application, in scenarios such as token issuance, token update, token deletion, or token sharing, the second device can be a configuration device.

[0214] Optionally, in the embodiments of the present application, if the second device is a configuration device, the method further includes at least one of the following:

[0215] The configuration device sends the selected master device identifier list and / or controlled device identifier list to the cloud device in response to a device selection operation;

[0216] The configuration device sends the selected master device identifier list, controlled device identifier, and service name list to the cloud device in response to a service selection operation;

[0217] In response to an attribute selection operation, the configuration device sends the selected list of master device identifiers, controlled device identifiers, service name, and attribute-related information to the cloud device, where the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

[0218] Optionally, in the embodiments of the present application, if the second device is a configuration device, the method further includes at least one of the following:

[0219] The configuration device receives a device-level access token from the cloud device;

[0220] The configuration device receives a service-level access token from the cloud device;

[0221] The configuration device receives an attribute-level access token from the cloud device.

[0222] Exemplarily, in the scenario of issuing tokens, access tokens at various levels can be issued to IoT devices through the configuration device.

[0223] For example, the user can select IoT devices (including master devices and / or controlled devices) through the configuration device. The configuration device can, in response to the user's device selection operation, obtain the selected list of master device identifiers and / or controlled device identifiers of the user and send them to the cloud device. After the cloud device generates a device-level access token based on the list of master device identifiers and / or controlled device identifiers, the cloud device can send the device-level access token to the configuration device. The configuration device issues the device-level access token to the IoT device. Refer to the process of the second device sending a device-level access token to the first device (master device and / or controlled device) described above.

[0224] Again, for example, the user can select the services of IoT devices (including master devices and / or controlled devices) through the configuration device. The configuration device can, in response to the user's service selection operation, obtain the selected list of master device identifiers, controlled device identifiers, and service name list of the user and send them to the cloud device. After the cloud device generates a service-level access token based on the selected list of master device identifiers, controlled device identifiers, and service name list, the cloud device can send the service-level access token to the configuration device. The configuration device issues the service-level access token to the IoT device. Refer to the process of the second device sending a service-level access token to the first device (master device and / or controlled device) described above.

[0225] For another example, a user can select attributes in the services of IoT devices (including master devices and / or slave devices) through a configuration device. The configuration device can, in response to the user's attribute selection operation, obtain the list of master device identifiers, slave device identifiers, service names, and attribute-related information selected by the user, and send them to the cloud device. After the cloud device generates an attribute-level access token based on the selected list of master device identifiers, slave device identifiers, service names, and attribute-related information, the cloud device can send the attribute-level access token to the configuration device. The configuration device then issues the attribute-level access token to the IoT device. Refer to the process of the second device sending a device-level access token to the first device (master device and / or slave device) described above.

[0226] For a specific example of the method 50 executed by the second device in this embodiment, reference can be made to the relevant descriptions of the second device such as the configuration device or the cloud device in the above method 40. For the sake of brevity, it will not be elaborated here.

[0227] Embodiments of the present application can provide multi-level access tokens and perform various management on the multi-level access tokens.

[0228] 1 Multi-level access token (Token): Examples of the attributes and levels of the multi-level access token (Token) are as follows:

[0229]

[0230]

[0231] Optionally, if a device belongs to multiple accounts on the same platform at the same time, the ID of the token can adopt a combination of the account ID and the index within the account to avoid conflicts in the token indexes under different accounts.

[0232] Optionally, if a device belongs to accounts on multiple different platforms at the same time, the ID of the token can adopt a combination of the platform ID, the account ID, and the index within the account to avoid conflicts in the token indexes under different accounts.

[0233] According to the actual permission control requirements of the user, a device can be set with zero, one, or more device-level tokens, can be set with zero, one, or more service-level tokens, or can be set with zero, one, or more attribute-level tokens.

[0234] 1.1 Permission scope example

[0235] Example of the permission scope of multi-level tokens: If device A has services S1, S2, and S3, S1 has attributes C1 and C2, S2 has attributes C3 and C4, and S3 has methods F1 and F2; device B has services S4, S5, and S6, S4 has attribute C5, S5 has attribute C6 and event E1, and S6 has attributes C7, C8, and method F3. The default account-level token is T0. The user sets a device-level Token T1 for A, a service-level token T2 for S1, an attribute-level token T20 for E0 of S1, a service-level token T3 for S2, an attribute-level token T4 for the write permission of C3, and an attribute-level token T21 for F2 of S3. The user sets a service-level token T5 for S5 and S6 of B, and an attribute-level token T6 for C8 and F3. The following is an exemplary relationship between devices, services, attributes, etc.:

[0236] A --T1

[0237] S1 (restricted service) --T2

[0238] C1 (rw) (unrestricted attribute)

[0239] C2 (rw) (unrestricted attribute)

[0240] E0 (restricted event)--T20

[0241] S2 (restricted service) --T3

[0242] C3 (r) (unrestricted attribute)

[0243] C3 (w) (restricted attribute) --T4

[0244] C4 (rw) (unrestricted attribute)

[0245] S3 (unrestricted service)

[0246] F1 (unrestricted method)

[0247] F2 (restricted method)--T21

[0248] B

[0249] S4 (unrestricted service)

[0250] C5 (rw) (unrestricted attribute)

[0251] S5 (restricted service) --T5

[0252] C6 (rw) (unrestricted attribute)

[0253] E1 (Unrestricted Event)

[0254] S6 (Restricted Service) -- T5

[0255] C7 (rw) (Unrestricted Attribute)

[0256] C8 (rw) (Restricted Attribute) -- T6

[0257] F3 (Restricted Method) -- T6

[0258] Based on the relationships among the above devices, services, and attributes, the following are examples of the permission scopes of access tokens:

[0259] (1) The permission scope of T0 can be represented in JSON (JavaScript Object Notation) as:

[0260]

[0261] (2) The permission scope of T1 can be represented in JSON as:

[0262]

[0263] (3) The permission scope of T2 can be represented in JSON as:

[0264]

[0265] (4) The permission scope of T3 can be represented in JSON as:

[0266]

[0267]

[0268] (5) The permission scope of T4 can be represented in JSON as:

[0269]

[0270] (6) The permission scope of T5 can be represented in JSON as:

[0271]

[0272] (7) The permission scope of T6 can be represented in JSON as:

[0273]

[0274] (8) The permission scope of T20 can be represented in JSON as:

[0275]

[0276] (9) The permission scope of T21 can be represented in JSON as follows:

[0277]

[0278] 1.2 Application Examples

[0279] Application example of multi - level tokens: In the scenario where the smoke alarm is triggered to alarm after the smoke sensor detects a delay, it can be that the alarm has the permission to read the attributes of the smoke sensor and controls itself, or it can be that another device, such as a smart speaker, acts as the master device and has the permission to access the smoke sensor device and the alarm method of the alarm service of the alarm.

[0280] Application example of attributes (distinguishing read and write): If the user grants device A the permission to read attribute D in service C of device B, an attribute - level token T1 is generated. If the user grants device A the permission to write attribute D in service C of device B, an attribute - level token T2 is generated. If the user grants device A the permission to read and write attribute D in service C of device B, either attribute - level tokens T1 and T2 can be generated simultaneously, or only one attribute - level token T3 can be generated.

[0281] Optionally, if the value of the attribute is a data list (array / list), the write permission of the attribute can be further split into add / delete / modify permissions. Example: If the user grants device A the permission to write attribute E (whose value is a data list) in service C of device B, an attribute - level token T4 is generated, and the permission of T4 is to be able to modify the value of attribute E arbitrarily (including adding / deleting / modifying elements in its data list). If the user grants device A the permission to add attribute E (whose value is a data list) in service C of device B, an attribute - level token T5 is generated, and the permission of T5 is to be able to add sub - elements of the value of E (i.e., add elements to its data list). If the user grants device A the permission to delete attribute E (whose value is a data list) in service C of device B, an attribute - level token T6 is generated, and the permission of T6 is to be able to delete sub - elements of the value of E (i.e., delete existing elements in its data list). If the user grants device A the permission to modify attribute E (whose value is a data list) in service C of device B, an attribute - level token T7 is generated, and the permission of T7 is to be able to modify sub - elements of the value of E (i.e., modify existing elements in its data list). Possible usage scenarios are, for example, the fingerprint data of a door lock (the value of this attribute is a list of fingerprints), the owner's mobile phone has add / delete / modify permissions, the child's mobile phone only has viewing permissions, and the guest's mobile phone only has adding permissions.

[0282] Optionally, on the device, the tokens for accessing other devices and the tokens for controlling its own access permissions can be stored separately. They can also be stored together, with an identifier added to each token for differentiation.

[0283] 1.3 Expansion of Permission Scope

[0284] 1.3.1 Service - level Tokens across Devices

[0285] Optionally, to meet the requirement of simultaneously accessing similar or related restricted services on multiple devices (e.g., turning on the switches of multiple air conditioners and setting the target temperatures of the air conditioners), the permission scope of the service - level token can be expanded to multiple devices rather than being limited to only one device. For example, in the aforementioned example, the user can set a service - level token T7 for S2 of device A and S4 of device B. The permission scope of T7 can be represented in JSON as:

[0286]

[0287]

[0288] 1.3.2 Attribute - level Tokens across Services

[0289] Optionally, to meet the requirement of simultaneously accessing similar or related restricted attributes / methods / events on one device (e.g., turning on the switch of the air conditioner and setting the temperature at the same time), the permission scope of the attribute - level token can also be expanded to multiple services on one device rather than being limited to only one service. For example, in the aforementioned example, the user can set an attribute - level token T8 for C6 and C7 of device B. The permission scope of T8 can be represented in JSON as:

[0290]

[0291] 1.3.3 Attribute - level Tokens across Devices

[0292] Optionally, to meet the requirement of simultaneously accessing similar or related restricted attributes / methods / events on multiple devices (e.g., turning on the switches of multiple air conditioners, obtaining the current temperature of the temperature sensor, and setting the target temperature of the air conditioner), the permission scope of the attribute - level token can be further expanded to multiple devices rather than being limited to only one device. For example, in the aforementioned example, the user can set an attribute - level token T9 for C1 of device A, C6 and C7 of device B. The permission scope of T9 can be represented in JSON as:

[0293]

[0294]

[0295] Users can create tokens, update the validity period of tokens, update the permission scope of tokens, update token values, delete tokens, and can also share tokens with other accounts and devices. The process is described as follows.

[0296] The following describes specific examples of application scenarios such as the creation, distribution, update, deletion, and sharing of tokens. In the following application scenarios, the configured device is a mobile application, the cloud device is the access cloud, and the first device is an IoT device (including the master device and / or the controlled device) as an example for illustration. The specific types of the configured device, cloud device, and first device are not limited.

[0297] 2 Creation of multi-level access tokens

[0298] The creation and distribution process of multi-level access tokens (Tokens) is described as follows:

[0299] 2.1 Example of distributing tokens 1 (the cloud distributes tokens to devices)

[0300] Users set access permissions on a device with the ability to log in to a user account and an operation interface (such as a mobile application), and the cloud platform (which can also be called a cloud device, access cloud, etc.) distributes corresponding access tokens (tokens) to the device. The specific process is as follows, and reference can be made to Figure 5 :

[0301] S101 and S102. Configure the device to access the network. Users can configure an IoT (Internet of Things) device to access the network through a configured device such as a mobile application.

[0302] S103. The device accesses the network for the first time.

[0303] S104. If there is no account-level token in the access cloud, an account-level token can be generated and saved; if there is an account-level token in the access cloud, directly execute S15 to distribute the account-level token to the device. Generally speaking, when the device accesses the network for the first time, there is no account-level token in the access cloud, and when the device accesses the network again, there may be access tokens in the access cloud.

[0304] S105. The access cloud distributes the account-level token to the device.

[0305] S106. Discover the device. For example, discover the IoT device through a mobile application.

[0306] S107. The user selects one or more controlled devices and / or one or more master devices through the mobile application.

[0307] S108. The mobile application sends the selected list of controlled device IDs and / or the list of master device IDs to the access cloud.

[0308] S109. The access cloud generates a device-level token for the selected controlled devices, and saves the token, the corresponding list of controlled device IDs and the list of master device IDs.

[0309] S110. The access cloud distributes the device-level token to all the selected controlled devices; and / or distributes the device-level token and the list of controlled device IDs to the selected master devices.

[0310] S111. Discover devices and services. For example, the mobile application discovers the services in the IoT devices. In the embodiments of the present application, the service can also be referred to as the device service.

[0311] S112. The user selects the controlled devices and some of the services of the devices through the mobile application, and selects one or more master devices.

[0312] S113. The mobile application sends the selected list of controlled device IDs and service names to the access cloud, and / or sends the selected list of master device IDs to the access cloud.

[0313] S114. The access cloud generates a service-level token for the controlled devices, and saves the token and at least one of the corresponding controlled device IDs, the list of device services names and the list of master device IDs.

[0314] S115. The access cloud distributes the service-level token and the list of service names to the controlled devices, and distributes the service-level token, the list of service names and the controlled device IDs to the selected master devices.

[0315] S116. Discover devices, services, attributes, methods and events. For example, discover the IoT devices, the services in the devices, the attributes, methods and events in the services through the mobile application. In the embodiments of the present application, the attribute can also be referred to as the device attribute.

[0316] S117. The user selects the controlled devices and some of the attributes (distinguishing read and write) / methods / events of the devices through the mobile application, and / or selects one or more master devices.

[0317] S118. The mobile application sends the list of controlled device IDs, service names, attributes (distinguishing read and write) / method / event names to the access cloud, and / or sends the list of master device IDs to the access cloud.

[0318] S119. The access cloud generates an attribute-level token for the controlled devices, and saves the token, the corresponding controlled device IDs, service names, attributes (distinguishing read and write) / method / event names, and the list of master device IDs.

[0319] S120. Access cloud issues an attribute-level token, service name, and a list of attributes (distinguishing read / write) / methods / event names to the controlled device; issues an attribute-level token, controlled device ID, service name, and a list of attributes (distinguishing read / write) / methods / event names to the selected master device.

[0320] In this example, the steps of issuing access tokens at the account level, device level, service level, and attribute level have no timing restrictions and do not need to be all executed. One or more levels of access token issuance steps can be executed according to specific requirements.

[0321] 2.2 Example of Issuing Tokens 2 (Issuing Tokens by Mobile Application)

[0322] A device with the ability to log in with a user account (such as a mobile application) issues an access token to the application terminal (intelligent device). The specific process is as follows, which can be referred to Figure 6 :

[0323] For S201 to S209, refer to the relevant descriptions of S101 to S109 in the above example of issuing tokens 1, which will not be elaborated here.

[0324] S210. The access cloud returns a device-level token to the mobile application.

[0325] S211. The mobile application issues the device-level token to all selected controlled devices; issues the device-level token and a list of controlled device IDs to the selected master device.

[0326] For S212 to S215, refer to the relevant descriptions of S111 to S114 in the above example of issuing tokens 1, which will not be elaborated here.

[0327] S216. The access cloud returns a service-level token to the mobile application.

[0328] S217. The mobile application issues the service-level token and a list of service names to the controlled devices, and issues the service-level token, a list of service names, and the controlled device IDs to the selected master device.

[0329] For S218 to S221, refer to the relevant descriptions of S116 to S119 in the above example of issuing tokens 1, which will not be elaborated here.

[0330] S222. The access cloud returns an attribute-level token to the mobile application.

[0331] S223. The mobile application sends the attribute-level token, service name, and list of attributes (distinguishing read and write) / methods / event names to the controlled device, and sends the attribute-level token, controlled device ID, service name, and list of attributes (distinguishing read and write) / methods / event names to the selected master device.

[0332] In this example, the steps of sending access tokens at the account level, device level, service level, and attribute level have no timing restrictions and do not need to be all executed. You can execute only the steps of sending access tokens at any one or more levels according to specific requirements.

[0333] 2.3 Example of sending a token 3 (device actively requests a token)

[0334] If a device needs to access a peer device but checks that it does not yet have the corresponding access permission, it can obtain the corresponding access token by sending a request to the access cloud to obtain user authorization.

[0335] Optionally, in this example, the step of the access cloud sending the token to the device can also be that the access cloud sends it to the mobile application, and the mobile application forwards it to the device (as shown in the example of sending a token 2). The specific process is as follows, you can refer to Figure 7 .

[0336] For S301 to S305, you can refer to the relevant descriptions of S101 to S105 in the above example of sending a token 1, which will not be elaborated here.

[0337] S306. The IoT device sends a list of controlled device IDs to the access cloud and requests a device-level token.

[0338] S307. The access cloud sends a list of controlled device IDs and the master device ID to the mobile application and requests user authorization.

[0339] S308. User authorization. For example, the user can choose whether to request this device-level token in the mobile application. If so, the user confirms the authorization.

[0340] S309. The mobile application sends the list of controlled device IDs and / or the master device ID after the user's confirmation to the access cloud to confirm the authorization.

[0341] S310. The access cloud generates a device-level token for the selected controlled device (if not saved), and saves (if already exists, updates) the token and the corresponding list of controlled device IDs and master device IDs.

[0342] S311. The access cloud sends the device-level token to all the confirmed controlled devices, and sends the device-level token and the list of controlled device IDs to the confirmed master device.

[0343] S312. The IoT device sends the controlled device ID and the list of device service names to the access cloud, and requests a service-level token.

[0344] S313. The access cloud sends the controlled device ID, the list of device service names, and the master control device ID to the mobile application, and requests user authorization.

[0345] S314. The user authorizes. For example, the user can choose whether to request this service-level token in the mobile application. If so, the user confirms the authorization.

[0346] S315. The mobile application sends the confirmed controlled device ID, the list of service names, and the master control device ID to the access cloud to confirm the authorization.

[0347] S316. The access cloud generates a service-level token for the controlled device (if not saved), and saves (updates if already exists) the token, the corresponding controlled device ID, the list of service names, and the list of master control device IDs.

[0348] S317. The access cloud distributes the service-level token and the list of service names to the confirmed controlled devices; distributes the service-level token, the list of service names, and the controlled device ID to the confirmed master control devices.

[0349] S318. The IoT device sends the controlled device ID, the service name, the list of attributes (distinguishing read / write), methods, and event names to the access cloud, and requests an attribute-level token.

[0350] S319. The access cloud sends the controlled device ID, the service name, the list of attributes (distinguishing read / write), methods, and event names, and the master control device ID to the mobile application, and requests user authorization.

[0351] S320. The user authorizes. For example, the user can choose whether to request this attribute-level token in the mobile application. If so, the user confirms the authorization.

[0352] S321. The mobile application sends the confirmed controlled device ID, the service name, the list of attributes (distinguishing read / write), methods, and event names, and the master control device ID to the access cloud to confirm the authorization.

[0353] S322. The access cloud generates an attribute-level token for the controlled device (if not saved), and saves; (updates if already exists) the token, the corresponding controlled device ID, the service name, the list of attributes (distinguishing read / write), methods, and event names, and the list of master control device IDs.

[0354] S323. Send the attribute-level token, service name, and attribute (distinguishing read and write) / method / event name list to the confirmed controlled device; send the attribute-level token, controlled device ID, service name, and attribute (distinguishing read and write) / method / event name list to the confirmed master device.

[0355] In this example, the steps of sending access tokens at the account level, device level, service level, and attribute level have no timing restrictions and do not need to be all executed. You can execute only the steps of sending any one or more levels of access tokens according to specific requirements.

[0356] 3 Update of Multi-Level Access Tokens

[0357] The update (at least one of the validity period, permission scope, and token value) and distribution process of the multi-level access token (Token) are described as follows:

[0358] 3.1 Example 1 of Updating Token (Cloud Updates Token for Device). The specific process is as follows. See Figure 8 :

[0359] S401. The mobile application obtains all token information of an account from the access cloud, or obtains relevant token information according to the involved device ID.

[0360] S402. The user can select a token from the tokens displayed in the mobile application and determine the content to be modified, such as modifying at least one of its validity period, permission scope, and token value.

[0361] S403. The mobile application sends the access token identifier token ID and the modified content, such as at least one of the modified token validity period, permission scope, and token value, to the access cloud.

[0362] S404. The access cloud caches the original information of the token corresponding to the token ID.

[0363] S405. The access cloud updates at least one of the validity period, permission scope, and token value of the token corresponding to the token ID.

[0364] S406. The access cloud sends the updated token information to all devices (master device and / or controlled device) involved in the token. For example, if a device is removed from the list, notify the device to delete the token; if a device is newly added to the list, send the token to the device newly; if a device is already in the original list, notify the device to update the token information.

[0365] In this example, the uses of caching the original information of the token may include: determining whether a device (master device and / or slave device) has been removed from or added to the list; or, re - sending an update message when the access to the cloud to update the token fails (e.g., the device is offline for a short time).

[0366] 3.2 Update Token Example 2 (The mobile phone updates the token for the device). The specific process is as follows. Refer to Figure 9 :

[0367] In this example, S501 and S502 can refer to S401 and S402 in Update Token Example 1.

[0368] S503. The mobile phone application caches the original information and the modified information of the token.

[0369] S504. The mobile phone application sends the access token identifier token ID and the modified content to the access cloud, such as at least one of the modified token validity period, permission scope, and token value.

[0370] S505. The access cloud updates at least one of the validity period, permission scope, and token value of the corresponding token according to the token ID.

[0371] S506. The change in the cloud is successful. The access cloud can send a message to the mobile phone application indicating that the token has been successfully updated in the cloud.

[0372] S507. The mobile phone application can send the updated token information to all devices (master and slave) involved in the token. For example, if a device is removed from the list, notify the device to delete the token; if a device is added to the list, send the new token to the device; if a device is already in the original list, notify the device to update the token information.

[0373] In this example, the uses of caching the original information of the token may include: determining whether a device (master device and / or slave device) has been removed from or added to the list; re - sending an update message when the mobile phone application fails to update the token (e.g., the device is offline for a short time).

[0374] 4 Deletion of Multi - level Access Tokens

[0375] The deletion process of the multi - level access token (Token) is described as follows:

[0376] 4.1 Deletion Token Example 1 (The cloud notifies the device to delete the token). The specific process is as follows. Refer to Figure 10 :

[0377] S601. The mobile application obtains all the token information of an account from the access cloud, or obtains the relevant token information according to the device ID involved.

[0378] S602. The user can select a token from the tokens displayed in the mobile application and request to delete it.

[0379] S603. The mobile application can send the token ID of the access token to be deleted to the access cloud.

[0380] S604. The access cloud caches the information of the token corresponding to the token ID.

[0381] S605. The access cloud deletes its token information according to the token ID.

[0382] S606. The access cloud notifies all devices involved in the token (including the master device and / or the controlled device) to delete the token according to the token ID.

[0383] In this example, the use of caching the original information of the token: when the access cloud fails to delete the token (for example, the device is offline for a short time), resend the deletion message.

[0384] 4.2 Example of deleting a token 2 (the mobile phone notifies the device to delete the token), the specific process is as follows, see Figure 11 :

[0385] In this example, for S701 and S702, refer to S601 and S602 in Example 1 of deleting a token.

[0386] S703. The mobile application caches the original information of the token.

[0387] S704. The mobile application can send the token ID of the access token to be deleted to the access cloud.

[0388] S705. The access cloud deletes its token information according to the token ID.

[0389] S706. Deletion is successful. The access cloud can send a message indicating that the token has been successfully deleted to the mobile application.

[0390] S707. The mobile application notifies all devices involved in the token (the master device and / or the controlled device) to delete the token according to the token ID.

[0391] 5 Sharing of multi-level access tokens

[0392] 5.1 Example of sharing a token 1 (sharing to the mobile application of other accounts on the same platform)

[0393] The mobile applications of user accounts A and B and the devices under the accounts are all connected to the same cloud platform C1. The mobile application implements an interface for searching devices and an interface that can be discovered as a device (the account ID can be used as the device ID of the mobile application, or the MAC / IMEI of the mobile phone, etc. can be used as the device ID of the mobile application). After the user uses the mobile application of account A to search for the mobile application of account B, one or more tokens under account A can be sent to the mobile application of account B, so that the mobile application of account B can also access the devices under account A. After the user uses the mobile application of account A to search for the mobile application of account B, the user can also request the application of account B to send one or more tokens under account B to the mobile application of account A, so that the mobile application of account A can also access the devices under account B. The request and sending message of the token can be directly transmitted by the mobile application of account A and the mobile application of account B through local communication. However, because the legality of the account cannot be verified, for the sake of security, it can also be relayed through the cloud platform C1 to verify the legality of the account on the cloud platform to obtain higher security.

[0394] 5.2 Sharing Token Example 2 (Sharing to Devices of Other Accounts on the Same Platform)

[0395] User account A and device D1, user account B and device D2 are all connected to the same cloud platform C1. After the user uses the mobile application of account A to locally search for device D2 under account B, one or more tokens under account A can be sent to D2, so that D2 can also access the devices under account A. This method uses local communication transmission. For the sake of security, it can also be relayed through the cloud platform C1 for legality verification to obtain higher security.

[0396] After the user uses the mobile application of account A to locally search for device D2 under account B, the user can also request the cloud platform C1 for control permissions for D2 (or more devices under account B to which D2 belongs). The cloud platform C1 forwards the request to the application of B to apply for B's authorization. After B authorizes, one or more tokens under account B are sent to the mobile application of A and / or the devices under account A through the cloud platform C1, so that the mobile application of A and / or the devices under account A can also access the devices under account B. This method can achieve higher security through legality verification on the cloud platform.

[0397] 5.3 Sharing Token Example 3 (Sharing to the Mobile Application of an Account on Another Platform)

[0398] User account A and device D1 are connected to cloud platform C1, and user account B and device D2 are connected to cloud platform C2. The mobile application implements an interface for searching devices and an interface that can be discovered as a device (the account ID can be used as the device ID of the mobile application, or the MAC / IMEI of the mobile phone, etc. can be used as the device ID of the mobile application). After the user uses the mobile application of account A to search for the mobile application of account B, one or more tokens under account A can be sent to the mobile application of B, so that the mobile application of B can also access the devices under account A. After the user uses the mobile application of account A to search for the mobile application of account B, the user can also request the application of B to send one or more tokens under account B to the mobile application of A, so that the mobile application of A can also access the devices under account B. The request and sending message of the token can be directly transmitted by the mobile application of A and the mobile application of B through local communication. However, since the legitimacy of the account cannot be verified, for the sake of improving security, it can also be relayed through cloud platform C1 and cloud platform C2 to verify the legitimacy of the account on the cloud platform to obtain higher security.

[0399] 5.4 Sharing Token Example 4 (Devices Shared with Other Platform Accounts)

[0400] User account A and device D1 are connected to cloud platform C1, and user account B and device D2 are connected to cloud platform C2. After the user uses the mobile application of account A to locally search for device D2 under account B, one or more tokens under account A can be sent to D2, so that D2 can also access the devices under account A. This method uses local communication transmission. For the sake of improving security, it can also be relayed through cloud platform C1 for legitimacy verification to obtain higher security.

[0401] After the user uses the mobile application of account A to locally search for device D2 under account B, the user can also request cloud platform C1 for control permissions over D2 (or more devices under account B to which D2 belongs). Cloud platform C1 forwards the request to cloud platform C2. Cloud platform C2 forwards the request to the application of account B to apply for the authorization of B. After account B authorizes, one or more tokens under account B are sent to cloud platform C1 through cloud platform C2. C1 forwards them to the mobile application of A and / or the devices under account A, so that the mobile application of A and / or the devices under account A can also access the devices under account B. This method can achieve higher security through legitimacy verification on the cloud platform.

[0402] In the embodiments of this application, by securely setting multi-level access tokens, IoT devices based on the OLA protocol can control access permissions with finer granularity, enhancing system security.

[0403] Figure 12 It is a schematic block diagram of a first device 400 according to an embodiment of the present application. The first device 400 may include:

[0404] A receiving unit 410, configured to receive at least one level of access tokens from a second device.

[0405] Optionally, in the embodiment of the present application, the at least one level of access tokens includes at least one of the following:

[0406] An account-level access token;

[0407] A device-level access token;

[0408] A service-level access token;

[0409] An attribute-level access token.

[0410] Optionally, in the embodiment of the present application, the service-level access token includes:

[0411] A service-level access token of the same device;

[0412] A service-level access token across devices.

[0413] Optionally, in the embodiment of the present application, the attribute-level access token includes:

[0414] An attribute-level access token of the same service;

[0415] An attribute-level access token across services;

[0416] An attribute-level access token across devices.

[0417] Optionally, in the embodiment of the present application, the account-level access token is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of the devices under the same account.

[0418] Optionally, in the embodiment of the present application, the device-level access token is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of the same device or multiple devices under the same account.

[0419] Optionally, in the embodiment of the present application,

[0420] The service-level access token of the same device is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service of the same device;

[0421] A service - level access token across devices is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service across multiple devices.

[0422] Optionally, in the embodiments of the present application,

[0423] An attribute - level access token for the same service is used to access at least one of the restricted attributes, restricted methods, and restricted events of the same service of the same device;

[0424] An attribute - level access token across services is used to access at least one of the restricted attributes, restricted methods, and restricted events of multiple services of the same device;

[0425] An attribute - level access token across devices is used to access at least one of the restricted attributes, restricted methods, and restricted events of multiple services of multiple devices.

[0426] Optionally, in the embodiments of the present application, wherein the receiving unit is further configured to:

[0427] When the first device is a controlled device, receive a device - level access token from the second device; or

[0428] When the first device is a master device, receive a device - level access token and a list of controlled device identifiers from the second device.

[0429] Optionally, in the embodiments of the present application, the receiving unit is further configured to:

[0430] When the first device is a controlled device, receive a service - level access token and a list of service names from the second device; or

[0431] When the first device is a master device, receive a service - level access token, a list of service names, and a controlled device identifier from the second device.

[0432] Optionally, in the embodiments of the present application, the receiving unit is further configured to:

[0433] When the first device is a controlled device, receive an attribute - level access token, a service name, and attribute - related information from the second device; or

[0434] When the first device is a master device, receive a service - level access token, a service name, attribute - related information, and a controlled device identifier from the second device;

[0435] Wherein, the attribute - related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

[0436] Optionally, in the embodiments of the present application, as Figure 13 shown, the first device 400 further includes:

[0437] A sending unit 420, configured to send a token issuance request to a second device.

[0438] Optionally, in the embodiments of the present application, the token issuance request includes one of the following:

[0439] A list of controlled device identifiers, and the token issuance request is used to request a device-level access token;

[0440] A list of controlled device identifiers and service names, and the token issuance request is used to request a service-level access token;

[0441] A list of controlled device identifiers, service names, and attribute-related information, and the token issuance request is used to request an attribute-level access token, where the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

[0442] Optionally, in the embodiments of the present application, the receiving unit is further configured to receive, from the second device, an identifier of at least one level of access token that needs to be updated and content that needs to be updated;

[0443] The first device further includes:

[0444] An updating unit 430, configured to update an access token corresponding to an identifier of at least one level of access token that needs to be updated based on the content that needs to be updated.

[0445] Optionally, in the embodiments of the present application, the receiving unit is further configured to receive, from the second device, an identifier of at least one level of access token that needs to be deleted;

[0446] The first device further includes:

[0447] A deleting unit 440, configured to delete a corresponding access token based on an identifier of at least one level of access token that needs to be deleted.

[0448] Optionally, in the embodiments of the present application, the second device is a configuration device or a cloud device.

[0449] Optionally, in the embodiments of the present application, the first device further includes the following sharing unit, configured to perform at least one of the sharing methods:

[0450] Share at least one level of access token with a configuration device or an Internet of Things device bound to another account on the same platform;

[0451] Share at least one level of access tokens to a configured device or an Internet of Things device bound to another account on the same platform through a cloud device;

[0452] Share at least one level of access tokens to a configured device or an Internet of Things device bound to another account on a different platform;

[0453] Share at least one level of access tokens to a configured device or an Internet of Things device bound to another account on a different platform through a cloud device.

[0454] The first device 400 in the embodiment of the present application can implement the corresponding functions of the first device in the foregoing method embodiment. For the corresponding processes, functions, implementation manners, and beneficial effects of each module (sub-module, unit, or component, etc.) in the first device 400, reference can be made to the corresponding descriptions in the foregoing method embodiment 40, which will not be elaborated here. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the first device 400 in the embodiment of the application can be implemented by different modules (sub-modules, units, or components, etc.), or can be implemented by the same module (sub-module, unit, or component, etc.).

[0455] Figure 14 It is a schematic block diagram of a second device 500 according to an embodiment of the present application. The second device 500 may include:

[0456] A sending unit 510, configured to send at least one level of access tokens to the first device.

[0457] Optionally, in the embodiment of the present application, the at least one level of access tokens includes at least one of the following:

[0458] An account-level access token;

[0459] A device-level access token;

[0460] A service-level access token;

[0461] An attribute-level access token.

[0462] Optionally, in the embodiment of the present application, the service-level access token includes:

[0463] A service-level access token for the same device;

[0464] A cross-device service-level access token.

[0465] Optionally, in the embodiment of the present application, the attribute-level access token includes:

[0466] An attribute-level access token for the same service;

[0467] A cross-service attribute-level access token;

[0468] Attribute-level access tokens across devices.

[0469] Optionally, in the embodiments of the present application, the account-level access token is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of the devices under the same account.

[0470] Optionally, in the embodiments of the present application, the device-level access token is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of the same device or multiple devices under the same account.

[0471] Optionally, in the embodiments of the present application,

[0472] The service-level access token of the same device is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service of the same device;

[0473] The service-level access token across devices is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service of multiple devices.

[0474] Optionally, in the embodiments of the present application,

[0475] The attribute-level access token of the same service is used to access at least one of the restricted attributes, restricted methods, and restricted events of at least one restricted service of the same device;

[0476] The attribute-level access token across services is used to access at least one of the restricted attributes, restricted methods, and restricted events of multiple services of the same device;

[0477] The attribute-level access token across devices is used to access at least one of the restricted attributes, restricted methods, and restricted events of multiple services of multiple devices.

[0478] Optionally, in the embodiments of the present application, the sending unit is further configured to:

[0479] When the first device is a controlled device, send a service-level access token and a service name list to the first device; or

[0480] When the first device is a master device, send a service-level access token, a service name list, and a controlled device identifier to the first device.

[0481] Optionally, in the embodiments of the present application, the sending unit is further configured to:

[0482] When the first device is a controlled device, send an access token at the attribute level, a service name, and attribute-related information to the first device; or

[0483] When the first device is a master device, send a service-level access token, a service name, attribute-related information, and a controlled device identifier to the first device;

[0484] Among them, the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

[0485] Optionally, in the embodiments of the present application, as Figure 15 shown, the second device further includes:

[0486] A first receiving unit 520, configured to receive a token issuance request from the first device.

[0487] Optionally, in the embodiments of the present application, the token issuance request includes one of the following:

[0488] A list of controlled device identifiers, and the token issuance request is used to request a device-level access token;

[0489] A list of controlled device identifiers and service names, and the token issuance request is used to request a service-level access token;

[0490] A list of controlled device identifiers, service names, and attribute-related information, and the token issuance request is used to request an attribute-level access token, where the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

[0491] Optionally, in the embodiments of the present application, the sending unit is further configured to send the identifier of at least one level of access token that needs to be updated and the content that needs to be updated to the first device.

[0492] Optionally, in the embodiments of the present application, the sending unit is further configured to send the identifier of at least one level of access token that needs to be deleted to the first device.

[0493] Optionally, in the embodiments of the present application, the second device is a cloud device.

[0494] Optionally, in the embodiments of the present application, the second device further includes a sharing unit, configured to perform at least one of the following sharing methods:

[0495] Share at least one level of access token from the first device to a configured device or an Internet of Things device bound to another account on the same platform as the first device;

[0496] Share at least one level of access tokens from the first device to a configured device or an Internet of Things device bound to other accounts on a different platform from the first device.

[0497] Optionally, in the embodiment of the present application, the second device further includes:

[0498] A second receiving unit 530, configured to receive a selected list of master device identifiers and / or a list of controlled device identifiers from a configured device;

[0499] A first generating unit 540, configured to generate an access token at the device level, and save the access token at the device level and its corresponding list of master device identifiers and / or list of controlled device identifiers.

[0500] Optionally, in the embodiment of the present application, the second device further includes:

[0501] A third receiving unit 550, configured to receive a selected list of master device identifiers, a list of controlled device identifiers, and a list of service names from a configured device;

[0502] A second generating unit 560, configured to generate an access token at the service level, and save the access token at the service level and its corresponding list of master device identifiers, list of controlled device identifiers, and list of service names.

[0503] Optionally, in the embodiment of the present application, the second device further includes:

[0504] A fourth receiving unit 570, configured to receive a selected list of master device identifiers, a list of controlled device identifiers, a service name, and attribute-related information from a configured device, where the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names;

[0505] A third generating unit 580, configured to generate an access token at the attribute level, and save the access token at the attribute level and its corresponding list of master device identifiers, list of controlled device identifiers, service name, and attribute-related information.

[0506] Optionally, in the embodiment of the present application, the second device is a configured device.

[0507] Optionally, in the embodiment of the present application, the sending unit is further configured to perform at least one of the following:

[0508] In response to a device selection operation, send a selected list of master device identifiers and / or a list of controlled device identifiers to a cloud device;

[0509] In response to a service selection operation, send the selected list of master device identifiers, controlled device identifiers, and service name list to the cloud device;

[0510] In response to an attribute selection operation, send the selected list of master device identifiers, controlled device identifiers, service name, and attribute-related information to the cloud device, where the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

[0511] Optionally, in the embodiments of the present application, the second device further includes a fifth receiving unit 590 for performing at least one of the following:

[0512] Receive a device-level access token from the cloud device;

[0513] Receive a service-level access token from the cloud device;

[0514] Receive an attribute-level access token from the cloud device.

[0515] The second device 500 in the embodiments of the present application can implement the corresponding functions of the second device in the foregoing method embodiments. The processes, functions, implementation manners, and beneficial effects corresponding to each module (sub-module, unit, or component, etc.) in the second device 500 can be referred to the corresponding descriptions in the foregoing method 50 embodiments, and will not be elaborated herein. It should be noted that the functions described for each module (sub-module, unit, or component, etc.) in the second device 500 of the application embodiments can be implemented by different modules (sub-modules, units, or components, etc.), or can be implemented by the same module (sub-module, unit, or component, etc.).

[0516] Figure 16 It is a schematic structural diagram of a communication device 600 according to an embodiment of the present application. The communication device 600 includes a processor 610, and the processor 610 can call and run a computer program from a memory to enable the communication device 600 to implement the method in the embodiments of the present application.

[0517] Optionally, the communication device 600 may further include a memory 620. Among them, the processor 610 can call and run a computer program from the memory 620 to enable the communication device 600 to implement the method in the embodiments of the present application.

[0518] Among them, the memory 620 can be an independent device from the processor 610, or can be integrated in the processor 610.

[0519] Optionally, the communication device 600 may further include a transceiver 630. The processor 610 may control the transceiver 630 to communicate with other devices. Specifically, it may send information or data to other devices, or receive information or data sent by other devices. For example, the transceiver 630 may implement the functions of the receiving unit and the sending unit of the first device. Again, for example, the transceiver 630 may implement the functions of each receiving unit and sending unit of the second device.

[0520] Among them, the transceiver 630 may include a transmitter and a receiver. The transceiver 630 may further include an antenna, and the number of antennas may be one or more.

[0521] Optionally, the communication device 600 may be the second device in the embodiments of the present application, and the communication device 600 may implement the corresponding processes implemented by the second device in the various methods of the embodiments of the present application. For the sake of brevity, it will not be elaborated here.

[0522] Optionally, the communication device 600 may be the first device in the embodiments of the present application, and the communication device 600 may implement the corresponding processes implemented by the first device in the various methods of the embodiments of the present application. For the sake of brevity, it will not be elaborated here.

[0523] Figure 17 is a schematic structural diagram of a chip 700 according to an embodiment of the present application. The chip 700 includes a processor 710, and the processor 710 may call and run a computer program from a memory to implement the methods in the embodiments of the present application.

[0524] Optionally, the chip 700 may further include a memory 720. Among them, the processor 710 may call and run a computer program from the memory 720 to implement the methods executed by the first device or the second device in the embodiments of the present application.

[0525] Among them, the memory 720 may be a separate device independent of the processor 710, or may be integrated in the processor 710.

[0526] Optionally, the chip 700 may further include an input interface 730. Among them, the processor 710 may control the input interface 730 to communicate with other devices or chips. Specifically, it may obtain information or data sent by other devices or chips.

[0527] Optionally, the chip 700 may further include an output interface 740. Among them, the processor 710 may control the output interface 740 to communicate with other devices or chips. Specifically, it may output information or data to other devices or chips.

[0528] Optionally, the chip can be applied to the second device in the embodiments of the present application, and the chip can implement the corresponding processes implemented by the second device in the various methods of the embodiments of the present application. For the sake of brevity, they will not be described herein again.

[0529] Optionally, the chip can be applied to the first device in the embodiments of the present application, and the chip can implement the corresponding processes implemented by the first device in the various methods of the embodiments of the present application. For the sake of brevity, they will not be described herein again.

[0530] The chips applied to the second device and the first device can be the same chip or different chips.

[0531] It should be understood that the chip mentioned in the embodiments of the present application can also be referred to as a system-on-chip, system chip, chip system, or system-on-chip, etc.

[0532] The aforementioned processor can be a general-purpose processor, a digital signal processor (DSP), a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), or other programmable logic devices, transistor logic devices, discrete hardware components, etc. Among them, the aforementioned general-purpose processor can be a microprocessor or any conventional processor, etc.

[0533] The aforementioned memory can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM).

[0534] It should be understood that the above memory is for illustrative but not limiting purposes. For example, the memory in the embodiments of the present application may also be a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synch link dynamic random access memory (SLDRAM), and a direct rambus random access memory (DR RAM), and so on. That is to say, the memory in the embodiments of the present application is intended to include but not limited to these and any other suitable types of memory.

[0535] Figure 18 FIG. 4 is a schematic block diagram of a communication system 800 according to an embodiment of the present application. The communication system 800 includes a first device 810 and a second device 820.

[0536] The first device is configured to receive at least one level of access token from the second device.

[0537] The second device is configured to send at least one level of access token to the first device.

[0538] Among them, the first device 810 may be configured to implement the corresponding functions of the first device, such as an IoT device, in the above method, and the second device 820 may be configured to implement the corresponding functions of the second device, such as a cloud device or a configuration device, in the above method. For the sake of brevity, details are not described herein again.

[0539] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, the processes or functions in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, Digital Subscriber Line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a Solid State Disk (SSD)), etc.

[0540] It should be understood that in various embodiments of the present application, the magnitudes of the serial numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0541] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be described herein again.

[0542] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present application and should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. An access token processing method, comprising: The first device receives at least one level of access tokens from the second device; wherein, the first device receives the identification of at least one level of access tokens that need to be updated and the content to be updated from the second device; the first device updates the access tokens corresponding to the identification of at least one level of access tokens that need to be updated based on the content to be updated, wherein the content to be updated includes the validity period and scope of permissions of the access tokens; wherein, the first device receiving at least one level of access tokens from the second device further includes: when the first device is a controlled device, the first device receives an attribute-level access token, a service name, and attribute-related information from the second device; and when the first device is a controlling device, the first device receives a service-level access token, a service name, attribute-related information, and a controlled device identification from the second device; wherein, the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

2. The method according to claim 1, wherein The at least one level of access tokens includes at least one of the following: An account-level access token; A device-level access token; A service-level access token; An attribute-level access token.

3. The method according to claim 2, wherein The service-level access token includes: A service-level access token for the same device; A service-level access token across devices.

4. The method according to claim 2, wherein, The attribute-level access token includes: An attribute-level access token for the same service; An attribute-level access token across services; An attribute-level access token across devices.

5. The method according to claim 2, wherein The account-level access token is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of the devices under the same account.

6. The method according to claim 2, wherein The device-level access token is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of the same device or multiple devices under the same account.

7. According to the method described in claim 3, wherein, The service-level access token for the same device is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service of the same device; The service-level access token across devices is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service of multiple devices.

8. According to the method described in claim 4, wherein, The attribute-level access token for the same service is used to access at least one of the restricted attributes, restricted methods, and restricted events of the same service of the same device; The attribute-level access token across services is used to access at least one of the restricted attributes, restricted methods, and restricted events of multiple services of the same device; The attribute-level access token across devices is used to access at least one of the restricted attributes, restricted methods, and restricted events of multiple services of multiple devices.

9. The method according to any one of claims 1 to 8, wherein The first device receiving at least one level of access tokens from the second device further includes: when the first device is a controlled device, the first device receives a device-level access token from the second device; or When the first device is the master device, the first device receives a device-level access token and a list of controlled device identifiers from the second device.

10. The method according to any one of claims 1 to 8, wherein The first device receiving at least one level of access token from the second device further includes: When the first device is a controlled device, the first device receives a service-level access token and a list of service names from the second device; or When the first device is the master device, the first device receives a service-level access token, a list of service names, and a controlled device identifier from the second device.

11. The method according to any one of claims 1 to 8, wherein The method further includes: The first device sends a token issuance request to the second device.

12. The method according to claim 11, wherein, The token issuance request includes one of the following: A list of controlled device identifiers, and the token issuance request is used to request a device-level access token; A controlled device identifier and a list of service names, and the token issuance request is used to request a service-level access token; A controlled device identifier, service names, and attribute-related information, and the token issuance request is used to request an attribute-level access token, where the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

13. The method according to any one of claims 1 to 8, wherein, The method further includes: The first device receives the identifier of at least one level of access token to be deleted from the second device; The first device deletes the corresponding access token based on the identifier of at least one level of access token to be deleted.

14. The method according to any one of claims 1 to 8, wherein, The second device is a configuration device or a cloud device.

15. The method according to claim 14, wherein, The method further includes at least one of the following sharing methods: The first device shares at least one level of access token with a configuration device or an Internet of Things device bound to another account on the same platform; The first device shares at least one level of access token with a configuration device or an Internet of Things device bound to another account on the same platform through a cloud device; The first device shares at least one level of access token with a configuration device or an Internet of Things device bound to another account on a different platform; The first device shares at least one level of access token with a configuration device or an Internet of Things device bound to another account on a different platform through a cloud device.

16. A method for processing access tokens, comprising: The second device sends at least one level of access token to the first device; Wherein, the method further includes: The second device sends the identifier of at least one level of access token to be updated and the content to be updated to the first device, where the identifier of at least one level of access token to be updated and the content to be updated are used for the first device to update the access token corresponding to the identifier of at least one level of access token to be updated based on the content to be updated, where the content to be updated includes the validity period and permission scope of the access token; Wherein, the second device sending at least one level of access token to the first device includes: When the first device is a controlled device, the second device sends an attribute-level access token, service names, and attribute-related information to the first device; and When the first device is the master device, the second device sends a service-level access token, service name, attribute-related information, and controlled device identifier to the first device; Among them, the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

17. The method according to claim 16, wherein The at least one level of access token includes at least one of the following: An account-level access token; A device-level access token; A service-level access token; An attribute-level access token.

18. The method according to claim 17, wherein The service-level access token includes: A service-level access token for the same device; A service-level access token across devices.

19. The method according to claim 17, wherein, The attribute-level access token includes: An attribute-level access token for the same service; An attribute-level access token across services; An attribute-level access token across devices.

20. The method according to claim 17, wherein, The account-level access token is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of the devices under the same account.

21. The method according to claim 17, wherein The device-level access token is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of the same device or multiple devices under the same account.

22. The method according to claim 18, wherein, The service-level access token for the same device is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service of the same device; The service-level access token across devices is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service of multiple devices.

23. The method according to claim 19, wherein, The attribute-level access token for the same service is used to access at least one of the restricted attributes, restricted methods, and restricted events of the same service of the same device; The attribute-level access token across services is used to access at least one of the restricted attributes, restricted methods, and restricted events of multiple services of the same device; The attribute-level access token across devices is used to access at least one of the restricted attributes, restricted methods, and restricted events of multiple services of multiple devices.

24. The method according to any one of claims 16 to 23, wherein, The second device sending at least one level of access token to the first device further includes: When the first device is a controlled device, the second device sends a service-level access token and a list of service names to the first device; or When the first device is the master device, the second device sends a service-level access token, a list of service names, and a controlled device identifier to the first device.

25. The method according to any one of claims 16 to 23, wherein The method further includes: The second device receives a token distribution request from the first device.

26. The method according to claim 25, wherein The token distribution request includes one of the following: A list of controlled device identifiers, and the token distribution request is used to request a device-level access token; A controlled device identifier and a list of service names, and the token distribution request is used to request a service-level access token; The controlled device identifier, service name, and attribute-related information, where the token issuance request is used to request an access token at the attribute level. Among them, the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

27. The method according to any one of claims 16 to 23, wherein, The method further includes: The second device sends the identifier of at least one level of access token to be deleted to the first device.

28. The method according to any one of claims 16 to 23, wherein The second device is a cloud device.

29. The method according to claim 28, wherein, The method further includes at least one of the following sharing methods: The cloud device shares at least one level of access token from the first device to a configured device or an Internet of Things device bound to another account on the same platform as the first device; The cloud device shares at least one level of access token from the first device to a configured device or an Internet of Things device bound to another account on a different platform from the first device.

30. The method according to claim 28, wherein, The method further includes: The cloud device receives a selected list of master device identifiers and / or a list of controlled device identifiers from the configured device; The cloud device generates a device-level access token and saves the device-level access token and its corresponding list of master device identifiers and / or list of controlled device identifiers.

31. The method according to claim 28, wherein, The method further includes: The cloud device receives a selected list of master device identifiers, a controlled device identifier, and a list of service names from the configured device; The cloud device generates a service-level access token and saves the service-level access token and its corresponding list of master device identifiers, controlled device identifier, and list of service names.

32. The method according to claim 28, wherein The method further includes: The cloud device receives a selected list of master device identifiers, a controlled device identifier, a service name, and attribute-related information from the configured device. Among them, the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names; The cloud device generates an attribute-level access token and saves the attribute-level access token and its corresponding list of master device identifiers, controlled device identifier, service name, and attribute-related information.

33. The method according to any one of claims 16 to 23, wherein The second device is a configured device.

34. The method according to claim 33, wherein, The method further includes at least one of the following: The configured device sends a selected list of master device identifiers and / or a list of controlled device identifiers to the cloud device in response to a device selection operation; The configured device sends a selected list of master device identifiers, a controlled device identifier, and a list of service names to the cloud device in response to a service selection operation; The configured device sends a selected list of master device identifiers, a controlled device identifier, a service name, and attribute-related information to the cloud device in response to an attribute selection operation. Among them, the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

35. The method according to claim 33, wherein, The method further includes at least one of the following: The configured device receives a device-level access token from the cloud device; The configured device receives a service-level access token from the cloud device; The configuration device receives an access token at the attribute level from a cloud device.

36. A first device, comprising: A receiving unit, configured to receive an access token at at least one level from a second device; wherein, the receiving unit is further configured to receive, from the second device, an identifier of an access token at at least one level that needs to be updated and content that needs to be updated; The first device further includes: An updating unit, configured to update an access token corresponding to an identifier of an access token at at least one level that needs to be updated based on the content that needs to be updated, where the content that needs to be updated includes a validity period and a scope of permissions of the access token; The receiving unit is further configured to: When the first device is a controlled device, receive an access token at the attribute level, a service name, and attribute-related information from the second device; and When the first device is a controlling device, receive an access token at the service level, a service name, attribute-related information, and an identifier of a controlled device from the second device; wherein, the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

37. The first device according to claim 36, wherein, The access token at at least one level includes at least one of the following: An access token at the account level; An access token at the device level; An access token at the service level; An access token at the attribute level.

38. The first device according to claim 37, wherein, The access token at the service level includes: An access token at the service level of the same device; An access token at the service level across devices.

39. The first device according to claim 37, wherein The access token at the attribute level includes: An access token at the attribute level of the same service; An access token at the attribute level across services; An access token at the attribute level across devices.

40. The first device according to claim 37, wherein, The access token at the account level is used to access at least one of non-restricted attributes, non-restricted methods, and non-restricted events of devices under the same account.

41. The first device according to claim 37, wherein The access token at the device level is used to access at least one of non-restricted attributes, non-restricted methods, and non-restricted events of the same device or multiple devices under the same account.

42. The first device according to claim 38, wherein The access token at the service level of the same device is used to access at least one of non-restricted attributes, non-restricted methods, and non-restricted events of at least one restricted service of the same device; The access token at the service level across devices is used to access at least one of non-restricted attributes, non-restricted methods, and non-restricted events of at least one restricted service of multiple devices.

43. The first device according to claim 39, wherein The access token at the attribute level of the same service is used to access at least one of at least one restricted attribute, restricted method, and restricted event of the same service of the same device; The access token at the attribute level across services is used to access at least one of at least one restricted attribute, restricted method, and restricted event of multiple services of the same device; The access token at the attribute level across devices is used to access at least one of at least one restricted attribute, restricted method, and restricted event of multiple services of multiple devices.

44. The first device according to any one of claims 36 to 43, wherein, The receiving unit is further configured to: When the first device is a controlled device, receive an access token at the device level from the second device; or When the first device is the master device, receive a device-level access token and a list of controlled device identifiers from the second device.

45. The first device according to any one of claims 36 to 43, wherein, The receiving unit is further configured to: When the first device is a controlled device, receive a service-level access token and a list of service names from the second device; or When the first device is the master device, receive a service-level access token, a list of service names, and a controlled device identifier from the second device.

46. The first device according to any one of claims 36 to 43 further includes: A sending unit configured to send a token issuance request to the second device.

47. The first device according to claim 46, wherein, The token issuance request includes one of the following: A list of controlled device identifiers, and the token issuance request is used to request a device-level access token; A list of controlled device identifiers and service names, and the token issuance request is used to request a service-level access token; A controlled device identifier, a service name, and attribute-related information, and the token issuance request is used to request an attribute-level access token, where the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

48. The first device according to any one of claims 36 to 43, wherein, The receiving unit is further configured to receive from the second device an identifier of at least one level of access token to be deleted; The first device further includes: A deletion unit configured to delete the corresponding access token based on the identifier of at least one level of access token to be deleted.

49. The first device according to any one of claims 36 to 43, wherein, The second device is a configuration device or a cloud device.

50. The first device according to claim 49, wherein, The first device further includes the following sharing unit configured to perform at least one of the sharing methods: Share at least one level of access token with a configuration device or an Internet of Things device bound to another account on the same platform; Share at least one level of access token with a configuration device or an Internet of Things device bound to another account on the same platform through a cloud device; Share at least one level of access token with a configuration device or an Internet of Things device bound to another account on a different platform; Share at least one level of access token with a configuration device or an Internet of Things device bound to another account on a different platform through a cloud device.

51. A second device, comprising: A sending unit configured to send at least one level of access token to the first device; Wherein, the sending unit is further configured to send to the first device an identifier of at least one level of access token to be updated and the content to be updated, where the identifier of at least one level of access token to be updated and the content to be updated are used for the first device to update the access token corresponding to the identifier of at least one level of access token to be updated based on the content to be updated, where the content to be updated includes the validity period and permission scope of the access token; Wherein, the sending unit is further configured to: When the first device is a controlled device, send an attribute-level access token, a service name, and attribute-related information to the first device; and When the first device is the master device, send a service-level access token, a service name, attribute-related information, and a controlled device identifier to the first device. Wherein, the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

52. The second device according to claim 51, wherein, The at least one level of access token includes at least one of the following: An access token at the account level; An access token at the device level; An access token at the service level; An access token at the attribute level.

53. The second device according to claim 52, wherein, The access token at the service level includes: An access token at the service level for the same device; An access token at the service level across devices.

54. The second device according to claim 52, wherein, The access token at the attribute level includes: An access token at the attribute level for the same service; An access token at the attribute level across services; An access token at the attribute level across devices.

55. The second device according to claim 52, wherein, The access token at the account level is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of the devices under the same account.

56. The second device according to claim 52, wherein, The access token at the device level is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of the same device or multiple devices under the same account.

57. The second device according to claim 53, wherein, The access token at the service level for the same device is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service of the same device; The access token at the service level across devices is used to access at least one of the unrestricted attributes, unrestricted methods, and unrestricted events of at least one restricted service of multiple devices.

58. The second device according to claim 55, wherein, The access token at the attribute level for the same service is used to access at least one of the restricted attributes, restricted methods, and restricted events of the same service of the same device; The access token at the attribute level across services is used to access at least one of the restricted attributes, restricted methods, and restricted events of multiple services of the same device; The access token at the attribute level across devices is used to access at least one of the restricted attributes, restricted methods, and restricted events of multiple services of multiple devices.

59. The second device according to any one of claims 51 to 58, wherein, The sending unit is further configured to: When the first device is a controlled device, send an access token at the service level and a list of service names to the first device; or When the first device is a master device, send an access token at the service level, a list of service names, and an identifier of the controlled device to the first device.

60. The second device according to any one of claims 51 to 58, wherein, The second device further includes: A first receiving unit, configured to receive a token distribution request from the first device.

61. The second device according to claim 60, wherein, The token distribution request includes one of the following: A list of controlled device identifiers, and the token distribution request is used to request an access token at the device level; A controlled device identifier and a list of service names, and the token distribution request is used to request an access token at the service level; A controlled device identifier, a service name, and attribute-related information, and the token distribution request is used to request an access token at the attribute level, wherein the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

62. The second device according to any one of claims 51 to 58, wherein, The sending unit is further configured to send an identifier of at least one level of access token that needs to be deleted to the first device.

63. The second device according to any one of claims 51 to 58, wherein, The second device is a cloud device.

64. The second device according to claim 63, wherein, The second device further includes a sharing unit for performing at least one of the following sharing methods: Sharing at least one level of access tokens from the first device to a configured device or an Internet of Things device bound to another account on the same platform as the first device; Sharing at least one level of access tokens from the first device to a configured device or an Internet of Things device bound to another account on a different platform from the first device.

65. The second device according to claim 63, wherein, The second device further includes: A second receiving unit for receiving a selected list of master device identifiers and / or a list of controlled device identifiers from a configured device; A first generating unit for generating device-level access tokens and storing the device-level access tokens and their corresponding lists of master device identifiers and / or lists of controlled device identifiers.

66. The second device according to claim 63, wherein, The second device further includes: A third receiving unit for receiving a selected list of master device identifiers, a list of controlled device identifiers, and a list of service names from a configured device; A second generating unit for generating service-level access tokens and storing the service-level access tokens and their corresponding lists of master device identifiers, lists of controlled device identifiers, and lists of service names.

67. The second device according to claim 63, wherein, The second device further includes: A fourth receiving unit for receiving a selected list of master device identifiers, a list of controlled device identifiers, a service name, and attribute-related information from a configured device, where the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names; A third generating unit for generating attribute-level access tokens and storing the attribute-level access tokens and their corresponding lists of master device identifiers, lists of controlled device identifiers, service names, and attribute-related information.

68. The second device according to any one of claims 51 to 58, wherein, The second device is a configured device.

69. The second device according to claim 68, wherein, The sending unit is further configured to perform at least one of the following: In response to a device selection operation, sending a selected list of master device identifiers and / or a list of controlled device identifiers to a cloud device; In response to a service selection operation, sending a selected list of master device identifiers, a list of controlled device identifiers, and a list of service names to a cloud device; In response to an attribute selection operation, sending a selected list of master device identifiers, a list of controlled device identifiers, a service name, and attribute-related information to a cloud device, where the attribute-related information includes at least one of a list of attribute names, read and / or write operations corresponding to the attributes, addition, deletion, or modification of attribute values, a list of method names, and a list of event names.

70. The second device according to claim 68, wherein, The second device further includes a fifth receiving unit for performing at least one of the following: Receiving device-level access tokens from a cloud device; Receiving service-level access tokens from a cloud device; Receiving attribute-level access tokens from a cloud device.

71. A first device, comprising: A processor and a memory, where the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory so that the first device executes the method according to any one of claims 1 to 16.

72. A second device, comprising: A processor and a memory for storing a computer program, the processor being configured to call and run the computer program stored in the memory so that the second device performs the method according to any one of claims 17 to 35.

73. A chip, comprising: A processor for calling and running a computer program from a memory, such that a device installed with the chip performs the method according to any one of claims 1 to 16.

74. A chip, comprising: A processor for calling and running a computer program from a memory, such that a device installed with the chip performs the method according to any one of claims 17 to 35.

75. A computer-readable storage medium for storing a computer program, which when run by a device causes the device to perform the method according to any one of claims 1 to 16.

76. A computer-readable storage medium for storing a computer program, which when run by a device causes the device to perform the method according to any one of claims 17 to 35.

77. A computer program product comprising computer program instructions that cause a computer to perform the method according to any one of claims 1 to 16.

78. A computer program product comprising computer program instructions that cause a computer to perform the method according to any one of claims 17 to 35.

Citation Information

Patent Citations

  • Data access method and device

    CN110601832A

  • Secure access control in communication system

    WO2020254918A1