A device control method, apparatus, storage medium, and electronic device

CN116127426BActive Publication Date: 2026-09-08ANT BLOCKCHAIN TECHNOLOGY (SHANGHAI) CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202211738049.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-30
Publication Date
2026-09-08
Estimated Expiration
2042-12-30

AI Technical Summary

Technical Problem

但是传统加密方法的安全性较低,一旦加密的密码被破译,很有可能造成物理实体上传的数据被恶意篡改,从而导致数字孪生体根据该数据进行模拟后生成错误的控制指令,进而影响物理实体的运行安全

Benefits of technology

[0053]In the device control method provided in this specification, the server obtains target data sent by the target device, retrieves the identity authentication identifier corresponding to the device identifier from the blockchain based on the device identifier of the target device, and sends the target data and the identity authentication identifier to a preset terminal device. The terminal device authenticates the data source of the target data based on the identity authentication identifier corresponding to the target device stored locally in advance. After confirming that the data source of the target data has been authenticated, the server uses the target data to simulate and control the digital twin deployed locally on the terminal device corresponding to the target device. Based on the results of the simulated control, the server determines and sends control instructions for the target device, receives the control instructions, and forwards the control instructions to the target device to control the target device.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116127426B_ABST
    Figure CN116127426B_ABST
Patent Text Reader

Abstract

The specification discloses a device control method, device, storage medium and electronic device. The device control method comprises: obtaining target data sent by a target device, querying an identity authentication identifier corresponding to the device identifier of the target device from a block chain according to the device identifier of the target device, sending the target data and the identity authentication identifier to a preset terminal device, authenticating the data source of the target data by the terminal device according to the identity authentication identifier corresponding to the target device stored in the local terminal device in advance, simulating the control of the digital twin corresponding to the target device deployed in the local terminal device by the target data after determining that the data source of the target data passes the authentication, determining the control instruction for the target device according to the result generated by the simulation control and sending the control instruction, receiving the control instruction and forwarding the control instruction to the target device to control the target device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of computer technology, and in particular to a device control method, apparatus, storage medium, and electronic device. Background Technology

[0002] With the deepening of digital transformation among major global enterprises, digital twin technology has become an important technical means for the manufacturing industry to move towards Industry 4.0. Digital twin technology enables deep interaction and integration between virtual space and physical entities. For example, for machine tools in industrial scenarios, a corresponding virtual model can be built on a computer as a digital twin. In this way, the virtual model can simulate the data sent by the machine tool entity, generate control commands based on the simulation results, and then send them to the machine tool entity.

[0003] However, because the connection between the physical entity and the digital twin in digital twin technology needs to be established on the basis of network data transmission, data privacy and transmission security face enormous challenges.

[0004] To ensure data transmission security, cryptographic encryption is commonly used to encrypt data transmitted between the digital twin and the physical entity. However, traditional encryption methods have low security. Once the encryption password is cracked, the data uploaded by the physical entity could be maliciously tampered with, causing the digital twin to generate incorrect control commands based on this data, thereby affecting the operational security of the physical entity.

[0005] Therefore, how to ensure data transmission security and further guarantee the safe operation of physical entities is an urgent problem to be solved. Summary of the Invention

[0006] This specification provides a device control method, apparatus, storage medium, and electronic device to ensure secure data transmission between the device and its corresponding virtual model.

[0007] The following technical solution is adopted in this specification:

[0008] This specification provides a device control method, including:

[0009] Acquire target data sent by the target device, the target data being used to represent the operating status of the target device;

[0010] Based on the device identifier of the target device, retrieve the identity authentication identifier corresponding to the device identifier from the blockchain;

[0011] The target data and the identity authentication identifier are sent to a preset terminal device, so that the terminal device authenticates the data source of the target data according to the identity authentication identifier corresponding to the target device that is pre-stored locally on the terminal device. After determining that the data source of the target data has been authenticated, the target data is used to simulate the digital twin deployed locally on the terminal device that corresponds to the target device, and the control command for controlling the target device is determined and sent based on the simulated digital twin.

[0012] The system receives the control command and forwards it to the target device to control the target device.

[0013] Optionally, sending the target data and the authentication identifier to a preset terminal device specifically includes:

[0014] The target data is encrypted to obtain encrypted data;

[0015] The encrypted data and the authentication identifier are sent to the terminal device, so that the terminal device can authenticate the data source of the encrypted data according to the authentication identifier corresponding to the target device that is pre-stored locally on the terminal device, and after determining that the data source of the target data has been authenticated, the encrypted data is decrypted to obtain the target data.

[0016] Optionally, before acquiring the target data sent by the target device, the method further includes:

[0017] Obtain the device identifier corresponding to the target device;

[0018] Based on the device identifier, an identity authentication identifier corresponding to the target device is generated and stored in the blockchain;

[0019] The identity authentication identifier is sent to the terminal device so that the terminal device stores the received identity authentication identifier locally on the terminal device.

[0020] Optionally, the authentication identifier is sent to the terminal device so that the terminal device stores the received authentication identifier locally, specifically including:

[0021] The identity authentication identifier is encrypted to obtain the encrypted identity authentication identifier;

[0022] The encrypted identity authentication identifier is sent to the terminal device so that the terminal device can decrypt the encrypted identity authentication identifier and store the decrypted identity authentication identifier locally on the terminal device.

[0023] Optionally, the control command carries an identity authentication identifier corresponding to the target device stored locally on the terminal device;

[0024] Forwarding the control command to the target device to control the target device specifically includes:

[0025] The control command is sent to the target device so that the target device can authenticate the source of the control command based on the authentication identifier carried in the control command, and control the target device based on the control command after determining that the control command has been authenticated.

[0026] This specification provides a device control method, which is applied to a terminal device and includes:

[0027] The terminal device receives target data sent by the blockchain node and an identity authentication identifier corresponding to the device identifier of the target device. The identity authentication identifier is retrieved by the blockchain node from the blockchain, and the target data is sent by the target device to the blockchain node to indicate the operating status of the target device.

[0028] The data source of the target data is authenticated based on the identity authentication identifier corresponding to the target device that is pre-stored locally on the terminal device;

[0029] After confirming that the data source of the target data has been authenticated, a digital twin corresponding to the target device is simulated based on the target data and deployed locally on the terminal device.

[0030] Based on the simulated digital twin, control commands for controlling the target device are determined and sent to the blockchain node, so that the blockchain node forwards the received control commands to the target device to control the target device.

[0031] Optionally, the data source of the target data is authenticated based on the identity authentication identifier corresponding to the target device pre-stored locally on the terminal device, specifically including:

[0032] Obtain encrypted data and an authentication identifier corresponding to the device identifier of the target device, wherein the encrypted data is obtained by the server encrypting the target data;

[0033] The data source of the encrypted data is authenticated based on the identity authentication identifier corresponding to the target device, which is pre-stored locally on the terminal device.

[0034] This specification provides a device control apparatus, including:

[0035] The acquisition module acquires target data sent by the target device, the target data being used to represent the operating status of the target device;

[0036] The query module retrieves the identity authentication identifier corresponding to the device identifier from the blockchain based on the device identifier of the target device.

[0037] The sending module sends the target data and the identity authentication identifier to a preset terminal device, so that the terminal device authenticates the data source of the target data according to the identity authentication identifier corresponding to the target device that is pre-stored locally on the terminal device. After determining that the data source of the target data has been authenticated, the module simulates a digital twin deployed locally on the terminal device corresponding to the target device according to the target data, and determines and sends control commands for controlling the target device based on the simulated digital twin.

[0038] The receiving module receives the control command and forwards the control command to the target device to control the target device.

[0039] Optionally, the sending module is specifically used to encrypt the target data to obtain encrypted data; send the encrypted data and the identity authentication identifier to the terminal device, so that the terminal device can authenticate the data source of the encrypted data according to the identity authentication identifier corresponding to the target device pre-stored locally on the terminal device, and after determining that the data source of the target data has passed the authentication, decrypt the encrypted data to obtain the target data.

[0040] Optionally, the acquisition module is further configured to: acquire the device identifier corresponding to the target device; generate an identity authentication identifier corresponding to the target device based on the device identifier and store it in the blockchain; and send the identity authentication identifier to the terminal device so that the terminal device stores the received identity authentication identifier locally on the terminal device.

[0041] Optionally, the acquisition module is specifically used to encrypt the identity authentication identifier to obtain an encrypted identity authentication identifier; send the encrypted identity authentication identifier to the terminal device so that the terminal device can decrypt the encrypted identity authentication identifier and store the decrypted identity authentication identifier locally on the terminal device.

[0042] Optionally, the control command carries an identity authentication identifier corresponding to the target device stored locally on the terminal device;

[0043] The receiving module is specifically used to send the control command to the target device, so that the target device can authenticate the source of the control command based on the identity authentication identifier carried in the control command, and control the target device based on the control command after determining that the control command has been authenticated.

[0044] This specification provides a device control apparatus, including:

[0045] The receiving module receives target data sent by the blockchain node and an identity authentication identifier corresponding to the device identifier of the target device. The identity authentication identifier is retrieved by the blockchain node from the blockchain, and the target data is sent by the target device to the blockchain node to indicate the operating status of the target device.

[0046] The authentication module authenticates the data source of the target data based on the identity authentication identifier corresponding to the target device that is pre-stored locally on the terminal device.

[0047] The control module, after confirming that the data source of the target data has been authenticated, simulates the digital twin corresponding to the target device deployed locally on the terminal device based on the target data;

[0048] The sending module determines the control command for controlling the target device based on the simulated digital twin, and sends the control command to the blockchain node, so that the blockchain node forwards the received control command to the target device to control the target device.

[0049] Optionally, the authentication module is specifically used to: obtain encrypted data and an identity authentication identifier corresponding to the device identifier of the target device, wherein the encrypted data is obtained by the server encrypting the target data; and authenticate the data source of the encrypted data according to the identity authentication identifier corresponding to the target device pre-stored locally on the terminal device.

[0050] This specification provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described device control method.

[0051] This specification provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the device control method described above.

[0052] The above-mentioned technical solutions adopted in this specification can achieve the following beneficial effects:

[0053] In the device control method provided in this specification, the server obtains target data sent by the target device, retrieves the identity authentication identifier corresponding to the device identifier from the blockchain based on the device identifier of the target device, and sends the target data and the identity authentication identifier to a preset terminal device. The terminal device authenticates the data source of the target data based on the identity authentication identifier corresponding to the target device stored locally in advance. After confirming that the data source of the target data has been authenticated, the server uses the target data to simulate and control the digital twin deployed locally on the terminal device corresponding to the target device. Based on the results of the simulated control, the server determines and sends control instructions for the target device, receives the control instructions, and forwards the control instructions to the target device to control the target device.

[0054] As can be seen from the above method, when the device sends target data, it first determines its identity authentication identifier through the blockchain node and sends the identity authentication identifier and the target data together to the terminal device. This allows the terminal to authenticate the source of the target data based on another identity authentication identifier stored locally. Only after successful authentication will a control command be generated and sent to the terminal device. Compared with the current method of encrypting transmitted data based solely on traditional cryptography, this solution can accurately verify the source of the target data, thereby effectively preventing the target data from being tampered with and generating incorrect control commands, ensuring the security of data transmission, and further guaranteeing the secure operation of the device. Attached Figure Description

[0055] The accompanying drawings, which are included to provide a further understanding of this specification and form part of this specification, illustrate exemplary embodiments and their descriptions, serving to explain this specification and do not constitute an undue limitation thereof.

[0056] In the picture:

[0057] Figure 1 This is a flowchart illustrating a device control method provided in this specification;

[0058] Figure 2 This is a schematic diagram of the identity registration process for a target device provided in this specification;

[0059] Figure 3 This is a schematic diagram of the data transmission relationship of a target device provided in this specification;

[0060] Figure 4 This is a flowchart illustrating a device control method provided in this specification;

[0061] Figure 5 This is a schematic diagram of a device control process provided in this specification;

[0062] Figure 6 This is a schematic diagram of a device control apparatus provided in this specification;

[0063] Figure 7 This is a schematic diagram of a device control apparatus provided in this specification;

[0064] Figure 8 This specification provides a corresponding Figure 1 A schematic diagram of an electronic device. Detailed Implementation

[0065] To make the objectives, technical solutions, and advantages of this specification clearer, the technical solutions of this specification will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of them. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this specification.

[0066] The technical solutions provided in the various embodiments of this specification are described in detail below with reference to the accompanying drawings.

[0067] Figure 1 This is a flowchart illustrating a device control method provided in this specification, including the following steps:

[0068] S100: Obtain target data sent by the target device, the target data being used to represent the operating status of the target device.

[0069] S102: Based on the device identifier of the target device, retrieve the identity authentication identifier corresponding to the device identifier from the blockchain.

[0070] Currently, digital twin technology has been widely applied in various fields such as product design, industrial manufacturing, medical analysis, engineering construction, aerospace equipment, and power grid control. Digital twins can fully utilize various sensor data and actual operational data of physical entities, integrating multi-disciplinary, multi-physical quantity, multi-scale, and multi-probabilistic simulation processes to complete mapping in virtual space, thereby reflecting the entire life cycle process of the corresponding physical entity. Then, based on the simulation results, corresponding control commands are issued to the physical entity.

[0071] For example, in a machine tool machining scenario, a virtual model of the machine tool can be constructed as a digital twin. This digital twin, after synchronously acquiring machine tool machining data (such as voltage, current, power, vibration frequency, etc.), will simulate the machining process to calculate potential risks or faults that may occur during subsequent machining, obtaining the calculation results. Then, based on these calculation results, corresponding control commands can be generated and sent to the physical entity (machine tool). Upon receiving the control commands, the machine tool will adjust its machining parameters accordingly, thereby avoiding potential risks or faults during subsequent machining.

[0072] However, since data transmission between the digital twin and the physical entity relies on network data transmission, the data received by the digital twin may be tampered with by unauthorized users, thereby generating incorrect control commands and seriously threatening the secure operation of the device.

[0073] Based on this, this specification provides a device control method, in which a blockchain node needs to obtain the target data sent by the target device and determine the identity authentication identifier corresponding to the target device. The target device may include: machine tools, motors, factory control systems, building control systems, power grids, urban water conservancy systems, urban power supply and distribution systems, and other physical devices actually existing in the physical environment; this specification does not specifically limit this type of device.

[0074] After a blockchain node receives target data sent by a target device, it can retrieve the corresponding identity authentication identifier from the blockchain based on this identifier, since the target data carries the target device's identification information (such as an identity document ID). This target data can be collected by sensors such as current sensors, voltage sensors, temperature sensors, and vibration sensors, representing data such as current, voltage, temperature, and vibration frequency generated during the device's actual operation, thus characterizing the target device's operating status.

[0075] In this manual, users can pre-build a virtual model of the target device on their terminal device, thus using this virtual model as a digital twin of the target device. The terminal device can use digital twin technology to construct a corresponding digital twin in a virtual environment based on parameters such as the device's size, structure, components, and operating data. This terminal device can be a specified device such as a laptop or desktop computer; this manual does not specify any particular type.

[0076] In addition, the target device also needs to register its identity in the blockchain node. Specifically, after the terminal device builds a digital twin of the target device, the target device can send its own identification information to the blockchain node. After obtaining the identification information, the blockchain node will generate an identity authentication identifier corresponding to the device and store it in the blockchain, and bind the device's identification information with the identity authentication identifier, thereby realizing the device's identity registration in the blockchain node.

[0077] Then, blockchain nodes can execute smart contracts to encrypt the identity authentication identifier and send the encrypted identifier to the terminal device where the digital twin resides. Upon receiving the identifier, the terminal device decrypts it and stores the decrypted identifier locally, thus achieving notarization of the identity authentication identifier corresponding to the target device. For ease of understanding, this specification provides a schematic diagram of the target device's identity registration process, such as... Figure 2 As shown.

[0078] Figure 2 This is a schematic diagram of the identity registration process for a target device provided in this specification.

[0079] In this process, the terminal device first needs to construct a digital twin of the target device. Then, the target device sends the identification information to the blockchain node, which generates an identity authentication identifier corresponding to the target device and associates the identity authentication identifier with the device. In addition, if the device information changes, the pre-stored identity authentication identifier can be updated through the blockchain node.

[0080] After generating an identity authentication identifier, the blockchain node can encrypt the identifier and send it to the terminal device. Upon receiving the encrypted identity authentication identifier, the terminal device stores the identifier and returns a successful storage result to the blockchain node. After receiving the execution result returned by the terminal device, the blockchain node can return a successful registration result to the device.

[0081] It should be noted that there are multiple ways to encrypt and decrypt identity authentication tokens. For example, a blockchain node can encrypt the identity authentication token using a public key, while the terminal device stores the corresponding private key locally. Upon receiving the encrypted identity authentication token, the terminal device can use the private key to decrypt it. Alternatively, the identity authentication token can also be encrypted and decrypted using a password.

[0082] Of course, blockchain nodes may also choose not to encrypt the identity authentication identifier, but instead send it directly to the terminal device. In this way, the terminal device can directly store the obtained identity authentication identifier.

[0083] S104: The target data and the identity authentication identifier are sent to a preset terminal device, so that the terminal device authenticates the data source of the target data according to the identity authentication identifier corresponding to the target device that is pre-stored locally on the terminal device. After determining that the data source of the target data has been authenticated, the terminal device simulates the digital twin deployed locally on the terminal device corresponding to the target device according to the target data, and determines and sends control commands for controlling the target device based on the simulated digital twin.

[0084] After a blockchain node determines the identity authentication identifier, it can further embed this identifier onto the target data, and then send both the identity authentication identifier and the target data to the terminal device. To further ensure data security, the blockchain node can first encrypt the target data, obtaining encrypted data, and then send the encrypted data, carrying the identity authentication identifier, to the terminal device.

[0085] Upon receiving the authentication identifier and encrypted data, the terminal device first authenticates the source of the encrypted data based on the locally stored authentication identifier. If the locally stored authentication identifier matches the received authentication identifier, it indicates that the encrypted data was sent by the target device corresponding to the digital twin in the terminal device. Authentication is then successful, and the terminal device can further decrypt the encrypted data to obtain the target data.

[0086] The method for encrypting and decrypting the target data can be the same as the method for encrypting and decrypting the identity authentication identifier described in step S102, and will not be elaborated on here.

[0087] After decrypting the target data, the terminal device can simulate the digital twin corresponding to the target device deployed locally on the terminal device based on the target data, thereby obtaining the simulation results. These results may include: the time of the device failure, the cause of the failure, and the predicted changes in operating parameters (such as voltage, current, power, etc.).

[0088] Of course, blockchain nodes can also choose not to encrypt the target data, so that after the terminal device authenticates the data source, it does not need to decrypt the acquired data.

[0089] The terminal device can then analyze the calculation results to determine control commands that are most effective in controlling the current simulation results, or control commands that match the current control results. This ensures that the target device achieves optimal operation or shuts down promptly to prevent malfunctions after executing the control command. For example, if the simulation reveals abnormal operating data of the target device, a control command to shut it down can be sent to allow for timely maintenance and prevent potential safety hazards. As another example, if the simulation shows that the target device's temperature is too high, the terminal device can send a control command to reduce its operating power to prevent the safety hazards caused by persistently high temperatures.

[0090] S106: Receive the control command and forward the control command to the target device to control the target device.

[0091] When a terminal device sends a control command, it can bind the locally stored identity authentication identifier to the stored command. When a blockchain node receives the control command sent by the terminal device, it can further forward the control command carrying the identity authentication identifier to the target device. Then, the target device can determine whether the identity authentication identifier carried by the control command matches its locally stored identity authentication identifier. If so, it means that the control command was generated by the terminal device where the digital twin of the target device is located, and at this time, the data source can be confirmed to be authenticated.

[0092] The target device can then execute the control command. For example, when the control command is a shutdown command, the device will immediately shut down after receiving the command and authenticating its source. When the control command is an operating parameter adjustment command, the target device can respond to the command and adjust its own operating parameters after authenticating its source. Of course, other types of control commands and corresponding transactions may also be included, but this specification does not specifically limit them.

[0093] It should be noted that the process of simulating and controlling the digital twin, and determining control commands, can be accomplished by the computing unit deployed in the terminal device. For ease of understanding, this specification provides a schematic diagram of the data transmission relationship of the target device, such as... Figure 3 As shown.

[0094] Figure 3 This is a schematic diagram of the data transmission relationship of a target device provided in this specification.

[0095] In this process, the terminal device will pre-build a digital twin corresponding to the target device. When the target device uploads data to the digital twin in the terminal device for data synchronization, the target data will first be uploaded to the blockchain node. The blockchain node will then authenticate the target data (identity verification). After successful authentication, the computing unit in the terminal device can simulate the target data through the digital twin, thereby enabling the monitoring and prediction of the device's status.

[0096] The computing unit can generate corresponding control commands based on the simulation control results, and send the control commands to the blockchain node. The blockchain node then forwards the control commands to the target device, which can execute the control commands after the commands are authenticated.

[0097] The above describes a device control method provided in this manual, using a blockchain node as the execution entity as an example. For ease of understanding, the following will further explain this device control method from the perspective of the terminal device, such as... Figure 4 As shown.

[0098] Figure 4 This is a flowchart illustrating a device control method provided in this specification, including the following steps:

[0099] S400: The terminal device receives target data sent by the blockchain node and an identity authentication identifier corresponding to the device identifier of the target device. The identity authentication identifier is retrieved by the blockchain node from the blockchain, and the target data is sent by the target device to the blockchain node to indicate the operating status of the target device.

[0100] The target device can first send the target data to the blockchain node. After receiving the target data, the blockchain node can query the identity authentication identifier corresponding to the target device in the blockchain and send the target data carrying the identity authentication identifier to the terminal device.

[0101] S402: Authenticate the data source of the target data based on the identity authentication identifier corresponding to the target device that is pre-stored locally on the terminal device.

[0102] S404: After confirming that the data source of the target data has been authenticated, simulate the digital twin corresponding to the target device deployed locally on the terminal device based on the target data.

[0103] After receiving target data carrying an identity authentication identifier, the terminal device can determine whether the identity authentication identifier matches the locally stored identity authentication identifier. If they match, authentication is passed, and the digital twin corresponding to the target device is simulated based on the target data deployed locally on the terminal device.

[0104] S406: Based on the simulated digital twin, determine the control command for controlling the target device, and send the control command to the blockchain node so that the blockchain node forwards the received control command to the target device to control the target device.

[0105] The terminal device can then generate corresponding control commands based on the simulation results and send the control commands to the blockchain node, which will then forward them to the device. Upon receiving the control commands, the device can first authenticate the source of the control commands and then execute the control commands after successful authentication.

[0106] To facilitate understanding, this manual provides a schematic diagram of the transaction execution process, such as... Figure 5 As shown.

[0107] Figure 5 This is a schematic diagram of a device control process provided in this specification.

[0108] In this process, the terminal device sends target data to the blockchain node. After receiving the target data, the blockchain node encrypts the target data through a smart contract, determines the device's identity authentication identifier, and sends the encrypted data carrying the identity authentication identifier to the terminal device.

[0109] After receiving the authentication identifier, the terminal device verifies the data source of the encrypted data through the locally stored authentication identifier, and decrypts the encrypted data after successful authentication. It then performs simulation calculations on the decrypted target data and sends corresponding control commands to the blockchain node based on the simulation calculation results.

[0110] Upon receiving the control command, the blockchain node determines the identity authentication identifier corresponding to the terminal device and sends it to the device along with the control command. The device, upon receiving the control command, also authenticates its source and, upon successful authentication, executes the transaction according to the control command.

[0111] As can be seen from the above method, when the device sends target data, it first determines its identity authentication identifier through the blockchain node and sends the identity authentication identifier and the target data together to the terminal device. This allows the terminal to authenticate the source of the target data based on another identity authentication identifier stored locally. Only after successful authentication will a control command be generated and sent to the terminal device. Compared with the current method of encrypting transmitted data based solely on traditional cryptography, this solution can accurately verify the source of the target data, thereby effectively preventing the target data from being tampered with and generating incorrect control commands, ensuring the security of data transmission, and further guaranteeing the secure operation of the device.

[0112] Based on the same concept, this specification also provides corresponding equipment control devices for one or more implementation methods of the equipment control methods, such as... Figure 6 or Figure 7 As shown.

[0113] Figure 6 A schematic diagram of a device control apparatus provided in this specification includes:

[0114] The acquisition module 600 is used to acquire target data sent by the target device, the target data being used to represent the operating status of the target device;

[0115] The query module 602 is used to query the identity authentication identifier corresponding to the device identifier from the blockchain based on the device identifier of the target device;

[0116] The sending module 604 is used to send the target data and the identity authentication identifier to a preset terminal device, so that the terminal device authenticates the data source of the target data according to the identity authentication identifier corresponding to the target device stored locally on the terminal device. After determining that the data source of the target data has been authenticated, the terminal device simulates a digital twin deployed locally on the terminal device corresponding to the target device according to the target data, and determines and sends control commands for controlling the target device based on the simulated digital twin.

[0117] The receiving module 606 is used to receive the control command and forward the control command to the target device to control the target device.

[0118] Optionally, the sending module 604 is specifically used to encrypt the target data to obtain encrypted data; send the encrypted data and the identity authentication identifier to the terminal device, so that the terminal device authenticates the data source of the encrypted data according to the identity authentication identifier corresponding to the target device pre-stored locally on the terminal device, and decrypts the encrypted data after determining that the data source of the target data has passed the authentication to obtain the target data.

[0119] Optionally, the acquisition module 600 is further configured to: acquire the device identifier corresponding to the target device; generate an identity authentication identifier corresponding to the target device based on the device identifier and store it in the blockchain; and send the identity authentication identifier to the terminal device so that the terminal device stores the received identity authentication identifier locally on the terminal device.

[0120] Optionally, the acquisition module 600 is specifically used to encrypt the identity authentication identifier to obtain an encrypted identity authentication identifier; send the encrypted identity authentication identifier to the terminal device so that the terminal device can decrypt the encrypted identity authentication identifier and store the decrypted identity authentication identifier locally on the terminal device.

[0121] Optionally, the control command carries an identity authentication identifier corresponding to the target device stored locally on the terminal device;

[0122] The receiving module 606 is specifically used to send the control command to the target device, so that the target device can authenticate the source of the control command based on the identity authentication identifier carried in the control command, and control the target device based on the control command after determining that the control command has been authenticated.

[0123] Figure 7 A schematic diagram of a device control apparatus provided in this specification includes:

[0124] The receiving module 700 is used for the terminal device to receive target data sent by the blockchain node and an identity authentication identifier corresponding to the device identifier of the target device, wherein the identity authentication identifier is retrieved by the blockchain node from the blockchain, and the target data is sent by the target device to the blockchain node to indicate the operating status of the target device;

[0125] Authentication module 702 is used to authenticate the data source of the target data based on the identity authentication identifier corresponding to the target device that is pre-stored locally on the terminal device;

[0126] Control module 704 is used to simulate a digital twin corresponding to the target device deployed locally on the terminal device based on the target data after determining that the data source of the target data has been authenticated;

[0127] The sending module 706 is used to determine the control command for controlling the target device based on the simulated digital twin, and send the control command to the blockchain node, so that the blockchain node forwards the received control command to the target device to control the target device.

[0128] Optionally, the authentication module 702 is specifically used to: obtain encrypted data and an identity authentication identifier corresponding to the device identifier of the target device, wherein the encrypted data is obtained by the server encrypting the target data; and authenticate the data source of the encrypted data according to the identity authentication identifier corresponding to the target device pre-stored locally on the terminal device.

[0129] This specification also provides a computer-readable storage medium storing a computer program that can be used to execute the above-described... Figure 1 or Figure 4 A device control method is provided.

[0130] This instruction manual also provides Figure 8 The one shown corresponds to Figure 1 or Figure 4 A schematic diagram of the structure of an electronic device. (e.g.) Figure 4 At the hardware level, the electronic device includes a processor, internal bus, network interface, memory, and non-volatile memory, and may also include other hardware required for the business operations. The processor reads the corresponding computer program from the non-volatile memory into memory and then runs it to achieve the above-mentioned functions. Figure 1 or Figure 4 The device control method described above. Of course, in addition to software implementation, this specification does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0131] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should understand that by simply performing some logic programming on the method flow using one of these hardware description languages ​​and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.

[0132] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, ASICs, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.

[0133] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0134] For ease of description, the above devices are described in terms of function, divided into various units. Of course, in implementing this specification, the functions of each unit can be implemented in one or more software and / or hardware components.

[0135] Those skilled in the art will understand that embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this specification may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0136] This specification is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0137] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0138] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0139] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0140] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0141] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0142] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0143] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this specification may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0144] This specification can be described in the general context of computer-executable instructions that are executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. This specification can also be practiced in distributed computing environments, where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0145] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

[0146] The above description is merely an embodiment of this specification and is not intended to limit this specification. Various modifications and variations can be made to this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims of this specification.

Claims

1. A device control method, the method being applied to a blockchain node, comprising: Obtain the device identifier corresponding to the target device; Based on the device identifier, an identity authentication identifier corresponding to the target device is generated and stored in the blockchain; The identity authentication identifier is sent to a preset terminal device so that the terminal device stores the received identity authentication identifier locally on the terminal device. Acquire target data sent by the target device, the target data being used to represent the operating status of the target device; Based on the device identifier of the target device, retrieve the identity authentication identifier corresponding to the device identifier from the blockchain; The target data and the identity authentication identifier are sent to the terminal device, so that the terminal device can authenticate the data source of the target data according to the identity authentication identifier corresponding to the target device that is pre-stored locally on the terminal device. After determining that the data source of the target data has been authenticated, the terminal device simulates the digital twin deployed locally on the terminal device corresponding to the target device according to the target data, and determines and sends control commands for controlling the target device based on the simulated digital twin. The terminal device receives the control command, which carries an authentication identifier corresponding to the target device stored locally. The terminal device then forwards the control command to the target device so that the target device can determine whether the authentication identifier stored locally matches the authentication identifier carried in the control command. If they match, the terminal device determines that the source of the control command has been authenticated. After determining that the control command has been authenticated, the terminal device controls the target device based on the control command.

2. The method as described in claim 1, wherein sending the target data and the identity authentication identifier to the terminal device specifically includes: The target data is encrypted to obtain encrypted data; The encrypted data and the authentication identifier are sent to the terminal device, so that the terminal device can authenticate the data source of the encrypted data according to the authentication identifier corresponding to the target device that is pre-stored locally on the terminal device, and after determining that the data source of the target data has been authenticated, the encrypted data is decrypted to obtain the target data.

3. The method as described in claim 1, wherein sending the authentication identifier to the terminal device so that the terminal device stores the received authentication identifier locally on the terminal device, specifically includes: The identity authentication identifier is encrypted to obtain the encrypted identity authentication identifier; The encrypted identity authentication identifier is sent to the terminal device so that the terminal device can decrypt the encrypted identity authentication identifier and store the decrypted identity authentication identifier locally on the terminal device.

4. A device control method, the method being applied to a terminal device, comprising: The terminal device receives the identity authentication identifier corresponding to the target device sent by the blockchain node, and stores the received identity authentication identifier locally on the terminal device. The identity authentication identifier is generated by the blockchain node based on the device identifier of the target device and stored in the blockchain. The terminal device receives target data sent by the blockchain node and an identity authentication identifier corresponding to the device identifier of the target device. The identity authentication identifier is retrieved by the blockchain node from the blockchain, and the target data is sent by the target device to the blockchain node to indicate the operating status of the target device. The data source of the target data is authenticated based on the identity authentication identifier corresponding to the target device that is pre-stored locally on the terminal device. After confirming that the data source of the target data has been authenticated, a digital twin corresponding to the target device is simulated based on the target data and deployed locally on the terminal device. Based on the simulated digital twin, a control command for controlling the target device is determined. The control command carries an identity authentication identifier corresponding to the target device stored locally on the terminal device. The control command is then sent to the blockchain node, which forwards the received control command to the target device. The target device then determines whether the identity authentication identifier stored locally on the target device matches the identity authentication identifier carried in the control command. If they match, the source of the control command is verified. After verifying that the control command is verified, the target device is controlled based on the control command.

5. The method as described in claim 4, wherein authenticating the data source of the target data based on the identity authentication identifier corresponding to the target device pre-stored locally on the terminal device, specifically includes: Obtain encrypted data and an identity authentication identifier corresponding to the device identifier of the target device, wherein the encrypted data is obtained by the server encrypting the target data; The data source of the encrypted data is authenticated based on the identity authentication identifier corresponding to the target device, which is pre-stored locally on the terminal device.

6. A device for controlling equipment, comprising: The acquisition module retrieves the device identifier corresponding to the target device. Based on the device identifier, an identity authentication identifier corresponding to the target device is generated and stored in the blockchain; The identity authentication identifier is sent to a preset terminal device, so that the terminal device stores the received identity authentication identifier locally; target data sent by the target device is obtained, the target data being used to represent the operating status of the target device; The query module retrieves the identity authentication identifier corresponding to the device identifier from the blockchain based on the device identifier of the target device. The sending module sends the target data and the identity authentication identifier to the terminal device, so that the terminal device can authenticate the data source of the target data according to the identity authentication identifier corresponding to the target device that is pre-stored locally on the terminal device. After determining that the data source of the target data has been authenticated, the module simulates the digital twin deployed locally on the terminal device corresponding to the target device according to the target data, and determines and sends control commands for controlling the target device based on the simulated digital twin. The receiving module receives the control command, which carries an authentication identifier corresponding to the target device stored locally on the terminal device, and forwards the control command to the target device so that the target device can determine whether the authentication identifier stored locally on the target device matches the authentication identifier carried in the control command. If they match, the source of the control command is determined to be authenticated, and after determining that the control command is authenticated, the module controls the target device based on the control command.

7. The apparatus of claim 6, wherein the sending module is specifically configured to: encrypt the target data to obtain encrypted data; send the encrypted data and the authentication identifier to the terminal device, so that the terminal device authenticates the data source of the encrypted data according to the authentication identifier corresponding to the target device pre-stored locally on the terminal device, and after determining that the data source of the target data has passed authentication, decrypt the encrypted data to obtain the target data.

8. The apparatus of claim 6, wherein the acquisition module is specifically configured to: encrypt the identity authentication identifier to obtain an encrypted identity authentication identifier; send the encrypted identity authentication identifier to the terminal device so that the terminal device decrypts the encrypted identity authentication identifier and stores the decrypted identity authentication identifier locally on the terminal device.

9. A device for controlling equipment, comprising: The receiving module receives an identity authentication identifier corresponding to the target device sent by a blockchain node, and stores the received identity authentication identifier locally on the terminal device. The identity authentication identifier is generated by the blockchain node based on the device identifier of the target device and stored in the blockchain. The module also receives target data sent by the blockchain node, along with the identity authentication identifier corresponding to the device identifier of the target device. The identity authentication identifier is retrieved by the blockchain node from the blockchain, and the target data is sent by the target device to the blockchain node to indicate the operating status of the target device. The authentication module authenticates the data source of the target data based on the identity authentication identifier corresponding to the target device that is pre-stored locally on the terminal device. After determining that the data source of the target data has been authenticated, the control module simulates the digital twin corresponding to the target device deployed locally on the terminal device based on the target data. The sending module determines a control command for controlling the target device based on the simulated digital twin. The control command carries an identity authentication identifier corresponding to the target device stored locally on the terminal device. The module then sends the control command to the blockchain node, which forwards the received control command to the target device. The target device then determines whether the identity authentication identifier stored locally on the target device matches the identity authentication identifier carried in the control command. If they match, the module determines that the source of the control command has been authenticated. After confirming that the control command has been authenticated, the module controls the target device based on the control command.

10. The apparatus of claim 9, wherein the authentication module is specifically configured to acquire encrypted data and an identity authentication identifier corresponding to the device identifier of the target device, wherein, The encrypted data is obtained by encrypting the target data by the server; The data source of the encrypted data is authenticated based on the identity authentication identifier corresponding to the target device, which is pre-stored locally on the terminal device.

11. A computer-readable storage medium storing a computer program that, when executed by a processor, implements the method described in any one of claims 1 to 5.

12. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Service data access method, apparatus and system, and electronic device

    CN109327314A

  • Identity verification method and device based on blockchain, equipment and storage medium

    CN111556007A

  • Cross-domain authentication method and device and user registration method and device

    CN114978635A

  • Production line management method, system and equipment based on digital twinning and medium

    CN115220411A