Unlocking Permission Configuration Method, Device, Equipment, and Storage Medium for Base Station Safety Lock
By building multiple geofences and temporary key mechanisms, the problem of time-consuming and low flexibility in unlocking permission configuration of base station security locks is solved, and the base station security is improved and permission management is efficient.
Patent Information
- Application Number
- CN202510239531.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-03-03
AI Technical Summary
In the prior art, the unlocking permission configuration operation of the base station security lock is time-consuming and has low flexibility, and it is impossible to effectively manage and maintain personnel's permission adjustments, which poses security risks.
Build a first geofence, a second geofence and a third geofence distributed in sequence from the inside to the outside. Through the base station security lock as the center, determine the preset account associated with the pending work order, generate temporary keys and verify them, and use near-field communication to achieve flexible configuration of unlocking permissions.
It realizes flexible configuration of base station security lock unlock permissions, ensuring that only maintenance personnel who need to execute work orders can be turned on, and improves the security and management efficiency of base stations.
Smart Images

Figure CN119729353B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of dynamic permission configuration, and in particular to an unlocking permission configuration method, device, equipment, and storage medium for a base station safety lock. Background Art
[0002] Currently, in order to ensure the safety of equipment inside a communication base station, a safety lock is usually configured at the entrance of the communication base station. The current safety lock already has certain storage capabilities, processing capabilities, and communication capabilities. The unlocking permissions of maintenance personnel can be pre-configured at the safety lock offline or online. The maintenance personnel can unlock by entering a password or biometric features, etc., which can effectively improve the security of the communication base station.
[0003] However, if the maintenance personnel are no longer responsible for the maintenance of the original communication base station due to work adjustments or other reasons and need to adjust the unlocking permissions stored in the safety lock, in the case of a large number of involved communication base stations, the permission configuration operation will consume a large amount of operation time, and the flexibility of permission management is relatively low. Even if the permissions of the maintenance personnel are not adjusted, if they enter and leave the communication base station randomly without maintenance tasks, it may also pose certain security risks. Summary of the Invention
[0004] The present invention aims to at least solve one of the technical problems existing in the prior art. For this purpose, the present invention provides an unlocking permission configuration method, device, equipment, and storage medium for a base station safety lock, which can flexibly configure the unlocking permissions of the base station safety lock and improve the security of the base station.
[0005] In a first aspect, an embodiment of the present invention provides an unlocking permission configuration method for a base station safety lock, which is applied to a server. The server is communicatively connected to a plurality of preset terminals and the base station safety lock of a target base station. Different preset accounts are logged in to each of the preset terminals. The method includes:
[0006] Based on the base station safety lock as the center, construct a first geographical fence, a second geographical fence, and a third geographical fence that are distributed in sequence from the inside to the outside, determine the work order to be processed of the target base station, and determine the preset account associated with the work order to be processed as a candidate account;
[0007] Determine the preset terminal that enters the third geographical fence and corresponds to the candidate account as a target terminal, and randomly generate a respective temporary key for each of the target terminals;
[0008] Send a verification instruction to the target terminal that enters the second geographical fence, obtain the target unlocking information input by the target terminal based on the verification instruction, send the target unlocking information to the base station security lock, and send the temporary key to the target terminal and the base station security lock, so that the base station security lock locks the target unlocking permission of the target unlocking information based on the temporary key, wherein, after the target terminal enters the first geographical fence, the base station security lock completes the verification of the temporary key with the target terminal through near-field communication to unlock the target unlocking permission.
[0009] According to some embodiments of the present invention, the construction of the first geographical fence, the second geographical fence, and the third geographical fence distributed in sequence from the inside to the outside includes:
[0010] Determine the terminal moving speed of each of the preset terminals, determine the key calculation duration for generating the temporary key, determine a first reference duration based on the number of the preset terminals, the key calculation duration, and a preset magnification factor, and determine a first distance based on the first reference duration and the terminal moving speed;
[0011] Based on any one of the preset terminals, determine a second reference duration based on historical data, and determine a second distance based on the second reference duration and the terminal moving speed, wherein the second reference duration is used to indicate the duration from sending the verification instruction to obtaining the target unlocking information;
[0012] Construct the first geographical fence based on the near-field communication range of the base station security lock;
[0013] Based on any one of the preset terminals, construct the second geographical fence based on the first geographical fence and the second distance, and construct the third geographical fence based on the second geographical fence and the first distance.
[0014] According to some embodiments of the present invention, after determining the preset terminal that enters the third geographical fence and corresponds to the candidate account as the target terminal, the method further includes:
[0015] Obtain the current first positioning information of the target terminal, and predict a third reference duration based on the first positioning information and the terminal moving speed, wherein the third reference duration is the predicted duration for the target terminal to enter the second geographical fence from the current position;
[0016] When the target terminal meets the revocation condition, revoke the temporary key;
[0017] Wherein, the revocation condition includes at least one of the following:
[0018] The target terminal does not enter the second geographic fence after the third reference duration;
[0019] The target terminal leaves the third geographic fence;
[0020] It is detected that the moving direction of the target terminal is away from the second geographic fence.
[0021] According to some embodiments of the present invention, after obtaining the target unlocking information input by the target terminal based on the verification instruction, the method further includes:
[0022] Obtain the current second positioning information of the target terminal, and predict a fourth reference duration based on the second positioning information and the terminal moving speed, where the fourth reference duration is the predicted duration for the target terminal to enter the first geographic fence from the current position;
[0023] Obtain a preset redundant duration, and configure the sum of the fourth reference duration and the redundant duration as the validity period of the temporary key;
[0024] When it is detected that the target terminal enters the third geographic fence from the second geographic fence, revoke the temporary key from the target terminal and the base station security lock.
[0025] According to some embodiments of the present invention, determining the preset account associated with the work order to be processed as a candidate account includes:
[0026] Determine multiple preset accounts that are associated with the same work order to be processed and have entered the third geographic fence as associated accounts, and determine the preset terminals corresponding to the associated accounts as associated terminals;
[0027] Generate a processing prompt message based on all the associated accounts and the work order to be processed that they commonly associate with, send the processing prompt message to the corresponding associated terminals, and obtain the target accounts selected by each associated terminal based on the processing prompt message;
[0028] When the target accounts are the same associated account, determine the target account as the candidate account, and the remaining associated accounts are not determined as the candidate accounts.
[0029] According to some embodiments of the present invention, after sending the target unlocking information to the base station security lock, the method further includes:
[0030] Based on the work order description information preset in the work order to be processed, determine the number of times of entry and exit for completing the work order to be processed;
[0031] Send the number of accesses to the base station security lock, so that the base station security lock configures the available number of times of the target unlocking information based on the number of accesses. Wherein, when the used number of times of the target unlocking information reaches the available number of times, the base station security lock stops the near-field communication with the target terminal and deletes the corresponding temporary key.
[0032] According to some embodiments of the present invention, before determining the number of accesses of the work order to be processed, the method further includes:
[0033] When obtaining the change information of any of the work orders to be processed, determine the work order to be processed with the change as the change work order, determine the candidate account associated with the change work order as the change account, and determine the preset terminal associated with the change account as the change terminal;
[0034] When the change information is used to indicate the stop of processing the change work order, and the change account does not include another work order to be processed associated with the base station security lock, delete the temporary key in the change terminal, and delete the corresponding temporary key and the target unlocking information in the base station security lock;
[0035] When the change information is used to indicate the change from another candidate account to the current change account, determine that the target unlocking information fed back by the change terminal is not obtained, and send the verification instruction to the change terminal.
[0036] In a second aspect, an embodiment of the present invention provides an unlocking permission configuration device for a base station security lock, including at least one control processor and a memory communicatively connected to the at least one control processor; the memory stores instructions executable by the at least one control processor, and the instructions are executed by the at least one control processor, so that the at least one control processor can execute the unlocking permission configuration method of the base station security lock as described in the first aspect above.
[0037] In a third aspect, an embodiment of the present invention provides an electronic device, including the unlocking permission configuration device of the base station security lock as described in the second aspect above.
[0038] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, storing computer-executable instructions for executing the unlocking permission configuration method of the base station security lock as described in the first aspect above.
[0039] The unlocking permission configuration method of the base station safety lock according to the embodiments of the present invention has at least the following beneficial effects: Based on the base station safety lock as the center, a first geographical fence, a second geographical fence, and a third geographical fence are constructed and distributed in sequence from the inside to the outside. The work order to be processed of the target base station is determined, and the preset account associated with the work order to be processed is determined as the candidate account; the preset terminal that enters the third geographical fence and corresponds to the candidate account is determined as the target terminal, and a respective temporary key is randomly generated for each target terminal; a verification instruction is sent to the target terminal that enters the second geographical fence, the target unlocking information input by the target terminal based on the verification instruction is obtained, the target unlocking information is sent to the base station safety lock, and the temporary key is sent to the target terminal and the base station safety lock, so that the base station safety lock locks the target unlocking permission of the target unlocking information based on the temporary key. Among them, after the target terminal enters the first geographical fence, the base station safety lock completes the verification of the temporary key with the target terminal through near-field communication to unlock the target unlocking permission. According to the technical solution of the embodiments of the present invention, after constructing multiple geographical fences, effective candidate accounts are determined in combination with the work order to be processed. Temporary keys for each target terminal are dynamically generated in the outermost third geographical fence. The deployment of the temporary key is triggered when entering the second geographical fence. The base station safety lock locks the target unlocking information customized by the target terminal based on the temporary key. After the target terminal enters the first geographical fence, the pairing of the temporary key is automatically triggered. After the matching is successful, the unlocking permission of the target unlocking information is automatically unlocked. There is no need to pre-configure the unlocking permission on the base station safety lock, realizing flexible configuration of the unlocking permission, ensuring that the unlocking permission is only opened for maintenance personnel who need to execute the work order, and improving the safety of the base station. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 is a schematic diagram of a system provided by an embodiment of the present invention;
[0041] Figure 2 is a flowchart of the unlocking permission configuration method of the base station safety lock provided by another embodiment of the present invention;
[0042] Figure 3 is a complete flowchart of the unlocking permission configuration method of the base station safety lock provided by another embodiment of the present invention;
[0043] Figure 4 is a structural diagram of the unlocking permission configuration device of the base station safety lock provided by another embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0044] Embodiments of the present invention will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below by referring to the accompanying drawings are exemplary and are only used to explain the present invention and should not be construed as limiting the present invention.
[0045] In the description of the present invention, it should be understood that with regard to the orientation description, such as the orientation or positional relationship indicated by up, down, front, back, left, right, etc., is based on the orientation or positional relationship shown in the accompanying drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as limiting the present invention.
[0046] In the description of the present invention, the meaning of "several" is one or more, the meaning of "multiple" is two or more, "greater than", "less than", "exceeding", etc. are understood as not including the recited number, and "above", "below", "within", etc. are understood as including the recited number. If there is a description of "first" and "second", it is only for the purpose of distinguishing technical features and should not be construed as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features or the sequence relationship of the indicated technical features.
[0047] In the description of the present invention, unless otherwise clearly defined, words such as "set", "installed", "connected", etc. should be understood in a broad sense. Those skilled in the art can reasonably determine the specific meanings of the above words in the present invention in combination with the specific content of the technical solution.
[0048] An embodiment of the present invention provides a method, apparatus, device, and storage medium for configuring unlocking permissions of a base station safety lock. The method for configuring unlocking permissions of the base station safety lock includes: based on the base station safety lock as the center, constructing a first geographical fence, a second geographical fence, and a third geographical fence that are sequentially distributed from the inside to the outside, determining a work order to be processed for the target base station, and determining a preset account associated with the work order to be processed as a candidate account; determining a preset terminal that enters the third geographical fence and corresponds to the candidate account as a target terminal, and randomly generating a respective temporary key for each target terminal; sending a verification instruction to the target terminal that enters the second geographical fence, obtaining target unlocking information input by the target terminal based on the verification instruction, sending the target unlocking information to the base station safety lock, and sending the temporary key to the target terminal and the base station safety lock, so that the base station safety lock locks the target unlocking permission of the target unlocking information based on the temporary key. After the target terminal enters the first geographical fence, the base station safety lock completes the verification of the temporary key with the target terminal through near-field communication to unlock the target unlocking permission. According to the technical solution of the embodiment of the present invention, after constructing multiple geographical fences, valid candidate accounts are determined in combination with the work order to be processed. A temporary key for each target terminal is dynamically generated in the outermost third geographical fence. The deployment of the temporary key is triggered when entering the second geographical fence. The base station safety lock locks the target unlocking information customized by the target terminal through the temporary key. When the target terminal enters the first geographical fence, the pairing of the temporary key is automatically triggered. After successful matching, the unlocking permission of the target unlocking information is automatically unlocked. There is no need to pre-configure the unlocking permission in the base station safety lock, realizing flexible configuration of the unlocking permission, ensuring that the unlocking permission is only opened for maintenance personnel who need to execute the work order, and improving the safety of the base station.
[0049] First, referring to Figure 1 , Figure 1 FIG. is a schematic diagram of a system provided by an embodiment of the present invention. This embodiment is applied to a server 10. The server 10 is communicatively connected to a plurality of preset terminals and a base station safety lock 30 of a target base station. Different preset accounts are logged in to each preset terminal.
[0050] It should be noted that the server 10 is used to manage multiple base stations. Multiple base stations can be configured in the server 10. A base station safety lock 30 and a work order to be processed are configured for each base station. In the case of having multiple base station safety locks 30, the technical solution of this embodiment can be independently executed for each base station safety lock 30.
[0051] It should be noted that the server 10 is bound to multiple preset terminals. The preset terminals are the mobile phones or maintenance terminals of maintenance personnel. Log in to the server 10 through the preset accounts of the maintenance personnel in the mobile phones, so that the server 10 can identify the corresponding maintenance personnel according to the preset accounts, and establish communication with the preset terminals and obtain positioning information after passing the verification.
[0052] Next, based on the Figure 1 system schematic diagram shown below, the technical solution of the embodiment of the present invention will be further elaborated.
[0053] Refer to Figure 2 , Figure 2 which is a flowchart of an unlocking permission configuration method for a base station safety lock provided by an embodiment of the present invention. The unlocking permission configuration method for the base station safety lock includes but is not limited to the following steps:
[0054] S10, centered on the base station safety lock, construct a first geographical fence, a second geographical fence, and a third geographical fence that are distributed in sequence from the inside to the outside, determine the work order to be processed of the target base station, and determine the preset account associated with the work order to be processed as the candidate account;
[0055] S20, determine the preset terminal that enters the third geographical fence and corresponds to the candidate account as the target terminal, and randomly generate respective corresponding temporary keys for each target terminal;
[0056] S30, send a verification instruction to the target terminal that enters the second geographical fence, obtain the target unlocking information input by the target terminal based on the verification instruction, send the target unlocking information to the base station safety lock, and send the temporary key to the target terminal and the base station safety lock, so that the base station safety lock locks the target unlocking permission of the target unlocking information based on the temporary key. Among them, after the target terminal enters the first geographical fence, the base station safety lock completes the verification of the temporary key with the target terminal through near-field communication to unlock the target unlocking permission.
[0057] It should be noted that as Figure 1 shown, the first geographical fence 41, the second geographical fence 42, and the third geographical fence 43 of this embodiment are all constructed centered on the base station safety lock 30. For the convenience of description, this embodiment shows each geographical fence as a circular area. Of course, different shapes can also be set according to actual needs. For example, the first geographical fence 41 is circular, the second geographical fence 42 is square, and the third geographical fence 43 is irregular.
[0058] It should be noted that in this embodiment, by setting three geofences from the inside to the outside, three determination areas can be constructed from the inside to the outside with the base station security lock as the center, and the entry of the preset terminal into any geofence is used as a trigger signal. When the preset terminal enters the third geofence, it is judged whether it is a candidate account, and when it is identified as a candidate account, a temporary key is triggered to be generated; when the target terminal enters the second geofence, a verification instruction is sent to confirm that the moving purpose of the target terminal is to go to the base station security lock, and after obtaining the target unlocking information, the deployment of the temporary key is triggered; when the target terminal enters the first geofence, the pairing and unlocking operations of the temporary key are executed. This embodiment does not limit the area sizes of the respective geofences, and it is sufficient to complete the above corresponding operations in the corresponding geofences.
[0059] It should be noted that each target base station can have multiple work orders to be processed, such as equipment maintenance work orders, system upgrade work orders, new equipment installation work orders, etc. Each work order to be processed can be pre-assigned specific maintenance personnel or construction personnel, and the preset accounts of the relevant personnel are recorded in the work order to be processed. The server determines the preset account recorded in the work order to be processed as a candidate account. Only the preset terminal corresponding to the candidate account can be determined as the target terminal. For maintenance personnel who have not been assigned a work order to be processed, there is no need to enter the target base station, so the subsequent unlocking permission assignment will not be executed, avoiding maintenance personnel from entering the target base station when there is no work task and improving the security of the target base station.
[0060] Exemplarily, as Figure 1 shown, the preset terminal includes a first terminal 21, a second terminal 22, and a third terminal 23. The first terminal 21 corresponds to the first account, the second terminal 22 corresponds to the second account, and the third terminal 23 corresponds to the third account. The first work order, the second work order, and the third work order are recorded in the server. When the target base station is the first base station, even if the above three terminals are all located in the third geofence 43, the first account and the second account are candidate accounts. Therefore, the first terminal 21 and the second terminal 22 are determined as the target terminals, and the third terminal 23 is not determined as the target terminal. At the same time, the first account also corresponds to the second work order, that is, a candidate account can correspond to multiple work orders to be processed, which is not limited here.
[0061] It should be noted that the server can mark each candidate account after determining the work order to be processed. Since the preset terminal of the candidate account can be located by the server, when it is detected that the preset terminal enters the third geographical fence, the preset terminal is determined as the target terminal. The target terminal has the tendency to go to the target base station. Therefore, in this embodiment, the entry of the target terminal into the third geographical fence is used as the trigger signal to generate a temporary key in the server. The temporary key in this embodiment is a random key. Not only are the temporary keys of each target terminal different from each other, but even the two temporary keys generated by the same target terminal are different, ensuring that different keys are used for each unlocking and avoiding the security risks caused by the loss of the preset terminal or the maintenance personnel going to the target base station again after completing this work order. This embodiment does not involve the improvement of the encryption algorithm, and it is only necessary to ensure that each temporary key is different from each other.
[0062] It is worth noting that generating a temporary key does not consume too much computing resources and storage resources. Moreover, the target terminal may pass through the third geographical fence when going to other destinations, and it cannot be ensured that the target terminal will necessarily go to the target base station. At this time, the server does not issue the temporary key but saves it in the server first. When the target terminal enters the second geographical fence, the server sends a verification instruction to the target terminal. The verification instruction can carry the work order to be processed corresponding to the candidate account and requires the maintenance personnel to enter the target unlocking information in the target terminal. If the purpose of the maintenance personnel at this time is not to go to the target base station, they will not respond to the verification instruction after seeing the work order to be processed. If the maintenance personnel respond to the verification instruction and enter the target unlocking information, it can be determined that the purpose of the maintenance personnel is to go to the target base station to execute the work order to be processed. Therefore, the temporary key generated by triggering in the third geographical fence can be issued to the target terminal and the base station security lock. The target terminal and the base station security lock can verify the legality of the device through the interaction of the temporary key.
[0063] Exemplarily, as Figure 1 shown, when the first terminal 21 enters the second geographical fence 42 from the third geographical fence 43, a verification instruction is sent to the first terminal 21, and the first work order and the second work order are displayed on the first terminal 21. The maintenance personnel enter their fingerprints as the target unlocking information in the first terminal 21 and use it as the basis for confirming the processing of the work order to be processed. After the server 10 obtains the digital password, it issues the temporary key (the first key) corresponding to the first account and the digital password to the base station security lock 30. The digital password is locked in the base station security lock 30 through the first key, and the first key is synchronously issued to the first terminal 21.
[0064] It should be noted that in this embodiment, the unlocking of the base station security lock is not performed through a temporary key, which may pose a security risk in the event that the target terminal is lost. Instead, in this embodiment, the target unlocking information obtained by the target terminal is used as the basis for unlocking. The target unlocking information can be a digital password or a biometric feature such as a fingerprint, which is input by the maintenance personnel in response to the verification instruction. After the server obtains it, it is sent to the base station security lock together with the temporary key, and the temporary key is used to lock the target unlocking information, that is, the target unlocking information is only valid for the base station security lock after the temporary key verification passes. By using the dual verification mechanism of the target terminal and the maintenance personnel, not only can the security risk caused by the loss of the target terminal be avoided, but also the security risk caused by password leakage can be avoided, further improving the security of the target base station.
[0065] It should be noted that the deployment of the temporary key and the target unlocking information is completed within the second geofence. After entering the first geofence, the base station security lock can establish a near-field communication with the target terminal, such as Bluetooth or NFC communication. The base station security lock sends a password verification request to the target terminal, and the target terminal feeds back the temporary key. After the base station security lock obtains the temporary key, it compares it with the temporary key sent by the server. After the verification passes, the corresponding target unlocking information becomes effective, and the maintenance personnel can input the target unlocking information at the base station security lock to complete the unlocking, such as inputting a digital password or unlocking through a fingerprint. Before the temporary key verification passes, even if the target unlocking information is input, it will not take effect for unlocking. By using the progressive relationship between the temporary key and the target unlocking information as the unlocking permission, the unlocking permission can be flexibly configured while effectively ensuring the security of the base station.
[0066] Exemplarily, continuing to refer to the example of the first terminal 21 above, after the first terminal 21 enters the first geofence 41, the base station security lock 30 detects the first terminal 21 through near-field communication, obtains the temporary key from the first terminal 21, unlocks the target unlocking information after the verification passes, and the maintenance personnel complete the unlocking after inputting the target unlocking information at the base station security lock 30. At this time, if the maintenance personnel corresponding to the second account go to the base station security lock 30 with the first terminal 21, even if the temporary key pairing is successful, they will not be able to unlock because the fingerprints do not match; or, when the target unlocking information is a digital password, if other people input the same digital password at the base station security lock 30, since the digital password is locked by the temporary key, the unlocking cannot be completed. Through the technical solution of this embodiment, only when the correct target terminal and the corresponding maintenance personnel perform the unlocking operation at the same time can the base station security lock 30 be unlocked, improving the security of the base station through dual verification.
[0067] In addition, in one embodiment, referring to Figure 3 , in step S10, a first geofence, a second geofence, and a third geofence are constructed and distributed from the inside to the outside in sequence, which specifically includes but is not limited to the following steps:
[0068] S11. Determine the terminal moving speed of each preset terminal, determine the key calculation duration for generating a temporary key, determine a first reference duration based on the number of preset terminals, the key calculation duration, and a preset magnification factor, and determine a first distance based on the first reference duration and the terminal moving speed.
[0069] S12. Based on any preset terminal, determine a second reference duration based on historical data, and determine a second distance based on the second reference duration and the terminal moving speed, where the second reference duration is used to indicate the duration from sending a verification instruction to obtaining target unlocking information.
[0070] S13. Construct a first geofence based on the near-field communication range of the base station security lock.
[0071] S14. Based on any preset terminal, construct a second geofence based on the first geofence and the second distance, and construct a third geofence based on the second geofence and the first distance.
[0072] It should be noted that since near-field communication is performed after the target terminal enters the first geofence, regardless of which preset terminal it is, the size of the first geofence is determined according to the near-field communication range of the base station security lock. Therefore, the first geofences of different base station security locks are different, enabling the first geofence to be dynamically configured according to the hardware capabilities of the base station security lock to ensure that the target terminal can trigger near-field communication after entering the first geofence.
[0073] It should be noted that for the same base station security lock, the sizes of the first geofences corresponding to all preset terminals are the same, which is determined based on the function of the first geofence. Similarly, the preset terminal needs to complete the interaction with the server within the second geofence and the third geofence, and the interaction process is completed during the movement. Therefore, the constructed second geofence and third geofence can at least meet the requirement that the preset terminal completes the interaction during the movement. Since the moving methods of each preset terminal are different, for example, some maintenance personnel may drive to the target base station, while some maintenance personnel may walk to the target base station, the distances moved by different preset terminals during the interaction with the server are different. In this embodiment, the sizes of the second geofence and the third geofence corresponding to each preset terminal are determined based on the terminal moving speed of each preset terminal to ensure that each preset terminal has a suitable area to complete the interaction with the server, that is, the sizes of the second geofences corresponding to different preset terminals can be different, and the same applies to the third geofence.
[0074] It should be noted that in the third geographical fence, only the generation of the temporary key needs to be completed, and the key calculation duration for calculating the temporary key is known. The difference between different preset terminals lies only in the different passwords generated. Therefore, it can be considered that the key calculation durations of different preset terminals are the same. However, different numbers of preset terminals will result in different total calculation durations of the server. To ensure that all preset terminals can obtain the temporary key, in this embodiment, the product of the key calculation duration and the number of preset terminals is used as the first base number. Considering that the key calculation duration is relatively short, this embodiment further sets an amplification factor to amplify the first base number to obtain the first reference duration. For example, if the key calculation duration is 10 ms and there are 10 preset terminals, the first base number is 100 ms, and the amplification factor is 1000, then the obtained first reference duration is 100 s. Then, the corresponding first distance can be obtained according to the terminal moving speed of different preset terminals.
[0075] It should be noted that when determining the second geographical fence, it is necessary to ensure that the maintenance personnel of the target terminal can complete the response to the verification instruction. However, different maintenance personnel have different habits and proficiencies when operating the target terminal. Therefore, the operation durations of different maintenance personnel are different. Based on the technical solution of this embodiment, a temporary key is generated each time the maintenance personnel go to the target base station. For example, the temporary key generated on the first day is different from that generated on the second day. Each time the maintenance personnel go to the target base station, the technical solution of this embodiment is independently executed. Therefore, more historical data can be accumulated based on the same preset account and the base station security lock, so as to determine how much time is required for this preset account to respond to the verification instruction each time, that is, the second reference duration determined based on historical data in this embodiment. After determining the second reference duration, multiplying it by the terminal moving speed can obtain the second distance. Of course, the second reference duration in this embodiment is the duration from when the server sends the verification instruction to the target terminal to obtaining the target unlocking information, and the average value of the historical data can be taken.
[0076] It should be noted that as Figure 1 shown, after determining the first geographical fence 41, the first distance, and the second distance, since they are all centered on the base station security lock 30, the first geographical fence 41 can be expanded by the second distance to obtain the second geographical fence 42, that is, the distance between the boundary of the second geographical fence 42 and the boundary of the first geographical fence 41 is the second distance. Similarly, on the basis of the second geographical fence 42, expanding it by the first distance can obtain the third geographical fence 43, which will not be repeated here.
[0077] In addition, in one embodiment, referring to Figure 3 , in step S20, after determining the preset terminal that enters the third geographical fence and corresponds to the candidate account as the target terminal, it further includes but is not limited to the following steps:
[0078] S21. Obtain the current first positioning information of the target terminal, and predict a third reference duration based on the first positioning information and the terminal moving speed, where the third reference duration is the predicted duration for the target terminal to enter the second geographical fence from the current position;
[0079] S22. When the target terminal meets the revocation condition, revoke the temporary key;
[0080] Among them, the revocation condition includes at least one of the following:
[0081] The target terminal does not enter the second geographical fence after the third reference duration;
[0082] The target terminal leaves the third geographical fence;
[0083] It is detected that the moving direction of the target terminal is away from the second geographical fence.
[0084] It should be noted that after the target terminal enters the third geographical fence, although it is associated with at least one work order to be processed, the target terminal may only pass by the third geographical fence instead of going to the target base station. If the target terminal is not going to the target base station, the corresponding temporary key needs to be revoked to improve the security of the base station.
[0085] It should be noted that in this embodiment, the first positioning information of the target terminal is obtained by using conventional positioning technology first. Since the boundaries of the third geographical fence and the second geographical fence are known, the distance required to move into the second geographical fence can be determined according to the first positioning information, and the third reference duration can be determined in combination with the terminal moving speed. The third reference duration represents the predicted duration for the target terminal to enter the second geographical fence from the current position. Of course, considering the actual commuting situation, the third reference duration can also be corrected to a certain extent, such as adding a preset redundancy value according to the traffic congestion situation, which will not be elaborated here.
[0086] It should be noted that when the target terminal does not enter the second geographical fence after the third reference duration, the maintenance personnel corresponding to the target terminal are not going to the target base station and pass by the third geographical fence when going to other destinations; when the target terminal enters the third geographical fence and then leaves the third geographical fence, it can also be determined that the target terminal is not going to the target base station; when the moving direction of the target terminal is away from the second geographical fence, even if it does not leave the third geographical fence, it can be determined that the target terminal is not going to the target base station. In the above situations where the revocation condition is met, the corresponding temporary key is revoked.
[0087] In addition, in one embodiment, referring to Figure 3 , in step S30, after obtaining the target unlocking information input by the target terminal based on the verification instruction, it further includes but is not limited to the following steps:
[0088] S31. Obtain the current second positioning information of the target terminal, and predict a fourth reference duration based on the second positioning information and the terminal moving speed, where the fourth reference duration is the predicted duration for the target terminal to enter the first geographical fence from the current position;
[0089] S32. Obtain a preset redundant duration, and configure the sum of the fourth reference duration and the redundant duration as the validity period of the temporary key;
[0090] S33. When it is detected that the target terminal enters the third geographical fence from the second geographical fence, revoke the temporary key from the target terminal and the base station security lock.
[0091] It should be noted that after determining the second positioning information, the fourth reference duration is calculated in the same principle as the above-mentioned third reference duration. The duration required to enter the first geographical fence can be determined through the fourth reference duration. According to the description of the above embodiments, after obtaining the target unlocking information, it can be determined that the target terminal is on the way to the target base station. To improve the security of the temporary key, in this embodiment, the validity period of the temporary key is configured according to the sum of the redundant duration and the fourth reference duration. The redundant duration can be determined according to empirical values, such as the redundant value set according to the traffic congestion situation in the current time period.
[0092] It should be noted that after the temporary key is issued to the target terminal and the base station security lock, it counts down according to the validity period obtained in this embodiment. If the target terminal normally goes to the target base station, it can enter the first geographical fence within the validity period, so as to complete the verification and unlocking within the validity period of the temporary key. If the target terminal does not enter the first geographical fence within the validity period, it can be determined that the target terminal has an abnormality on the way. To ensure the security of the base station, the temporary key is automatically revoked after the validity period. Of course, an emergency mechanism can be set in the server to reactivate the temporary key. For example, when the maintenance personnel encounter sudden traffic congestion or vehicle breakdown during the commute, they can send an emergency request to the server after arriving at the first geographical fence, and the server administrator can verify and reactivate the temporary key.
[0093] It is worth noting that when it is detected that the target terminal enters the third geographical fence from the second geographical fence, it can be determined that the destination of the target terminal has changed from the target base station to other positions, and the maintenance personnel no longer go to the target base station to work. The server revokes the temporary key from the target terminal and the base station security lock, and re-executes the technical solution of this embodiment to allocate a new temporary key after entering the third geographical fence again next time. For example, when the maintenance personnel are on the way to the first base station, an emergency occurs at the second base station that needs to be processed first. The maintenance personnel change the destination to the second base station, resulting in the situation of entering the third geographical fence from the second geographical fence of the first base station, and the temporary key configured for the base station security lock of the first base station is revoked.
[0094] In addition, in one embodiment, referring to Figure 3 , in step S10, the preset account associated with the work order to be processed is determined as the candidate account, specifically including but not limited to the following steps:
[0095] S15, determine multiple preset accounts that are associated with the same work order to be processed and have entered the third geofence as associated accounts, and determine the preset terminals corresponding to the associated accounts as associated terminals;
[0096] S16, generate a processing prompt message based on all the associated accounts and the work order to be processed jointly, send the processing prompt message to the corresponding associated terminals, and obtain the target accounts selected by each associated terminal based on the processing prompt message;
[0097] S17, when the target accounts are the same associated account, determine the target account as the candidate account, and the remaining associated accounts are not determined as candidate accounts.
[0098] It should be noted that when allocating a work order to be processed, multiple preset accounts can be allocated for collaborative processing. For example, an equipment installation work order requires multiple maintenance personnel to jointly process. If each preset account is determined as a candidate account, it will result in configuring duplicate unlocking permissions for multiple target terminals at the same time, consuming unnecessary server resources. In actual operation, as long as one target terminal has the unlocking permission and completes the unlocking, other maintenance personnel can also enter the target base station to work together. Based on this, in this embodiment, after detecting that multiple preset accounts associated with the same work order to be processed enter the third geofence, the multiple preset accounts are determined as associated accounts, and the corresponding associated terminals are determined. A processing prompt message is generated based on the associated accounts and the work order to be processed, so that each associated terminal can receive the processing prompt message within the third geofence. The maintenance personnel can view the work order to be processed and each associated account after clicking on the processing prompt message, select the target account from multiple associated accounts and feedback it to the server. If the target accounts are the same associated account, only the target account is determined as the candidate account to perform subsequent operations, and the remaining associated accounts are not determined as candidate accounts.
[0099] Exemplarily, as Figure 1 shown, taking the first work order as an example, the first account and the second account are associated accounts, and the first terminal 21 and the second terminal 22 are associated terminals. After entering the third geofence, the server 10 sends the first work order, the first account, and the second account to the first terminal 21 and the second terminal 22. The maintenance personnel can determine who will perform the unlocking operation through offline communication. When the first account is selected on both the first terminal 21 and the second terminal 22, the first account is determined as the candidate account to perform subsequent operations, and the second account is not determined as the candidate account, that is, the server will not generate a temporary key for the second account.
[0100] In addition, in one embodiment, referring to Figure 3 , after the target unlocking information is sent to the base station security lock in step S30, it further includes but is not limited to the following steps:
[0101] S41. Based on the preset work order description information in the work order to be processed, determine the number of times of entering and leaving to complete the work order to be processed;
[0102] S42. Send the number of times of entering and leaving to the base station security lock so that the base station security lock configures the available number of times of the target unlocking information based on the number of times of entering and leaving. Wherein, when the used number of times of the target unlocking information reaches the available number of times, the base station security lock stops the near-field communication with the target terminal and deletes the corresponding temporary key.
[0103] It should be noted that when performing different base station maintenance operations, the number of times of entering and leaving the base station is not necessarily the same. For example, only one entry and exit of the target base station is required during system upgrade, and multiple entries and exits are required to carry equipment during equipment installation. In order to improve the security of the base station, the base station door cannot be kept open. In this embodiment, the number of times of entering and leaving required for the work order to be processed is determined based on the work order description information of the preset work order, and the available number of times of the target unlocking information is configured in the base station security lock according to the number of times of entering and leaving. The work order description information can record the specific number of times of entering and leaving. For example, it is recorded in the work order description information that "it is necessary to carry N times", where N is a positive integer, and N is configured as the number of times of entering and leaving. Or it is recorded in the work order description information that "system upgrade", then the server determines that only one entry is required according to the specific work item and sets the number of times of entering and leaving to 1.
[0104] It should be noted that after the target terminal enters the first geofence, the near-field communication between the target terminal and the base station security lock can be maintained, and the unlocking effect of the temporary key can be maintained without disconnecting the communication, so that the target unlocking information remains in an available state, and the base station security lock counts the used number of times of the target unlocking information. After reaching the available number of times, the near-field communication with the target terminal is disconnected and the temporary key is deleted. Of course, if the validity period of the temporary key is set, the temporary key can be directly deleted after the validity period. As long as the near-field communication is maintained, the target unlocking information can be ensured to be available.
[0105] In addition, in one embodiment, referring to Figure 3 , before determining the number of times of entering and leaving to complete the work order to be processed in step S41, it further includes but is not limited to the following steps:
[0106] S411. When the change information of any work order to be processed is obtained, determine the changed work order to be processed as the change work order, determine the candidate account associated with the change work order as the change account, and determine the preset terminal associated with the change account as the change terminal;
[0107] S412. When the change information is used to indicate stopping the processing of the change work order, and the changed account does not include another pending work order associated with the base station security lock, delete the temporary key in the change terminal, and delete the corresponding temporary key and target unlocking information in the base station security lock;
[0108] S413. When the change information is used to indicate changing from another candidate account to the current changed account, if it is determined that the target unlocking information fed back by the change terminal has not been obtained, send a verification instruction to the change terminal.
[0109] It should be noted that the pending work order may change during actual operation. For example, the originally associated maintenance personnel are temporarily transferred to another urgent task, resulting in a change in the preset account; another example is that in a troubleshooting work order, the fault has been automatically eliminated after the device is restarted, and there is no need to process the troubleshooting work order anymore. In this embodiment, the work order with changes is determined as the pending work order, the changed candidate account is determined as the changed account, and the corresponding change terminal is determined.
[0110] It should be noted that if the change information is to stop processing the change work order and there is no other associated pending work order, it can be determined that the change terminal does not need to go to the target base station to perform operations anymore. If the temporary key corresponding to the change terminal has been generated, then directly delete the temporary key and the target unlocking information.
[0111] It should be noted that if the change information is an account change, that is, the changed account is added to the change work order. If the changed account has already fed back the target unlocking information for the same target base station, but only the matters to be processed have increased, then no subsequent operations are required, and the changed account can already complete the unlocking based on the temporary key of another pending work order. If the changed account has not fed back the target unlocking information, since the target unlocking information is obtained based on the verification instruction of the pending work order, it can be determined that the changed account does not have the unlocking permission, and just send the verification instruction according to the method of the above embodiment.
[0112] As Figure 4 shown, Figure 4 is the structural diagram of the unlocking permission configuration device of the base station security lock provided by an embodiment of the present invention. The present invention also provides an unlocking permission configuration device for a base station security lock, including:
[0113] A processor 401, which can be implemented by using a general-purpose central processing unit (CPU), a microprocessor, an application specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided by the embodiments of the present application;
[0114] The memory 402 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM), etc. The memory 402 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 402, and the processor 401 is called to execute the unlocking permission configuration method of the base station security lock in the embodiments of this application;
[0115] The input / output interface 403 is used to implement information input and output;
[0116] The communication interface 404 is used to implement communication and interaction between this device and other devices. It can communicate through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.);
[0117] The bus 405 transmits information between various components of the device (such as the processor 401, the memory 402, the input / output interface 403, and the communication interface 404);
[0118] Among them, the processor 401, the memory 402, the input / output interface 403, and the communication interface 404 are communicatively connected to each other inside the device through the bus 405.
[0119] The embodiments of this application also provide an electronic device, including the unlocking permission configuration device of the base station security lock as described above.
[0120] The embodiments of this application also provide a storage medium. The storage medium is a computer-readable storage medium. The storage medium stores a computer program, and when the computer program is executed by a processor, it implements the unlocking permission configuration method of the base station security lock as described above.
[0121] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof. The device embodiments described above are merely illustrative, where the units described as separate components may or may not be physically separated, and may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0122] Those of ordinary skill in the art can understand that all or some of the steps and systems disclosed above can be implemented as software, firmware, hardware, and appropriate combinations thereof. Some physical components or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or can be implemented as hardware, or can be implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those of ordinary skill in the art, a communication medium typically includes computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery medium.
[0123] The above is a specific description of the preferred embodiments of the present invention, but the present invention is not limited to the above embodiments. Those skilled in the art can also make various equivalent deformations or substitutions without departing from the spirit of the present invention, and these equivalent deformations or substitutions are all included within the scope defined by the claims of the present invention.
Claims
1. A method for configuring the unlocking permission of a base station safety lock, characterized in that, Applied to a server, the server is communicatively connected to a base station security lock of multiple preset terminals and a target base station, and different preset accounts are logged in to each of the preset terminals. The method includes: Centering on the base station security lock, construct a first geographical fence, a second geographical fence, and a third geographical fence that are distributed in sequence from the inside to the outside, determine the work order to be processed of the target base station, and determine the preset account associated with the work order to be processed as the candidate account; Determine the preset terminal that enters the third geographical fence and corresponds to the candidate account as the target terminal, and randomly generate respective corresponding temporary keys for each of the target terminals; Send a verification instruction to the target terminal that enters the second geographical fence, obtain the target unlocking information input by the target terminal based on the verification instruction, send the target unlocking information to the base station security lock, and send the temporary key to the target terminal and the base station security lock, so that the base station security lock locks the target unlocking permission of the target unlocking information based on the temporary key. Among them, after the target terminal enters the first geographical fence, the base station security lock completes the verification of the temporary key with the target terminal through near-field communication to unlock the target unlocking permission; The construction of the first geographical fence, the second geographical fence, and the third geographical fence that are distributed in sequence from the inside to the outside includes: Determine the terminal moving speed of each of the preset terminals, determine the key calculation duration for generating the temporary key, determine the first reference duration based on the number of the preset terminals, the key calculation duration, and a preset magnification factor, and determine the first distance based on the first reference duration and the terminal moving speed; Based on any one of the preset terminals, determine the second reference duration based on historical data, and determine the second distance based on the second reference duration and the terminal moving speed, where the second reference duration is used to indicate the historical average value of the duration from sending the verification instruction to the candidate account to obtaining the target unlocking information feedback from the same candidate account; Construct the first geographical fence based on the near-field communication range of the base station security lock; Based on any one of the preset terminals, construct the second geographical fence based on the first geographical fence and the second distance, and construct the third geographical fence based on the second geographical fence and the first distance.
2. The unlocking permission configuration method of the base station safety lock according to claim 1, wherein After determining the preset terminal that enters the third geographical fence and corresponds to the candidate account as the target terminal, the method further includes: Obtain the current first positioning information of the target terminal, and predict the third reference duration based on the first positioning information and the terminal moving speed, where the third reference duration is the predicted duration for the target terminal to enter the second geographical fence from the current position; When the target terminal meets the revocation condition, revoke the temporary key; Among them, the revocation condition includes at least one of the following: The target terminal does not enter the second geographical fence after the third reference duration; The target terminal leaves the third geographical fence; It is detected that the moving direction of the target terminal is away from the second geographical fence.
3. The unlocking permission configuration method of the base station safety lock according to claim 2, characterized in that, After obtaining the target unlocking information input by the target terminal based on the verification instruction, the method further includes: Obtaining the current second positioning information of the target terminal, and predicting a fourth reference duration based on the second positioning information and the terminal moving speed, where the fourth reference duration is the predicted duration for the target terminal to enter the first geographical fence from the current position; Obtaining a preset redundant duration, and configuring the sum of the fourth reference duration and the redundant duration as the validity period of the temporary key; When it is detected that the target terminal enters the third geographical fence from the second geographical fence, revoke the temporary key from the target terminal and the base station security lock.
4. The unlocking permission configuration method of the base station safety lock according to claim 2, characterized in that, Determining the preset account associated with the work order to be processed as a candidate account includes: Determining multiple preset accounts that are associated with the same work order to be processed and have entered the third geographical fence as associated accounts, and determining the preset terminals corresponding to the associated accounts as associated terminals; Generating a processing prompt message based on all the associated accounts and the work order to be processed that they commonly associate with, sending the processing prompt message to the corresponding associated terminals, and obtaining the target accounts selected by each of the associated terminals based on the processing prompt message; When the target accounts are the same associated account, determining the target account as the candidate account, and not determining the remaining associated accounts as the candidate accounts.
5. The unlocking permission configuration method of the base station safety lock according to claim 1, characterized in that, After sending the target unlocking information to the base station security lock, the method further includes: Determining the number of times of entering and leaving for completing the work order to be processed based on the work order description information preset in the work order to be processed; Sending the number of times of entering and leaving to the base station security lock, so that the base station security lock configures the available number of times of the target unlocking information based on the number of times of entering and leaving. Wherein, when the used number of times of the target unlocking information reaches the available number of times, the base station security lock stops the near-field communication with the target terminal and deletes the corresponding temporary key.
6. The unlocking permission configuration method of the base station safety lock according to claim 5, characterized in that, Before determining the number of times of entering and leaving for completing the work order to be processed, the method further includes: When obtaining the change information of any work order to be processed, determining the work order to be processed with the change as a change work order, determining the candidate account associated with the change work order as a change account, and determining the preset terminal associated with the change account as a change terminal; When the change information is used to indicate stopping the processing of the change work order, and the change account does not include another work order to be processed associated with the base station security lock, deleting the temporary key in the change terminal, and deleting the corresponding temporary key and the target unlocking information in the base station security lock; When the change information is used to indicate changing from another candidate account to the current change account, determining that the target unlocking information fed back by the change terminal is not obtained, and sending the verification instruction to the change terminal.
7. An unlocking permission configuration device for a base station safety lock, characterized in that, Comprising at least one control processor and a memory communicatively connected to the at least one control processor; the memory stores instructions executable by the at least one control processor, and the instructions are executed by the at least one control processor to enable the at least one control processor to execute the unlocking permission configuration method of the base station security lock according to any one of claims 1 to 6.
8. An electronic device, characterized in that, Comprising the unlocking permission configuration device of the base station security lock according to claim 7.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions for causing a computer to execute the unlocking permission configuration method of the base station security lock according to any one of claims 1 to 6.
Citation Information
Patent Citations
Intelligent access control management system based on base station
CN107240179A
Intelligent lock unlocking method and related device
CN114694283A
System and method for controlling door lock
KR1020120103827A