Monitoring data access method and device, electronic equipment and storage medium
By generating and comparing dynamic verification codes in real time in the monitoring data access system, the problem of poor monitoring data access protection in the prior art is solved, and higher data access security and integrity are achieved.
Patent Information
- Application Number
- CN202411843171.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-05-09
AI Technical Summary
The existing monitoring data access methods have poor protection effects when facing attacks, making it difficult to ensure the authenticity and integrity of the monitoring data.
By generating and comparing dynamic verification codes in real time between the client and the server, we ensure that the latest dynamic information is used to generate verification codes every time we access monitoring data, thereby improving the security of access control.
The real-time generation and comparison mechanism of dynamic verification codes improves the protection effect during monitoring data access, reduces the possibility of attackers cracking verification codes, and ensures the authenticity and integrity of the data.
Smart Images

Figure CN119967119A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data processing technology, and in particular to a monitoring data access method, device, electronic equipment and storage medium. Background Art
[0002] With the rapid development of computer, network and image processing technology, video surveillance technology has also made great progress. Video surveillance is an important part of the security system. Video surveillance is widely used in many occasions because of its intuitive, accurate, timely and rich information content.
[0003] In the monitoring system, the security and integrity of monitoring data are crucial. However, with the continuous development of network technology, the risk of tampering with monitoring data is also increasing. Especially when accessing monitoring data, since monitoring data may be subject to various forms of attacks during transmission and access, such as man-in-the-middle attacks and replay attacks, it is particularly important to ensure the authenticity and integrity of monitoring data during access.
[0004] In the current monitoring data access method, in order to improve the security of monitoring data, a fixed password or access permission is usually set for the monitoring data, and the fixed password or access permission is used for static verification when accessing the monitoring data. However, once an attacker breaks through the initial defense of the system and obtains the above fixed password or access permission, the monitoring data will be leaked or tampered, so the protection effect of this method is poor. Summary of the invention
[0005] In view of the above problems, embodiments of the present invention are proposed to provide a monitoring data access method, device, electronic device and storage medium that overcome the above problems or at least partially solve the above problems.
[0006] In a first aspect, an embodiment of the present invention discloses a monitoring data access method, the method comprising:
[0007] After receiving a first access request from a client, generating a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request, returning the first dynamic verification code to the client, and storing the first dynamic verification code;
[0008] After receiving the second access request from the client, comparing the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request with the stored first dynamic verification code;
[0009] After the comparison is successful, access to the monitoring data to be accessed is allowed.
[0010] Optionally, based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request, a first dynamic verification code corresponding to the monitoring data to be accessed is generated, including: extracting the dynamic information corresponding to the monitoring data to be accessed from the first access request, the dynamic information including at least one of a timestamp, a device identifier, and a video stream identifier; and generating a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information according to a set verification code generation method.
[0011] Optionally, the dynamic information includes a device identifier; storing the first dynamic verification code includes: storing the first dynamic verification code in association with the device identifier corresponding to the monitoring data to be accessed; comparing the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request with the stored first dynamic verification code, including: extracting the device identifier corresponding to the monitoring data to be accessed from the second access request, and searching for the first dynamic verification code corresponding to the monitoring data to be accessed that is associated with the device identifier corresponding to the monitoring data to be accessed; comparing the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request with the first dynamic verification code found.
[0012] Optionally, the dynamic information includes a device identification; based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request, a first dynamic verification code corresponding to the monitoring data to be accessed is generated, including: according to the verification code generation method corresponding to the device identification corresponding to the monitoring data to be accessed, based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request, a first dynamic verification code corresponding to the monitoring data to be accessed is generated; the method also includes: when it is monitored that the update time corresponding to the device identification has been reached, the verification code generation method corresponding to the device identification is updated, and the update time corresponding to the device identification is reset.
[0013] Optionally, each monitoring device corresponds to one device identifier, or each type of monitoring device corresponds to one device identifier.
[0014] Optionally, returning the first dynamic verification code to the client includes: encrypting the first dynamic verification code to obtain an encrypted dynamic verification code, and returning the encrypted dynamic verification code to the client.
[0015] Optionally, the method further includes: after the comparison fails, prohibiting access to the monitoring data to be accessed, and recording an access exception log corresponding to the monitoring data to be accessed.
[0016] In a second aspect, an embodiment of the present invention discloses a monitoring data access device, the device comprising:
[0017] a verification code generation module, configured to, after receiving a first access request from a client, generate a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request, return the first dynamic verification code to the client, and store the first dynamic verification code;
[0018] The access control module is used to compare the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request with the stored first dynamic verification code after receiving the second access request from the client; after the comparison is successful, access to the monitoring data to be accessed is allowed.
[0019] Optionally, the verification code generation module is specifically used to extract dynamic information corresponding to the monitoring data to be accessed from the first access request, and the dynamic information includes at least one of a timestamp, a device identifier, and a video stream identifier; and generate a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information according to a set verification code generation method.
[0020] Optionally, the dynamic information includes a device identifier; the verification code generation module is specifically used to store the first dynamic verification code in association with the device identifier corresponding to the monitoring data to be accessed; the access control module is specifically used to extract the device identifier corresponding to the monitoring data to be accessed from the second access request, and search for the first dynamic verification code corresponding to the monitoring data to be accessed that is associated with the device identifier corresponding to the monitoring data to be accessed; and compare the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request with the first dynamic verification code found.
[0021] Optionally, the dynamic information includes a device identifier; the verification code generation module is specifically used to generate a first dynamic verification code corresponding to the monitoring data to be accessed according to the verification code generation method corresponding to the device identifier corresponding to the monitoring data to be accessed, based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request; the device also includes: an update module, which is used to update the verification code generation method corresponding to the device identifier and reset the update time corresponding to the device identifier when it is detected that the update time corresponding to the device identifier has been reached.
[0022] Optionally, each monitoring device corresponds to one device identifier, or each type of monitoring device corresponds to one device identifier.
[0023] Optionally, the verification code generation module is specifically configured to encrypt the first dynamic verification code to obtain an encrypted dynamic verification code, and return the encrypted dynamic verification code to the client.
[0024] Optionally, the access control module is further configured to prohibit access to the monitoring data to be accessed, and record an access exception log corresponding to the monitoring data to be accessed, after the comparison fails.
[0025] In a third aspect, an embodiment of the present invention discloses an electronic device, comprising a processor and a computer-readable storage medium, wherein a computer program is stored on the computer-readable storage medium; when the computer program is executed by the processor, the processor executes the monitoring data access method as described in any one of the above items.
[0026] In a fourth aspect, an embodiment of the present invention discloses a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the processor executes the monitoring data access method as described in any one of the above items.
[0027] In an embodiment of the present invention, when a client needs to access monitoring data, first, the client sends the dynamic information corresponding to the monitoring data to be accessed to the server, and the server generates a first dynamic verification code corresponding to the monitoring data to be accessed in real time based on the dynamic information corresponding to the monitoring data to be accessed, and returns the first dynamic verification code to the client, and then the client sends the second dynamic verification code corresponding to the monitoring data to be accessed to the server, and the server compares the received second dynamic verification code with the first dynamic verification code generated previously. If the comparison is successful, it means that the second dynamic verification code sent by the client is the first dynamic verification code generated by the server, so the server allows the client to access the monitoring data to be accessed. It can be seen that in an embodiment of the present invention, a dynamic verification code is generated in real time each time the monitoring data is accessed, and the dynamic verification code is used to control the access to the monitoring data. Since the dynamic verification code is generated in real time based on the dynamic information corresponding to the monitoring data to be accessed, it changes dynamically and has a strong randomness, so attackers cannot crack the dynamic verification code, thereby improving the protection effect during the access to the monitoring data.
[0028] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented according to the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] In order to more clearly illustrate the technical solution of the embodiment of the present invention, the drawings required for use in the description of the embodiment of the present invention will be briefly introduced below. Obviously, the drawings described below are only some drawings of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0030] Figure 1 is a structural block diagram of a monitoring system according to an embodiment of the present invention;
[0031] Figure 2 is a flowchart of the steps of a monitoring data access method according to an embodiment of the present invention;
[0032] Figure 3 is a flowchart of another monitoring data access method according to an embodiment of the present invention;
[0033] Figure 4 is a structural block diagram of a monitoring data access device according to an embodiment of the present invention;
[0034] Figure 5 is a structural block diagram of an electronic device according to an embodiment of the present invention;
[0035] Figure 6 It is a structural block diagram of a computer-readable storage medium according to an embodiment of the present invention. DETAILED DESCRIPTION
[0036] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0037] Reference Figure 1 , shows a structural block diagram of a monitoring system according to an embodiment of the present invention.
[0038] like Figure 1 As shown, the monitoring system may include monitoring equipment, a data transmission layer, a verification code generation module, a security database, an access control module, and a monitoring center or a cloud platform.
[0039] Monitoring equipment: including various cameras, sensors and other monitoring equipment, responsible for collecting monitoring data.
[0040] Data transmission layer: responsible for transmitting monitoring data from monitoring devices to the monitoring center or cloud platform.
[0041] Verification code generation module: responsible for generating a unique dynamic verification code based on multiple factors such as timestamp, video stream ID, device ID, etc.
[0042] Security database: responsible for storing the dynamic verification code generated by the verification code generation module for subsequent verification code comparison.
[0043] Access control module: responsible for monitoring data access control, including verifying whether the dynamic verification code in the access request matches the dynamic verification code stored in the security database.
[0044] Monitoring center or cloud platform: provides storage, analysis and display functions for monitoring data.
[0045] The monitoring data access method in the embodiment of the present invention can be applied to the above-mentioned monitoring system, and specifically can be applied to the server in the above-mentioned monitoring system. The server can include the above-mentioned verification code generation module and access control module.
[0046] Reference Figure 2 , shows a step flow chart of a monitoring data access method according to an embodiment of the present invention.
[0047] like Figure 2 As shown, the monitoring data access method may include the following steps:
[0048] Step 201, after receiving a first access request from a client, generate a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request, return the first dynamic verification code to the client, and store the first dynamic verification code.
[0049] When the client wants to access monitoring data, the client generates a first access request and sends the first access request to the server.
[0050] The first access request may include, but is not limited to, dynamic information corresponding to the monitoring data to be accessed, wherein the dynamic information corresponding to the monitoring data to be accessed is used by the server to generate a first dynamic verification code corresponding to the monitoring data to be accessed.
[0051] Exemplarily, the dynamic information corresponding to the monitoring data to be accessed may include, but is not limited to, at least one of the following: a timestamp corresponding to the monitoring data to be accessed, a device identifier corresponding to the monitoring data to be accessed, a video stream identifier corresponding to the monitoring data to be accessed, and the like.
[0052] The timestamp corresponding to the monitoring data to be accessed may be the timestamp of the first access request generated by the client, etc.
[0053] The device identifier corresponding to the monitoring data to be accessed may be the device identifier corresponding to the monitoring device that collected the monitoring data to be accessed. Each monitoring device may correspond to one device identifier, or each type of monitoring device may correspond to one device identifier. For example, a camera is one type of monitoring device, a sensor is another type of monitoring device, and so on.
[0054] The video stream identifier corresponding to the monitoring data to be accessed may be the video stream identifier corresponding to the monitoring device that collects the monitoring data to be accessed, and the video stream identifier is also the identifier of the monitoring data. In implementation, the video stream identifier may also include the access time period of the monitoring data to be accessed that the user wants to access, so as to access the monitoring data to be accessed within the access time period.
[0055] After receiving the first access request sent by the client, the server generates a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request.
[0056] Exemplarily, the server parses the first access request, extracts dynamic information corresponding to the monitoring data to be accessed from the first access request, and then generates a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information according to a set verification code generation method.
[0057] Among them, the verification code generation method may include but is not limited to: hash function algorithm, encryption algorithm, random number generation algorithm, and the like. For example, based on the hash function algorithm, a hash function calculation may be performed on the dynamic information, and the calculation result may be used as the first dynamic verification code corresponding to the monitoring data to be accessed. For example, based on the encryption algorithm, an encryption calculation may be performed on the dynamic information, and the calculation result may be used as the first dynamic verification code corresponding to the monitoring data to be accessed. For example, based on a random number generation algorithm, a random number generation may be performed based on the dynamic information, and the generated random number may be used as the first dynamic verification code corresponding to the monitoring data to be accessed. The specific process of generating the first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information according to the set verification code generation method can be processed according to actual experience, and this embodiment will not be discussed in detail here.
[0058] After generating the first dynamic verification code corresponding to the monitoring data to be accessed, the server may return the first dynamic verification code corresponding to the monitoring data to be accessed to the client.
[0059] After generating the first dynamic verification code corresponding to the monitoring data to be accessed, the server may store the first dynamic verification code corresponding to the monitoring data to be accessed, for example, storing the first dynamic verification code corresponding to the monitoring data to be accessed in the security database for subsequent comparison.
[0060] Step 202: after receiving the second access request from the client, the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request is compared with the stored first dynamic verification code.
[0061] After receiving the first dynamic verification code corresponding to the monitoring data to be accessed returned by the server, the client may generate a second access request and send the second access request to the server.
[0062] Exemplarily, the second access request may include, but is not limited to: a second dynamic verification code corresponding to the monitoring data to be accessed, a video stream identifier corresponding to the monitoring data to be accessed, and the like.
[0063] Among them, under normal circumstances, if it is a legitimate visitor, since the legitimate visitor can obtain the first dynamic verification code corresponding to the monitoring data to be accessed returned by the server, the second dynamic verification code corresponding to the monitoring data to be accessed will be the same as the first dynamic verification code corresponding to the monitoring data to be accessed returned by the server and received by the client. If it is an illegal visitor, since the illegal visitor cannot know the first dynamic verification code corresponding to the monitoring data to be accessed returned by the server, the second dynamic verification code corresponding to the monitoring data to be accessed will not be the same as the first dynamic verification code corresponding to the monitoring data to be accessed returned by the server.
[0064] Exemplarily, in order to further ensure the transmission security of the first dynamic verification code, the server may, after generating the first dynamic verification code corresponding to the monitoring data to be accessed, encrypt the first dynamic verification code corresponding to the monitoring data to be accessed to obtain an encrypted dynamic verification code, and return the encrypted dynamic verification code to the client. After receiving the encrypted dynamic verification code, the client decrypts the encrypted dynamic verification code according to the key or encryption algorithm agreed in advance with the server, thereby obtaining the first dynamic verification code corresponding to the monitoring data to be accessed.
[0065] When encrypting the first dynamic verification code corresponding to the monitoring data to be accessed, any applicable encryption algorithm may be used, such as a strong encryption algorithm.
[0066] After receiving the second access request sent by the client, the server compares the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request with the stored first dynamic verification code.
[0067] Exemplarily, when storing the first dynamic verification code corresponding to the monitoring data to be accessed, the server may store the first dynamic verification code corresponding to the monitoring data to be accessed in association with the video stream identifier corresponding to the monitoring data to be accessed.
[0068] Correspondingly, after receiving the second access request sent by the client, the server parses the second access request and extracts information such as the second dynamic verification code corresponding to the monitoring data to be accessed and the video stream identifier corresponding to the monitoring data to be accessed. The server can traverse from the stored first dynamic verification codes according to the video stream identifier corresponding to the monitoring data to be accessed, so as to find the first dynamic verification code corresponding to the monitoring data to be accessed that is associated with the video stream identifier corresponding to the monitoring data to be accessed, and compare the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request with the first dynamic verification code found.
[0069] Exemplarily, when storing the first dynamic verification code corresponding to the monitoring data to be accessed, the server may store the first dynamic verification code corresponding to the monitoring data to be accessed in association with the device identifier corresponding to the monitoring data to be accessed, and of course, the first dynamic verification code corresponding to the monitoring data to be accessed must also be associated with the video stream identifier corresponding to the monitoring data to be accessed.
[0070] Correspondingly, after receiving the second access request sent by the client, the server parses the second access request and extracts information contained therein, such as the second dynamic verification code corresponding to the monitoring data to be accessed, the video stream identifier corresponding to the monitoring data to be accessed, and the device identifier corresponding to the monitoring data to be accessed. The server can traverse the first dynamic verification code associated with the device identifier corresponding to the monitoring data to be accessed from the stored first dynamic verification codes, according to the device identifier corresponding to the monitoring data to be accessed, so as to find the first dynamic verification code associated with the device identifier corresponding to the monitoring data to be accessed and the first dynamic verification code corresponding to the monitoring data to be accessed associated with the video stream identifier corresponding to the monitoring data to be accessed, and compare the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request with the first dynamic verification code found.
[0071] In this way, the first dynamic verification code is associated with the device identification and stored, so that when searching for the first dynamic verification code, only the first dynamic verification code associated with the corresponding device identification needs to be searched, thus avoiding the operation of traversing the entire security database to search for the verification code and reducing the time complexity of the algorithm.
[0072] Exemplarily, in order to further ensure the storage security of the first dynamic verification code, the server may encrypt the first dynamic verification code corresponding to the monitoring data to be accessed to obtain an encrypted dynamic verification code after generating the first dynamic verification code corresponding to the monitoring data to be accessed, and store the encrypted dynamic verification code. When searching for the first dynamic verification code, the server decrypts the encrypted dynamic verification code.
[0073] Step 203: after the comparison is successful, access to the monitoring data to be accessed is allowed.
[0074] The server determines that the comparison is successful after comparing the first dynamic verification code corresponding to the monitoring data to be accessed and the second dynamic verification code corresponding to the monitoring data to be accessed to be the same. After the comparison is successful, the server allows the client to access the monitoring data to be accessed.
[0075] In the embodiment of the present invention, a dynamic verification code is generated in real time each time the monitoring data is accessed, and the dynamic verification code is used to control access to the monitoring data. Since the dynamic verification code is generated in real time based on the dynamic information corresponding to the monitoring data to be accessed, it changes dynamically and has a strong randomness. Therefore, attackers cannot crack the dynamic verification code, thereby improving the protection effect during the access to the monitoring data.
[0076] Exemplarily, a corresponding verification code generation method may be set for each device identifier. Therefore, in the process of generating the first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request, the client may generate the first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request according to the verification code generation method corresponding to the device identifier corresponding to the monitoring data to be accessed.
[0077] Accordingly, in order to further improve the security of dynamic verification codes, an update mechanism for the verification code generation method can be set. For each device identifier, an update time corresponding to the device identifier can be set, and real-time or periodic monitoring can be performed to determine whether the update time corresponding to the device identifier has been reached. When the update time corresponding to the device identifier is detected, the verification code generation method corresponding to the device identifier is updated, and the update time corresponding to the device identifier is reset. The specific form of the update time can be set according to actual needs, and this embodiment does not limit this. For example, the update time can be set to be updated once every set time after the preset time after this update, and so on.
[0078] In an embodiment of the present invention, in order to prevent the verification code from being cracked or leaked, a verification code generation method is set to be updated regularly, and when updating, only the record of the corresponding device identification needs to be found without traversing the entire database, thereby reducing the time complexity of the algorithm model. Each monitoring device or each type of monitoring device has an independent update cycle and strategy for the verification code generation method, thereby enhancing the security and flexibility of the system. The system administrator can easily configure and manage the verification code generation method of the monitoring device, thereby improving the maintainability of the system.
[0079] In an embodiment of the present invention, the security database can specifically store the following information: a verification code identifier, which is used to uniquely identify each dynamic verification code; a device identifier, which is a unique identifier of a monitoring device associated with a dynamic verification code; a video stream identifier, which is used to further identify a video stream corresponding to a dynamic verification code; a verification code value, which is a generated dynamic verification code value; a generation time, which is the generation time of the dynamic verification code; and an update time: the update time of a preset verification code generation method according to the security policy of the monitoring device.
[0080] In the embodiment of the present invention, the access rights of the monitoring system can also be strictly controlled, and only authorized users can access the monitoring data.
[0081] Reference Figure 3 , shows a step flow chart of another monitoring data access method according to an embodiment of the present invention.
[0082] like Figure 3 As shown, the monitoring data access method may include the following steps:
[0083] Step 301, after receiving a first access request from a client, generate a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request, return the first dynamic verification code to the client, and store the first dynamic verification code.
[0084] Step 302: after receiving the second access request from the client, the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request is compared with the stored first dynamic verification code.
[0085] Step 303: after the comparison is successful, access to the monitoring data to be accessed is allowed.
[0086] Step 304: after the comparison fails, prohibit access to the monitoring data to be accessed, and record an access exception log corresponding to the monitoring data to be accessed.
[0087] The server determines that the comparison fails after comparing the first dynamic verification code corresponding to the monitoring data to be accessed and the second dynamic verification code corresponding to the monitoring data to be accessed are different. After the comparison fails, the server prohibits the client from accessing the monitoring data to be accessed and records the access exception log corresponding to the monitoring data to be accessed.
[0088] In the embodiment of the present invention, access logs of monitoring data are recorded and regular audits are performed to timely discover and investigate abnormal access behaviors.
[0089] Reference Figure 4 , shows a structural block diagram of a monitoring data access device according to an embodiment of the present invention.
[0090] like Figure 4 As shown, the monitoring data access device may include the following modules:
[0091] The verification code generation module 401 is used to generate a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request after receiving the first access request from the client, return the first dynamic verification code to the client, and store the first dynamic verification code;
[0092] The access control module 402 is used to compare the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request with the stored first dynamic verification code after receiving the second access request from the client; after successful comparison, access to the monitoring data to be accessed is allowed.
[0093] Optionally, the verification code generation module 401 is specifically used to extract dynamic information corresponding to the monitoring data to be accessed from the first access request, and the dynamic information includes at least one of a timestamp, a device identifier, and a video stream identifier; and generate a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information according to a set verification code generation method.
[0094] Optionally, the dynamic information includes a device identifier; the verification code generation module 401 is specifically used to store the first dynamic verification code in association with the device identifier corresponding to the monitoring data to be accessed; the access control module 402 is specifically used to extract the device identifier corresponding to the monitoring data to be accessed from the second access request, and search for the first dynamic verification code corresponding to the monitoring data to be accessed that is associated with the device identifier corresponding to the monitoring data to be accessed; and compare the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request with the first dynamic verification code found.
[0095] Optionally, the dynamic information includes a device identifier; the verification code generation module 401 is specifically used to generate a first dynamic verification code corresponding to the monitoring data to be accessed according to the verification code generation method corresponding to the device identifier corresponding to the monitoring data to be accessed, based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request; the device also includes: an update module, which is used to update the verification code generation method corresponding to the device identifier and reset the update time corresponding to the device identifier when it is detected that the update time corresponding to the device identifier has been reached.
[0096] Optionally, each monitoring device corresponds to one device identifier, or each type of monitoring device corresponds to one device identifier.
[0097] Optionally, the verification code generation module 401 is specifically configured to encrypt the first dynamic verification code to obtain an encrypted dynamic verification code, and return the encrypted dynamic verification code to the client.
[0098] Optionally, the access control module 402 is further configured to prohibit access to the monitoring data to be accessed, and record an access exception log corresponding to the monitoring data to be accessed, after the comparison fails.
[0099] In the embodiment of the present invention, a dynamic verification code is generated in real time each time the monitoring data is accessed, and the dynamic verification code is used to control access to the monitoring data. Since the dynamic verification code is generated in real time based on the dynamic information corresponding to the monitoring data to be accessed, it changes dynamically and has a strong randomness. Therefore, attackers cannot crack the dynamic verification code, thereby improving the protection effect during the access to the monitoring data.
[0100] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0101] In an embodiment of the present invention, an electronic device is also provided. The electronic device may include a processor and a computer-readable storage medium, wherein a computer program is stored on the computer-readable storage medium; when the computer program is executed by the processor, the processor executes the monitoring data access method of any of the above embodiments.
[0102] Reference Figure 5 , shows a structural block diagram of an electronic device according to an embodiment of the present invention. Figure 5 As shown, the electronic device 11 includes a processor 111 and a computer-readable storage medium 112 , on which a computer program 1121 is stored.
[0103] The processor 111 is used to execute the computer program 1121 stored on the computer-readable storage medium 112. When executing the computer program 1121, the processor 111 implements the monitoring data access method of any of the above-mentioned embodiments and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0104] The processor 111 mentioned above may include but is not limited to: a central processing unit (CPU), a network processor (NP), a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.
[0105] The computer-readable storage medium 112 mentioned above may include but is not limited to: read-only memory (ROM), random access memory (RAM), compact disc read-only memory (CD-ROM), electronic erasable programmable read-only memory (EEPROM), hard disk, floppy disk, flash memory, etc.
[0106] In an embodiment of the present invention, a computer-readable storage medium is also provided, on which a computer program is stored. The computer program can be executed by a processor of an electronic device. When the computer program is executed by the processor, the processor executes the monitoring data access method described in any of the above embodiments.
[0107] Reference Figure 6 , shows a block diagram of a computer-readable storage medium according to an embodiment of the present invention. Figure 6 As shown, a computer program 211 is stored on the computer-readable storage medium 21. When the computer program 211 is executed by the processor, the processor executes the monitoring data access method described in any of the above embodiments and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
[0108] It should be noted that all actions of acquiring signals, information or data in the present invention are performed in compliance with the corresponding data protection laws and policies of the location and with the authorization given by the owner of the corresponding device.
[0109] The various embodiments in this specification are interrelated, and each embodiment is described in a progressive manner. Each embodiment focuses on the differences from other embodiments, and the same or similar parts between the various embodiments can be referenced to each other.
[0110] It will be appreciated by those skilled in the art that the embodiments of the present invention may be provided as methods, devices, or computer program products. Therefore, the embodiments of the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0111] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0112] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0113] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0114] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.
[0115] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or terminal device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or terminal device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or terminal device including the elements.
[0116] The above is a detailed introduction to a monitoring data access method, device, electronic device and storage medium provided by the present invention. Specific examples are used in this article to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea; at the same time, for general technical personnel in this field, according to the idea of the present invention, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.
Claims
1. A monitoring data access method, characterized in that: The method comprises: After receiving a first access request from a client, generating a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request, returning the first dynamic verification code to the client, and storing the first dynamic verification code; After receiving the second access request from the client, comparing the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request with the stored first dynamic verification code; After the comparison is successful, access to the monitoring data to be accessed is allowed.
2. The method according to claim 1, characterized in that Generating a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request includes: Extracting dynamic information corresponding to the monitoring data to be accessed from the first access request, the dynamic information including at least one of a timestamp, a device identifier, and a video stream identifier; According to the set verification code generation method, a first dynamic verification code corresponding to the monitoring data to be accessed is generated based on the dynamic information.
3. The method according to claim 1, characterized in that: The dynamic information includes a device identification; Storing the first dynamic verification code includes: storing the first dynamic verification code in association with a device identifier corresponding to the monitoring data to be accessed; Comparing the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request with the stored first dynamic verification code, including: Extracting the device identification corresponding to the monitoring data to be accessed from the second access request, and searching for the first dynamic verification code corresponding to the monitoring data to be accessed and associated with the device identification corresponding to the monitoring data to be accessed; The second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request is compared with the first dynamic verification code found.
4. The method according to claim 1, characterized in that The dynamic information includes a device identification; Generating a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request, including: generating a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request according to a verification code generation method corresponding to a device identifier corresponding to the monitoring data to be accessed; The method further includes: when it is detected that the update time corresponding to the device identification has arrived, updating the verification code generation method corresponding to the device identification, and resetting the update time corresponding to the device identification.
5. The method according to claim 3 or 4, characterized in that: Each monitoring device corresponds to one device identifier, or each type of monitoring device corresponds to one device identifier.
6. The method according to claim 1, characterized in that Returning the first dynamic verification code to the client includes: The first dynamic verification code is encrypted to obtain an encrypted dynamic verification code, and the encrypted dynamic verification code is returned to the client.
7. The method according to claim 1, characterized in that The method further comprises: After the comparison fails, access to the monitoring data to be accessed is prohibited, and an access exception log corresponding to the monitoring data to be accessed is recorded.
8. A monitoring data access device, characterized in that: The device comprises: a verification code generation module, configured to, after receiving a first access request from a client, generate a first dynamic verification code corresponding to the monitoring data to be accessed based on the dynamic information corresponding to the monitoring data to be accessed contained in the first access request, return the first dynamic verification code to the client, and store the first dynamic verification code; The access control module is used to compare the second dynamic verification code corresponding to the monitoring data to be accessed contained in the second access request with the stored first dynamic verification code after receiving the second access request from the client; after the comparison is successful, access to the monitoring data to be accessed is allowed.
9. An electronic device, characterized in that: The electronic device includes a processor and a computer-readable storage medium, wherein a computer program is stored on the computer-readable storage medium; when the computer program is executed by the processor, the processor executes the monitoring data access method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the processor executes the monitoring data access method according to any one of claims 1 to 7.