Equipment cloud platform user authentication and authorization system and method

By using Spring Boot and Apache Shiro frameworks on the device cloud platform, the distributed communication connection and authentication and authorization business logic is built, and the complexity and security problems of traditional user authentication and authorization methods are solved when facing massive devices and diversified user roles are achieved, and efficient and secure user authentication and authorization management is achieved.

CN119995949AActive Publication Date: 2025-05-13NANJING COLLEGE OF CHEM TECH
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510059573.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-13
Estimated Expiration
2045-01-15

AI Technical Summary

Technical Problem

When facing massive device connections, diversified user roles and frequent permission changes, traditional device cloud platform user authentication and authorization methods have problems such as complex development, high maintenance costs, and difficult to guarantee security.

Method used

Introducing Spring Boot to simplify configuration and rapid development, combining the Apache Shiro framework for authentication, authorization and access control, building distributed communication connections to manage user information of IoT devices, and configuring authentication and authorization business logic in the cloud platform.

Benefits of technology

It realizes accurate and reliable construction of user authentication and authorization, reduces development complexity and maintenance costs, and improves the security and reliability of users login to the cloud platform.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995949A_ABST
    Figure CN119995949A_ABST
Patent Text Reader

Abstract

The invention provides an equipment cloud platform user authentication and authorization system and method, and the system comprises an equipment access module which is used for carrying out distributed communication connection between a cloud platform and each piece of Internet of Things equipment; the management module is used for managing each piece of Internet of Things equipment and user information corresponding to each piece of Internet of Things equipment after the communication connection is completed, constructing authentication and authorization service logic, and configuring the authentication and authorization service logic in the cloud platform to obtain a user authentication and authorization mechanism; and the authentication and authorization module is used for receiving a user login request of the Internet of Things equipment in real time based on the cloud platform, performing full-process authentication and authorization on the user login authorization request according to a user authentication and authorization mechanism, and logging in the cloud platform when the authentication and authorization are passed. Effective identity verification and authorization operation are carried out on the user, and the safety and reliability of the user logging in the cloud platform are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a device cloud platform user authentication and authorization system and method. Background Art

[0002] At present, with the rapid development of Internet of Things technology, a large number of devices are connected to the cloud platform. The device cloud platform faces complex user management, security authentication and authorized access requirements;

[0003] Traditional user authentication and authorization methods often have problems such as complex development, high maintenance costs, and difficulty in ensuring security when faced with massive device connections, diverse user roles, and frequent permission changes;

[0004] Therefore, in order to overcome the above technical problems, the present invention provides a device cloud platform user authentication and authorization system and method, which introduces Spring Boot with its simplified configuration and rapid development features, providing an efficient way to build cloud platform backend services; the Apache Shiro framework has powerful identity authentication, authorization and access control functions, and can accurately manage user access rights to cloud platform resources and associated devices. Summary of the invention

[0005] The present invention provides a device cloud platform user authentication and authorization system and method, which are used to connect various Internet of Things devices with the cloud platform through distributed communication, so as to facilitate the management of user information of various Internet of Things devices through the cloud platform. Secondly, the authentication and authorization business logic is constructed and configured on the cloud platform to achieve accurate and reliable construction of the user authentication and authorization mechanism, which provides convenience for cloud platform user authentication and authorization. Finally, the cloud platform receives the user login request of the Internet of Things device and performs full-process authentication and authorization operations, thereby achieving effective identity authentication and authorization operations for the user, and ensuring the security and reliability of the user logging into the cloud platform.

[0006] The present invention provides a device cloud platform user authentication and authorization system, comprising:

[0007] The device access module is used to connect the cloud platform with various IoT devices through distributed communication;

[0008] The management module is used to manage each IoT device and the user information corresponding to each IoT device after the communication connection is completed. At the same time, it builds the authentication and authorization business logic and configures it in the cloud platform to obtain the user authentication and authorization mechanism;

[0009] The authentication and authorization module is used to receive user login requests from IoT devices in real time based on the cloud platform, and perform full-process authentication and authorization on user login authorization requests according to the user authentication and authorization mechanism, and log in to the cloud platform when the authentication and authorization are passed.

[0010] Preferably, a device cloud platform user authentication and authorization system, a device access module, comprises:

[0011] A communication protocol construction unit, used to collect communication information between each IoT device and the cloud platform, and to construct a communication protocol between each IoT device and the cloud platform according to the communication information between each IoT device and the cloud platform;

[0012] A distributed communication network acquisition unit, used to acquire a distributed communication network between the cloud platform and each IoT device;

[0013] The distributed communication connection unit is used to establish distributed communication connection between each IoT device and the cloud platform in a distributed communication network according to the communication protocol between each IoT device and the cloud platform.

[0014] Preferably, a device cloud platform user authentication and authorization system, in a mechanism acquisition module, includes: the authentication and authorization business logic is based on the management and control authentication and authorization process built by integrating the Spring Boot framework to carry Web services and embedding the Apache Shiro framework.

[0015] Preferably, a device cloud platform user authentication and authorization system, a communication protocol building unit, comprises:

[0016] The information acquisition subunit is used to obtain the device name of each IoT device and read the device address information of each IoT device;

[0017] A first protocol element determination subunit, configured to generate a first protocol element corresponding to each IoT device according to a device name and corresponding device address information of each IoT device;

[0018] A second protocol element determination subunit, configured to read the platform address information of the cloud platform and the platform name of the cloud platform, and generate a second protocol element corresponding to the cloud platform according to the platform address information of the cloud platform and the platform name of the cloud platform;

[0019] The communication protocol generation subunit is used to obtain the communication method between the cloud platform and each IoT device, and merge each first protocol element with the second protocol element according to the communication method between the cloud platform and each IoT device to generate a communication protocol between each IoT device and the cloud platform.

[0020] Preferably, a device cloud platform user authentication and authorization system, management module, includes:

[0021] Business logic acquisition unit, used to:

[0022] Obtain the authentication method and authentication dimension for authenticating the user, and determine the authentication business logic for the user based on the authentication method and authentication dimension;

[0023] Retrieve the user management table, determine the access rights of each user based on the user management table, and determine the authorization business logic based on the access rights of each user;

[0024] An association unit, used to add a first verification serial number to the authentication business logic and a second verification serial number to the authorization business logic, and at the same time, associate the authentication business logic with the authorization business logic according to the first verification serial number and the second verification serial number to obtain the authentication and authorization business logic;

[0025] The configuration unit is used to create an authentication and authorization management interval in the cloud platform, and configure the authentication and authorization business logic in the authentication and authorization management interval to obtain a user authentication and authorization mechanism.

[0026] Preferably, a device cloud platform user authentication and authorization system, management module, includes:

[0027] The device management interval building unit is used to:

[0028] Obtain the device name of each IoT device, and build multiple device management intervals in the cloud platform according to the device name of each IoT device;

[0029] Perform device information management on the corresponding IoT device according to the device management interval, wherein the device information includes: the device number of the IoT device and the multiple user accounts corresponding to the IoT device;

[0030] User management section building block, used to:

[0031] Construct a user management interval according to the correspondence between each device management interval and multiple user accounts, and at the same time, construct a sub-user management interval consistent with the device management interval in the user management interval;

[0032] Obtain the user management table of each IoT device, and read the user management table of each IoT device to determine the accessible scope of each user of each IoT device to access information on the cloud platform;

[0033] Sort the user access rights according to the access scope of each user in each IoT device to the cloud platform from large to small, and determine the access rights level of each user in each IoT device to the cloud platform;

[0034] The user information of the corresponding IoT device and the access permission level of each user are stored in the sub-user management section;

[0035] Management interval encapsulation unit, used for:

[0036] The sub-user management interval is correspondingly connected to the device management interval, and at the same time, the device management interval and the user management interval are first encapsulated according to the connection result to obtain the device-user management interval;

[0037] Construct the authorization and authentication management interval, and at the same time, perform a second encapsulation of the device-user management interval and the authorization and authentication management interval;

[0038] Validation analysis unit for:

[0039] Create a data receiving interface for the authorization and authentication management interval, and receive real-time user login information based on the data receiving interface;

[0040] Based on the authorization and authentication management interval and calling the device-user management interval, the user's real-time login information is analyzed.

[0041] Preferably, a device cloud platform user authentication and authorization system, an authentication and authorization module, comprises:

[0042] A request receiving unit, used to receive a user login request of an IoT device in real time based on a cloud platform;

[0043] An authentication unit, used to authenticate a user account based on a user login request;

[0044] The authorization unit is used to determine the user's access permission level according to the user account when the user passes the authentication, and retrieve the accessible information in the cloud platform according to the access permission level, and at the same time, authorize the user account according to the accessible information.

[0045] Preferably, a device cloud platform user authentication and authorization system, an authentication unit, comprises:

[0046] A request reading subunit is used to read the user login request of the IoT device based on the cloud platform, and determine the login code and user account of the user login request;

[0047] Authentication subunit, used to:

[0048] Retrieve the base login code and determine whether the base login code is consistent with the login code requested by the user;

[0049] If the base login code is consistent with the login code of the user login request, read the base user account corresponding to the base login code;

[0050] If the base login code is inconsistent with the login code of the user login request, it is determined that the user authentication has not been passed;

[0051] Determine whether the base user account is consistent with the user account requested by the user for login;

[0052] When the reference user account is consistent with the user account of the user login request, it is determined that the user authentication is passed; otherwise, it is determined that the user authentication is not passed.

[0053] The present invention provides a device cloud platform user authentication and authorization method, comprising:

[0054] Step 1: Connect the cloud platform with each IoT device through distributed communication;

[0055] Step 2: After the communication connection is completed, manage each IoT device and the user information corresponding to each IoT device. At the same time, build the authentication and authorization business logic and configure it in the cloud platform to obtain the user authentication and authorization mechanism;

[0056] Step 3: Receive user login requests from IoT devices in real time based on the cloud platform, and perform full-process authentication and authorization on the user login authorization request according to the user authentication and authorization mechanism, and log in to the cloud platform when the authentication and authorization are passed.

[0057] Preferably, a device cloud platform user authentication and authorization method, in step 1, the cloud platform is connected to each IoT device through distributed communication, including:

[0058] Collect the communication information between each IoT device and the cloud platform, and build the communication protocol between each IoT device and the cloud platform based on the communication information between each IoT device and the cloud platform;

[0059] Obtain a distributed communication network between the cloud platform and various IoT devices;

[0060] According to the communication protocol between each IoT device and the cloud platform, each IoT device is connected to the cloud platform through distributed communication in the distributed communication network.

[0061] Compared with the prior art, the present invention has the following beneficial effects:

[0062] By connecting each IoT device to the cloud platform through distributed communication, it is convenient to manage the user information of each IoT device through the cloud platform. Secondly, the authentication and authorization business logic is constructed and configured on the cloud platform to achieve accurate and reliable construction of the user authentication and authorization mechanism, which provides convenience for cloud platform user authentication and authorization. Finally, the cloud platform receives user login requests from IoT devices and performs full-process authentication and authorization operations, thereby achieving effective identity authentication and authorization operations for users, ensuring the security and reliability of user login to the cloud platform.

[0063] Other features and advantages of the present invention will be described in the following description, and partly become apparent from the description, or understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures specifically pointed out in this application document.

[0064] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0066] Figure 1 This is a structural diagram of a device cloud platform user authentication and authorization system in an embodiment of the present invention;

[0067] Figure 2 It is a structural diagram of a device access module in a device cloud platform user authentication and authorization system in an embodiment of the present invention;

[0068] Figure 3 The present invention is a flowchart of a method for authenticating and authorizing a user of a device cloud platform in an embodiment of the present invention. DETAILED DESCRIPTION

[0069] The preferred embodiments of the present invention are described below in conjunction with the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0070] Embodiment 1:

[0071] This embodiment provides a device cloud platform user authentication and authorization system, such as Figure 1 As shown, including:

[0072] The device access module is used to connect the cloud platform with various IoT devices through distributed communication;

[0073] The management module is used to manage each IoT device and the user information corresponding to each IoT device after the communication connection is completed. At the same time, it builds the authentication and authorization business logic and configures it in the cloud platform to obtain the user authentication and authorization mechanism;

[0074] The authentication and authorization module is used to receive user login requests from IoT devices in real time based on the cloud platform, and perform full-process authentication and authorization on user login authorization requests according to the user authentication and authorization mechanism, and log in to the cloud platform when the authentication and authorization are passed.

[0075] In this embodiment, the distributed communication connection refers to connecting each IoT device to the cloud platform separately, and the communication between each IoT device and the cloud platform does not affect each other.

[0076] In this embodiment, the authentication and authorization service logic is used to represent the execution order of the corresponding process or authentication steps when performing the authentication and authorization service.

[0077] In this embodiment, the user authentication and authorization mechanism refers to a scheme or policy for user authentication and authorization.

[0078] In this embodiment, the full-process authentication and authorization refers to verifying and authorizing the user login authorization request step by step according to the authentication process.

[0079] The working principle and beneficial effects of the above technical solution are: by connecting each IoT device with the cloud platform through distributed communication, it is convenient to manage the user information of each IoT device through the cloud platform. Secondly, the authentication and authorization business logic is constructed and configured on the cloud platform to achieve accurate and reliable construction of the user authentication and authorization mechanism, which provides convenience for cloud platform user authentication and authorization. Finally, the cloud platform receives the user login request of the IoT device and performs full-process authentication and authorization operations, thereby achieving effective identity authentication and authorization operations for users, ensuring the security and reliability of user login to the cloud platform.

[0080] Embodiment 2:

[0081] Based on Example 1, this embodiment provides a device cloud platform user authentication and authorization system, such as Figure 2 As shown, the device access module includes:

[0082] A communication protocol construction unit, used to collect communication information between each IoT device and the cloud platform, and to construct a communication protocol between each IoT device and the cloud platform according to the communication information between each IoT device and the cloud platform;

[0083] A distributed communication network acquisition unit, used to acquire a distributed communication network between the cloud platform and each IoT device;

[0084] The distributed communication connection unit is used to establish distributed communication connection between each IoT device and the cloud platform in a distributed communication network according to the communication protocol between each IoT device and the cloud platform.

[0085] In this embodiment, the communication information refers to the conditions and communication requirements based on which each IoT device communicates with the cloud platform.

[0086] In this embodiment, the communication protocol is used to characterize the requirements and conditions to be met when each IoT device communicates with the cloud platform.

[0087] The working principle and beneficial effects of the above technical solution are: by obtaining the communication information between each IoT device and the cloud platform, the communication protocol between each IoT device and the cloud platform can be accurately and effectively determined. Secondly, the distributed communication network between the cloud platform and each IoT device is obtained, and finally the distributed communication connection between the cloud platform and each IoT device is realized according to the communication protocol and the distributed communication network, which provides convenience for cloud platform user authentication and authorization management.

[0088] Embodiment 3:

[0089] Based on Example 1, this embodiment provides a device cloud platform user authentication and authorization system, in which the mechanism acquisition module includes: the authentication and authorization business logic is based on the management and control authentication and authorization process built on the integrated Spring Boot framework to host Web services and embedded in the Apache Shiro framework.

[0090] Embodiment 4:

[0091] Based on Example 2, this embodiment provides a device cloud platform user authentication and authorization system, a communication protocol construction unit, including:

[0092] The information acquisition subunit is used to obtain the device name of each IoT device and read the device address information of each IoT device;

[0093] A first protocol element determination subunit, configured to generate a first protocol element corresponding to each IoT device according to a device name and corresponding device address information of each IoT device;

[0094] A second protocol element determination subunit, configured to read the platform address information of the cloud platform and the platform name of the cloud platform, and generate a second protocol element corresponding to the cloud platform according to the platform address information of the cloud platform and the platform name of the cloud platform;

[0095] The communication protocol generation subunit is used to obtain the communication method between the cloud platform and each IoT device, and merge each first protocol element with the second protocol element according to the communication method between the cloud platform and each IoT device to generate a communication protocol between each IoT device and the cloud platform.

[0096] In this embodiment, the first protocol element is generated according to the device name of each IoT device and the corresponding device address information, and is a set of parameters in the communication protocol.

[0097] In this embodiment, the second protocol element is generated according to the platform address information of the platform and the platform name of the cloud platform, and is another set of parameters in the communication protocol.

[0098] The working principle and beneficial effects of the above technical solution are: by obtaining the device name and the corresponding device address information of each IoT device and using them as the first protocol element, a set of communication protocol parameters between the IoT device and the cloud platform are determined; secondly, a second protocol element corresponding to the cloud platform is generated according to the platform address information and the platform name of the cloud platform, so as to effectively determine another set of communication protocol parameters between the IoT device and the cloud platform; finally, the first protocol element and the second protocol element are integrated to accurately and effectively construct the communication protocol between each IoT device and the cloud platform, thereby providing convenience and guarantee for user information management.

[0099] Embodiment 5:

[0100] Based on Example 1, this embodiment provides a device cloud platform user authentication and authorization system, a management module, including:

[0101] Business logic acquisition unit, used to:

[0102] Obtain the authentication method and authentication dimension for authenticating the user, and determine the authentication business logic for the user based on the authentication method and authentication dimension;

[0103] Retrieve the user management table, determine the access rights of each user based on the user management table, and determine the authorization business logic based on the access rights of each user;

[0104] An association unit, used to add a first verification serial number to the authentication business logic and a second verification serial number to the authorization business logic, and at the same time, associate the authentication business logic with the authorization business logic according to the first verification serial number and the second verification serial number to obtain the authentication and authorization business logic;

[0105] The configuration unit is used to create an authentication and authorization management interval in the cloud platform, and configure the authentication and authorization business logic in the authentication and authorization management interval to obtain a user authentication and authorization mechanism.

[0106] In this embodiment, the authentication dimension refers to the type of authentication item corresponding to the user authentication.

[0107] In this embodiment, the first verification serial number refers to a serial number marking for the authentication business logic.

[0108] In this embodiment, the second verification serial number refers to a serial number marking for the authorization business logic.

[0109] In this embodiment, the authentication and authorization management interval refers to an interval created in the cloud platform and used to limit the corresponding limited range when authenticating and authorizing user information, for example, it can be through authenticating and authorizing the user's basic information.

[0110] The working principle and beneficial effects of the above technical solution are: by determining the authentication dimensions for authenticating users and the authentication business logic and authorization business logic for users, and associating and summarizing the authentication business logic and authorization business logic, accurate and effective determination of the authentication and authorization business logic is achieved. Finally, an authentication and authorization management interval is created in the cloud platform, and the authentication and authorization business logic is configured in the authentication and authorization management interval, so as to achieve accurate and effective formulation of the user authentication and authorization mechanism, providing a guarantee for user information.

[0111] Embodiment 6:

[0112] Based on Example 1, this embodiment provides a device cloud platform user authentication and authorization system, a management module, including:

[0113] The device management interval building unit is used to:

[0114] Obtain the device name of each IoT device, and build multiple device management intervals in the cloud platform according to the device name of each IoT device;

[0115] Perform device information management on the corresponding IoT device according to the device management interval, wherein the device information includes: the device number of the IoT device and the multiple user accounts corresponding to the IoT device;

[0116] User management section building block, used to:

[0117] Construct a user management interval according to the correspondence between each device management interval and multiple user accounts, and at the same time, construct a sub-user management interval consistent with the device management interval in the user management interval;

[0118] Obtain the user management table of each IoT device, and read the user management table of each IoT device to determine the accessible scope of each user of each IoT device to access information on the cloud platform;

[0119] Sort the user access rights according to the access scope of each user in each IoT device to the cloud platform from large to small, and determine the access rights level of each user in each IoT device to the cloud platform;

[0120] The user information of the corresponding IoT device and the access permission level of each user are stored in the sub-user management section;

[0121] Management interval encapsulation unit, used for:

[0122] The sub-user management interval is correspondingly connected to the device management interval, and at the same time, the device management interval and the user management interval are first encapsulated according to the connection result to obtain the device-user management interval;

[0123] Construct the authorization and authentication management interval, and at the same time, perform a second encapsulation of the device-user management interval and the authorization and authentication management interval;

[0124] Validation analysis unit for:

[0125] Create a data receiving interface for the authorization and authentication management interval, and receive real-time user login information based on the data receiving interface;

[0126] Based on the authorization and authentication management interval and calling the device-user management interval, the user's real-time login information is analyzed.

[0127] In this embodiment, the device management interval refers to all devices created in the cloud platform corresponding to the need to manage the IoT devices.

[0128] In this embodiment, the user management interval refers to a specific user object corresponding to the management of different devices.

[0129] In this embodiment, the sub-user management interval refers to the correspondence between users and devices.

[0130] In this embodiment, the user management table refers to a data table that records information such as the users that each IoT device is allowed to access and the data content that different users can access when accessing the IoT device.

[0131] In this embodiment, the access authority level is determined according to the accessible range of different users. The larger the accessible range, the greater the user's access authority.

[0132] In this embodiment, correspondingly connecting the sub-user management interval with the device management interval refers to determining the access relationship between the user and the device.

[0133] In this embodiment, the authorization and authentication management interval refers to the permission range when the user's permission is configured according to the user's access permission level.

[0134] The working principle and beneficial effects of the above technical solution are: by constructing multiple device management intervals, device information management of corresponding IoT devices is realized according to the device management intervals. At the same time, user management intervals and sub-user management intervals are constructed, and the user management table of each IoT device is combined to effectively determine the accessible scope of each user to access information on the cloud platform. Secondly, the access permission level of each user to the cloud platform is determined according to the determined accessible scope, so as to facilitate the effective limitation of the access management process of user information by different users, and also ensure the security of user information. Finally, the sub-user management interval is encapsulated with the device management interval, and the device-user management interval is encapsulated with the authorization and authentication management interval, and a data receiving interface is constructed according to the encapsulation result, so as to realize timely and effective analysis and processing of user login information received by the data receiving interface, thereby ensuring the reliability of user authentication and authorization management.

[0135] Embodiment 7:

[0136] Based on Example 1, this embodiment provides a device cloud platform user authentication and authorization system, an authentication and authorization module, including:

[0137] A request receiving unit, used to receive a user login request of an IoT device in real time based on a cloud platform;

[0138] An authentication unit, used to authenticate a user account based on a user login request;

[0139] The authorization unit is used to determine the user's access permission level according to the user account when the user passes the authentication, and retrieve the accessible information in the cloud platform according to the access permission level, and at the same time, authorize the user account according to the accessible information.

[0140] In this embodiment, the user login request may be request information for logging into the cloud platform, including a login code and a user account.

[0141] In this embodiment, the access permission level refers to the level at which a user can access cloud platform information. The higher the level, the more cloud platform information a user can access.

[0142] The working principle and beneficial effects of the above technical solution are: by receiving user login requests and performing authentication, the security of the cloud platform is effectively guaranteed. When the authentication is passed, the accessible information is effectively retrieved based on the user's access permission level, and a large number of users can be managed more flexibly, and their access permissions can be easily adjusted according to different user roles, business needs, etc.

[0143] Embodiment 8:

[0144] Based on Example 7, this embodiment provides a device cloud platform user authentication and authorization system, the authentication unit includes:

[0145] A request reading subunit is used to read the user login request of the IoT device based on the cloud platform, and determine the login code and user account of the user login request;

[0146] Authentication subunit, used to:

[0147] Retrieve the base login code and determine whether the base login code is consistent with the login code requested by the user;

[0148] If the base login code is consistent with the login code of the user login request, read the base user account corresponding to the base login code;

[0149] If the base login code is inconsistent with the login code of the user login request, it is determined that the user authentication has not been passed;

[0150] Determine whether the base user account is consistent with the user account requested by the user for login;

[0151] When the reference user account is consistent with the user account of the user login request, it is determined that the user authentication is passed; otherwise, it is determined that the user authentication is not passed.

[0152] In this embodiment, the login code refers to the hash value of the password.

[0153] In this embodiment, the user account refers to the user's username or the user's ID.

[0154] In this embodiment, the reference login code refers to a code that is stored in advance in the cloud platform and is used as a criterion for matching and verifying the login code in the user login request.

[0155] In this embodiment, the reference user account is account information determined according to the reference login code, and is used as a measure of whether the user account of the user login request is consistent.

[0156] The working principle and beneficial effects of the above technical solution are: by reading and parsing the user login request, the login code and user account of the user login request are effectively obtained, and then double verification is effectively performed based on the benchmark user account and benchmark login code stored in the cloud platform, thereby effectively ensuring the security of the cloud platform and avoiding the disadvantages of illegal access. At the same time, it effectively manages user access to cloud platform resources.

[0157] Embodiment 9:

[0158] This embodiment provides a device cloud platform user authentication and authorization method, such as Figure 3 As shown, including:

[0159] Step 1: Connect the cloud platform with each IoT device through distributed communication;

[0160] Step 2: After the communication connection is completed, manage each IoT device and the user information corresponding to each IoT device. At the same time, build the authentication and authorization business logic and configure it in the cloud platform to obtain the user authentication and authorization mechanism;

[0161] Step 3: Receive user login requests from IoT devices in real time based on the cloud platform, and perform full-process authentication and authorization on the user login authorization request according to the user authentication and authorization mechanism, and log in to the cloud platform when the authentication and authorization are passed.

[0162] The working principle and beneficial effects of the above technical solution are: by connecting each IoT device with the cloud platform through distributed communication, it is convenient to manage the user information of each IoT device through the cloud platform. Secondly, the authentication and authorization business logic is constructed and configured on the cloud platform to achieve accurate and reliable construction of the user authentication and authorization mechanism, which provides convenience for cloud platform user authentication and authorization. Finally, the cloud platform receives the user login request of the IoT device and performs full-process authentication and authorization operations, thereby achieving effective identity authentication and authorization operations for users, ensuring the security and reliability of user login to the cloud platform.

[0163] Embodiment 10:

[0164] Based on Example 9, this embodiment provides a device cloud platform user authentication and authorization method. In step 1, the cloud platform is connected to each IoT device through distributed communication, including:

[0165] Collect the communication information between each IoT device and the cloud platform, and build the communication protocol between each IoT device and the cloud platform based on the communication information between each IoT device and the cloud platform;

[0166] Obtain a distributed communication network between the cloud platform and various IoT devices;

[0167] According to the communication protocol between each IoT device and the cloud platform, each IoT device is connected to the cloud platform through distributed communication in the distributed communication network.

[0168] The working principle and beneficial effects of the above technical solution are: by obtaining the communication information between each IoT device and the cloud platform, the communication protocol between each IoT device and the cloud platform can be accurately and effectively determined. Secondly, the distributed communication network between the cloud platform and each IoT device is obtained, and finally the distributed communication connection between the cloud platform and each IoT device is realized according to the communication protocol and the distributed communication network, which provides convenience for cloud platform user authentication and authorization management.

[0169] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.

Claims

1. A device cloud platform user authentication and authorization system, characterized in that: include: The device access module is used to connect the cloud platform with various IoT devices through distributed communication; The management module is used to manage each IoT device and the user information corresponding to each IoT device after the communication connection is completed. At the same time, it builds the authentication and authorization business logic and configures it in the cloud platform to obtain the user authentication and authorization mechanism; The authentication and authorization module is used to receive user login requests from IoT devices in real time based on the cloud platform, and perform full-process authentication and authorization on user login authorization requests according to the user authentication and authorization mechanism, and log in to the cloud platform when the authentication and authorization are passed.

2. A device cloud platform user authentication and authorization system according to claim 1, characterized in that: Device access module, including: A communication protocol construction unit, used to collect communication information between each IoT device and the cloud platform, and to construct a communication protocol between each IoT device and the cloud platform according to the communication information between each IoT device and the cloud platform; A distributed communication network acquisition unit, used to acquire a distributed communication network between the cloud platform and each IoT device; The distributed communication connection unit is used to establish distributed communication connection between each IoT device and the cloud platform in a distributed communication network according to the communication protocol between each IoT device and the cloud platform.

3. A device cloud platform user authentication and authorization system according to claim 1, characterized in that: The mechanism acquisition module includes: The authentication and authorization business logic is based on the management and control authentication and authorization process built by integrating the Spring Boot framework to host Web services and embedding the Apache Shiro framework.

4. A device cloud platform user authentication and authorization system according to claim 2, characterized in that: Communication protocol building blocks, including: The information acquisition subunit is used to obtain the device name of each IoT device and read the device address information of each IoT device; A first protocol element determination subunit, configured to generate a first protocol element corresponding to each IoT device according to a device name and corresponding device address information of each IoT device; A second protocol element determination subunit, configured to read the platform address information of the cloud platform and the platform name of the cloud platform, and generate a second protocol element corresponding to the cloud platform according to the platform address information of the cloud platform and the platform name of the cloud platform; The communication protocol generation subunit is used to obtain the communication method between the cloud platform and each IoT device, and merge each first protocol element with the second protocol element according to the communication method between the cloud platform and each IoT device to generate a communication protocol between each IoT device and the cloud platform.

5. A device cloud platform user authentication and authorization system according to claim 1, characterized in that: Management modules, including: Business logic acquisition unit, used to: Obtain the authentication method and authentication dimension for authenticating the user, and determine the authentication business logic for the user based on the authentication method and authentication dimension; Retrieve the user management table, determine the access rights of each user based on the user management table, and determine the authorization business logic based on the access rights of each user; An association unit, used to add a first verification serial number to the authentication business logic and a second verification serial number to the authorization business logic, and at the same time, associate the authentication business logic with the authorization business logic according to the first verification serial number and the second verification serial number to obtain the authentication and authorization business logic; The configuration unit is used to create an authentication and authorization management interval in the cloud platform, and configure the authentication and authorization business logic in the authentication and authorization management interval to obtain a user authentication and authorization mechanism.

6. A device cloud platform user authentication and authorization system according to claim 1, characterized in that: Management modules, including: The device management interval building unit is used to: Obtain the device name of each IoT device, and build multiple device management intervals in the cloud platform according to the device name of each IoT device; Perform device information management on the corresponding IoT device according to the device management interval, wherein the device information includes: the device number of the IoT device and the multiple user accounts corresponding to the IoT device; User management section building block, used to: Construct a user management interval according to the correspondence between each device management interval and multiple user accounts, and at the same time, construct a sub-user management interval consistent with the device management interval in the user management interval; Obtain the user management table of each IoT device, and read the user management table of each IoT device to determine the accessible scope of each user of each IoT device to access information on the cloud platform; Sort the user access rights according to the access scope of each user in each IoT device to the cloud platform from large to small, and determine the access rights level of each user in each IoT device to the cloud platform; The user information of the corresponding IoT device and the access permission level of each user are stored in the sub-user management section; Management interval encapsulation unit, used for: The sub-user management interval is correspondingly connected to the device management interval, and at the same time, the device management interval and the user management interval are first encapsulated according to the connection result to obtain the device-user management interval; Construct the authorization and authentication management interval, and at the same time, perform a second encapsulation of the device-user management interval and the authorization and authentication management interval; Validation analysis unit for: Create a data receiving interface for the authorization and authentication management interval, and receive real-time user login information based on the data receiving interface; Based on the authorization and authentication management interval and calling the device-user management interval, the user's real-time login information is analyzed.

7. A device cloud platform user authentication and authorization system according to claim 1, characterized in that: Authentication and authorization modules, including: A request receiving unit, used to receive a user login request of an IoT device in real time based on a cloud platform; An authentication unit, used to authenticate a user account based on a user login request; The authorization unit is used to determine the user's access permission level according to the user account when the user passes the authentication, and retrieve the accessible information in the cloud platform according to the access permission level, and at the same time, authorize the user account according to the accessible information.

8. A device cloud platform user authentication and authorization system according to claim 7, characterized in that: Certification units include: A request reading subunit is used to read the user login request of the IoT device based on the cloud platform, and determine the login code and user account of the user login request; Authentication subunit, used to: Retrieve the base login code and determine whether the base login code is consistent with the login code requested by the user; If the base login code is consistent with the login code of the user login request, read the base user account corresponding to the base login code; If the base login code is inconsistent with the login code of the user login request, it is determined that the user authentication has not been passed; Determine whether the base user account is consistent with the user account requested by the user for login; When the reference user account is consistent with the user account of the user login request, it is determined that the user authentication is passed; otherwise, it is determined that the user authentication is not passed.

9. A device cloud platform user authentication and authorization method, characterized in that: include: Step 1: Connect the cloud platform with each IoT device through distributed communication; Step 2: After the communication connection is completed, manage each IoT device and the user information corresponding to each IoT device. At the same time, build the authentication and authorization business logic and configure it in the cloud platform to obtain the user authentication and authorization mechanism; Step 3: Receive user login requests from IoT devices in real time based on the cloud platform, and perform full-process authentication and authorization on the user login authorization request according to the user authentication and authorization mechanism, and log in to the cloud platform when the authentication and authorization are passed.

10. A device cloud platform user authentication and authorization method according to claim 9, characterized in that: In step 1, the cloud platform is connected to each IoT device through distributed communication, including: Collect the communication information between each IoT device and the cloud platform, and build the communication protocol between each IoT device and the cloud platform based on the communication information between each IoT device and the cloud platform; Obtain a distributed communication network between the cloud platform and various IoT devices; According to the communication protocol between each IoT device and the cloud platform, each IoT device is connected to the cloud platform through distributed communication in the distributed communication network.

Citation Information

Patent Citations

  • Internet of Things (IoT) authentication and access control method and IoT security gateway system

    CN108650212A

  • Internet of Things device access control method based on of smart contract of blockchain

    CN108737348A

  • Intelligent lock control system based on cloud platform

    CN212694473U

  • Quantifying usage of disparate computing resources as a single unit of measure

    US20210125128A1