Remote control method and device, electronic equipment and storage medium
By generating and storing control passwords locally on the device, the problem of lower security in existing remote assistance methods is solved, and higher control password security and user privacy protection are achieved.
Patent Information
- Application Number
- CN202510253558.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-05-13
AI Technical Summary
The existing remote assistance methods have low security problems, especially in the complex network environment, temporary passwords stored on the server are easily leaked, resulting in user privacy information being stolen and equipment being illegally controlled remotely.
Generate and store control passwords locally on the device to avoid the risks brought about by storing control passwords on the server. Even if the external environment of the device is attacked, as long as the local security mechanism of the device is not broken, the control password will not be leaked, thereby improving the security of the control password.
By locally generating and storing control passwords, the security of control passwords is significantly improved, the security risks caused by password leakage are reduced, and user privacy and device protection are enhanced.
Smart Images

Figure CN119996486A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to a remote control method, device, electronic device and storage medium. Background Art
[0002] At present, the remote assistance method mainly generates the device code and temporary password that can be connected through the server. The remote connection can be completed by filling in the device code and temporary password of the controlled end on the control end and clicking connect. Among them, the device code and temporary password are stored on the server.
[0003] However, as the network environment becomes increasingly complex, security threats are also increasing. Storing temporary passwords on the server side faces many risks. For example, when users actively share device functions and applications maintain long connections, the device is exposed to the network environment for a long time. The server-side storage of passwords makes it easy for the password to be leaked once the device is attacked, which in turn leads to serious consequences such as the theft of user privacy information and illegal remote control of the device. Therefore, the existing remote assistance methods have the problem of low security. Summary of the invention
[0004] The embodiments of the present application provide a remote control method, device, electronic device and storage medium, which can generate and store control passwords locally on the device to avoid the risks caused by storing control passwords on the server side. At the same time, even if the external environment of the device is attacked, as long as the local security mechanism of the device is not breached, the control password will not be leaked, thereby greatly improving the security of the control password.
[0005] In a first aspect, an embodiment of the present application provides a remote control method, which is applied to a controlled end, and the method includes:
[0006] Receiving a remote connection request sent by a control terminal, wherein the remote connection request carries a device identifier of the controlled terminal;
[0007] In response to the remote connection request, obtaining a control password stored on the controlled terminal, wherein the control password is generated on the controlled terminal;
[0008] The control password is sent to the control terminal, so that the control terminal establishes a remote control connection with the controlled terminal based on the control password and the device identification of the controlled terminal.
[0009] In a second aspect, an embodiment of the present application provides a remote control device, applied to a controlled end, comprising:
[0010] A request receiving module, used for receiving a remote connection request sent by a control terminal, wherein the remote connection request carries a device identification of the controlled terminal;
[0011] a data acquisition module, configured to acquire a control password stored on the controlled terminal in response to the remote connection request, wherein the control password is generated on the controlled terminal;
[0012] The data sending module is used to send the control password to the control terminal, so that the control terminal establishes a remote control connection with the controlled terminal based on the control password and the device identification of the controlled terminal.
[0013] In a third aspect, an embodiment of the present application provides a remote control method, which is applied to a control terminal, and the method includes:
[0014] Obtain the device identification of the controlled end to be controlled;
[0015] generating a remote connection request carrying the device identification;
[0016] Sending the remote connection request to the controlled end indicated by the device identifier, so that the controlled end sends a control password to the controlling end based on the remote connection request;
[0017] A remote control connection is established with the controlled terminal according to the control password and the device identification of the controlled terminal.
[0018] In a fourth aspect, an embodiment of the present application provides a remote control device, applied to a control terminal, comprising:
[0019] An identification acquisition module is used to acquire the device identification of the controlled terminal to be controlled;
[0020] A request generation module, used to generate a remote connection request carrying the device identification;
[0021] A request sending module, used for sending the remote connection request to the controlled end indicated by the device identifier, so that the controlled end sends a control password to the control end based on the remote connection request;
[0022] The connection establishment module is used to establish a remote control connection with the controlled terminal according to the control password and the device identification of the controlled terminal.
[0023] In a fifth aspect, an embodiment of the present application provides a remote control method, which is applied to a server, and the method includes:
[0024] Receiving verification association information sent by the controlled terminal, and associating and storing the verification association information with the device identification of the controlled terminal;
[0025] In response to receiving a password verification request sent by the control end, the control password received by the control end is verified based on the verification association information, and if the verification is successful, a verification success instruction is sent to the controlled end and the control end respectively.
[0026] In a sixth aspect, an embodiment of the present application provides a remote control device, applied to a server, comprising:
[0027] A first receiving module, used for receiving the verification association information sent by the controlled terminal, and storing the verification association information in association with the device identification of the controlled terminal;
[0028] The second receiving module is used to verify the control password received by the control end based on the verification association information in response to receiving the password verification request sent by the control end, and if the verification is successful, send a verification success instruction to the controlled end and the control end respectively.
[0029] In a seventh aspect, an embodiment of the present application further provides an electronic device, comprising a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor performs the steps of any remote control method.
[0030] In an eighth aspect, an embodiment of the present application further provides a computer-readable storage medium, which includes a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor performs the steps of any remote control method.
[0031] In the ninth aspect, an embodiment of the present application also provides a computer program product, including a computer program, which is stored in a computer-readable storage medium; when a processor of an electronic device reads the computer program from the computer-readable storage medium, the processor executes the computer program, so that the electronic device performs any step of the remote control method provided in the embodiment of the present application.
[0032] By adopting the scheme of the embodiment of the present application, the controlled end can receive a remote connection request sent by the control end, wherein the remote connection request carries the device identification of the controlled end; in response to the remote connection request, obtain a control password stored on the controlled end, wherein the control password is generated on the controlled end; send the control password to the control end so that the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end. Based on this, the control password is generated and stored locally on the device to avoid the risks brought by the storage of the control password on the server end. At the same time, even if the external environment of the device is attacked, as long as the local security mechanism of the device is not breached, the control password will not be leaked, thereby greatly improving the security of the control password. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.
[0034] Figure 1 This is a schematic diagram of an implementation environment scenario of the remote control method provided in the embodiments of the present application;
[0035] Figure 2 This is a schematic diagram of an embodiment of a remote control method applied to a controlled terminal provided in an embodiment of the present application;
[0036] Figure 3 It is a schematic diagram of an embodiment of a remote control method applied to a control terminal provided in an embodiment of the present application;
[0037] Figure 4 This is a flow chart of an embodiment of a remote control method applied to a server provided in an embodiment of the present application;
[0038] Figure 5 is a schematic diagram of the structure of a remote control device applied to a controlled terminal provided in an embodiment of the present application;
[0039] Figure 6 is a schematic diagram of the structure of a remote control device applied to a control terminal provided in an embodiment of the present application;
[0040] Figure 7 is a schematic diagram of the structure of a remote control device applied to a server provided in an embodiment of the present application;
[0041] Figure 8 It is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0042] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of the present application. At the same time, in the description of the embodiments of the present application, the terms "first", "second", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more features. In the description of the embodiments of the present application, the meaning of "multiple" is two or more, unless otherwise clearly and specifically defined.
[0043] After research, it was found that the main method of remote assistance is that the user starts the remote software. When starting the software, the server automatically generates a device code and a temporary password that can be connected. For example, the device code may be a string of numbers such as "856 936 331", and the corresponding temporary password is also generated at the same time. After starting the controlled end to generate the device code and temporary password, the control end is then started. The user needs to fill in the device code and temporary password of the controlled end on the control end, and click Connect to complete the remote connection. Among them, the device code and temporary password are stored on the server.
[0044] However, as the network environment becomes increasingly complex, security threats are also increasing. Storing temporary passwords on the server side faces many risks. For example, when users actively share device functions and applications maintain long connections, the device is exposed to the network environment for a long time. The server-side storage of passwords makes it easy for the password to be leaked once the device is attacked, which in turn leads to serious consequences such as the theft of user privacy information and illegal remote control of the device. Therefore, the existing remote assistance methods have the problem of low security.
[0045] To this end, the embodiments of the present application provide a remote control method, device, electronic device and computer-readable storage medium. The remote control device can be integrated in an electronic device, which can be a server or a terminal device such as a controlled terminal or a control terminal.
[0046] Among them, the server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, network acceleration services (Content Delivery Network, CDN), and basic cloud computing services such as big data and artificial intelligence platforms. Terminals may include but are not limited to mobile phones, computers, intelligent voice interaction devices, smart home appliances, vehicle-mounted terminals, aircraft, etc. The terminal and the server can be directly or indirectly connected via wired or wireless communication, and this application does not limit this.
[0047] The terminal device may be a controlled terminal that can be remotely controlled, or a control terminal that actively initiates remote control of other devices.
[0048] It should be noted that both the controlled end and the controlling end are terminal devices, and the difference between them is only in the state of remote control (ie, passive control or active control).
[0049] In the embodiment of the present application, the control password can be generated and stored locally in the terminal device. However, the control password required when establishing a remote control connection is the control password of the controlled end. At this time, the control password of the control end is not transmitted.
[0050] See also Figure 1 , taking the remote control device integrated into the electronic device as an example, Figure 1 A schematic diagram of an implementation scenario of the remote control method provided in an embodiment of the present application, wherein the electronic device can be a terminal device, which receives a remote connection request sent by a control terminal through a controlled terminal, wherein the remote connection request carries a device identification of the controlled terminal; in response to the remote connection request, obtains a control password stored on the controlled terminal, wherein the control password is generated on the controlled terminal; sends the control password to the control terminal, so that the control terminal establishes a remote control connection with the controlled terminal based on the control password and the device identification of the controlled terminal. Based on this, a control password is generated and stored locally on the device to avoid the risks brought by storage of the control password on the server side. At the same time, even if the external environment of the device is attacked, as long as the local security mechanism of the device is not breached, the control password will not be leaked, thereby greatly improving the security of the control password.
[0051] It should be noted that Figure 1The implementation environment scenario diagram of the remote control method shown is only an example. The implementation environment scenario of the remote control method described in the embodiment of the present application is to more clearly illustrate the technical solution of the embodiment of the present application, and does not constitute a limitation on the technical solution provided by the embodiment of the present application. It is known to those skilled in the art that with the evolution of data processing and the emergence of new business scenarios, the technical solution provided by the present application is also applicable to similar technical problems.
[0052] The solutions provided by the embodiments of the present application are specifically described by the following embodiments. It should be noted that the description order of the following embodiments is not intended to limit the preferred order of the embodiments.
[0053] This embodiment will be described from the perspective of a remote control device. The remote control device may be integrated into an electronic device. The electronic device may be a terminal and / or a server, and this application does not limit this.
[0054] See also Figure 2 , Figure 2 The remote control method provided in the embodiment of the present application and applied to the controlled terminal, the specific process of the remote control method can be as follows: Step 101 to Step 103, wherein:
[0055] Step 101: Receive a remote connection request sent by a control terminal, wherein the remote connection request carries a device identifier of a controlled terminal.
[0056] The control end refers to a device that initiates a communication or interaction request, while the controlled end refers to a device that receives these requests. The remote connection mentioned in the embodiments of the present application is a communication or interaction request.
[0057] Among them, the remote connection request refers to the request initiated by the control end device to try to establish a remote control connection with the controlled end device. Through this connection, the control end can access and manage the controlled end through the network. Even if the user is not at the site of the controlled end, after successfully establishing the connection, the user can remotely manage the controlled end device.
[0058] The device ID is a string of codes randomly generated by the server, which is used as a unique identifier to distinguish devices. The device ID can help the server accurately identify different devices during the remote connection process to ensure the accuracy and security of the connection.
[0059] Step 102: In response to the remote connection request, obtain a control password stored on the controlled terminal, wherein the control password is generated on the controlled terminal.
[0060] The control password refers to a temporary password generated locally on the device and used to access the device.
[0061] The control password mentioned in the embodiment of the present application is generated and stored locally on the device. For example, the control password of the controlled end is generated and stored locally on the controlled end device. For another example, the control password of the control end is generated and stored locally on the control end device.
[0062] In some embodiments, a control password is generated in response to a password generation event of the controlled end, wherein the password generation event includes turning on the connectable state of the controlled end, or the controlled end is in a connectable state and no control password is stored in the secure storage area when a remote connection request is received; and the control password is stored in the secure storage area of the controlled end.
[0063] The password generation event refers to an event that triggers the generation of a control password locally on the device.
[0064] There are many ways to generate a password, and the specific content can be adjusted according to the actual situation, and the embodiments of this application do not limit it.
[0065] For example, the password generation event includes turning on the connectable state of the controlled terminal, where the connectable state means that the device is in the "connection-allowed state", that is, the controlled terminal supports other devices to remotely control it. Turning on the connectable state of the controlled terminal can be done by the user manually triggering the device to enter the "connection-allowed state" at the controlled terminal.
[0066] For another example, the password generation event includes that the controlled terminal is in a connectable state and no control password is stored in the secure storage area when a remote connection request is received. The secure storage area refers to a storage area on the device for storing the generated control password.
[0067] It should be noted that the password generation event may also include other methods. The embodiments of the present application are only examples and do not constitute a limiting condition. For example, the password generation event may also include generating a control password within a predetermined time and updating the control password in the secure storage area. The predetermined time may be set to 60 minutes or 1 day. For another example, the control password is a one-time password. When the previous control password is read and after the predetermined time, a new control password is triggered to be generated.
[0068] There are many ways to generate a control password, and the specific content can be adjusted according to actual conditions, and the embodiments of this application do not limit it.
[0069] For example, the control password can be generated by a dedicated password generation module integrated inside the device, which supports multiple generation methods and can be flexibly adjusted according to actual needs. Among them, the module can support the use of advanced elliptic curve encryption algorithms, combined with the device's unique hardware identification information, such as the device's unique hardware serial number, and combined with the current accurate system timestamp, to generate a highly complex and device-tightly bound one-time password. The module can also support the generation of passwords based on user-defined rules, such as generating passwords containing specific characters or numbers based on the user's personalized settings. The module can also support random generation functions to ensure that each control password is unique, greatly improving the security of the control password.
[0070] This password generation scheme not only improves security, but also ensures the uniqueness and unpredictability of the control password, thereby effectively protecting the device from unauthorized access and potential security threats. In addition, the password generation module can adapt to a variety of application scenarios and provide fast and reliable password generation services without affecting device performance, providing users with higher security protection.
[0071] In traditional remote control methods, users have limited control over passwords. Once a password is generated and stored on the server, it is difficult for the user to directly intervene in the management and use of the password, and the user must rely on the security measures of the server to ensure the security of the password. In contrast, the embodiments provided in this application significantly enhance the user's control over device connections by managing the entire life cycle of the password locally on the user's device. Users can more independently decide when the device can be remotely connected, thereby improving the ability to control device security.
[0072] It should be noted that every time the user manually triggers the device to enter the "allowed connection state", the device will regenerate a new control password. This generation process is the same as before, ensuring that the control password used for each connection is unique and highly secure, avoiding the security risks that may be caused by the repeated use of the control password, thereby providing continuous security protection for the remote connection of the device.
[0073] In some embodiments, the control password stored in the secure storage area is a password encrypted by a local storage key.
[0074] Among them, there are many types of secure storage areas, and their specific contents can be adjusted according to actual conditions, and the embodiments of this application do not limit them.
[0075] For example, the secure storage area can be a trusted execution environment (TEE) chip based on the device hardware. The TEE chip provides a secure execution environment independent of the device's main operating system, which can effectively prevent external malware or unauthorized processes from accessing passwords. For another example, the secure storage area can also be an encrypted partition in the device's memory.
[0076] After the control password is generated, it will be quickly transferred to the local secure storage area of the device. When stored in the secure storage area, the control password is usually encrypted using a strong encryption algorithm to enhance the security of the control password during the storage stage and ensure the confidentiality and integrity of the control password during the local storage process.
[0077] For example, the control password is encrypted once by a local storage key, and the encrypted control password is stored in a local secure storage area of the device. The local storage key refers to a key used to store and encrypt the control password, and is a key configured locally on the device.
[0078] The generated password is only temporarily stored locally on the device in a protected secure storage area. This secure storage area is strictly isolated through the security mechanism of the operating system and can only be accessed by specific authorized processes. The control password will not be uploaded to the server, ensuring that the generation and initial storage of the control password are completely secure in the local environment.
[0079] Step 103: Send the control password to the control terminal, so that the control terminal establishes a remote control connection with the controlled terminal based on the control password and the device identification of the controlled terminal.
[0080] Specifically, through the remote control connection established between the control terminal and the controlled terminal, the control terminal remotely controls the controlled terminal.
[0081] In some embodiments, before sending the control password to the control end, it also includes: decrypting the control password after storage encryption according to the local storage key of the controlled end; and encrypting the decrypted control password according to the communication key between the controlled end and the control end.
[0082] The communication key refers to the key used to encrypt the control password, and is the key configured for communication between the control end and the controlled end.
[0083] The communication key is related to the specific encryption protocol. The specific content of the encryption protocol can be adjusted according to the actual situation, and the embodiments of the present application do not limit it. For example, Hypertext Transfer Protocol Secure (HTTPS), User Datagram Protocol (UDP), Datagram Transport Layer Security (DTLS), etc. can be used as encryption protocols.
[0084] Exemplarily, during the transmission process, an industry-standard secure transmission protocol, such as Hypertext Transfer Protocol Security, may be used, and the control password may be encrypted twice to ensure the security of the control password during network transmission.
[0085] There are multiple ways to send the control password to the control end. The specific content can be adjusted according to actual conditions and is not limited in the embodiments of the present application.
[0086] In some embodiments, the control password encrypted by communication can be sent to the control end through the communication connection between the control end and the controlled end, so that the control end can decrypt the control password encrypted by communication based on the communication key.
[0087] Among them, there are many ways to implement the communication connection, and the specific content can be adjusted according to actual conditions, and the embodiments of this application are not limited.
[0088] Exemplarily, a WebSocket connection can be established between the control end and the controlled end. After the controlled end reads the control password from the local secure storage area, it uses the device's built-in secure communication module to transmit the control password and the device code to the control end through the WebSocket connection.
[0089] For example, the controlled end can also establish a secure channel with the control end through the handshake protocol in DTLS, so as to encapsulate the control password and the device code into a data packet and directly send it after being encrypted by DTLS.
[0090] During the password transmission process, high-strength encryption algorithms (such as TLS1.3 protocol) are used to encrypt the control and controlled ends. At the beginning of the communication, the two parties negotiate the session key for encrypted communication through a complex key exchange mechanism, and all data will be encrypted and decrypted using this key. At the same time, strict two-way authentication is performed on the identities of both parties in the communication to prevent security threats such as man-in-the-middle attacks, ensure the confidentiality, integrity and authenticity of the control password during transmission, and provide solid protection for the secure transmission of the control password.
[0091] In some embodiments, the control password encrypted by communication may also be sent to the control end through the service end, so that the control end decrypts the control password encrypted by communication based on the communication key.
[0092] Among them, there are many ways to control the sending of passwords through the server, and the specific content can be adjusted according to actual conditions, and the embodiments of this application do not limit it.
[0093] For example, the control end sends an HTTP request to the server end, and the server end keeps the connection open until the controlled end generates a control password. The controlled end sends the control password and device code to the control end through the server end.
[0094] During the password transmission process, high-strength encryption algorithms (such as TLS1.3 protocol) are used to encrypt between the control end and the controlled end, as well as between the control end and the signaling server (i.e., the server end). At the beginning of the communication, the two parties negotiate a session key for encrypted communication through a complex key exchange mechanism, and all data thereafter is encrypted and decrypted using this key. At the same time, strict two-way authentication is performed on the identities of both parties in the communication to prevent security threats such as man-in-the-middle attacks, ensure the confidentiality, integrity, and authenticity of the control password during transmission, and provide solid protection for the secure transmission of the control password.
[0095] Through the above steps, the transmission link of the control password in the network is strictly protected and is only securely transmitted between the control end and the controlled end. This design greatly reduces the risk of the control password being stolen by network attackers during transmission.
[0096] In some embodiments, the remote control method further includes: in response to a password destruction event, destroying the control password and the local storage key stored in the secure storage area, wherein the password destruction event includes at least one of the validity period of the control password exceeding a validity period threshold and the remote control connection being successfully established.
[0097] The password destruction event refers to an event that requires the destruction of the control password stored locally on the device.
[0098] The validity threshold refers to the time limit of the control password. For example, the validity threshold is set to 3 minutes. The time starts from the moment the control password is generated. Once the set time is exceeded, even if the control password is not used, it will be automatically destroyed locally and can no longer be used for connection verification. The timeliness mechanism effectively reduces the time window for the control password to be intercepted and used by attackers, further enhancing the security of the system.
[0099] Specifically, in response to a password destruction event, a destruction program is started to destroy the control password and the local storage key stored in the secure storage area.
[0100] There are many specific implementation methods for the destruction program, and the specific content can be adjusted according to actual conditions, and the embodiments of the present application do not limit it. For example, the destruction program uses multiple rounds of data overwriting and encryption key erasure technology to ensure that all traces of the password data in the storage medium are completely cleared and cannot be restored by any data recovery means.
[0101] After the control password expires, or after a remote control connection is successfully established based on the control password, the password destruction process is immediately started in the local secure storage area of the controlled device. At the same time, the local key used to encrypt the password is also securely destroyed to prevent the key from being maliciously used to decrypt the residual data of the destroyed password, thereby ensuring the thoroughness and irreversibility of password destruction.
[0102] In some embodiments, when generating a control password, the remote control method further includes: generating verification association information of the control password; sending the verification association information to the server so that the server associates and stores the verification association information with the device identification of the controlled terminal.
[0103] The verification-related information refers to the related information used to verify the correctness of the control password.
[0104] The verification-related information includes, but is not limited to, the validity period information of the control password, the hash value of the generated control password, etc.
[0105] Based on this, the above-mentioned process of sending the control password to the control end so that the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end also includes: sending the control password to the control end so that the control end sends a password verification request including the control password and the device identification of the controlled end to the server end, triggering the server end to verify the control password based on the verification association information, and if the verification is successful, sending verification success instructions to the controlled end and the control end respectively, in response to the verification success instruction, the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end.
[0106] Specifically, after receiving the control password, the control end will send the received control password and the device code of the controlled end that it needs to control to the signaling server for verification. After receiving the request, the signaling server only verifies the correctness of the control password. The verification process strictly follows the pre-set encryption algorithm and verification rules to ensure the matching of the control password and the device code and the timeliness of the control password. After the verification is passed, the signaling server sends a verification success instruction to the control end and the controlled end, and a secure connection (i.e., remote control connection) is established between the control end and the controlled end to facilitate the start of remote assistance operations. During the whole process, the signaling server does not store the control password, but only performs verification operations, minimizing the risk of retaining the control password on the server side.
[0107] Compared with traditional remote control methods, the server is usually responsible for the storage, management and verification of control passwords, which not only increases the computing and storage burden on the server, but may also affect performance and response speed, especially when used by large-scale users. In addition, the frequent password data interaction between the server and the device increases the communication complexity and network bandwidth occupancy of the system. The embodiments of the present application effectively reduce the burden on the server, requiring only simple password verification without the need to store control passwords, thereby reducing resource consumption and improving stability and performance. At the same time, it reduces unnecessary communication between the device and the server due to password management, optimizes the communication process, reduces network latency, and improves the response speed and fluency of remote assistance operations.
[0108] In some embodiments, multi-level local security measures can also be adopted, including firewalls, intrusion detection systems and the latest encryption algorithms, to ensure that any unauthorized access can be detected and blocked in a timely manner. In order to further enhance the security of transmission, the system sets up an encrypted communication channel and encrypts the data using the Advanced Encryption Standard (AES), so that even if an attacker intercepts the communication data, he cannot decipher the content. Through these comprehensive measures, the absolute security of the control password is guaranteed during the entire transmission process, thereby improving the overall security protection capability of the system and ensuring the confidentiality and integrity of user data.
[0109] Specifically, the controlled end is configured with an intrusion detection system.
[0110] An intrusion detection system is a system that monitors the operating status of the equipment system in real time and promptly detects and alarms any abnormal behavior that attempts to access the secure storage area of the control password or interferes with the generation, transmission, and destruction of the control password.
[0111] Based on this, the above-mentioned remote control method also includes: monitoring the controlled end through an intrusion detection system to see whether there are any abnormal events in the remote connection scenario, the abnormal events including at least one of abnormal number of accesses to the secure storage area, abnormal password generation, abnormal password transmission, and abnormal password destruction; in the event of an abnormal event on the controlled end, early warning processing is performed through the intrusion detection system.
[0112] At the same time, the device regularly updates system security patches to fix possible security vulnerabilities, ensuring that the local security mechanism is always in the latest and most effective state, providing comprehensive security protection for local management of control passwords.
[0113] By adopting the scheme of the embodiment of the present application, the controlled end can receive a remote connection request sent by the control end, wherein the remote connection request carries the device identification of the controlled end; in response to the remote connection request, obtain a control password stored on the controlled end, wherein the control password is generated on the controlled end; send the control password to the control end so that the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end. Based on this, the control password is generated and stored locally on the device to avoid the risks brought by the storage of the control password on the server end. At the same time, even if the external environment of the device is attacked, as long as the local security mechanism of the device is not breached, the control password will not be leaked, thereby greatly improving the security of the control password.
[0114] See also Figure 3 , Figure 3 The remote control method provided in the embodiment of the present application is applied to the control terminal. The specific process of the remote control method can be as follows: Step 201 to Step 204, wherein:
[0115] Step 201: Obtain the device identification of the controlled terminal to be controlled.
[0116] The device identifier refers to an identifier used to distinguish a controlled terminal from multiple devices.
[0117] For obtaining the device identification of the controlled terminal to be controlled, reference may be made to the prior art, and the embodiments of the present application do not impose any limitation thereto.
[0118] Step 202: Generate a remote connection request carrying a device identifier.
[0119] A remote connection request refers to a request initiated by the control end to the controlled end, in which the control end attempts to establish a remote control connection with the controlled end.
[0120] The remote connection request carries the device identification of the controlled end.
[0121] The method of generating the remote connection request may refer to the prior art, and the embodiments of the present application do not limit it.
[0122] Step 203: Send a remote connection request to the controlled end indicated by the device identifier, so that the controlled end sends a control password to the controlling end based on the remote connection request.
[0123] Specifically, a remote connection request is sent to the controlled end indicated by the device identifier, so that the controlled end responds to the remote connection request, obtains the control password stored on the controlled end, and sends the control password to the control end.
[0124] For details about how the controlled end sends the control password to the controlling end in response to the remote connection request, please refer to the relevant description in the above remote control method applied to the controlled end, which will not be repeated here.
[0125] Step 204: Establish a remote control connection with the controlled terminal according to the control password and the device identification of the controlled terminal.
[0126] In some embodiments, the above process of establishing a remote control connection with the controlled end based on the control password and the device identification of the controlled end may include: generating a password verification request based on the control password and the device identification of the controlled end; sending the password verification request to the server, triggering the server to verify the control password based on the verification-related information, and if the verification is successful, sending a verification success instruction to the controlled end and the control end respectively; in response to the verification success instruction, the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end.
[0127] The password verification request refers to a request initiated by the control end to the service end for verifying the correctness of the control password received by the control end.
[0128] It should be noted that when the controlled end sends a control password to the controlling end, the control password may have become invalid during the transmission process. Therefore, when the controlling end receives the control password, it is necessary to verify the correctness of the control password (i.e., validity verification) through the server.
[0129] The specific process of sending a password verification request to the server, triggering the server to verify the control password based on the verification-related information, and sending verification success instructions to the controlled end and the controlling end respectively when the verification is successful can be: sending a password verification request to the server, triggering the server to query the corresponding verification-related information according to the device code carried in the password verification request, verifying the control password corresponding to the password verification request according to the queried verification-related information, and sending verification success instructions to the controlled end and the controlling end respectively when the verification is successful.
[0130] By adopting the scheme of the embodiment of the present application, the device identification of the controlled end to be controlled can be obtained; a remote connection request carrying the device identification can be generated; a remote connection request can be sent to the controlled end indicated by the device identification, so that the controlled end can send a control password to the control end based on the remote connection request; and a remote control connection can be established with the controlled end according to the control password and the device identification of the controlled end. Based on this, by adopting the above method, the transmission link of the control password on the network can be reduced, and the control password is only securely transmitted between the control end and the controlled end, which reduces the password from being obtained by network attacks and improves the security of the control password.
[0131] See also Figure 4 , Figure 4 The remote control method applied to the server provided in the embodiment of the present application may include the following steps 301 to 302:
[0132] Step 301: Receive verification association information sent by the controlled terminal, and associate the verification association information with the device identification of the controlled terminal and store them.
[0133] Step 302: in response to receiving the password verification request sent by the control end, verify the control password received by the control end based on the verification association information, and if the verification is successful, send a verification success instruction to the controlled end and the control end respectively.
[0134] It should be noted that the server mentioned in the embodiment of the present application does not involve the generation and storage of control passwords.
[0135] Compared with traditional remote control methods, the server is usually responsible for the storage, management and verification of passwords, which not only increases the computing and storage burden on the server, but may also affect performance and response speed, especially when used by large-scale users. In addition, the frequent password data interaction between the server and the device increases the communication complexity and network bandwidth occupancy of the system. The embodiments of the present application effectively reduce the burden on the server, requiring only simple password verification without the need to store passwords, thereby reducing resource consumption and improving stability and performance. At the same time, it reduces unnecessary communications between the device and the server due to password management, optimizes the communication process, reduces network latency, and improves the response speed and fluency of remote assistance operations.
[0136] By adopting the scheme of the embodiment of the present application, the verification association information sent by the controlled end can be received, and the verification association information can be associated and stored with the device identification of the controlled end; in response to receiving the password verification request sent by the control end, the control password received by the control end is verified based on the verification association information, and when the verification is successful, a verification success instruction is sent to the controlled end and the control end respectively. Based on this, the burden on the server is reduced, and the server is only responsible for simple password verification work, and there is no need to store the control password, which reduces the resource consumption of the server and helps to improve the stability and performance of the server. In addition, unnecessary communication between the device and the server due to password management is reduced, the system communication process is optimized, the network delay is reduced, and the response speed and fluency of the remote assistance operation are improved. At the same time, since the control password is generated and stored locally on the device and does not involve server storage, it effectively avoids the exposure of user privacy data on the server, and better protects the privacy of users.
[0137] This embodiment also provides a remote control device, which can be integrated into a terminal device.
[0138] For example, Figure 5 As shown, the remote control device is applied to the controlled end, and the remote control device may include:
[0139] The request receiving module 401 is used to receive a remote connection request sent by the control end, wherein the remote connection request carries a device identification of the controlled end;
[0140] The data acquisition module 402 is used to obtain the control password stored on the controlled terminal in response to the remote connection request, wherein the control password is generated on the controlled terminal;
[0141] The data sending module 403 is used to send the control password to the control end, so that the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end.
[0142] In some embodiments, the remote control device further comprises:
[0143] A password generation module, for generating a control password in response to a password generation event of the controlled terminal, wherein the password generation event includes turning on the connectable state of the controlled terminal, or the controlled terminal is in the connectable state and no control password is stored in the secure storage area when receiving a remote connection request;
[0144] The password storage module is used to store the control password in the secure storage area of the controlled end.
[0145] In some embodiments, the control password stored in the above-mentioned secure storage area is a password encrypted by a local storage key.
[0146] Based on this, before the data sending module 403, the remote control device further includes:
[0147] A decryption unit, used to decrypt the control password after storage encryption according to the local storage key of the controlled terminal;
[0148] The encryption unit is used to encrypt the decrypted control password according to the communication key between the controlled terminal and the control terminal;
[0149] Based on this, the data sending module 403 includes:
[0150] The data sending unit is used to send the control password encrypted by communication to the control terminal through the communication connection between the control terminal and the controlled terminal, or through the service terminal, so that the control terminal can decrypt the control password encrypted by communication based on the communication key.
[0151] In some embodiments, the remote control device further comprises:
[0152] The password destruction module is used to destroy the control password and the local storage key stored in the secure storage area in response to a password destruction event, wherein the password destruction event includes at least one of the validity period of the control password exceeding the validity period threshold and the remote control connection being successfully established.
[0153] In some embodiments, when generating the control password, the remote control device further includes:
[0154] A message generation module, used to generate verification associated information of the control password;
[0155] A message sending module, used for sending the verification association information to the server, so that the server associates the verification association information with the device identification of the controlled terminal and stores it;
[0156] Based on this, the control password is sent to the control end so that the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end, including:
[0157] The control password is sent to the control end, so that the control end sends a password verification request including the control password and the device identification of the controlled end to the server end, triggering the server end to verify the control password based on the verification association information, and if the verification is successful, sending a verification success instruction to the controlled end and the control end respectively. In response to the verification success instruction, the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end.
[0158] In some embodiments, the verification-related information includes validity period information of the control password.
[0159] In some embodiments, the controlled end is configured with an intrusion detection system.
[0160] Based on this, the above remote control device also includes:
[0161] A monitoring module, used to monitor whether there are abnormal events in the remote connection scenario on the controlled end through an intrusion detection system, wherein the abnormal events include at least one of abnormal number of accesses to the secure storage area, abnormal password generation, abnormal password transmission, and abnormal password destruction;
[0162] The early warning module is used to perform early warning processing through the intrusion detection system when there are abnormal events on the controlled end.
[0163] By adopting the scheme of the embodiment of the present application, the remote connection request sent by the control end can be received by the request receiving module 401, wherein the remote connection request carries the device identification of the controlled end; the data acquisition module 402 responds to the remote connection request and obtains the control password stored on the controlled end, wherein the control password is generated on the controlled end; the data sending module 403 sends the control password to the control end, so that the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end. Based on this, the control password is generated and stored locally on the device to avoid the risks brought by the storage of the control password on the server side. At the same time, even if the external environment of the device is attacked, as long as the local security mechanism of the device is not breached, the control password will not be leaked, thereby greatly improving the security of the control password.
[0164] For example, Figure 6 As shown, the remote control device is applied to a control end, and the remote control device may include:
[0165] The identification acquisition module 501 is used to acquire the device identification of the controlled terminal to be controlled;
[0166] The request generation module 502 is used to generate a remote connection request carrying a device identification;
[0167] The request sending module 503 is used to send a remote connection request to the controlled end indicated by the device identifier, so that the controlled end sends a control password to the control end based on the remote connection request;
[0168] The connection establishing module 504 is used to establish a remote control connection with the controlled terminal according to the control password and the device identification of the controlled terminal.
[0169] In some embodiments, the connection establishment module 504 includes:
[0170] A password verification request generating unit, used to generate a password verification request according to the control password and the device identification of the controlled terminal;
[0171] A password verification request sending unit is used to send a password verification request to the server, triggering the server to verify the control password based on the verification association information, and in the case of successful verification, send a verification success instruction to the controlled terminal and the control terminal respectively;
[0172] The connection establishing unit is used for responding to the verification success instruction, and the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end.
[0173] By adopting the scheme of the embodiment of the present application, the device identification of the controlled end to be controlled can be obtained through the identification acquisition module 501; the request generation module 502 generates a remote connection request carrying the device identification; the request sending module 503 sends a remote connection request to the controlled end indicated by the device identification, so that the controlled end sends a control password to the control end based on the remote connection request; the connection establishment module 504 establishes a remote control connection with the controlled end according to the control password and the device identification of the controlled end. Based on this, through the above method, the transmission link of the control password on the network is reduced, and the control password is only securely transmitted between the control end and the controlled end, which reduces the password from being obtained by network attacks and improves the security of the password.
[0174] For example, Figure 7 As shown, the remote control device is applied to the server, and the remote control device may include:
[0175] The first receiving module 601 is used to receive the verification association information sent by the controlled terminal, and associate the verification association information with the device identification of the controlled terminal and store it;
[0176] The second receiving module 602 is used to verify the control password received by the control end based on the verification association information in response to receiving the password verification request sent by the control end, and send a verification success instruction to the controlled end and the control end respectively if the verification passes.
[0177] By adopting the scheme of the embodiment of the present application, the verification association information sent by the controlled end can be received by the first receiving module 601, and the verification association information can be associated with the device identification of the controlled end and stored; the second receiving module 602 responds to the password verification request sent by the control end, verifies the control password received by the control end based on the verification association information, and sends a verification success instruction to the controlled end and the control end respectively when the verification is passed. Based on this, the burden on the server is reduced, and the server is only responsible for simple password verification work, without the need to store passwords, which reduces the resource consumption of the server and helps to improve the stability and performance of the server. In addition, unnecessary communication between the device and the server due to password management is reduced, the system communication process is optimized, the network delay is reduced, and the response speed and fluency of the remote assistance operation are improved. At the same time, since the control password is generated and stored locally on the device, it does not involve server storage, which effectively avoids the exposure of user privacy data on the server, and better protects the privacy of users.
[0178] Accordingly, the embodiment of the present application also provides an electronic device, which may be a terminal, and the terminal may be a smart phone, a tablet computer, a laptop computer, a touch screen, a game console, a personal computer (PC, Personal Computer), a personal digital assistant (Personal Digital Assistant, PDA) and other terminal devices. Alternatively, the electronic device may be a server.
[0179] like Figure 8 As shown, Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device 700 includes a processor 701 having one or more processing cores, a memory 702 having one or more computer-readable storage media, and a computer program stored in the memory 702 and executable on the processor. The processor 701 is electrically connected to the memory 702. Those skilled in the art will appreciate that the electronic device structure shown in the figure does not constitute a limitation on the electronic device, and may include more or fewer components than shown, or combine certain components, or arrange components differently.
[0180] The processor 701 is the control center of the electronic device 700, and uses various interfaces and lines to connect various parts of the entire electronic device 700. By running or loading software programs and / or units stored in the memory 702, and calling data stored in the memory 702, the processor 701 executes various functions of the electronic device 700 and processes data, thereby monitoring the electronic device 700 as a whole. The processor 701 can be a central processing unit CPU, a graphics processing unit GPU, a network processor (Network Processor, NP), etc., and can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application.
[0181] In the embodiment of the present application, the processor 701 in the electronic device 700 will load instructions corresponding to the processes of one or more application programs into the memory 702 according to the following steps, and the processor 701 will run the application programs stored in the memory 702 to implement various functions, such as:
[0182] Receiving a remote connection request sent by the control end, wherein the remote connection request carries a device identifier of the controlled end;
[0183] In response to the remote connection request, obtaining a control password stored on the controlled terminal, wherein the control password is generated on the controlled terminal;
[0184] The control password is sent to the control end, so that the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end.
[0185] By using the electronic device provided by the embodiment of the present application, the controlled end can receive a remote connection request sent by the control end, wherein the remote connection request carries the device identification of the controlled end; in response to the remote connection request, obtain a control password stored on the controlled end, wherein the control password is generated on the controlled end; send the control password to the control end, so that the control end can establish a remote control connection with the controlled end based on the control password and the device identification of the controlled end. Based on this, the control password is generated and stored locally on the device to avoid the risks brought by the storage of the control password on the server end. At the same time, even if the external environment of the device is attacked, as long as the local security mechanism of the device is not breached, the control password will not be leaked, thereby greatly improving the security of the password.
[0186] The specific implementation of the above operations can be found in the previous embodiments, which will not be described in detail here.
[0187] Optional, such as Figure 8 As shown, the electronic device 700 further includes: a touch screen 703, a radio frequency circuit 704, an audio circuit 705, an input unit 706, and a power supply 707. The processor 701 is electrically connected to the touch screen 703, the radio frequency circuit 704, the audio circuit 705, the input unit 706, and the power supply 707, respectively. Those skilled in the art can understand that Figure 8 The electronic device structure shown in the figure does not constitute a limitation of the electronic device, and may include more or less components than shown in the figure, or combine certain components, or arrange the components differently.
[0188] The touch display screen 703 can be used to display a graphical user interface and receive operation instructions generated by the user acting on the graphical user interface. The touch display screen 703 may include a display panel and a touch panel. Among them, the display panel may be used to display information input by the user or information provided to the user and various graphical user interfaces of the electronic device, and these graphical user interfaces may be composed of graphics, text, icons, videos and any combination thereof. Optionally, the display panel may be configured in the form of a liquid crystal display (LCD, Liquid Crystal Display), an organic light-emitting diode (OLED, Organic Light-Emitting Diode) and the like. The touch panel may be used to collect the user's touch operation on or near it (such as the user using any suitable object or attachment such as a finger, a stylus, etc. on the touch panel or near the touch panel), and generate corresponding operation instructions, and the operation instructions execute corresponding programs. Optionally, the touch panel may include two parts, a touch detection device and a touch controller. Among them, the touch detection device detects the user's touch orientation, detects the signal brought by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device, converts it into the touch point coordinates, and then sends it to the processor 701, and can receive the command sent by the processor 701 and execute it. The touch panel can cover the display panel. When the touch panel detects a touch operation on or near it, it is transmitted to the processor 701 to determine the type of touch event, and then the processor 701 provides a corresponding visual output on the display panel according to the type of touch event. In an embodiment of the present application, the touch panel and the display panel can be integrated into the touch display screen 703 to realize the input and output functions. However, in some embodiments, the touch panel and the touch panel can be used as two independent components to realize the input and output functions. That is, the touch display screen 703 can also be used as a part of the input unit 706 to realize the input function.
[0189] The radio frequency circuit 704 may be used to send and receive radio frequency signals, so as to establish wireless communication with a network device or other electronic devices through wireless communication, and to send and receive signals between the network device or other electronic devices.
[0190] The audio circuit 705 can be used to provide an audio interface between the user and the electronic device through a speaker and a microphone. The audio circuit 705 can transmit the electrical signal converted from the received audio data to the speaker, which is converted into a sound signal for output; on the other hand, the microphone converts the collected sound signal into an electrical signal, which is received by the audio circuit 705 and converted into audio data, and then the audio data is output to the processor 701 for processing, and then sent to another electronic device through the radio frequency circuit 704, or the audio data is output to the memory 702 for further processing. The audio circuit 705 may also include an earplug jack to provide communication between an external headset and an electronic device.
[0191] The input unit 706 may be used to receive a user trigger to enable the device to be in a connectable state, receive a user trigger to enable the device to perform remote connection control, and the like.
[0192] The power supply 707 is used to supply power to various components of the electronic device 700. Optionally, the power supply 707 can be logically connected to the processor 701 through a power management system, so that the power management system can manage charging, discharging, and power consumption. The power supply 707 can also include one or more DC or AC power supplies, recharging systems, power failure detection circuits, power converters or inverters, power status indicators, and other arbitrary components.
[0193] although Figure 8 Not shown, the electronic device 700 may also include a camera, a sensor, a wireless fidelity module, a Bluetooth module, etc., which will not be described in detail here.
[0194] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0195] A person of ordinary skill in the art will appreciate that all or part of the steps in the various methods of the above embodiments may be completed by instructions, or by controlling related hardware through instructions. The instructions may be stored in a computer-readable storage medium and loaded and executed by a processor.
[0196] To this end, an embodiment of the present application provides a computer-readable storage medium, in which multiple computer programs are stored, and the computer program can be loaded by a processor to execute any remote control method provided in the embodiment of the present application. The computer program can execute the following steps of the remote control method:
[0197] Receiving a remote connection request sent by the control end, wherein the remote connection request carries a device identifier of the controlled end;
[0198] In response to the remote connection request, obtaining a control password stored on the controlled terminal, wherein the control password is generated on the controlled terminal;
[0199] The control password is sent to the control end, so that the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end.
[0200] By using the computer-readable storage medium provided in the embodiment of the present application, a remote connection request sent by a control terminal can be received by a controlled terminal, wherein the remote connection request carries the device identification of the controlled terminal; in response to the remote connection request, a control password stored on the controlled terminal is obtained, wherein the control password is generated on the controlled terminal; the control password is sent to the control terminal, so that the control terminal establishes a remote control connection with the controlled terminal based on the control password and the device identification of the controlled terminal. Based on this, the control password is generated and stored locally on the device to avoid the risks brought by the storage of the control password on the server side. At the same time, even if the external environment of the device is attacked, as long as the local security mechanism of the device is not breached, the control password will not be leaked, thereby greatly improving the security of the password.
[0201] The specific implementation of the above operations can be found in the previous embodiments, which will not be described in detail here.
[0202] The computer-readable storage medium may include: a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0203] Since the computer program stored in the computer-readable storage medium can execute any remote control method provided in the embodiments of the present application, the beneficial effects that can be achieved by any remote control method provided in the embodiments of the present application can be achieved. Please refer to the previous embodiments for details and will not be repeated here.
[0204] According to one aspect of the present application, a computer program product or a computer program is also provided, the computer program product or the computer program including computer instructions, the computer instructions being stored in a computer-readable storage medium. A processor of an electronic device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the electronic device executes the methods provided in various optional implementations of the above embodiments.
[0205] In the above-mentioned remote control device, computer-readable storage medium, electronic device, and computer program product embodiments, the description of each embodiment has its own emphasis. For parts not described in detail in a certain embodiment, reference can be made to the relevant description of other embodiments. Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working process and beneficial effects of the above-described remote control device, computer-readable storage medium, computer program product, electronic device, and its corresponding units can refer to the description of the remote control method in the above embodiment, and will not be repeated here.
[0206] The above is a detailed introduction to a remote control method, device, electronic device, computer-readable storage medium and computer program product provided in the embodiments of the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for technical personnel in this field, according to the ideas of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A remote control method, characterized in that: Applied to the controlled end, the method includes: Receiving a remote connection request sent by a control terminal, wherein the remote connection request carries a device identifier of the controlled terminal; In response to the remote connection request, obtaining a control password stored on the controlled terminal, wherein the control password is generated on the controlled terminal; The control password is sent to the control terminal, so that the control terminal establishes a remote control connection with the controlled terminal based on the control password and the device identification of the controlled terminal.
2. The remote control method according to claim 1, characterized in that: The method further comprises: In response to a password generation event of the controlled terminal, generating a control password, wherein the password generation event includes turning on the connectable state of the controlled terminal, or the controlled terminal is in a connectable state and does not store a control password in a secure storage area when receiving a remote connection request; The control password is stored in the secure storage area of the controlled terminal.
3. The remote control method according to claim 2, characterized in that: The control password stored in the secure storage area is a password encrypted by a local storage key. Before sending the control password to the control terminal, the method further includes: Decrypting the control password after storage encryption according to the local storage key of the controlled terminal; encrypting the decrypted control password according to the communication key between the controlled terminal and the control terminal; The sending the control password to the control terminal includes: The control password encrypted by communication is sent to the control terminal through the communication connection between the control terminal and the controlled terminal, or through the service terminal, so that the control terminal decrypts the control password encrypted by communication based on the communication key.
4. The remote control method according to claim 3, characterized in that: The method further comprises: In response to a password destruction event, the control password and the local storage key stored in the secure storage area are destroyed, wherein the password destruction event includes at least one of the validity period of the control password exceeding a validity period threshold and the remote control connection being successfully established.
5. The remote control method according to claim 2, characterized in that: When generating the control password, the method further includes: Generating verification associated information of the control password; Sending the verification association information to the server, so that the server associates the verification association information with the device identification of the controlled terminal and stores it; The step of sending the control password to the control terminal so that the control terminal establishes a remote control connection with the controlled terminal based on the control password and the device identification of the controlled terminal includes: The control password is sent to the control end, so that the control end sends a password verification request including the control password and the device identification of the controlled end to the server end, triggering the server end to verify the control password based on the verification association information, and if the verification is successful, sending a verification success instruction to the controlled end and the control end respectively. In response to the verification success instruction, the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end.
6. The remote control method according to claim 5, characterized in that: The verification-related information includes validity period information of the control password.
7. The remote control method according to any one of claims 1 to 6, characterized in that: The controlled end is configured with an intrusion detection system, and the method further comprises: Monitoring the controlled end for abnormal events in remote connection scenarios through the intrusion detection system, wherein the abnormal events include at least one of abnormal number of accesses to the secure storage area, abnormal password generation, abnormal password transmission, and abnormal password destruction; In the event that an abnormal event occurs at the controlled end, an early warning process is performed through the intrusion detection system.
8. A remote control method, characterized in that: Applied to the control end, the method includes: Obtain the device identification of the controlled end to be controlled; generating a remote connection request carrying the device identification; Sending the remote connection request to the controlled end indicated by the device identifier, so that the controlled end sends a control password to the controlling end based on the remote connection request; A remote control connection is established with the controlled terminal according to the control password and the device identification of the controlled terminal.
9. The remote control method according to claim 8, characterized in that: The step of establishing a remote control connection with the controlled terminal according to the control password and the device identification of the controlled terminal includes: Generate a password verification request according to the control password and the device identification of the controlled terminal; Sending the password verification request to the server, triggering the server to verify the control password based on the verification association information, and sending a verification success instruction to the controlled terminal and the control terminal respectively if the verification is successful; In response to the verification success instruction, the control end establishes a remote control connection with the controlled end based on the control password and the device identification of the controlled end.
10. A remote control method, characterized in that: Applied to the server, the method includes: Receiving verification association information sent by the controlled terminal, and associating and storing the verification association information with the device identification of the controlled terminal; In response to receiving a password verification request sent by the control end, the control password received by the control end is verified based on the verification association information, and if the verification is successful, a verification success instruction is sent to the controlled end and the control end respectively.
11. A remote control device, characterized in that: Applied to the controlled end, the device comprises: A request receiving module, used for receiving a remote connection request sent by a control terminal, wherein the remote connection request carries a device identification of the controlled terminal; a data acquisition module, configured to acquire a control password stored on the controlled terminal in response to the remote connection request, wherein the control password is generated on the controlled terminal; The data sending module is used to send the control password to the control terminal, so that the control terminal establishes a remote control connection with the controlled terminal based on the control password and the device identification of the controlled terminal.
12. An electronic device, characterized in that: The remote control method comprises a processor and a memory, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the remote control method according to any one of claims 1 to 10.
13. A computer-readable storage medium, characterized in that: The remote control method comprises a computer program. When the computer program is run on an electronic device, the computer program is used to enable the electronic device to execute the steps of the remote control method according to any one of claims 1 to 10.