Access control method, electronic equipment and storage medium

By generating prompt information in remote access technology, users are required to authorize the second device to access the privacy information collection function module, which solves the problem that users cannot perceive remote access in a timely manner and enhances privacy and security protection.

CN120030520APending Publication Date: 2025-05-23ZTE CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311564732.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-21
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

In remote access technology, users cannot sense the occurrence of remote access in a timely manner, resulting in the inability to take necessary security measures in a timely manner, posing a threat to users' privacy and security.

Method used

By generating prompt information in the first device, the user is prompted to grant the second device permission to remotely access the functional module used to collect privacy information, thereby enhancing the user's remote access awareness and control rights.

Benefits of technology

Enhance users' control over remote access, ensure users' privacy and security, and prevent unauthorized access to privacy information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030520A_ABST
    Figure CN120030520A_ABST
Patent Text Reader

Abstract

The invention provides an access control method, electronic equipment and a storage medium, relates to the field of communication, and is used for guaranteeing privacy security of a user. The method comprises the following steps: receiving a remote access request of second equipment; under the condition that the remote access request is used for requesting to access a first type of function module of the first device, first prompt information is generated, the first prompt information is used for prompting a user whether to grant a permission to remotely access the first type of function module to the second device, and the first type of function module is a function module used for collecting privacy information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of communications, and in particular to an access control method, an electronic device, and a storage medium. Background Art

[0002] With the development of science and technology, remote access technology is becoming more and more mature; remote access technology has been widely used in different fields such as enterprises, institutions and individuals. It can provide convenience for users, such as providing users with functions such as remote office, remote monitoring and remote collaboration.

[0003] When a remote device accesses a local device (such as IoT devices, smart home devices, and surveillance cameras), if the user cannot promptly perceive the occurrence of remote access, the user will not be able to take necessary security measures in time to manage the permissions of the remote access device, which may cause the user's privacy security to be violated. Summary of the invention

[0004] The embodiments of the present disclosure provide an access control method, an electronic device, and a storage medium, which are used to at least protect the privacy security of a user.

[0005] In a first aspect, an access control method is provided, which is applied to a first device; the method comprises:

[0006] receiving a remote access request from a second device;

[0007] When the remote access request is used to request access to a first type of functional module of a first device, a first prompt message is generated, and the first prompt message is used to prompt the user whether to grant the second device remote access to the first type of functional module, and the first type of functional module is a functional module used to collect privacy information.

[0008] Based on the access control method provided by the embodiment of the present disclosure, after receiving the remote access request from the second device, the first device generates a first prompt message to prompt the user whether to grant the second device remote access to the first type of functional module when the remote access request is used to request access to the first type of functional module of the first device (the first type of functional module is a functional module used to collect privacy information), that is, when the second device has the risk of collecting the privacy information of the user or the first device. It can be seen that in the method provided by the embodiment of the present disclosure, the first device generates the first prompt message, which not only enhances the user's perception of the remote access of the second device, but also provides the user with the control right of whether to grant the second device remote access, thereby enhancing the user's control over the remote access of the second device and thus protecting the user's privacy security.

[0009] In a second aspect, an electronic device is provided, comprising: a memory and a processor; the memory and the processor are coupled; the memory is used to store a computer program; and the processor implements the access control method of any of the above embodiments when executing the computer program.

[0010] In a third aspect, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the access control method of any of the above embodiments is implemented.

[0011] For the specific description of the second to third aspects and their various implementations in the embodiments of the present disclosure, reference can be made to the detailed description in the first aspect and its various implementations; and for the beneficial effects of the second to third aspects and their various implementations, reference can be made to the analysis of the beneficial effects in the first aspect and its various implementations, which will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the technical solutions in the present disclosure, the drawings required for use in some embodiments of the present disclosure will be briefly introduced below. Obviously, the drawings described below are only drawings of some embodiments of the present disclosure, and a person skilled in the art can also obtain other drawings based on these drawings.

[0013] Figure 1 A schematic diagram of a system architecture provided for an embodiment of the present disclosure;

[0014] Figure 2 A schematic diagram of the structure of a first device provided in an embodiment of the present disclosure;

[0015] Figure 3 A flowchart of an access control method provided by an embodiment of the present disclosure;

[0016] Figure 4 A flowchart of another access control method provided by an embodiment of the present disclosure;

[0017] Figure 5 A flowchart of another access control method provided by an embodiment of the present disclosure;

[0018] Figure 6 A flowchart of another access control method provided by an embodiment of the present disclosure;

[0019] Figure 7 A flowchart of another access control method provided by an embodiment of the present disclosure;

[0020] Figure 8 A flowchart of another access control method provided by an embodiment of the present disclosure;

[0021] Fig. 9A schematic diagram of the structure of an access control device provided by an embodiment of the present disclosure;

[0022] Fig.10 A schematic diagram of the structure of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0023] The following will be combined with the drawings in the present disclosure to clearly and completely describe the technical solutions in the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present disclosure.

[0024] It should be noted that, in the present disclosure, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the present disclosure should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.

[0025] In the following, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features.

[0026] In the description of the present disclosure, unless otherwise specified, " / " means "or", for example, A / B can mean A or B. "And / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, "at least one" means one or more, and "a plurality" means two or more.

[0027] With the development of science and technology, remote access technology is becoming more and more mature. Remote access technology has been widely used in different fields such as enterprises, institutions and individuals, and it can provide convenience for users. For example, the home version of the smart speaker has the function of care mode. Users can remotely access the home version of the smart speaker and use the camera configured on the home version of the smart speaker to take care of the elderly and children at home. However, if the home version of the smart speaker is placed in other scenarios (such as hotels, homestays, etc.), there may be some remote devices (or remote accounts) that accidentally or illegally access the home version of the smart speaker. If the user cannot perceive the access of the remote device in time, it will not be possible to restrict and control it in time, which may cause the user's privacy and security to be violated.

[0028] In response to the above technical problems, the embodiments of the present disclosure provide an access control method, the idea of ​​which is that after receiving a remote access request from a second device, the first device generates a first prompt message to prompt the user whether to grant the second device remote access to the first type of functional module when the remote access request is used to request access to the first type of functional module of the first device (the first type of functional module is a functional module used to collect privacy information), that is, when the second device has a risk of collecting the privacy information of the user or the first device. It can be seen that the method provided by the embodiments of the present disclosure enhances the user's perception of remote access to the second device by generating the first prompt message, and provides the user with control over whether to grant remote access to the second device, thereby enhancing the user's control over remote access to the second device and thereby protecting the user's privacy security.

[0029] See also Figure 1 , is a schematic diagram of the architecture of the system involved in the access control method provided in the embodiment of the present disclosure. Figure 1 As shown, the system includes: a first device 100, a second device 200 and a server 300; wherein the second device 200 and the server 300 are respectively communicatively connected with the first device 100.

[0030] The first device 100 is used to receive a remote access request from the second device 200 , and based on the remote access request, confirm whether to grant the second device 200 the permission to remotely access the first device 100 .

[0031] In some embodiments, remote access refers to the act of sending a request message from one device to another device to obtain or operate a remote resource through a communication method such as a cellular network or a wireless fidelity (WiFi) network.

[0032] In some embodiments, Figure 2 As shown, the first device 100 includes: a receiving module 101, a query module 102, a parsing module 103, a detection module 104, a request module 105, a prompt module 106 and a playing module 107.

[0033] In some embodiments, the receiving module 101 is used to receive a remote access request from the second device 200. Exemplarily, the receiving module 101 receives a data message from the second device 200 via a cellular network or a WIFI network, and the data message includes the remote access request from the second device 200.

[0034] In some embodiments, the query module 102 is used to query whether the remote access permission function of the first device 100 is turned on, and is also used to query whether the first device 100 has set a remote access whitelist and whether the first device 100 has turned on the privacy mode.

[0035] The parsing module 103 is used to parse the remote access request to determine the relevant information of the second device 200, and the remote access request of the second device 200 is used to access the first type of functional module of the first device 100. In some embodiments, the remote access request includes at least one of the following: the login account, device identification, geographic location, time of requesting remote access, and the local area network where the second device 200 is located; the first type of functional module is a functional module for collecting privacy information. Exemplarily, the first type of functional module can be a camera, a microphone, a sensor, etc.

[0036] It should be noted that the above remote access content is only an example given in the embodiment of the present disclosure. In actual application, the content of the remote access request may be more or less than that given in the embodiment of the present disclosure, and the embodiment of the present disclosure does not limit this.

[0037] The request module 105 is used to send a request to the first device 100 and / or the server 300 so that the first device 100 and / or the server 300 confirms whether the access behavior of the second device 200 is compliant.

[0038] The prompt module 106 is used to prompt the user whether to grant the second device 200 the permission to remotely access the first type of functional modules of the first device 100. In some embodiments, the prompt module 106 is also used to prompt the user that the second device 200 is performing remote access.

[0039] The playing module 107 is used to play the audio and video preset locally on the first device 100 after the user refuses to grant the second device 200 the permission to remotely access the first device 100, so as to prompt the user of the second device 200 that it does not allow remote access.

[0040] The detection module 104 is used to receive the request sent by the request module 105, and detect whether the access behavior of the second device 200 is compliant based on the request.

[0041] Exemplarily, the first device 100 may be a smart speaker, a smart watch, a smart bracelet, a smart TV, a mobile phone, a tablet computer, a camera, a smart air conditioner, a smart refrigerator, a smart curtain, or other device that can access the network and collect user information. The embodiment of the present disclosure does not impose any special restrictions on the specific form of the first device 100.

[0042] The second device 200 is used to send a remote access request to the first device 100, and remotely access the first type of functional modules when the first device 100 grants the second device 200 a permission to remotely access the first type of functional modules of the first device 100.

[0043] Exemplarily, the second device 200 may be a mobile phone, a tablet computer, a desktop, a laptop, a handheld computer, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, a personal digital assistant (PDA), an augmented reality (AR) or virtual reality (VR) device, and other devices with remote access capabilities. The embodiments of the present disclosure do not impose any special restrictions on the specific form of the second device 200.

[0044] The server 300 is used to store user data and device information. In some embodiments, the server 300 is used to receive a request sent by the request module 105, and detect whether the access behavior of the second device 200 is compliant based on the request.

[0045] In some embodiments, the receiving module 101 is further used to receive a detection result of whether the access behavior of the server 300 to the second device 200 is compliant.

[0046] Exemplarily, the server 300 may be a single server, or may be a server cluster composed of multiple servers. In some implementations, the server cluster may also be a distributed cluster.

[0047] It should be noted that the system architecture and application scenarios described in the embodiments of the present disclosure are intended to more clearly illustrate the technical solutions of the embodiments of the present disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. A person of ordinary skill in the art can appreciate that with the evolution of the system architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of the present disclosure are equally applicable to similar technical problems.

[0048] An access control method provided by an embodiment of the present disclosure is described below in conjunction with the accompanying drawings.

[0049] See also Figure 3 , is a flow chart of an access control method provided by an embodiment of the present disclosure. Figure 3 As shown, the access control method provided in the embodiment of the present disclosure is applied to a terminal, and can be specifically implemented as the following steps:

[0050] S101: Receive a remote access request from a second device.

[0051] In some embodiments, the first device receives a data packet sent by the second device, where the data packet includes a remote access request of the second device; the remote access request is used to request access to the first device.

[0052] In some embodiments, the remote access request includes at least one of the following: the login account of the second device, the device identification, the geographic location, the time of the remote access request, and the local area network where the second device is located. Exemplarily, the remote access request of the second device includes: the login account of the second device: 123; the device identification: 321; the geographic location: Shanghai; the time of the remote access request: 16:25; the local area network where the second device is located: local area network A.

[0053] In some embodiments, the remote access request also includes: relevant information of the functional module requested to be accessed by the second device. As an example, the remote access request may include the module name of the functional module requested to be accessed. Exemplarily, if the second device requests access to a camera, the remote access request includes: functional module requested to be accessed: camera. As another example, the remote access request may include the module identifier of the functional module requested to be accessed. Exemplarily, if the second device requests access to a microphone, and the module identifier of the microphone is 222, the remote access request includes: functional module requested to be accessed: 222.

[0054] S102: When the remote access request is used to request access to a first type of functional module of a first device, generate first prompt information.

[0055] The first prompt information is used to prompt the user whether to grant the second device permission to remotely access the first type of functional modules.

[0056] As an example, the first prompt information may be audio information, for example, audio for prompting the user whether to grant the second device permission to remotely access the first type of functional modules.

[0057] As another example, the first prompt information may be image information, for example, an image used to prompt the user whether to grant the second device permission to remotely access the first type of functional modules.

[0058] It should be noted that the form of the above-mentioned first prompt information is only some examples given in the embodiments of the present disclosure. In actual implementation, the form of the first prompt information may be different according to actual needs and the device capabilities of the first device, and the embodiments of the present disclosure are not limited to this.

[0059] In some embodiments, the first device includes a first type of functional module and a second type of functional module. The first type of functional module is a functional module for collecting private information, such as a camera, a microphone, a sensor, etc. The second type of functional module is a functional module that does not involve the collection of private information, such as a timer, a switch, etc.

[0060] In some embodiments, after receiving the remote access request, the first device parses the remote access request to determine whether the functional module requested by the second device to access is a first-category functional module or a second-category functional module. Exemplarily, when the first device parses the remote access request and determines that the functional module requested by the second device to access is a camera, that is, when the second device requests to access the first-category functional module, the first prompt information is generated.

[0061] It is understandable that after receiving the remote access request from the second device, the first device generates a first prompt message to prompt the user whether to grant the second device remote access to the first type of functional module when the remote access request is used to request access to the first type of functional module of the first device (the first type of functional module is a functional module for collecting privacy information), that is, when the second device has the risk of collecting the privacy information of the user or the first device. It can be seen that in the method provided by the embodiment of the present disclosure, the first device generates the first prompt message, which not only enhances the user's perception of the remote access of the second device, but also provides the user with the control right of whether to grant the second device remote access, thereby enhancing the user's control over the remote access of the second device, and thus protecting the user's privacy security.

[0062] As a possible implementation method, after generating the first prompt information, Figure 4 As shown, the above method also includes: steps S103a-S105a.

[0063] S103a: Receive a first operation from a user for instructing to grant the second device permission to remotely access a first type of functional module.

[0064] As an example, the first operation can be a voice command operation that the user can perform through a voice assistant of the first device or a voice recognition function of the first device. Exemplarily, the user directly issues a voice command to the first device through the voice recognition function of the first device to grant the second device remote access to the first type of functional module. For example, the user can say: "Allow the second device to access the camera", and the first device will receive the user's first operation.

[0065] As another example, the first operation may be a click operation of the user on the display interface of the first device. Exemplarily, the user opens the system setting interface on the first device and grants the second device remote access to the first type of functional modules through a simple click operation.

[0066] It should be noted that the specific content of the above-mentioned first operation is only some examples given in the embodiments of the present disclosure. In specific implementation, the content of the first operation may also be different based on different user selections and different capabilities of the first device, and the embodiments of the present disclosure are not limited to this.

[0067] S104a: In response to the first operation, execute an operation corresponding to the remote access request.

[0068] In some embodiments, after receiving the first operation, the first device executes the operation corresponding to the remote access request. At this time, the second device can access the first type of functional module of the first device.

[0069] S105a: Generate second prompt information.

[0070] The second prompt information is used to prompt the user that the second device is remotely accessing the first type of functional module of the first device.

[0071] As an example, the second prompt information may be audio information, for example, audio for prompting the user that the second device is remotely accessing the first type of functional module.

[0072] As another example, the second prompt information may be text information, for example, text prompting the user that the second device is remotely accessing the first type of functional module.

[0073] It should be noted that the form of the above-mentioned second prompt information is only some examples given in the embodiments of the present disclosure. In actual implementation, the form of the second prompt information may be different according to actual needs and the device capabilities of the first device, and the embodiments of the present disclosure are not limited to this.

[0074] It can be understood that in the method provided by the embodiment of the present disclosure, when the second device accesses the first type of functional module of the first device, the first device prompts the user by generating a second prompt message, so that the user can perceive the access behavior of the second device, which is convenient for the user to manage and control the second device according to the access behavior of the second device, thereby reducing the risk of user privacy leakage and improving the user's usage experience.

[0075] As an example, in response to the first operation, after executing the operation corresponding to the remote access request, in addition to generating the second prompt information, such as Figure 5 As shown, the above method also includes: steps S201a-S202a.

[0076] S201a: Determine the duration of this visit of the second device.

[0077] In some embodiments, after the first device performs the operation corresponding to the remote access request, that is, after the second device starts to remotely access the first type of functional module, the access duration of the second device is accumulated.

[0078] S202a: When the duration of the current visit is greater than the first threshold, generate third prompt information.

[0079] The third prompt information is used to prompt the user whether to disconnect the remote access of the second device.

[0080] As an example, the third prompt information may be audio information, for example, audio for prompting the user whether to disconnect the remote access of the second device.

[0081] As another example, the third prompt information may be text information, such as text for prompting the user whether to disconnect the remote access of the second device. In addition, the first device may also provide the user with a button for disconnecting the remote access so that the user can operate it.

[0082] It should be noted that the form of the third prompt information mentioned above is only some examples given in the embodiments of the present disclosure. In actual implementation, the form of the third prompt information may be different depending on actual needs and the device capabilities of the first device, and the embodiments of the present disclosure are not limited to this.

[0083] In some embodiments, the first threshold may be 30 minutes. For example, if the duration of this access is 31 minutes, which is greater than the first threshold, the first device plays an audio message "Access has timed out" to prompt the user whether to disconnect the remote access of the second device.

[0084] It is understandable that the method provided by the embodiment of the present disclosure, after the first device grants the second device permission to access the first type of functional module, will also determine the duration of this access of the second device to ensure that the second device does not excessively access the first type of functional module. At the same time, the method provided by the embodiment of the present disclosure generates a third prompt message when the duration of this access is greater than the first threshold, thereby enhancing the user's perception of the duration of the access to the second device, so that the user can further determine whether to disconnect the remote access of the second device, thereby improving the management and control of remote access to the second device.

[0085] In some embodiments, if the user disconnects the remote access of the second device based on the third prompt information, then after the above step S202a, the above method further includes: receiving a second operation of the user for instructing to disconnect the remote access of the second device, and in response to the second operation, sending a prompt information to the second device for indicating that the first device disconnects the remote access of the second device. Exemplarily, the prompt information for indicating that the first device disconnects the remote access of the second device can be audio information. For example, the first device generates an audio of "remote access disconnected" and sends it to the second device.

[0086] As an example, the second operation may be a voice command operation that the user can perform through a voice assistant of the first device or a voice recognition function of the first device. Exemplarily, the user directly issues a voice command to the first device through the voice recognition function of the first device, instructing to disconnect the remote access of the second device. For example, the user may say: "Disconnect the remote access of the second device".

[0087] As another example, the second operation may be a click operation by the user on the display interface of the first device; illustratively, the user clicks a button for disconnecting remote access on the first device to indicate disconnecting remote access of the second device.

[0088] It should be noted that the specific content of the above-mentioned second operation is only some examples given in the embodiments of the present disclosure. In specific implementation, the content of the second operation may also be different based on different user selections and different capabilities of the first device, and the embodiments of the present disclosure are not limited to this.

[0089] It can be understood that in the method provided by the embodiment of the present disclosure, after receiving the second operation of the user, the first device will disconnect the remote access of the second device to reduce potential security risks; at the same time, the first device will send a prompt message to the second device to prompt the second device that the remote access has been disconnected, so that the second device can determine the status of its remote access in time and enhance user perception.

[0090] As another example, in response to the first operation, after executing the operation corresponding to the remote access request, in addition to generating the second prompt information, such as Figure 6 As shown, the above method also includes: steps S201b-S202b.

[0091] S201b: Determine the duration of this visit of the second device.

[0092] In some embodiments, after the first device performs the operation corresponding to the remote access request, that is, after the second device starts to remotely access the first type of functional module, the access duration of the second device is accumulated.

[0093] S202b: When the duration of the current visit is greater than the first threshold, generate fourth prompt information.

[0094] The fourth prompt information is used to indicate that the first device disconnects the remote access of the second device.

[0095] As an example, the fourth prompt information may be audio information, for example, audio used to indicate that the first device disconnects the remote access of the second device.

[0096] As another example, the fourth prompt information may be text information, such as text indicating that the first device disconnects the remote access of the second device.

[0097] It should be noted that the form of the above-mentioned fourth prompt information is only some examples given in the embodiments of the present disclosure. In actual implementation, the form of the fourth prompt information may be different according to actual needs and the device capabilities of the first device, and the embodiments of the present disclosure are not limited to this.

[0098] In some embodiments, the first threshold may be 20 minutes. For example, if the duration of this access is 21 minutes, which is greater than the first threshold, the first device plays an audio message "This access has timed out, remote access has been disconnected" to prompt the first device to disconnect the remote access of the second device.

[0099] It is understandable that the method provided in the embodiment of the present disclosure, after the first device grants the second device permission to access the first type of functional module, will also determine the duration of the second device's current access to ensure that the second device does not excessively access the first type of functional module. At the same time, the method provided in the embodiment of the present disclosure generates a fourth prompt message when the duration of the current access is greater than the first threshold, thereby enhancing the user's perception of the duration of the access to the second device and promptly prompting the second device that its remote access has been disconnected.

[0100] As another possible implementation, Figure 7 As shown, after generating the first prompt information, the method further includes: steps S103b-S104b.

[0101] S103b: Receive a third operation from the user indicating a refusal to grant the second device the permission to remotely access the first type of functional modules.

[0102] As an example, the third operation may be a voice command operation that the user can perform through a voice assistant of the first device or a voice recognition function of the first device. Exemplarily, the user directly issues a voice command to the first device through the voice recognition function of the first device, indicating that the second device is denied remote access to the first category of functional modules. For example, the user may say: "Reject remote access".

[0103] As another example, the third operation may be a click operation of the user on the display interface of the first device. Exemplarily, the user clicks a button for rejecting remote access on the first device, indicating that the second device is rejected from remotely accessing the first type of functional modules.

[0104] It should be noted that the specific content of the third operation mentioned above is only some examples given in the embodiments of the present disclosure. In specific implementation, the content of the third operation may also be different based on different user selections and different capabilities of the first device, and the embodiments of the present disclosure are not limited to this.

[0105] S104b. In response to the third operation, send fifth prompt information to the second device.

[0106] The fifth prompt information is used to indicate that the first device rejects the remote access request.

[0107] As an example, the fifth prompt information may be audio information. For example, the first device generates an audio message of "remote access denied" and sends it to the second device as the fifth prompt information.

[0108] As another example, the fifth prompt information may be a text message. For example, the first device generates a text message "deny remote access" and sends it to the second device as the fifth prompt information.

[0109] It should be noted that the form of the fifth prompt information mentioned above is only some examples given in the embodiments of the present disclosure. In actual implementation, the form of the fifth prompt information may be different depending on actual needs and the device capabilities of the first device, and the embodiments of the present disclosure are not limited to this.

[0110] It is understandable that after receiving the third operation of the user refusing to grant the second device remote access to the first type of functional module, the first device will send a fifth prompt message to the second device, so that the operator of the second device can promptly know that his remote access request is rejected, so that the second device can promptly adjust or improve its remote access request.

[0111] In some embodiments, after receiving the remote access request of the second device, the method further includes: determining whether the second device is allowed to remotely access the first device. That is, after receiving the remote access request of the second device, the first device does not directly grant the second device remote access permission, but first determines whether the first device allows the second device to remotely access. Therefore, the generation of the first prompt information in the case where the remote access request is used to request access to the first type of functional module of the first device can be implemented as: when the second device is allowed to remotely access the first device, and the remote access request is used to request access to the first type of functional module of the first device, the first prompt information is generated.

[0112] It can be understood that after the first device receives the remote access request from the second device, it determines whether to allow the second device to perform remote access, which can prevent the second device from accessing the first device without authorization and reduce the risk of privacy leakage. At the same time, the embodiment of the present disclosure can strengthen the access control of the second device and protect the privacy security of the user by determining whether to allow the second device to perform remote access.

[0113] In some embodiments, determining whether to allow the second device to remotely access the first device includes at least one of the following: determining whether the remote access function of the first device is turned on; determining whether the access behavior of the second device is compliant; and determining whether the functional module accessed by the remote access request is within the functional module allowed to be accessed by the first device.

[0114] In some embodiments, the first device records past remote access requests of the second device, for example, the second device's login account, device identification, geographic location, time of remote access request, local area network where the second device is located, reason for success / failure of remote access of the second device, reason for denying remote access of the second device, etc., and performs statistics, analysis and integration on them to facilitate subsequent judgment on whether the access behavior of the second device is compliant.

[0115] As a possible implementation, it is determined that the second device is allowed to remotely access the first device when at least one of the following conditions is met: the remote access permission function of the first device is turned on; the access behavior of the second device is compliant; the function module accessed by the remote access request is within the function module allowed to be accessed by the first device. As an example, if the remote access permission function of the first device is turned on, it is determined that the second device is allowed to remotely access the first device.

[0116] As another example, if the access behavior of the second device complies with the regulations, it is determined that the second device is allowed to remotely access the first device. In some embodiments, the access behavior of the second device complies with the regulations, including at least one of ai:

[0117] a. The login account and / or device identification is in the whitelist. In some embodiments, the user sets a whitelist for login accounts and / or device identifications that are allowed to access (for example, configuring a whitelist for login accounts of parents, friends, and classmates), and the user can update the whitelist at any time as needed to determine whether the access behavior of the second device is compliant based on the whitelist. Exemplarily, if the login accounts in the whitelist include: 123, 124, 125, and the login account of the second device is 123, then the login account is in the whitelist, that is, the access behavior of the second device meets the requirements of rule a.

[0118] b. The geographical location is within the preset login range. In some embodiments, the preset login range may be a province, city, region, etc. For example, if the preset login range is Fengtai District and Haidian District of Beijing, and the geographical location of the second device is Chaoyang District of Beijing, then the access behavior of the second device does not meet the requirements of rule b.

[0119] It should be noted that the above-mentioned preset login range is only an example given in the present disclosure. In actual implementation, the preset login range can be flexibly selected according to actual conditions, and the embodiments of the present disclosure do not limit this.

[0120] c. The time of requesting remote access is within the preset access period. For example, the preset access period may be: 9:00-12:00. If the time of requesting remote access is 9:32, the access behavior of the second device meets the requirements of rule c.

[0121] d. The second device is in the same local area network as the first device. For example, if the second device and the first device are both in local area network A (for example, a parent's mobile phone remotely accesses a camera on the desk in the child's room in the living room, and the parent's mobile phone and the camera on the desk are connected to the same WIFI network), then the access behavior of the second device meets the requirements of rule d.

[0122] e. The number of devices accessed by the login account of the second device is less than or equal to the second threshold. In some embodiments, the server can configure a device record table for each login account to record the device information accessed by the account; the first device can send the login account of the second device to the server based on the remote access request, so that the server can query the number of devices accessed by the login account of the second device based on the device record table. Exemplarily, the second threshold can be 3. If the number of devices accessed by the login account of the second device is 4, the access behavior of the second device meets the requirements of rule e.

[0123] f. The historical access duration of the second device to the first device is less than or equal to the third threshold. For example, the third threshold may be 2 hours. If the historical access duration is 1 hour and 20 minutes, which is less than 2 hours, it is determined that the access behavior of the second device meets the requirements of rule f.

[0124] g. The access frequency of the second device to the first device is less than or equal to the fourth threshold. Exemplarily, the fourth threshold may be 3 times / day. If the second device accesses the first device 2 times on the same day, that is, the access frequency is 2 times / day, then it is determined that the access behavior of the second device meets the requirements of rule g.

[0125] h. The number of times the second device is denied access rights by the first device is less than or equal to the fifth threshold. As an example, the number of times access rights are denied may be the number of times access rights are denied on the same day. As another example, the number of times access rights are denied may also be the number of times access rights are denied in history. Exemplarily, the fifth threshold may be 4 times. If the number of times the second device is denied access rights by the first device is 3 times, it is determined that the access behavior of the second device meets the requirements of rule h.

[0126] i. The number of times the second device is granted access rights by the first device is greater than or equal to the sixth threshold. For example, the sixth threshold may be 5 times. If the number of times the second device is granted access rights by the first device is 8 times, it is determined that the access behavior of the second device meets the requirements of rule i.

[0127] It can be understood that the method provided by the embodiment of the present disclosure judges whether the access behavior of the second device is compliant based on different dimensions, thereby improving the judgment of the security and credibility of the second device, avoiding the problem of user privacy leakage caused by the second device accidentally or maliciously accessing the first device, and improving the security of remote access.

[0128] As another example, if the function module accessed by the remote access request is within the function module that the first device allows to access, it is determined that the second device is allowed to remotely access the first device. In some embodiments, when the first device turns on the privacy protection mode, the function modules that the first device allows to access include the second category function modules; or, when the first device turns off the privacy protection mode, the function modules that the first device allows to access include the first category function modules and the second category function modules. Therefore, when determining whether the function module accessed by the remote access request is within the function module that the first device allows to access, it can be determined first whether the first device has turned on the privacy protection mode. Exemplarily, if the first device turns on the privacy protection mode, the function modules that the first device allows to access include the second category function modules. If the function module that the second device requests to access is the first category function module, the second device is not allowed to remotely access the first device.

[0129] It is understandable that when managing the remote access rights of the second device, the related technology often simply determines whether the second device has access rights based on a single access of the second device. The judgment latitude is single and not precise enough, and the security of access is not guaranteed. In the method provided by the embodiment of the present disclosure, by judging whether the remote access permission function of the first device is turned on, judging whether the access behavior of the second device is compliant, and judging whether the function module accessed by the remote access request is within the function module allowed to be accessed by the first device, it is achieved that when the second device requests remote access, the remote access rights of the second device are judged in multiple dimensions through different management and control methods, thereby strengthening the management and control of the remote access rights of the second device, and thus protecting the privacy and security of the user.

[0130] As another possible implementation, since the first device is configured with a function that allows remote access, the user can flexibly turn this function on or off. Therefore, when the function that allows remote access is turned off, even if the access behavior of the second device is compliant or the function module accessed by the remote access request is within the function module that the first device allows access to, the second device cannot remotely access the first device. When the function that allows remote access is turned on, if the access behavior of the second device is compliant and / or the function module accessed by the remote access request is within the function module that the first device allows access to, it is determined that the second device is allowed to remotely access the first device. Exemplarily, if the function that allows remote access of the first device is turned off, it is determined that the second device is denied remote access to the first device; if the function that allows remote access of the first device is turned on, and the access behavior of the second device is compliant, it is determined that the second device is allowed to remotely access the first device.

[0131] It is understandable that when the first device is configured with a function that allows remote access, once this function is turned off, the second device will not be able to remotely access the first device, eliminating the risk of user privacy leakage caused by remote access of the second device and ensuring the privacy security of the user.

[0132] For ease of understanding, the access control method provided by the embodiment of the present disclosure is described below using different scenarios as examples.

[0133] Scenario 1: The second device requests to access the camera of the first device.

[0134] For example, Figure 8 As shown, in scenario 1, the access control method provided by the embodiment of the present disclosure can be implemented as the following steps:

[0135] Step a1: receiving a remote access request from a second device.

[0136] Step a2: determine whether the remote access permission function of the first device is enabled; if so, execute step a3; if not, execute step a8.

[0137] Step a3: parse the remote access request and determine the device information of the second device.

[0138] Step a4: confirm whether the access behavior of the second device is compliant; if so, execute step a5; if not, execute step a7.

[0139] In some embodiments, the first device may send a request to the server, requesting the server to confirm whether the access behavior of the second device is compliant. Exemplarily, the first device may send the login account of the second device to the server, requesting the server to confirm whether the number of devices accessed by the login account of the second device is greater than a second threshold; if it is greater than the second threshold, confirming that the access behavior of the second device is compliant.

[0140] Step a5: Send a first prompt message.

[0141] The first prompt information is used to prompt the user whether to grant the second device permission to remotely access the camera.

[0142] Step a6: In response to the user granting the second device permission to remotely access the camera, a second prompt message is issued, and step a8 is executed.

[0143] The second prompt information is used to prompt the user that the second device is remotely accessing the camera.

[0144] Step a7: The first device sends a third prompt message to the second device.

[0145] The third prompt information is used to prompt the second device user not to allow remote access. In some embodiments, the third prompt information may be locally preset audio and video information.

[0146] Step a8: This session ends.

[0147] It can be understood that in the access control method provided by the embodiment of the present disclosure, after receiving the remote access request from the second device, the first device generates a first prompt message to prompt the user whether to grant the second device remote access to the first type of functional module when the remote access request is used to request access to the first type of functional module of the first device (the first type of functional module is a functional module for collecting privacy information), that is, when the second device has the risk of collecting the privacy information of the user or the first device. It can be seen that in the method provided by the embodiment of the present disclosure, the first device generates the first prompt message, which not only enhances the user's perception of the remote access of the second device, but also provides the user with the control right of whether to grant the second device remote access, thereby enhancing the user's control over the remote access of the second device, and thus protecting the user's privacy security.

[0148] The above mainly introduces the scheme of the embodiment of the present disclosure from the perspective of the method. It can be understood that in order to realize the above functions, the access control device includes at least one of the hardware structure and software modules corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiment disclosed in this article, the embodiment of the present disclosure can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the embodiment of the present disclosure.

[0149] It is understandable that, in order to realize the above functions, the access control device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the algorithm steps of each example described in the embodiments of the present disclosure, the present disclosure can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present disclosure.

[0150] The disclosed embodiment can divide the access control device into functional modules according to the above method embodiment. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one functional module. The above integrated module can be implemented in the form of hardware or software. It should be noted that the division of modules in the disclosed embodiment is schematic and is only a logical functional division. There may be other division methods in actual implementation. The following is an example of dividing each functional module corresponding to each function.

[0151] Fig. 9 is a schematic diagram of the structure of an access control device provided by an embodiment of the present disclosure. The access control device is applied to a first device and can execute the access control method provided by the above method embodiment. Fig. 9 As shown, the access control device 400 includes: a receiving module 401 , a generating module 402 , an executing module 403 , a determining module 404 , a sending module 405 and a judging module 406 .

[0152] The receiving module 401 is configured to receive a remote access request from a second device.

[0153] Generation module 402 is used to generate a first prompt message when the remote access request is used to request access to a first type of functional module of the first device. The first prompt message is used to prompt the user whether to grant the second device remote access to the first type of functional module. The first type of functional module is a functional module used to collect privacy information.

[0154] In some embodiments, the receiving module 401 is further used to receive a first operation from a user indicating granting the second device permission to remotely access the first type of functional modules; the executing module 403 is used to execute an operation corresponding to the remote access request in response to the first operation.

[0155] In some embodiments, the generating module 402 is further used to generate second prompt information, where the second prompt information is used to prompt the user that the second device is remotely accessing the first type of functional module of the first device.

[0156] In some embodiments, the determination module 404 is used to determine the duration of this access of the second device; the generation module 402 is used to generate a third prompt message when the duration of this access is greater than the first threshold; the third prompt message is used to prompt the user whether to disconnect the remote access of the second device.

[0157] In some embodiments, the determination module 404 is used to determine the duration of this access of the second device; the generation module 402 is used to generate a fourth prompt message when the duration of this access is greater than the first threshold; the fourth prompt message is used to indicate that the first device disconnects the remote access of the second device.

[0158] In some embodiments, the receiving module 401 is further used to receive a third operation from a user indicating a refusal to grant the second device permission to remotely access the first type of functional modules; the sending module 405 is further used to send a fifth prompt message to the second device in response to the third operation, and the fifth prompt message is used to indicate that the first device rejects the remote access request.

[0159] In some embodiments, the judgment module 406 is used to determine whether the second device is allowed to remotely access the first device; the generation module 402 is specifically used to generate a first prompt message when the second device is allowed to remotely access the first device and when the remote access request is used to request access to a first type of functional module of the first device.

[0160] In some embodiments, determining whether to allow the second device to remotely access the first device includes at least one of the following:

[0161] Determine whether a remote access permission function of the first device is enabled;

[0162] Determining whether the access behavior of the second device is compliant;

[0163] It is determined whether the function module accessed by the remote access request is within the function modules allowed to be accessed by the first device.

[0164] In some embodiments, allowing the second device to remotely access the first device is determined when at least one of the following is satisfied:

[0165] The remote access permission function of the first device is turned on;

[0166] The access behavior of the second device complies with the regulations;

[0167] The function modules accessed by the remote access request are within the function modules that the first device is allowed to access.

[0168] In some embodiments, the remote access request includes at least one of the following: a login account of the second device, a device identification, a geographic location, a time when the remote access is requested, and a local area network where the second device is located.

[0169] In some embodiments, the access behavior compliance of the second device includes at least one of the following:

[0170] The login account and / or device ID is in the whitelist;

[0171] The geographical location is within the preset login range;

[0172] The time of requesting remote access is within the preset access period;

[0173] The second device and the first device are in the same local area network;

[0174] The number of devices accessed by the login account of the second device is less than or equal to the second threshold;

[0175] The historical access duration of the second device to the first device is less than or equal to a third threshold;

[0176] The access frequency of the second device to the first device is less than or equal to a fourth threshold;

[0177] The number of times that the second device is denied access permission by the first device is less than or equal to a fifth threshold;

[0178] The number of times the second device is granted access rights by the first device is greater than or equal to a sixth threshold.

[0179] In some embodiments, when the first device turns on the privacy protection mode, the functional modules that the first device allows to access include the second category functional modules; or, when the first device turns off the privacy protection mode, the functional modules that the first device allows to access include the first category functional modules and the second category functional modules; wherein the second category functional modules are functional modules that do not involve the collection of privacy information.

[0180] In the case of implementing the functions of the above-mentioned integrated modules in the form of hardware, the embodiments of the present disclosure provide a possible structure of the electronic device involved in the above-mentioned embodiments. Fig.10 As shown, the electronic device 500 includes: a processor 502 and a bus 504. Optionally, the electronic device 500 may further include a memory 501; optionally, the electronic device 500 may further include a communication interface 503.

[0181] The processor 502 may be a processor that implements or executes various exemplary logic blocks, modules, and circuits described in conjunction with the embodiments of the present disclosure. The processor 502 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array, or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It may implement or execute various exemplary logic blocks, modules, and circuits described in conjunction with the embodiments of the present disclosure. The processor 502 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, and the like.

[0182] The communication interface 503 is used to connect with other devices via a communication network, such as Ethernet, wireless access network, wireless local area network (WLAN), etc.

[0183] The memory 501 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program codes in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.

[0184] As a possible implementation, the memory 501 may exist independently of the processor 502, and the memory 501 may be connected to the processor 502 via a bus 504 to store instructions or program codes. When the processor 502 calls and executes the instructions or program codes stored in the memory 501, the access control method provided in the embodiment of the present disclosure can be implemented.

[0185] In another possible implementation, the memory 501 may also be integrated with the processor 502 .

[0186] The bus 504 may be an extended industry standard architecture (EISA) bus, etc. The bus 504 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.10 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0187] Some embodiments of the present disclosure provide a computer-readable storage medium (e.g., a non-transitory computer-readable storage medium), in which computer program instructions are stored. When the computer program instructions are executed on a computer, the computer executes the access control method described in any of the above embodiments.

[0188] Exemplarily, the above-mentioned computer-readable storage media may include, but are not limited to: magnetic storage devices (e.g., hard disks, floppy disks or magnetic tapes, etc.), optical disks (e.g., compact disks (CD), digital versatile disks (DVD), etc.), smart cards and flash memory devices (e.g., erasable programmable read-only memory (EPROM), cards, sticks or key drives, etc.). The various computer-readable storage media described in the present disclosure may represent one or more devices and / or other machine-readable storage media for storing information. The term "machine-readable storage medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing and / or carrying instructions and / or data.

[0189] An embodiment of the present disclosure provides a computer program product including instructions. When the computer program product is run on a computer, the computer is enabled to execute the access control method described in any one of the above embodiments.

[0190] The above is only a specific implementation of the present disclosure, but the protection scope of the present disclosure is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present disclosure should be included in the protection scope of the present disclosure. Therefore, the protection scope of the present disclosure should be based on the protection scope of the claims.

Claims

1. An access control method, It is characterized in that Applied to a first device; the method comprises: receiving a remote access request from a second device; In the case where the remote access request is used to request access to a first type of functional module of the first device, a first prompt message is generated, and the first prompt message is used to prompt the user whether to grant the second device remote access to the first type of functional module. The first type of functional module is a functional module used to collect privacy information.

2. The method according to claim 1, It is characterized in that The method further comprises: receiving a first operation by a user for instructing to grant the second device a permission to remotely access the first type of functional modules; In response to the first operation, an operation corresponding to the remote access request is performed.

3. The method according to claim 2, It is characterized in that The method further comprises: Generate second prompt information, where the second prompt information is used to prompt the user that the second device is remotely accessing the first type of functional module of the first device.

4. The method according to claim 2, It is characterized in that The method further comprises: Determine the duration of this access by the second device; When the duration of the current access is greater than the first threshold, a third prompt message is generated; the third prompt message is used to prompt the user whether to disconnect the remote access of the second device.

5. The method according to claim 2, It is characterized in that The method further comprises: Determine the duration of this access by the second device; When the duration of the current access is longer than the first threshold, fourth prompt information is generated; the fourth prompt information is used to indicate that the first device disconnects the remote access of the second device.

6. The method according to claim 1, It is characterized in that The method further comprises: receiving a third operation from a user indicating a refusal to grant the second device a permission to remotely access the first type of functional modules; In response to the third operation, fifth prompt information is sent to the second device, where the fifth prompt information is used to indicate that the first device rejects the remote access request.

7. The method according to claim 1, It is characterized in that After receiving the remote access request from the second device, the method further includes: Determining whether to allow the second device to remotely access the first device; The generating first prompt information when the remote access request is used to request access to a first type of functional module of the first device includes: When the second device is allowed to remotely access the first device and the remote access request is used to request access to a first type of functional module of the first device, first prompt information is generated.

8. The method according to claim 7, It is characterized in that The determining whether to allow the second device to remotely access the first device includes at least one of the following: Determining whether a remote access permission function of the first device is enabled; Determining whether the access behavior of the second device is compliant; It is determined whether the function module accessed by the remote access request is within the function modules allowed to be accessed by the first device.

9. The method according to claim 8, It is characterized in that It is determined that the second device is allowed to remotely access the first device when at least one of the following is satisfied: The remote access permission function of the first device is turned on; The access behavior of the second device complies with the regulations; The function module accessed by the remote access request is within the function modules that the first device is allowed to access.

10. The method according to claim 9, It is characterized in that The remote access request includes at least one of the following: a login account, a device identifier, a geographic location, a time of requesting remote access, and a local area network where the second device is located.

11. The method according to claim 10, It is characterized in that The access behavior compliance of the second device includes at least one of the following: The login account and / or the device identification is in the whitelist; The geographical location is within a preset login range; The time of requesting remote access is within a preset access period; The second device and the first device are in the same local area network; The number of devices accessed by the login account of the second device is less than or equal to a second threshold; The historical access duration of the second device to the first device is less than or equal to a third threshold; The access frequency of the second device to the first device is less than or equal to a fourth threshold; The number of times that the first device refuses to grant access rights to the second device is less than or equal to a fifth threshold; The number of times that the first device grants access rights to the second device is greater than or equal to a sixth threshold.

12. The method according to claim 8, It is characterized in that When the privacy protection mode is turned on for the first device, the functional modules that the first device allows access to include the second category functional modules; or, when the privacy protection mode is turned off for the first device, the functional modules that the first device allows access to include the first category functional modules and the second category functional modules; wherein, the second category functional modules are functional modules that do not involve the collection of privacy information.

13. An electronic device, It is characterized in that include: a processor and a memory for storing instructions executable by the processor; The processor is configured to execute the instructions so that the electronic device performs the method as claimed in any one of claims 1 to 12.

14. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores computer instructions, and when the computer instructions are executed on an electronic device, the electronic device executes the method according to any one of claims 1 to 12.