Security protection authentication method and device and electronic equipment

By dynamically searching preset authentication information in a secure database and determining the access level based on the device identifier, the problem that traditional camera equipment authentication mechanism cannot meet the needs of modern business flexibility is solved, and a flexible and adaptable security protection authentication method is realized, reducing the risk of security authentication.

CN120046137APending Publication Date: 2025-05-27INFORMATION & COMM BRANCH OF STATE GRID JIANGSU ELECTRIC POWER
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510184307.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The authentication mechanism of traditional camera equipment cannot meet the flexibility needs of modern services and cannot adapt to the complex needs of diverse application scenarios, resulting in mismatch in authentication information and fixed access levels.

Method used

By obtaining the authentication information and device identifiers in the transmission data packet of the camera device, query the corresponding preset authentication information in the secure database, verify the authentication information, and determine the access level based on the device identifier, and grant corresponding access permissions.

Benefits of technology

It realizes the flexibility and adaptability of the authentication method, avoids the problem of mismatch in authentication information, ensures that the access permissions match the device requirements, and reduces potential security authentication risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046137A_ABST
    Figure CN120046137A_ABST
Patent Text Reader

Abstract

The invention discloses a security protection authentication method and device and electronic equipment, and the method comprises the steps: obtaining authentication information and an equipment identifier in a transmission data package of camera equipment, and obtaining preset authentication information corresponding to the equipment identifier in a security database; verifying the authentication information according to preset authentication information, and determining an access level of the camera equipment in a security policy database according to the equipment identifier; and granting a corresponding access authority to the camera device according to the access level. According to the invention, the preset authentication information is dynamically searched in the security database by using the device identifier to verify the authentication information, so that the authentication method can flexibly cope with changes of various authentication requirements, and the flexibility and adaptability of the authentication method are enhanced; different access levels and corresponding access permissions are configured for the camera equipment, so that the access levels are matched with equipment requirements, the camera equipment is ensured to only access authorized resources, and potential security authentication risks are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of security technologies, and in particular, to a security protection authentication method, apparatus, and electronic device. Background Art

[0002] With the rapid development of Internet of Things (IoT) technology, a large number of camera devices are allowed to be connected to the IoT network for various application scenarios such as monitoring or security monitoring. These camera devices transmit data through the network to achieve remote monitoring and management. However, due to the large number and diverse types of camera devices, it has become increasingly difficult to implement traditional IoT network security authentication and protection. To ensure the secure access and data transmission of camera devices in the IoT network, a secure and flexible authentication mechanism is particularly important. Currently, the authentication mechanisms of traditional camera devices often use unified authentication information for authentication, which cannot meet the flexibility requirements of modern services. In addition, a fixed access level is often assigned to a camera device after successful authentication of a traditional camera device, making the authentication mechanism of traditional camera devices unable to adapt to the complex requirements of diverse application scenarios. Therefore, providing a security protection authentication method based on camera devices with high flexibility and strong adaptability is an urgent problem to be solved in the current field of security technologies. Summary of the Invention

[0003] Embodiments of the present invention provide a security protection authentication method, apparatus, and electronic device. The embodiments of the present invention improve the flexibility and adaptability of the authentication method, avoid the problem of mismatched authentication information, achieve the matching of access permissions and device requirements, and reduce potential security authentication risks.

[0004] On the one hand, an embodiment of the present invention provides a security protection authentication method, including:

[0005] Obtain the authentication information and device identifier in the data packet transmitted by the camera device, and obtain the preset authentication information corresponding to the device identifier in the security database;

[0006] Verify the authentication information according to the preset authentication information, and determine the access level of the camera device in the security policy database according to the device identifier;

[0007] Grant the corresponding access permission to the camera device according to the access level.

[0008] On the other hand, an embodiment of the present invention provides a security protection authentication apparatus, including:

[0009] An information acquisition module, configured to obtain the authentication information and device identifier in the data packet transmitted by the camera device, and obtain the preset authentication information corresponding to the device identifier in the security database;

[0010] A level determination module, configured to verify authentication information according to preset authentication information, and determine the access level of the camera device in a security policy database according to the device identifier;

[0011] A permission granting module, configured to grant corresponding access permissions to the camera device according to the access level.

[0012] Another aspect of the embodiments of the present invention provides an electronic device, including:

[0013] At least one processor;

[0014] And a memory communicatively connected to the at least one processor;

[0015] Wherein, the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor, so that the at least one processor can execute the security protection authentication method described in any one of the above embodiments.

[0016] In the embodiments of the present invention, by obtaining the transmission data packet of the camera device, extraction operations can be performed on the obtained transmission data packet to extract the authentication information for verifying the device identity and the device identifier for uniquely identifying the camera device. Based on the device identifier, the preset authentication information that is predefined and used to verify the identity of the camera device can be queried in the security database. The preset authentication information can be used to verify the authentication information. After the verification is passed, the access level of the camera device to access the network can be determined in the security policy database using the device identifier. Corresponding access permissions can be assigned to the camera device according to different access levels of the camera device. In the embodiments of the present invention, by dynamically searching for the corresponding preset authentication information in the security database, the authentication method can flexibly adapt to changes in various authentication requirements, enhancing the flexibility and adaptability of the authentication method; by using the device identifier as the query condition, it is ensured that the corresponding preset authentication information can be accurately found in the security database, avoiding the problem of mismatch between the preset authentication information and the authentication information, and improving the pertinence and accuracy of the authentication method; by verifying the authentication information, it is ensured that only authorized camera devices can access the Internet of Things, preventing unauthorized access; by using the device identifier, the access level of the camera device can be accurately set, ensuring the accuracy and pertinence of the access permission allocation, and realizing the matching of the access level and the device requirements; by configuring different levels of access permissions for the camera device according to different access levels, it is ensured that the camera device can only access the resources it is authorized to access, reducing the potential security protection authentication risk.

[0017] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0019] Figure 1 FIG. is a flowchart of a security protection authentication method provided in Embodiment 1 of the present invention;

[0020] Figure 2 FIG. is a flowchart of another security protection authentication method provided in Embodiment 2 of the present invention;

[0021] Figure 3 FIG. is a flowchart of another security protection authentication method provided in Embodiment 3 of the present invention;

[0022] Figure 4 FIG. is a schematic structural diagram of a security protection authentication device for implementing the embodiments of the present invention;

[0023] Figure 5 FIG. is a schematic structural diagram of another security protection authentication device for implementing the embodiments of the present invention;

[0024] Figure 6 FIG. is a block diagram of an electronic device for executing the security protection authentication method of the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] In order to enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0026] It should be noted that the terms "first", "second", etc. in the description, claims and above-mentioned drawings of the present invention are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0027] Embodiment 1

[0028] Figure 1 The following is a flowchart of a security protection authentication method provided in Embodiment 1 of the present invention. The embodiments of the present invention are applicable to the situation of protecting and authenticating camera devices. This method can be executed by a security protection authentication device, which can be implemented in the form of hardware and / or software, and the security protection authentication device can be configured in an electronic device. As Figure 1 shown, the method includes:

[0029] S101. Obtain the authentication information and device identifier in the data packet transmitted by the camera device, and obtain the preset authentication information corresponding to the device identifier in the security database.

[0030] Among them, the transmitted data packet can be understood as a set of data sent or received by a camera device. For example, the transmitted data packet at least includes data such as the authentication information of the camera device and the device identifier of the camera device.

[0031] The authentication information can be understood as a series of data used to verify the identity of the camera device. For example, the authentication information may include data such as the name of the camera device or the location of the camera device.

[0032] The device identifier can be understood as a string used to uniquely identify a camera device and can be used to distinguish different camera devices.

[0033] The security database can be understood as a storage system that can be used to store data related to camera devices. For example, the data related to camera devices at least includes data such as device identifiers and preset authentication information corresponding to the device identifiers.

[0034] The preset authentication information can be understood as a series of data that are predefined and used to verify the identity of the camera device. It can be understood that the data in the preset authentication information is the same as the data in the authentication information. The preset authentication information is associated with the device identifier and stored in the security database.

[0035] Specifically, obtain the transmission data packet of the camera device. An extraction operation can be performed on the obtained transmission data packet to extract the authentication information for verifying the device identity and the device identifier for uniquely identifying the camera device. Based on the device identifier, query in the security database for the preset authentication information that is predefined and used to verify the identity of the camera device and corresponds to the device identifier.

[0036] Exemplarily, the steps of obtaining the preset authentication information corresponding to the device identifier in the security database may include: using the device identifier as a query condition to construct a query statement for the security database, and executing the query statement in the security database to obtain the preset authentication information corresponding to the device identifier.

[0037] S102. Verify the authentication information according to the preset authentication information, and determine the access level of the camera device in the security policy database according to the device identifier.

[0038] Among them, the security policy database can be understood as another storage system, which can be used to store device information related to the camera device. Exemplarily, the security policy database may include: device information such as device type data, device usage data, or device usage scenario data.

[0039] The access level can be understood as a kind of permission level. Exemplarily, the access level may include: no access level, basic access level, or high - level access level, etc.

[0040] Specifically, obtain the authentication information, preset authentication information, and device identifier of the camera device. Use the preset authentication information to verify the authentication information. After the verification passes, use the device identifier to determine the access level for the camera device to access the network in the security policy database.

[0041] Exemplarily, the steps of using the device identifier to determine the access level for the camera device to access the network in the security policy database may include: using the device identifier as a query condition to construct a query statement, executing the query statement in the security database to find the device information related to the camera device, and determining the access level for the camera device to access the network based on the device information.

[0042] S103. Grant the corresponding access permission to the camera device according to the access level.

[0043] Among them, the access right can be understood as the ability that the camera device is explicitly given to perform specified operations. For example, the access right can include: zero access right, basic operation right, comprehensive management right, etc.

[0044] Specifically, to determine the access level of the camera device, corresponding access rights can be assigned to the camera device according to different access levels of the camera device.

[0045] For example, the process of assigning corresponding access rights to the camera device according to different access levels of the camera device can include: when it is determined that the access level is the no-access level, zero access right can be assigned to the camera device; when it is determined that the access level is the basic access level, basic operation right can be assigned to the camera device; when it is determined that the access level is the advanced access level, comprehensive management right can be assigned to the camera device.

[0046] In the embodiment of the present invention, to obtain the transmission data packet of the camera device, extraction operations can be performed on the obtained transmission data packet to extract the authentication information for verifying the device identity and the device identifier for uniquely identifying the camera device. Based on the device identifier, the preset authentication information that is predefined and used to verify the identity of the camera device can be queried in the security database. The authentication information can be verified by using the preset authentication information. After the verification is passed, the access level of the camera device to access the network can be determined in the security policy database by using the device identifier. Corresponding access rights can be assigned to the camera device according to different access levels of the camera device. In the embodiment of the present invention, by dynamically searching for the corresponding preset authentication information in the security database, the authentication method can flexibly adapt to changes in various authentication requirements, enhancing the flexibility and adaptability of the authentication method; by using the device identifier as the query condition, it is ensured that the corresponding preset authentication information can be accurately found in the security database, avoiding the problem of mismatch between the preset authentication information and the authentication information, improving the pertinence and accuracy of the authentication method; by verifying the authentication information, it is ensured that only authorized camera devices can access the Internet of Things, preventing unauthorized access; by the device identifier, the access level of the camera device can be accurately set, ensuring the accuracy and pertinence of the access right assignment, and realizing the matching of the access level and the device requirements; by configuring different levels of access rights for the camera device according to different access levels, it is ensured that the camera device can only access the resources it is authorized to, reducing the potential security protection authentication risk.

[0047] On the basis of the above embodiment, before obtaining the authentication information and the device identifier in the transmission data packet of the camera device in the embodiment of the present invention, it includes:

[0048] Obtain the communication key of the camera device; call the challenge value generation rule to generate a challenge random number, encrypt the challenge random number using the communication key to obtain an encrypted random number; send the encrypted random number to the camera device, and obtain the decrypted random number corresponding to the encrypted random number, where the decrypted random number is obtained by the camera device decrypting the encrypted random number using the communication key; determine that the challenge random number is the same as the decrypted random number, and decrypt the encrypted transmission data packet using the communication key.

[0049] Among them, the challenge value generation rule can be understood as a set of algorithms for generating random numbers, and the challenge value generation rule can ensure the uniqueness of the random numbers generated each time.

[0050] The challenge random number can be understood as a string of numbers, which is unpredictable and can be used for subsequent key verification.

[0051] The encrypted random number can be understood as another string of numbers, and the decrypted random number can be obtained by decrypting the encrypted random number using the communication key to verify the validity of the communication key.

[0052] The decrypted random number can be understood as another string of numbers, which is the result of decrypting the encrypted random number using the communication key, and can be compared with the challenge random number to verify the validity of the communication key.

[0053] The communication key can be understood as a sequence of character strings and can be used to decrypt the encrypted transmission data packet. Specifically, before obtaining the authentication information and device identifier in the camera device transmission data packet, the following steps can also be included: obtain the communication key of the camera device, call the challenge value generation rule to generate a string of challenge random numbers for subsequent verification of the communication key, encrypt the challenge random number using the obtained communication key, use the encrypted challenge random number as the encrypted random number, transmit the encrypted random number to the camera device, the camera device can decrypt the encrypted random number using the same communication key, use the decrypted encrypted random number as the decrypted random number, compare the challenge random number and the decrypted random number, when the comparison result is that the challenge random number is the same as the decrypted random number, it can be determined that the communication key is valid, and the encrypted transmission data packet can be decrypted using the obtained communication key to obtain the decrypted transmission data packet of the camera device. It can be understood that the decrypted transmission data packet of the camera device is equivalent to the camera device transmission data packet.

[0054] Exemplarily, the method for obtaining the communication key of the camera device can include: before or after the deployment of the camera device, distribute the communication key to the camera device through a secure channel or when encrypting or decrypting data, the camera device retrieves the pre-stored communication key from the key management module.

[0055] Based on the above embodiments, the embodiments of the present invention obtain the communication key of the camera device, including: determining the update of the security policy of the camera device, obtaining the newly generated communication key of the camera device; after verifying that the communication key passes the verification, saving the communication key.

[0056] Specifically, a security policy can be configured for the camera device, and the security policy configured for the camera device can be continuously monitored. When it is monitored that the security policy configured for the camera device is updated, the camera device can be triggered to generate a new communication key. Based on the new communication key, the new communication key can be verified. When it is determined that the new communication key passes the verification, the new communication key can be stored for decrypting subsequent transmitted data packets.

[0057] Embodiment 2

[0058] Figure 2 The following is a flowchart of another security protection authentication method provided by the embodiments of the present invention. Based on the above embodiments, the embodiments of the present invention provide another security protection authentication method. As Figure 2 shown, the method includes:

[0059] S201. Obtain the authentication information and device identifier in the data packet transmitted by the camera device.

[0060] S202. Use a preset hash algorithm to perform a hash process on the device identifier to obtain the device hash value corresponding to the device identifier, and construct a first query statement for the security database using the device hash value as the query condition.

[0061] Among them, the preset hash algorithm can be understood as a preset calculation rule that can be used to convert input data into a hash value.

[0062] The device hash value can be understood as a string of characters. The device hash value is unique and can be used as a query condition to construct a query statement.

[0063] The first query statement can be understood as a statement written in structured query language for finding the preset authentication information associated with the device identifier in the security database.

[0064] Specifically, to obtain the device identifier, a preset hash algorithm for converting input data into a hash value can be obtained. The device identifier can be used as the input data of the preset hash algorithm, and the device identifier can be converted into a string using the preset hash algorithm. This string can be used as the device hash value, and the obtained device hash value can be set as the query condition to write the first query statement.

[0065] Exemplarily, based on the set query conditions, the steps of writing a first query statement using Structured Query Language may include: determining the column names for querying target information, i.e., the column names of the preset authentication information; determining the location where the preset authentication information is stored in the security database, i.e., the table name; setting the query conditions, i.e., setting the device identifier as the query condition; and writing a first query statement using Structured Query Language based on the determined column names, table name, and the set query conditions.

[0066] S203. Establish a data connection pool for connecting to the security database, and execute the first query statement in the security database through the data connection pool to obtain the preset authentication information corresponding to the device identifier.

[0067] Among them, the data connection pool can be understood as a database connection mechanism and can be used to create a connection to the security database.

[0068] Specifically, to establish a data connection pool that can connect to the security database, the data connection pool can be used to obtain a connection to the security database, and this connection can be used to execute the first query statement in the security database. When executing the first query statement, the data in the security database can be traversed to extract the preset authentication information associated with the device identifier.

[0069] Exemplarily, when executing the first query statement, the steps of traversing the data in the security database to extract the preset authentication information associated with the device identifier may include: constructing a first query statement based on the determined column names, table name, and the set query conditions of the preset authentication information, and in the security database, execute the first query statement. Based on the column names, table name, and query conditions of the preset authentication information included in the first query statement, the preset authentication information can be extracted from the security database.

[0070] S204. Verify the authentication information according to the preset authentication information.

[0071] Specifically, the preset authentication information extracted from the security database can be used to verify the authentication information, and subsequent operations can be performed after passing the verification.

[0072] Exemplarily, when the authentication information fails to pass the verification, the corresponding camera device can also be isolated according to the device identifier, and a real-time alarm notification can be generated. The real-time alarm notification at least includes: the camera device that fails to pass the verification, the area where the camera device that fails to pass the verification is located, and the countermeasures, etc.

[0073] S205. Use the first query statement to query the camera device information corresponding to the device identifier in the security policy database. The camera device information includes at least one of the following: device type information, device usage information, device usage scenario information.

[0074] Among them, the camera device information can be understood as a series of attribute information about the camera device. By way of example, the camera device information includes, but is not limited to: device type information, device usage information, and device usage scenario information. The device type information can be understood as a series of data used to describe the camera device model. The device usage information can be understood as a series of data used to describe the design purpose or usage function of the camera device. The device usage scenario information can be understood as a series of data used to describe the actual deployment or usage environment of the camera device. The device type information, device usage information, and device usage scenario information can be used to determine the access level of the camera device.

[0075] Specifically, the first query statement can be used to traverse the data in the security policy database to extract the camera device information associated with the device identifier.

[0076] By way of example, when executing the first query statement, the steps of traversing the data in the security policy database to extract the device information associated with the device identifier can include: constructing the first query statement based on the column name, table name, and set query conditions for determining the device information. In the security policy database, execute the first query statement, and based on the column name, table name, and query conditions of the device information included in the first query statement, extract the device information from the security policy database.

[0077] S206. Determine the access level of the camera device according to the camera device information. The access level includes at least one of the following: no access level, basic access level, and advanced access level.

[0078] Among them, the no access level refers to the level at which the camera device does not have access rights. It can be understood that at the no access level, the camera device cannot perform any form of resource access.

[0079] The basic access level refers to the level at which the camera device has limited access rights. It can be understood that at the basic access level, the camera device is allowed to access some basic resources.

[0080] The advanced access level refers to the level at which the camera device has full access rights. It can be understood that at the advanced access level, the camera device is allowed to access all resources.

[0081] Specifically, obtain the camera device information of the camera device. Among them, the device information at least includes: device type information, device usage information, and device usage scenario information. The permission level of the camera device can be determined according to the camera device information to obtain a determination result. The access determination result at least includes three levels: no access level, basic access level, and advanced access level. The access determination result can be used as the access level of the camera device.

[0082] When it is determined that the access level is the no-access level, set the access permission to zero access permission; when it is determined that the access level is the basic access level, set the access permission to basic operation permission; when it is determined that the access level is the advanced access level, set the access permission to full management permission.

[0083] Among them, the zero access permission refers to the permission status of the camera device at the no-access level. It can be understood that when the camera device has zero access permission, the camera device cannot access any resources.

[0084] The basic operation permission refers to the permission status of the camera device at the basic access level. It can be understood that when the camera device has the basic operation permission, the camera device is allowed to access some basic resources.

[0085] The full management permission refers to the permission status of the camera device at the advanced access level. It can be understood that when the camera device has the full management permission, the camera device is allowed to access all resources.

[0086] Specifically, when the access level of the camera device determined according to the camera device information is the no-access level, it can be indicated that the camera device cannot access any resources. At this time, the permission status corresponding to the camera device can be set to zero access permission; when the access level of the camera device determined according to the camera device information is the basic access level, it can be indicated that the camera device is allowed to access some basic resources. At this time, the permission status corresponding to the camera device can be set to basic operation permission; when the access level of the camera device determined according to the camera device information is the advanced access level, it can be indicated that the camera device is allowed to access all resources. At this time, the permission status corresponding to the camera device can be set to full management permission.

[0087] In an embodiment of the present invention, the authentication information and device identifier in the data packet transmitted by the camera device are obtained. A preset hash algorithm that is preset for converting input data into a hash value can be obtained. The device identifier can be used as the input data of the preset hash algorithm, and the device identifier can be converted into a string by using the preset hash algorithm. This string can be used as the device hash value. The obtained device hash value can be set as a query condition. Based on the set query condition, a first query statement can be written using Structured Query Language (SQL), a data connection pool for connecting to the security database can be established, and a connection to the security database can be obtained using the data connection pool. The first query statement can be executed in the security database using this connection. When executing the first query statement, the data in the security database can be traversed to extract the preset authentication information associated with the device identifier. The authentication information can be verified using the preset authentication information extracted from the security database. After passing the verification, the data in the security policy database can be traversed using the first query statement to extract the camera device information associated with the device identifier. The permission level of the camera device can be determined based on the camera device information to obtain a determination result. This determination result includes at least three levels: no access level, basic access level, and advanced access level. This determination result can be used as the access level of the camera device. When the access level of the camera device determined according to the camera device information is the no access level, it indicates that the camera device cannot access any resources. At this time, the permission status corresponding to the camera device can be set to zero access permission. When the access level of the camera device determined according to the camera device information is the basic access level, it indicates that the camera device is allowed to access some basic resources. At this time, the permission status corresponding to the camera device can be set to basic operation permission. When the access level of the camera device determined according to the camera device information is the advanced access level, it indicates that the camera device is allowed to access all resources. At this time, the permission status corresponding to the camera device can be set to full management permission. In the embodiment of the present invention, by using the device hash value as a query condition to construct a query statement, the required information can be automatically and accurately retrieved from the database, avoiding the cumbersome manual search and improving the authentication efficiency. By executing the query statement using the data connection pool, the efficiency of information query is improved. By setting different access levels for different camera devices according to the device identifier, fine control of the access permissions of the camera devices can be achieved, preventing unauthorized access and reducing potential security risks. By configuring corresponding access permissions for the camera devices according to different access levels, it is ensured that the camera devices can only access the resources they are authorized to, avoiding security risks caused by over-authorization.

[0088] Based on the above embodiments, the embodiments of the present invention further include: when it is monitored that the security policy of the camera device is updated, detecting the current firmware version information of the camera device; extracting the stored firmware version information of the camera device in the firmware version database, and when the firmware version information is lower than the stored firmware version information, performing a firmware upgrade on the camera device.

[0089] Among them, the security policy can be understood as a series of measures for protecting the camera device. It can be understood that configuring the security policy for the camera device is a dynamic process and can be continuously updated or improved.

[0090] The firmware version information refers to the version number data embedded in the camera device and is used to identify the current version status of the camera device.

[0091] The firmware version database can be understood as a database for storing firmware version information. The firmware version information recorded in the firmware version database can be used to manage the update of the firmware version of the camera device.

[0092] The stored firmware version information refers to the version number data stored in the firmware version database and is used to compare with the current firmware version information to determine whether the camera device needs to perform a firmware upgrade.

[0093] Specifically, a security policy can be configured for the camera device, continuously monitor the security policy configured for the camera device, extract the pre-stored stored firmware version information from the firmware version database. When it is monitored that the security policy configured for the camera device is updated, detect the current firmware version information of the camera device, and compare the detected firmware version information with the stored firmware version information to obtain a comparison result. When the comparison result is that the firmware version information is lower than the stored firmware version information, the stored firmware version information can be used to upgrade the camera device.

[0094] Embodiment III

[0095] Figure 3 The following is a flowchart of another security protection authentication method provided by the third embodiment of the present invention. Based on the above embodiments, the embodiments of the present invention provide another security protection authentication method. As Figure 3 shown, the method includes:

[0096] S301. Obtain the authentication information and device identifier in the data packet transmitted by the camera device.

[0097] S302. Use a preset hash algorithm to perform a hash process on the device identifier to obtain a device hash value corresponding to the device identifier, and construct a first query statement for the security database using the device hash value as a query condition.

[0098] S303. Establish a data connection pool for connecting to the security database, and execute a first query statement in the security database through the data connection pool to obtain preset authentication information corresponding to the device identifier.

[0099] S304. Verify the authentication information according to the preset authentication information.

[0100] S305. Real-time collect the behavior data of the camera device, and obtain the behavior determination result of the camera device according to the behavior data. The behavior determination result includes at least one of the following: normal behavior, warning behavior, and abnormal behavior.

[0101] Among them, the behavior data can be understood as a series of behavior activity information of the camera device, which can be used to determine the behavior activities of the camera device and obtain the behavior determination result.

[0102] The behavior determination result refers to the conclusion obtained after analyzing the behavior data. For example, the behavior determination result can be at least divided into three categories: normal behavior, warning behavior, and abnormal behavior. Normal behavior can be understood as the behavior without any potential safety hazards, warning behavior can be understood as the behavior with potential safety hazards, and abnormal behavior can be understood as the behavior of the camera device that significantly deviates from the normal behavior.

[0103] Specifically, the behavior data for determining the behavior activities of the camera device can be collected in real time, and the behavior activities of the camera device can be determined and classified based on the real-time collected behavior data, and at least three determination classification results such as normal behavior, warning behavior, and abnormal behavior can be obtained. The determination classification result can be used as the behavior determination result for subsequent operations.

[0104] S306. When the behavior determination result is determined to be normal behavior, adjust the access permission of the camera device to full management permission; when the behavior determination result is determined to be warning behavior, adjust the access permission of the camera device to basic operation permission; when the behavior determination result is determined to be abnormal behavior, adjust the access permission of the camera device to zero access permission.

[0105] Specifically, when the behavior determination result of the camera device is determined to be a normal behavior based on the behavior data of the camera device, it can indicate that there are no behaviors with potential safety hazards in the current camera device. At this time, the access permission of the camera device can be adjusted to the full management permission; when the behavior determination result of the camera device is determined to be a warning behavior based on the behavior data of the camera device, it can indicate that there are potential behaviors with safety hazards in the current camera device. At this time, the access permission of the camera device can be adjusted to the basic operation permission; when the behavior determination result of the camera device is determined to be an abnormal behavior based on the behavior data of the camera device, it can indicate that the current camera device has behaviors that deviate significantly from the normal behavior. At this time, the access permission of the camera device can be adjusted to the zero access permission.

[0106] In an embodiment of the present invention, the authentication information and the device identifier in the data packet transmitted by the camera device are obtained. The device identifier is hashed using a preset hash algorithm to obtain a device hash value corresponding to the device identifier. The device hash value is used as a query condition to construct a first query statement for the security database. A data connection pool connected to the security database can be established. The first query statement can be executed in the security database through the data connection pool to obtain the preset authentication information corresponding to the device identifier. The authentication information can be verified according to the obtained preset authentication information. After the authentication information passes the verification, the behavior data for determining the behavior activities of the camera device can be collected in real time. The behavior activities of the camera device can be determined and classified based on the behavior data collected in real time, and at least three determination and classification results such as normal behavior, warning behavior, and abnormal behavior can be obtained. The determination and classification results can be used as the behavior determination result. When it is determined according to the behavior data of the camera device that the behavior determination result of the camera device is normal behavior, it can be indicated that there is no behavior with potential safety hazards in the current camera device. At this time, the access permission of the camera device can be adjusted to full management permission; when it is determined according to the behavior data of the camera device that the behavior determination result of the camera device is warning behavior, it can be indicated that there is a potential behavior with safety hazards in the current camera device. At this time, the access permission of the camera device can be adjusted to basic operation permission; when it is determined according to the behavior data of the camera device that the behavior determination result of the camera device is abnormal behavior, it can be indicated that the current camera device has a behavior significantly deviating from the normal behavior. At this time, the access permission of the camera device can be adjusted to zero access permission. The embodiment of the present invention can also determine the behavior activities of the camera device in real time by collecting and analyzing the behavior data of the camera device in real time to obtain the behavior determination result. The camera device can be hierarchically managed according to the behavior determination result, realizing the matching of the access level and the behavior activities of the camera device, reducing the potential security protection authentication risk, and ensuring the accuracy of the granted access permission and the compliance of the camera device to access resources by adjusting the access permission according to the behavior determination result.

[0107] Optionally, on the basis of the above embodiment, the embodiment of the present invention can also record the access log of the camera device for subsequent security audit, where the access log at least includes: the access time of the camera device, the access content, the usage situation of the access permission, etc.

[0108] Embodiment 4

[0109] Figure 4 A security protection authentication device provided in Embodiment 4 of the present invention, as Figure 4 shown, the device includes:

[0110] An information acquisition module 401, configured to acquire authentication information and a device identifier in a data packet transmitted by a camera device, and acquire preset authentication information corresponding to the device identifier in a security database;

[0111] A level determination module 402, configured to verify the authentication information according to the preset authentication information, and determine the access level of the camera device in a security policy database according to the device identifier;

[0112] A permission granting module 403, configured to grant corresponding access permissions to the camera device according to the access level.

[0113] In an embodiment of the present invention, a data packet transmitted by a camera device is acquired, an extraction operation can be performed on the acquired data packet to extract authentication information for verifying the device identity and a device identifier for uniquely identifying the camera device, and based on the device identifier, preset authentication information that is predefined and used to verify the identity of the camera device can be queried in a security database. The preset authentication information can be used to verify the authentication information. After the verification is passed, the access level of the camera device to access the network can be determined in a security policy database by using the device identifier. Corresponding access permissions can be allocated to the camera device according to different access levels of the camera device. In the embodiment of the present invention, by dynamically searching for corresponding preset authentication information in a security database, the authentication method can flexibly adapt to changes in various authentication requirements, enhancing the flexibility and adaptability of the authentication method; by using the device identifier as a query condition, it is ensured that the corresponding preset authentication information can be accurately found in the security database, avoiding the problem of mismatch between the preset authentication information and the authentication information, and improving the pertinence and accuracy of the authentication method; by verifying the authentication information, it is ensured that only authorized camera devices can access the Internet of Things, preventing unauthorized access; by the device identifier, the access level of the camera device can be accurately set, ensuring the accuracy and pertinence of the access permission allocation, and realizing the matching of the access level and the device requirements; by configuring different levels of access permissions for the camera device according to different access levels, it is ensured that the camera device can only access the resources it is authorized to access, reducing the potential security protection authentication risk.

[0114] Based on the above embodiment, an embodiment of the present invention further includes: when it is monitored that the security policy of the camera device is updated, detecting the current firmware version information of the camera device; extracting the stored firmware version information of the camera device in a firmware version database, and when the firmware version information is lower than the stored firmware version information, performing a firmware upgrade on the camera device.

[0115] Based on the above embodiments, in the embodiment of the present invention, the information acquisition module 401 includes: a key acquisition unit, configured to acquire the communication key of the camera device; a decryption unit, configured to send the encrypted random number to the camera device, acquire the decrypted random number corresponding to the encrypted random number, where the decrypted random number is obtained by the camera device decrypting the encrypted random number using the communication key; a random number verification unit, configured to determine that the challenge random number is the same as the decrypted random number, and decrypt the transmitted data packet encrypted using the communication key.

[0116] Based on the above embodiments, in the embodiment of the present invention, the key acquisition unit is specifically configured to determine the security policy update of the camera device, acquire the newly generated communication key of the camera device; after the communication key verification passes, save the communication key.

[0117] Based on the above embodiments, in the embodiment of the present invention, the information acquisition module 401 is specifically configured to

[0118] Perform a hashing process on the device identifier using a preset hashing algorithm to obtain the device hash value corresponding to the device identifier, and use the device hash value as a query condition to construct the first query statement of the security database; establish a data connection pool connected to the security database, and execute the first query statement in the security database through the data connection pool to acquire the preset authentication information corresponding to the device identifier.

[0119] Based on the above embodiments, in the embodiment of the present invention, the level determination module 402 is specifically configured to

[0120] Use the first query statement to query the camera device information corresponding to the device identifier in the security policy database, where the camera device information includes at least one of the following: device type information, device usage information, device usage scenario information; determine the access level of the camera device according to the camera device information, and the access level includes at least one of the following: no access level, basic access level, and advanced access level.

[0121] Based on the above embodiments, in the embodiment of the present invention, the permission granting module 403 is specifically configured to, when determining that the access level is the no access level, set the access permission to zero access permission; when determining that the access level is the basic access level, set the access permission to basic operation permission; when determining that the access level is the advanced access level, set the access permission to comprehensive management permission.

[0122] Based on the above embodiments, in the embodiments of the present invention, the permission granting module 402 is further specifically configured to: collect the behavior data of the camera device in real time, obtain the behavior determination result of the camera device according to the behavior data, and the behavior determination result includes at least one of the following: normal behavior, warning behavior, and abnormal behavior; when it is determined that the behavior determination result is normal behavior, adjust the access permission of the camera device to the full management permission; when it is determined that the behavior determination result is a warning behavior, adjust the access permission of the camera device to the basic operation permission; when it is determined that the behavior determination result is an abnormal behavior, adjust the access permission of the camera device to zero access permission.

[0123] Embodiment Five

[0124] Based on the above embodiments, the embodiments of the present invention provide another security protection authentication device, such as Figure 5As shown in the figure, the device includes: a device identification module 501, which can be used to collect and identify the device identifier of a camera device accessing the Internet of Things network, and can implement different security policies for the camera device based on the device identifier; an authentication request processing module 502, which can be used to receive an authentication request from the camera device. The authentication request is integrated in the communication data packet of the camera device, and the device identifier and preset authentication information are included in the communication data packet; an authentication information comparison module 503, which is used to compare the authentication information in the authentication request with the corresponding information pre-stored in the security database. When all the authentication information matches, it is considered that the authentication is passed; an access permission granting module 504, which is used to grant corresponding permissions to the camera device when it is determined that the authentication is successful; a real-time monitoring and logging module 505, which is used to continuously monitor the network activities of the camera device and send them to the logging subsystem. The logging subsystem can adopt efficient data storage and retrieval technologies to record the access logs of the camera device, including access time, access content, and usage of access permissions, for security auditing and tracking; an automated patch module 506, which is used to detect the security policy of the camera device. When it detects that the security policy is updated, it compares the current firmware version of the camera device with the firmware versions stored in the firmware version library. When the current firmware version of the camera device is lower than the firmware versions stored in the firmware version library, it pushes corresponding patches to the camera device to update the firmware version of the camera device; a dynamic key update module 507, which is used to detect the security policy of the camera device. When it detects that the security policy is updated, it generates a new key for decrypting the encrypted communication data packet; an exception response module 508, which is used to isolate the affected device or network area and provide an automated response policy. Among them, the automated response policy can include the following policies: isolation policy: quickly isolate the affected device or network area to prevent the spread of threats; notification policy: send real-time alert notifications to system administrators or security teams, including the type of exception, the affected device or area, and recommended countermeasures; recovery policy: provide recovery guidelines or automated tools after the threat is controlled to help system administrators quickly restore the normal operation of the affected device or network area. The above-mentioned modules work together to jointly ensure the security of the camera device accessing the Internet of Things.

[0125] Embodiment Six

[0126] The embodiment of the present invention provides an electronic device for executing a security protection authentication method, a computer-readable storage medium, and a computer program product.

[0127] Figure 6The structural schematic diagram of an electronic device that can be used to implement the embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown in the embodiments of the present invention, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the embodiments of the present invention described and / or claimed herein.

[0128] As Figure 6 shown, the electronic device includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. The memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the ROM 12 or the computer program loaded from the storage unit 18 into the RAM 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0129] Multiple components in the electronic device are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0130] The processor 11 can be various general and / or special processing components with processing and computing capabilities. Some examples of the processor 11 include but are not limited to a central processing unit, a graphics processing unit, various dedicated artificial intelligence computing chips, various processors running machine learning model algorithms, a digital signal processor, and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the security protection authentication method.

[0131] In some embodiments, the security protection authentication method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by the processor 11, one or more steps of the security protection authentication method may be performed. Alternatively, in other embodiments, the processor 11 may be configured for the security protection authentication method by any other suitable means (e.g., by means of firmware).

[0132] The various implementations of the systems and techniques described above in the embodiments of the present invention may be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays, application specific integrated circuits, application specific standard products, systems-on-a-chip, programmable logic devices loaded with a program, computer hardware, firmware, software, and / or combinations thereof. These various implementations may include: implemented in one or more computer programs that may be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a special or general programmable processor that may receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0133] The computer program for implementing the method of the embodiments of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general purpose computer, a special purpose computer, or other programmable data processing device, such that the computer program, when executed by the processor, causes the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on the remote machine or server.

[0134] In the context of embodiments of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a RAM, a ROM, an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0135] In order to provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a cathode ray tube or a liquid crystal display monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including: acoustic input, voice input, or tactile input).

[0136] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area networks, wide area networks, blockchain networks, and the Internet.

[0137] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is created by computer programs running on respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and virtual private server services.

[0138] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is made herein.

[0139] The above specific embodiments do not constitute a limitation on the protection scope of the embodiments of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A security protection authentication method, characterized in that: The method comprises: Obtain authentication information and a device identifier in a data packet transmitted by the camera device, and obtain preset authentication information corresponding to the device identifier in a security database; Verifying the authentication information according to the preset authentication information, and determining the access level of the camera device in a security policy database according to the device identifier; According to the access level, the corresponding access rights are granted to the camera device.

2. The method according to claim 1, characterized in that: The method of obtaining the authentication information and the device identifier in the data packet transmitted by the camera device includes: Obtaining a communication key for the camera device; Calling a challenge value generation rule to generate a challenge random number, and encrypting the challenge random number using the communication key to obtain an encrypted random number; Sending the encrypted random number to the camera device, obtaining a decrypted random number corresponding to the encrypted random number, wherein the decrypted random number is obtained by the camera device decrypting the encrypted random number using the communication key; Determine that the challenge random number is the same as the decryption random number, and use the communication key to decrypt the encrypted transmission data packet.

3. The method according to claim 2, characterized in that: The obtaining of the communication key of the camera device includes: Determine the security policy update of the camera device, and obtain the communication key newly generated by the camera device; After verifying that the communication key is verified, the communication key is saved.

4. The method according to claim 1, characterized in that: The obtaining preset authentication information corresponding to the device identifier in the security database includes: Performing hash processing on the device identifier using a preset hash algorithm to obtain a device hash value corresponding to the device identifier, and using the device hash value as a query condition to construct a first query statement for the security database; A data connection pool connected to the security database is established, and the first query statement is executed in the security database through the data connection pool to obtain preset authentication information corresponding to the device identifier.

5. The method according to claim 4, characterized in that: The step of determining the access level of the camera device in a security policy database according to the device identifier includes: Using the first query statement, query the security policy database for camera device information corresponding to the device identifier, where the camera device information includes at least one of the following: device type information, device usage information, and device usage scenario information; An access level of the camera device is determined according to the camera device information, where the access level includes at least one of the following: an unauthorized access level, a basic access level, and an advanced access level.

6. The method according to claim 5, characterized in that: Granting the camera device corresponding access rights according to the access level includes: When determining that the access level is the unauthorized access level, setting the access right to zero access right; When determining that the access level is the basic access level, setting the access permission as the basic operation permission; When it is determined that the access level is the advanced access level, the access permission is set to full management permission.

7. The method according to claim 1, characterized in that: The step of determining the access level of the camera device in the security policy database according to the device identifier further includes: Collecting behavior data of the camera device in real time, and obtaining a behavior determination result of the camera device according to the behavior data, wherein the behavior determination result includes at least one of the following: normal behavior, warning behavior, and abnormal behavior; When it is determined that the behavior is normal, adjusting the access permission of the camera device to full management permission; When it is determined that the behavior determination result is a warning behavior, adjusting the access permission of the camera device to the basic operation permission; When it is determined that the behavior determination result is an abnormal behavior, the access permission of the camera device is adjusted to zero access permission.

8. The method according to claim 1, characterized in that: Also includes: When monitoring the security policy update of the camera device, detecting the current firmware version information of the camera device; The stored firmware version information of the camera device in the firmware version database is extracted, and when the firmware version information is lower than the stored firmware version information, the firmware of the camera device is upgraded.

9. A security protection authentication device, characterized in that: The device comprises: An information acquisition module, used to acquire authentication information and a device identifier in a data packet transmitted by a camera device, and to acquire preset authentication information corresponding to the device identifier in a security database; A level determination module, used to verify the authentication information according to the preset authentication information, and determine the access level of the camera device in the security policy database according to the device identifier; The permission granting module is used to grant the corresponding access rights to the camera device according to the access level.

10. An electronic device, characterized in that: The electronic device comprises: At least one processor and a memory communicatively connected to the at least one processor, wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the security protection authentication method described in any one of claims 1 to 8.