Intelligent lock access control method and system based on attributes
By adopting attribute-based access control methods in the smart lock system, the shortcomings of the existing smart lock system in terms of permission management are solved, flexible permission management and high-security access control are realized, and smart lock systems are suitable for homes and commercial places.
Patent Information
- Application Number
- CN202510548614.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-06-20
AI Technical Summary
The existing smart lock system has shortcomings in permission management, including the inability to revoke user permissions in a timely manner, the lack of fine-grained access control capabilities, and the complexity and security risks in handling cascading deletion of permissions.
The smart lock access control method based on attributes is adopted to collect and store subject attributes, object attributes, environment attributes and permission attributes, establish the corresponding relationship between attributes and permissions, form an attribute authorization list, and check it during the access control execution stage. This method includes authentication mechanisms, the use of attribute authorization lists, and local storage of policy sets for flexible permission management and secure access control.
It realizes flexible setting of access permissions based on the visitor's identity, time, date and location, improves the applicability and security of the smart lock system, avoids the dependence of permission updates on cloud servers, and simplifies permission management operations and reduces security risks.
Smart Images

Figure CN120185918A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of intelligent locks, and particularly to an attribute-based intelligent lock access control method and system. Background Art
[0002] With the rapid development of Internet of Things technology, intelligent locks, as an important part of smart home systems, have gradually replaced traditional mechanical locks and are widely used in homes and commercial places. Existing intelligent lock systems usually adopt the Device-Gateway-Cloud (DGC) architecture. Through a user mobile device (such as a smart phone) as a gateway, it communicates with the intelligent lock using Bluetooth Low Energy (BLE), and performs permission management and data storage through a cloud server. This architecture provides users with a convenient unlocking method, such as remote or near-field unlocking through digital keys.
[0003] However, there are significant deficiencies in the permission management of existing intelligent lock systems. First, due to the lack of a direct Internet connection for intelligent locks, permission updates rely on the communication between the user device and the cloud server. When the user device disconnects from the network (such as entering airplane mode), the administrator cannot revoke its permissions in a timely manner, resulting in potential security risks. For example, a user whose permission has been revoked can still unlock through an offline device. Second, existing systems lack fine-grained access control capabilities and cannot flexibly set permissions based on attributes such as the identity, time, date, or location of the visitor. For example, different roles in a family (such as permanent residents, regular visitors, or temporary visitors) require different access restrictions, but existing systems usually only provide a single permission allocation method and are difficult to adapt to complex home or commercial scenarios. In addition, existing intelligent lock systems have defects in handling cascading deletion of permissions. When the permission of a certain authorizer is revoked, the sub-permissions assigned by it often need to be manually deleted one by one, which is complex to operate and prone to security hazards. Some intelligent lock systems attempt to enhance security through biometric technology or Near Field Communication (NFC), but these methods still do not solve the dynamic and fine-grained problems of permission management, and NFC is vulnerable to relay attacks.
[0004] Therefore, there is an urgent need in the prior art for an intelligent lock access control method that can be highly secure and effectively prevent offline circumvention of permission revocation to improve the security and applicability of the system. Summary of the Invention
[0005] In view of the above technical problems, the present invention provides an attribute-based intelligent lock access control method and system to solve the problems of poor security, complex operation, and insufficient dynamic permission management of existing intelligent locks.
[0006] Other features and advantages of the present invention will become apparent through the following detailed description, or be learned in part through the practice of the present invention.
[0007] According to one aspect of the present invention, a method for attribute-based intelligent lock access control is proposed, and the method includes:
[0008] Collect and store subject attributes, object attributes, environmental attributes, and permission attributes, where the subject attributes include the unique identifier, role, and location of the visitor, the object attributes include the device identifier of the intelligent lock, the environmental attributes include the access time, access date, and access location, and the permission attributes include the unlocking operation;
[0009] Establish the correspondence between attributes and permissions to form an attribute authorization list for checking during the access control execution phase;
[0010] When receiving an access request, verify the identity of the visitor through an authentication mechanism;
[0011] Parse the access request to obtain the subject attributes, object attributes, environmental attributes, and the requested operation;
[0012] Judge whether the access request is authorized according to the attribute authorization list and a preset policy set, where the policy set is stored in the intelligent lock;
[0013] Execute or reject the access request according to the judgment result.
[0014] Furthermore, the unique identifier is used to distinguish different visitors and associate their permissions; the role is used to identify the identity category of the visitor, and the identity category includes the owner, resident, regular visitor, and temporary visitor; the location is used to determine the geographical location of the visitor relative to the intelligent lock, and its physical distance is estimated through the RSSI of the Bluetooth Low Energy (BLE) signal strength.
[0015] Furthermore, the access time is generated by the internal time tool of the intelligent lock and is used to limit the unlocking time range of the visitor; the access date is generated by the internal time tool of the intelligent lock and is used to limit the unlocking date range of the visitor; the access location is used to judge whether the visitor is within the preset range of the intelligent lock.
[0016] Furthermore, the authentication mechanism adopts an Identity-Based Encryption (IBE) scheme, including the following steps:
[0017] On the mobile device of the visitor, sign the access request with the private key of the visitor to generate signature data;
[0018] Send the signature data to the intelligent lock through Bluetooth Low Energy (BLE);
[0019] The intelligent lock uses the public key and identity identifier of the visitor to verify the authenticity of the signature data. If the verification is passed, the access request is continued to be processed; otherwise, the request is rejected and an error symbol is output.
[0020] Further, the policy set includes authorization policies for different subjects, objects, and environments, and is constrained by subject predicates, object predicates, and environment predicates, where:
[0021] The subject predicates include: the condition that the unique identifier is a preset subject identifier value and the role is a preset subject role;
[0022] The object predicates include: the condition that the device identifier is the default smart lock identifier;
[0023] The environment predicates include: the condition that the access time is within a default time range and the access location is within a default range;
[0024] The authorization policy includes: when the subject attribute, the object attribute, and the environment attribute of an access request respectively satisfy the subject predicate, the object predicate, and the environment predicate, and the requested operation is an unlocking operation, authorizing the execution of the unlocking operation.
[0025] Further, the access control execution phase further includes:
[0026] When an administrator needs to modify the access permission, the administrator needs to directly modify the policy set in the smart lock within the Bluetooth Low Energy (BLE) connection range of the smart lock through a mobile device;
[0027] The modified policy set takes effect immediately locally.
[0028] Further, the method further includes:
[0029] Associating the authorizer with one or more authorized persons through the role field in the subject attribute and assigning the same role identity;
[0030] Allowing the administrator to configure the access permission by adding a prohibition policy for a specific role in the policy set;
[0031] When the configured prohibition policy sets the unlocking operation of a specific role to be refused, cancel the unlocking permission of that specific role and all its associated entities.
[0032] Further, the method prevents time fraud by setting a time tool in the smart lock, specifically including:
[0033] Integrating an independent time tool in the smart lock for generating the access time and the access date;
[0034] When receiving an access request, the smart lock only compares the time information of the internal time tool with the environment predicate in the policy set and rejects the time provided by the visitor's device.
[0035] According to another aspect of the present invention, there is provided an attribute-based intelligent lock access control system, comprising:
[0036] An acquisition module, which is used to collect and store subject attributes, object attributes, environmental attributes and permission attributes, wherein the subject attributes include the unique identifier, role and location of the visitor, the object attributes include the device identifier of the intelligent lock, the environmental attributes include the access time, access date and access location, and the permission attributes include unlocking operations; establish a correspondence between attributes and permissions to form an attribute authorization list for checking during the access control execution phase;
[0037] An execution module, which is used to verify the identity of the visitor through an authentication mechanism when receiving an access request; parse the access request to obtain the subject attributes, object attributes, environmental attributes and the requested operations; determine whether the access request is authorized according to the attribute authorization list and a preset policy set, wherein the policy set is stored in the intelligent lock; execute or reject the access request according to the judgment result.
[0038] The technical solution of the present invention has the following beneficial effects:
[0039] Through the combination of subject attributes (such as unique identifier, role, location), object attributes (such as intelligent lock identifier), environmental attributes (such as time, date, location) and permission attributes, the present invention can flexibly set access permissions according to conditions such as the identity, time, date and location of the visitor, meet the differentiated needs of multiple roles (such as owner, resident, regular visitor, temporary visitor) in family or commercial places, and effectively improve the applicability of the intelligent lock system.
[0040] By storing the permission policy set inside the intelligent lock and requiring the administrator to directly modify the policy within the Bluetooth Low Energy (BLE) connection range of the intelligent lock, the present invention avoids the dependence on the cloud server for permission updates. Even if the visitor puts the device in an offline state (such as flight mode), it is impossible to avoid permission revocation, thus significantly enhancing the security of the system.
[0041] By associating the subject attributes with the authorizer and the authorized person, the present invention realizes hierarchical management of permissions. When the administrator disables the permissions of a certain role, the permissions of all authorized persons associated with that role will be revoked simultaneously, simplifying the permission management operation and reducing the security risks caused by permission omissions.
[0042] Adopt an identity-based encryption scheme to sign and verify access requests to ensure the authenticity of the visitor's identity, prevent malicious users from illegally unlocking by forging or tampering with identity identifiers, and further improve the anti-attack ability of the system.
[0043] By integrating an independent time tool inside the smart lock to generate access time and date, the present invention avoids fraud that may be caused by relying on the time of the visitor's device, ensures the accurate execution of time and date restrictions, and effectively guards against replay attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 It is a flowchart of an attribute-based smart lock access control method in an embodiment of this specification;
[0045] Figure 2 It is a structural block diagram of an attribute-based smart lock access control system in an embodiment of this specification. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the concept of example embodiments to those skilled in the art. The features, structures, or characteristics described may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present invention. However, those skilled in the art will realize that the technical solutions of the present invention can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. may be employed. In other instances, well-known technical solutions are not shown or described in detail to avoid obscuring the various aspects of the present invention.
[0047] In addition, the accompanying drawings are only schematic illustrations of the present invention. The same reference numerals in the drawings denote the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0048] The present invention provides an attribute-based smart lock access control method for a product. Referring to Figure 1 As shown, it is a schematic flow diagram of an attribute-based smart lock access control method for a product provided by an embodiment of the present invention. This method can be applied to electronic devices such as personal computers and servers. This method can be executed by a device, which can be implemented by software and / or hardware. Specifically, this method can include the following steps S101 to S102:
[0049] In step S101, the subject attributes, object attributes, environmental attributes, and permission attributes are collected and stored. The subject attributes include the unique identifier, role, and location of the visitor. The object attributes include the device identifier of the smart lock. The environmental attributes include the access time, access date, and access location. The permission attributes include the unlocking operation. A correspondence between the attributes and permissions is established to form an attribute authorization list for checking during the access control execution phase.
[0050] As compensation, the unique identifier is used to distinguish different visitors and associate their permissions; the role is used to identify the identity category of the visitor, and the identity category includes the owner, resident, regular visitor, and temporary visitor; the location is used to determine the geographical location of the visitor relative to the smart lock, and its physical distance is estimated through the received signal strength indicator (RSSI) of the Bluetooth Low Energy (BLE) signal. The access time is generated by the internal time tool of the smart lock and is used to limit the unlocking time range of the visitor; the access date is generated by the internal time tool of the smart lock and is used to limit the unlocking date range of the visitor; the access location is used to determine whether the visitor is within the preset range of the smart lock.
[0051] In this step, it is the preparation stage of the attribute-based smart lock access control method, and the focus is on collecting and storing the necessary attributes for access control decisions. These attributes are divided into four categories: subject attributes, object attributes, environmental attributes, and permission attributes. The subject attributes include the user's unique identifier (sID), role (sRole), and location (Position). The sID is assigned during user registration and serves as the unique code to distinguish different users. The sRole defines the user's access level, such as "owner", "resident", or "visitor", and each role corresponds to different permissions. The Position is calculated in real time through the received signal strength indicator (RSSI) of the Bluetooth Low Energy (BLE) signal. Specifically, if the RSSI value exceeds the predefined threshold, the Position is classified as "near", indicating that the user is near the smart lock, thus preventing unauthorized access from a distance. This enhances the security of the system, especially in preventing physical attacks. The object attributes include the device identifier (oID) of the smart lock, which is the unique identifier of each lock and is preconfigured in the system to ensure that the access control policy is applied to the correct device. The environmental attributes include the time (Time), date (Date), and location (Position) of the access request. The Time and Date are generated by the internal clock tool of the smart lock to ensure the accuracy and integrity of the time data and prevent users from committing fraud by modifying the device time. The Position attribute reconfirms the proximity of the user at the time of the access request, which is consistent with the Position of the subject attributes. The permission attributes define the allowed operations, mainly the "unlock" action, which allows the user to open the smart lock.
[0052] These attributes are stored in the memory of the smart lock in a structured format, such as a key-value pair database. In a specific implementation, Raspberry Pi 3B+ can be used as the hardware platform to provide sufficient storage and processing capabilities to manage these attributes. The core of this preparation stage is to establish an attribute authorization list. The attribute authorization list is a mapping that associates a combination of specific subject attributes, object attributes, and environmental attributes with the granted permissions. For example, an entry in the attribute authorization list can specify that a user with the role of "owner" can perform the "unlock" operation on the smart lock identified by oID when the location is "near" at any time. The attribute authorization list is configured by the administrator during the setup process and stored locally on the smart lock. This local storage ensures that access control decisions can be made efficiently and securely without relying on an external network, especially in cases where the network connection is unreliable or disconnected by malicious users.
[0053] In step S102, when receiving an access request, verify the identity of the visitor through an authentication mechanism; parse the access request to obtain the subject attributes, object attributes, environmental attributes, and the requested operation; determine whether the access request is authorized according to the attribute authorization list and a preset policy set, where the policy set is stored in the smart lock; execute or reject the access request according to the determination result.
[0054] Among them, the smart lock receives access requests from the user's mobile device via Bluetooth Low Energy (BLE) and uses an Identity-Based Encryption (IBE) mechanism to verify the identity of the visitor. The user device signs the access request with its private key to generate signature data and transmits it to the smart lock via BLE. The smart lock verifies the authenticity of the signature using the public key and identity identifier of the visitor. If the verification passes, the request is processed; if the verification fails, the request is rejected and an error message is returned. The smart lock parses the access request to extract the subject attributes, object attributes, environmental attributes, and the requested operation. The subject attributes include the unique identifier of the visitor (sID, such as "P1"), role (sRole, such as "owner" or "resident"), and location (Position, estimated by the BLE signal strength RSSI to determine if it is "near"). The object attributes include the device identifier of the smart lock (oID, such as "SmartLock"). The environmental attributes include the access time (Time, generated by the internal clock of the smart lock, such as "12:00"), access date (Date, such as "2023-01-01"), and access location (Position, the same as the subject attribute). The requested operation is usually to unlock (unlock). Then, the smart lock determines whether the access request is authorized based on the Attribute Authorization List (AA list) stored internally and the preset policy set. The policy set includes Subject Attribute Predicate (SAP), Object Attribute Predicate (OAP), and Environmental Attribute Predicate (EAP). For example, SAP requires that the sID be a specific value and the sRole be "owner", OAP requires that the oID be the target smart lock, and EAP requires that the access time be within 0:00 to 24:00 and the location be "near". The Policy Decision Point (PDP) of the smart lock evaluates these predicates. If all conditions are met and the requested operation is unlock, access is authorized; otherwise, the request is rejected. Finally, according to the judgment result, the Policy Enforcement Point (PEP) of the smart lock executes the unlock operation or rejects the request. If authorized, the smart lock activates the electronic bolt to complete the unlocking; if rejected, the request log is recorded for subsequent auditing. This method ensures the prevention of unauthorized access even when the user device is offline through local storage of the policy set and IBE verification, and at the same time supports fine-grained permission control, which is applicable to smart lock systems in home and commercial scenarios.
[0055] Specifically, the identity verification mechanism adopts an Identity-Based Encryption IBE scheme, including the following steps:
[0056] On the mobile device of the visitor, sign the access request with the private key of the visitor to generate signature data;
[0057] Send the signature data to the smart lock via Bluetooth Low Energy BLE;
[0058] The intelligent lock uses the public key and identity of the visitor to verify the authenticity of the signature data. If the verification passes, the access request is processed continuously; otherwise, the request is rejected and an error symbol is output.
[0059] Specifically, the policy set includes authorization policies for different subjects, objects, and environments, and is constrained by subject predicates, object predicates, and environment predicates, where:
[0060] The subject predicates include: the condition that the unique identifier is a preset subject identifier value and the role is a preset subject role;
[0061] The object predicates include: the condition that the device identifier is the default intelligent lock identifier;
[0062] The environment predicates include: the condition that the access time is within the default time range and the access location is within the default range;
[0063] The authorization policy includes: when the subject attribute, object attribute, and environment attribute of the access request respectively satisfy the subject predicate, object predicate, and environment predicate, and the requested operation is an unlocking operation, authorizing the execution of the unlocking operation.
[0064] Specifically, the access control execution stage further includes:
[0065] When the administrator needs to modify the access permission, the administrator needs to directly modify the policy set in the intelligent lock within the Bluetooth Low Energy (BLE) connection range of the intelligent lock through a mobile device;
[0066] The modified policy set takes effect immediately locally.
[0067] In an embodiment, the method further includes: associating the authorizer with one or more authorized persons through the role field in the subject attribute and assigning the same role identity; allowing the administrator to configure the access permission by adding a prohibition policy for a specific role to the policy set; when the configured prohibition policy sets the unlocking operation of a specific role to be rejected, canceling the unlocking permission of the specific role and all its associated entities.
[0068] Among them, the attribute-based intelligent lock access control method realizes hierarchical management of permissions through the role field (sRole) in the subject attributes. The system uses sRole to associate the authorizer with one or more authorized parties and assigns the same role identity to these entities. For example, a user with the "resident2" role (such as P2) can grant the same role to other users (such as P4 and P5), forming a role group sharing the same access permissions. This association is achieved through an attribute authorization list, which associates sRole with other attributes (such as user identification, time, location) and permissions, ensuring that users within the role group are subject to unified rules.
[0069] The administrator can configure access permissions by directly modifying the policy set inside the intelligent lock. Specifically, within the Bluetooth Low Energy (BLE) connection range of the intelligent lock, the administrator adds a prohibition policy for a specific role through a mobile device. For example, a policy of prohibiting unlocking is added for sRole = "resident2", clearly rejecting the "unlock" operation for this role. Since the policy set is stored locally in the intelligent lock, the permission modification takes effect immediately, and users cannot avoid permission revocation by disconnecting the network (such as entering airplane mode), thus enhancing the security of the system.
[0070] When the prohibition policy sets the unlocking operation of a specific role to be rejected, the system will automatically cancel the unlocking permissions of this role and all its associated entities, achieving cascading deletion of permissions. For example, if a prohibition policy of unlocking is configured for sRole = "resident2", then all users with this role (such as P2, P4, P5) will lose the ability to unlock. This cascading deletion mechanism simplifies permission management operations, avoids the cumbersome steps of revoking user permissions one by one, and at the same time ensures no residual permissions, improving the security and management efficiency of the system.
[0071] In one embodiment, the method prevents time fraud by setting a time tool inside the intelligent lock, specifically including: integrating an independent time tool inside the intelligent lock for generating the access time and the access date; when receiving an access request, the intelligent lock only compares the time information of the internal time tool with the environmental predicates in the policy set and rejects the time provided by the visitor's device.
[0072] In the embodiment of the present invention, the attribute-based intelligent lock access control method prevents time fraud by setting an independent time tool inside the intelligent lock. Specifically, an independent time tool is integrated inside the intelligent lock for generating the access time and the access date. These time information are maintained by the intelligent lock itself and do not depend on the time data of the user device, ensuring the credibility of the time source. The policy set of the intelligent lock is stored locally and contains environmental predicates, such as the access time range for a specific role (for example, a "regular visitor" unlocks between 12:00 and 14:00).
[0073] When the intelligent lock receives an access request, it first verifies the identity of the visitor through an Identity-Based Encryption (IBE) mechanism, and then parses the request to extract the subject attributes, object attributes, environmental attributes, and request operations. The intelligent lock only uses the current time and date generated by its internal time tool to compare with the environmental predicates in the policy set. For example, if the policy set stipulates that a certain user can only unlock within a specific time period, the intelligent lock will check whether its internal time meets this condition. If the condition is met, the unlocking is authorized; otherwise, the request is rejected, and the time information provided by the user device is ignored.
[0074] By relying only on the internal time tool, the intelligent lock effectively prevents time fraud behaviors, such as the situation where users modify the device time to bypass access restrictions. This mechanism can also prevent replay attacks, and expired access requests will be recognized as invalid by the internal time.
[0075] Based on the same idea, as Figure 2 shown, there is provided an attribute-based intelligent lock access control system, including:
[0076] A collection module 201, which is used to collect and store subject attributes, object attributes, environmental attributes, and permission attributes, where the subject attributes include the unique identifier, role, and location of the visitor, the object attributes include the device identifier of the intelligent lock, the environmental attributes include the access time, access date, and access location, and the permission attributes include the unlocking operation; establish the correspondence between attributes and permissions to form an attribute authorization list for checking during the access control execution stage;
[0077] An execution module 202, which is used to verify the identity of the visitor through an authentication mechanism when receiving an access request; parse the access request to obtain the subject attributes, object attributes, environmental attributes, and the requested operation; judge whether the access request is authorized according to the attribute authorization list and the preset policy set, where the policy set is stored in the intelligent lock; execute or reject the access request according to the judgment result.
[0078] As can be seen from the above system, in this embodiment, through the combination of subject attributes (such as unique identifier, role, location), object attributes (such as smart lock identifier), environmental attributes (such as time, date, location), and permission attributes, the present invention can flexibly set access permissions according to conditions such as the identity, time, date, and location of the visitor, meeting the differentiated needs of multiple roles (such as owner, resident, regular visitor, temporary visitor) in a home or commercial premise, and effectively enhancing the applicability of the smart lock system. By storing the permission policy set inside the smart lock and requiring the administrator to directly modify the policy within the Bluetooth Low Energy (BLE) connection range of the smart lock, the present invention avoids the dependence on the cloud server for permission updates. Even if the visitor puts the device in an offline state (such as flight mode), the permission revocation cannot be circumvented, thus significantly enhancing the security of the system. By associating the authorizer and the authorizee through subject attributes, the present invention realizes hierarchical management of permissions. When the administrator disables the permissions of a certain role, the permissions of all the authorizees associated with that role will be revoked simultaneously, simplifying the permission management operation and reducing the security risk caused by permission omission. By using an identity-based encryption scheme to sign and verify the access request, the authenticity of the visitor's identity is ensured, preventing malicious users from illegally unlocking by forging or tampering with the identity identifier, and further improving the anti-attack ability of the system. By integrating an independent time tool inside the smart lock to generate the access time and date, the present invention avoids fraud that may be caused by relying on the visitor's device time, ensures the accurate execution of time and date restrictions, and effectively guards against replay attacks.
[0079] The specific details of each module in the above system have been described in detail in the implementation manner of the method part. The details not disclosed can be referred to the content of the implementation manner in the method part, and thus will not be elaborated here.
[0080] Through the description of the above implementation manners, those skilled in the art can easily understand that the exemplary implementation manners described here can be implemented by software or by the way of software combined with necessary hardware. Therefore, the technical solution according to the embodiment of the present invention can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on the network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the exemplary embodiment of the present invention.
[0081] In addition, the above drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiment of the present invention, rather than for limiting purposes. It can be easily understood that the processes shown in the above drawings do not indicate or limit the time sequence of these processes. Additionally, it can also be easily understood that these processes can be executed synchronously or asynchronously in, for example, multiple modules.
[0082] It should be noted that although several modules or units of the device for action execution are mentioned in the above detailed description, such division is not mandatory. In fact, according to the exemplary embodiments of the present invention, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0083] Other embodiments of the present invention will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the invention following the general principles of the invention and including known common knowledge or conventional technical means in the technical field not disclosed herein. The specification and embodiments are to be considered exemplary only, and the true scope and spirit of the invention are pointed out by the claims.
[0084] It should be understood that the present invention is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.
Claims
1. A smart lock access control method based on attributes, characterized in that: The method comprises: Collect and store subject attributes, object attributes, environment attributes and permission attributes, wherein the subject attributes include the unique identifier, role and location of the visitor, the object attributes include the device identifier of the smart lock, the environment attributes include the access time, access date and access location, and the permission attributes include the unlocking operation; Establish the correspondence between attributes and permissions and form an attribute authorization list for checking during the access control execution phase; When receiving an access request, verify the identity of the visitor through an authentication mechanism; Parsing the access request to obtain the subject attributes, object attributes, environment attributes and requested operation; Determining whether the access request is authorized according to the attribute authorization list and a preset policy set, wherein the policy set is stored in the smart lock; The access request is executed or rejected according to the determination result.
2. The attribute-based smart lock access control method according to claim 1, characterized in that: The unique identifier is used to distinguish different visitors and associate their permissions; The role is used to identify the identity category of the visitor, which includes owner, resident, regular visitor and temporary visitor; the location is used to determine the visitor's geographic location relative to the smart lock, which estimates the physical distance through the Bluetooth low energy BLE signal strength RSSI.
3. The attribute-based smart lock access control method according to claim 1, characterized in that: The access time is generated by the internal time tool of the smart lock and is used to limit the visitor's unlocking time range; the access date is generated by the internal time tool of the smart lock and is used to limit the visitor's unlocking date range; the access location is used to determine whether the visitor is within the preset range of the smart lock.
4. The attribute-based smart lock access control method according to claim 1, characterized in that: The authentication mechanism adopts an identity-based encryption (IBE) scheme, which includes the following steps: On the visitor's mobile device, the visitor's private key is used to sign the access request to generate signature data; Sending the signature data to the smart lock via Bluetooth low energy BLE; The smart lock uses the visitor's public key and identity to verify the authenticity of the signature data. If the verification is successful, the access request will continue to be processed; otherwise, the request will be rejected and an error symbol will be output.
5. The attribute-based smart lock access control method according to claim 1, characterized in that: The policy set includes authorization policies for different subjects, objects and environments, and is constrained by subject predicates, object predicates and environment predicates, where: The subject predicate includes: the condition that the unique identifier is a preset subject identifier value and the role is a preset subject role; The object predicate includes: a condition that the device identifier is a default smart lock identifier; The environmental predicate includes: the condition that the access time is within a default time range and the access location is within a default range; The authorization policy includes: when the subject attribute, the object attribute and the environment attribute of the access request satisfy the subject predicate, the object predicate and the environment predicate respectively, and the requested operation is an unlock operation, authorizing execution of an unlock operation.
6. The attribute-based smart lock access control method according to claim 1, characterized in that: The access control execution phase also includes: When the administrator needs to modify the access rights, the administrator needs to directly modify the policy set in the smart lock through the mobile device within the Bluetooth low energy BLE connection range of the smart lock; The modified policy set takes effect locally immediately.
7. The attribute-based smart lock access control method according to claim 1, characterized in that: The method further comprises: By using the role field in the subject attribute, the authorizer is associated with one or more authorized persons and assigned the same role identity; Allows administrators to configure access permissions by adding role-specific prohibition policies to a policy set; When the configured prohibition policy sets the unlocking operation of a specific role to be denied, the unlocking permission of the specific role and all its associated entities is revoked.
8. The attribute-based smart lock access control method according to claim 1, characterized in that: The method prevents time fraud by setting a time tool in the smart lock, specifically comprising: Integrate an independent time tool in the smart lock to generate the access time and the access date; When receiving an access request, the smart lock only compares the time information of the internal time tool with the environmental predicate in the policy set and rejects the time provided by the visitor's device.
9. An attribute-based smart lock access control system, characterized in that: include: A collection module, which is used to collect and store subject attributes, object attributes, environmental attributes and permission attributes, wherein the subject attributes include the unique identifier, role and location of the visitor, the object attributes include the device identifier of the smart lock, the environmental attributes include the access time, access date and access location, and the permission attributes include the unlocking operation; establish a corresponding relationship between attributes and permissions, and form an attribute authorization list for checking during the access control execution phase; An execution module, the execution module is used to verify the identity of the visitor through the identity authentication mechanism when receiving the access request; parse the access request to obtain the subject attributes, object attributes, environment attributes and requested operations; determine whether the access request is authorized according to the attribute authorization list and a preset policy set, wherein the policy set is stored in the smart lock; The access request is executed or rejected according to the determination result.
Citation Information
Patent Citations
Attribute-based intelligent door lock access control method
CN111815832A
Intelligent lock control method and device
CN114764954A
Method for ensuring safe access and operation of equipment for smart home
CN115664767A
Automatic time service method and device of intelligent door lock, computer equipment and storage medium
CN118158794A
Multi-tenant access control method and device and computer-readable storage medium
WO2020038273A1
Cited By
Cloud platform remote permission configuration method, system and device for door lock management
CN121462255A