Registration method and device of security and protection equipment, electronic equipment and storage medium
Through the root server generation verification requirements, combined with device type estimation and reverse data type verification, the problem of low credibility of identity verification during the security device registration process is solved, achieving higher security and efficiency.
Patent Information
- Application Number
- CN202510757159.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-09
AI Technical Summary
During the registration process of existing security equipment, the credibility of the identity verification results is low, and there is a risk of being cracked by third parties, resulting in insufficient data security.
Through the root server generates verification requirements based on the device information of the security device, the device is required to send specific types of verification data, and authenticate based on these data, combining device type estimation and reverse data type verification to improve the credibility of identity verification.
It improves the credibility of the identity verification results, enhances the security of the security device registration process, effectively resists forged data and replay attacks, and improves registration efficiency and information security.
Smart Images

Figure CN120281814A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of registration communication of security devices, and particularly to a registration method, device, electronic device and storage medium for security devices. Background Art
[0002] In the current market, when a security device registers with a server, it is usually similar to the registration method of general Internet of Things devices. The device registration is achieved through steps such as time synchronization, identity authentication, device registration, and communication establishment to access the server. In the prior art, the identity authentication is usually achieved by comparing the information sent by the security device with the device list stored locally on the server, and the information is encrypted during the information transmission process to protect the user's data security. However, the encryption method adopted by the server has a risk of being cracked by a third party, resulting in a problem of low credibility of the identity authentication result during the registration process of the security device. Summary of the Invention
[0003] In view of the above problems, the embodiments of the present application provide a registration method, device, electronic device and storage medium for security devices. The solution of the present application is beneficial to improving the credibility of the identity authentication result during the registration process of security devices.
[0004] In a first aspect, the embodiments of the present application provide a registration method for a security device, which is applied to a root server. The method includes: receiving device information sent by a target security device, where the device information includes a device identifier of the target security device; determining a first target data type according to the device identifier, where the first target data type is one of multiple data types generated by the target security device during operation; generating a first verification requirement for the target security device according to the first target data type, and sending the first verification requirement to the target security device, where the first verification requirement is used to instruct the target security device to send first verification data of the first target data type; receiving the first verification data sent by the target security device according to the first verification requirement, and determining an identity authentication result of the target security device according to the first verification data; if the identity authentication result is verified, generating registration information of the target security device in the Internet of Things system, and sending the registration information to the target security device.
[0005] It can be seen that in the embodiments of the present application, the root server generates a verification requirement according to the device information of the security device, so that the security device sends the first verification data to the root server according to the verification requirement. The root server performs identity authentication based on the verification information of the security device to obtain the identity authentication result. The identity authentication result is supported by the first verification data provided by the security device, which improves the credibility of the identity authentication result, and further improves the security of the security device in the registration process, ensuring the data security of the security device users.
[0006] In combination with the first aspect, in a possible embodiment, determining the first target data type according to the device identifier includes: determining the device type and device model of the target security device according to the device identifier; determining the first target data type according to the device type and device model of the target security device; if the determination of the device type and device model of the target security device fails according to the device identifier, determining the presumed device type of the target security device according to the device identifier; determining the second target data type and the third target data type according to the presumed device type; wherein, the second target data type is one of the data types of various data generated during the operation of the security device of the presumed device type, and the third target data type is not the data type generated during the operation of the security device of the presumed device type; generating a second verification requirement according to the second target data type and the third target data type, and sending the second verification requirement to the target security device, and the second verification requirement is used to instruct the target security device to send the second verification data of the second target data type and the third verification data of the third target data type; if the second verification data and the third verification data sent by the target security device are received at the same time, determining that the identity verification result of the target security device is verification failed; if the second verification data and the third verification data sent by the target security device are not received at the same time, determining the first target data type according to the presumed device type.
[0007] It can be seen that in this embodiment, through the combination of device type presumption and reverse data type verification, it effectively deals with the scenarios of fuzzy or forged device identifiers, significantly improves the recognition accuracy of counterfeit devices while reducing the misjudgment rate, improves the credibility of the identity verification result, and ensures the data security of security device users.
[0008] In combination with the first aspect, in a possible embodiment, determining the identity verification result of the target security device according to the first verification data includes: determining the device type and device model of the target security device according to the device identifier; determining whether the first verification data is of the first target data type; if the first verification data is of the first target data type and the device type is a sensing device, determining the reasonable numerical range of the first verification data according to the device model; if the first verification data conforms to the reasonable numerical range, determining that the identity verification result is verification passed; if the first verification data is of the first target data type and the device type is a camera device, determining the reasonable image parameters of the first verification data according to the device model; if the first verification data conforms to the reasonable image parameters, determining that the identity verification result is verification passed.
[0009] In combination with the first aspect, in a possible embodiment, if the device type is a sensor device, the method further includes: if the first verification data is not of the first target data type, determining that the authentication result is failed; if the first verification data does not meet the reasonable numerical range, obtaining the verification times of the target security device, and if the verification times are not greater than the preset times, generating a second verification requirement, where the second verification requirement is used to instruct the target security device to send the first verification data of the fourth target data type; sending the second verification requirement to the target security device; if the verification times are greater than the preset times, determining that the authentication result is failed.
[0010] It can be seen that in the embodiments of the present application, for security devices of the sensor device type, through two mechanisms of data numerical range verification and dynamic verification strength adjustment, while ensuring the authentication efficiency of security devices of the sensor device type, effectively resisting security threats such as forged data and replay attacks, improving the registration efficiency of security devices while also ensuring information security.
[0011] In combination with the first aspect, in a possible embodiment, if the device type is a camera device, the method further includes: if the data type of the first verification data is not the image data type, determining that the authentication result is failed; if the first verification data does not meet the reasonable image parameters, obtaining the verification times of the target security device, and if the verification times are not greater than the preset times, generating a third verification requirement, where the third verification requirement is used to instruct the target security device to send the first verification data of the image data type including at least one verification feature, and the verification feature includes a scaling feature or a moving feature; sending the third verification requirement to the target security device; if the verification times are greater than the preset times, determining that the authentication result is failed.
[0012] It can be seen that in the embodiments of the present application, for security devices of the image device type, through three layers of protection of data type filtering, technical parameter verification, and dynamic behavior verification, while ensuring the fast response of camera devices, effectively resisting security threats such as image forgery, replay attacks, and device hijacking, improving the registration efficiency of security devices while also ensuring information security.
[0013] In combination with the first aspect, in a possible embodiment, before determining the target data type according to the device identifier, the method further includes: generating query information according to the device identifier and sending the query information to the cache device; where the cache device is used to cache the registration information of the security device, and the query information is used to request the registration information of the target security device in the cache device; determining that the registration information sent by the cache device is not received.
[0014] In combination with the first aspect, in a possible embodiment, after generating the registration information of the target security device in the Internet of Things system when the authentication result is verification passed, the method further includes: sending the registration information to a cache device so that the cache device stores the registration information of the security device.
[0015] It can be seen that in the embodiments of the present application, by caching the registration information of the registered security devices in the cache device, the root server can directly send the registration information to the security device when the registered device submits a registration request again, thereby reducing the amount of data processed by the root server and improving the processing and transmission efficiency of the root server.
[0016] In a second aspect, an embodiment of the present application provides a registration device for a security device. The registration device for a security device is used to execute the registration method for a security device. The registration device for a security device includes: A receiving unit, configured to receive device information sent by a target security device, where the device information includes a device identifier of the target security device.
[0017] A determining unit, configured to determine a target data type according to the device identifier, where the target data type is one of the data types of multiple data generated during the operation of the target security device.
[0018] A sending unit, configured to generate a first verification requirement for the target security device according to the target data type, and send the first verification requirement to the target security device, where the first verification requirement is used to instruct the target security device to send first verification data of the target data type.
[0019] A receiving unit, configured to receive the first verification data sent by the target security device according to the first verification requirement, and determine the authentication result of the target security device according to the first verification data.
[0020] A sending unit, configured to generate the registration information of the target security device in the Internet of Things system when the authentication result is verification passed, and send the registration information to the target security device.
[0021] In a third aspect, an embodiment of the present application provides an electronic device, including a processor, a memory, a communication interface, and one or more programs. The one or more programs are stored in the memory and are configured to be executed by the processor. One or more instructions are adapted to be loaded and executed by the processor to perform part or all of the methods in the first aspect and / or the second aspect.
[0022] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program for electronic data exchange. The computer program causes a computer to execute part or all of the methods in the first aspect and / or the second aspect.
[0023] In a fifth aspect, the present application provides a computer program product, which, when read and executed by a computer, causes the computer to execute some or all of the methods in the first aspect and / or the second aspect.
[0024] Understandably, the beneficial effects of the embodiments in the second aspect to the fifth aspect can refer to the beneficial effects in the method of the first aspect, which will not be elaborated here. Description of the Drawings
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0026] Figure 1 It is a schematic diagram of the application scenario of a registration method for a security device provided by an embodiment of the present application; Figure 2 It is a schematic flowchart of a registration method for a security device provided by an embodiment of the present application; Figure 3 It is a schematic flowchart of another registration method for a security device provided by an embodiment of the present application; Figure 4 It is a schematic structural diagram of an Internet of Things system for a security device provided by an embodiment of the present application; Figure 5 It is a schematic diagram of communication between a target security device and a root server provided by an embodiment of the present application; Figure 6 It is a schematic flowchart of yet another registration method for a security device provided by an embodiment of the present application; Figure 7 It is a schematic structural diagram of a registration device for a security device provided by an embodiment of the present application; Figure 8 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application.
[0027] Explanation of the reference numerals in the drawings: 100: Application scenario; 101: Target security device; 102: Root server; 103: Communication server; 700: Registration device for security device; 701: Receiving unit; 702: Determining unit; Sending unit 703; 800: Electronic device; 801: Memory; 802: Processor; 803: Communication interface; 804: Bus. Detailed Embodiments
[0028] To enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts fall within the scope of protection of this application.
[0029] The terms "first", "second", etc. in the specification and claims of this application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or devices.
[0030] Referring to "embodiment" in this context means that the specific features, structures, or characteristics described in connection with the embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0031] The embodiments of this application will be described below in conjunction with the accompanying drawings.
[0032] Embodiment 1: Please refer to Figure 1 , Figure 1 , which is a schematic diagram of an application scenario of a registration method for a security device provided in an embodiment of this application. The application scenario 100 includes a target security device 101, a root server 102, and a communication server 103. The target security device 101 is specifically a security protection device, specifically a fire alarm, a temperature alarm, an access control device, a smart doorbell, a smart camera device, etc. The root server 102 is used to communicate directly with the target security device 101 or communicate with the target security device 101 through the communication server 103, so as to implement functions such as message sending and receiving, updating device firmware and application software. Here, the communication server 103 is a distributed stream processing middleware, which is used to implement asynchronous message passing between the target security device 101 and the root server 102, as well as data processing and other functions.
[0033] The communication server 103 is specifically a Kafka communication server or an EMQX communication server.
[0034] In the embodiment of the present application, the root server 102 receives the device information sent by the target security device 101. The device information includes the device identifier of the target security device 101. The device information specifically includes information related to the target security device 101 such as the device identifier and the MAC (Media Access Control) address. Subsequently, the root server 102 will perform identity verification of the security device based on the device information of the target security device 101.
[0035] It should be noted that in the prior art, the root server 102 usually compares and checks the device information of the target security device 101 with the device information list pre-stored in the local or cache device. If the device information list includes the device information of the target security device 101, it is determined that the target security device 101 passes the identity verification.
[0036] In the embodiment of the present application, the root server 102 needs to determine the first target data type through the device identifier of the target security device 101. The first target data type is one of the data types of the multiple types of data generated during the operation of the target security device 101. That is to say, the first target data type is one of the data types of the multiple types of data that the target security device 101 will generate during operation. Further, the root server 102 can determine multiple first target data types based on the multiple data types described above.
[0037] After determining the first target data type, the root server 102 generates a first verification requirement for the target security device 101 according to the first target data type and sends the first verification requirement to the target security device 101. The first verification requirement is used to instruct the target security device 101 to send the first verification data of the first target data type. Exemplarily, the first verification requirement specifically refers to requiring the target security device 101 to send all the data of the first target data type collected within the next 30 minutes.
[0038] The root server 102 receives the first verification data sent by the target security device 101 according to the first verification requirement and determines the identity verification result of the target security device 101 based on the first verification data. The root server 102 specifically determines the identity verification result of the target security device 101 according to the characteristics (such as data values, distribution rules, data integrity, etc.) of all the data of the first target data type sent by the target security device 101 within the next 30 minutes.
[0039] If the authentication result is successful, the root server 102 generates the registration information of the target security device 101 in the Internet of Things system and sends the registration information to the target security device 101. The registration information here specifically includes information such as the account password and server address of the communication server 103. The target security device 101 can establish a connection with the communication server 103 based on the registration information, thereby establishing a stable communication channel between the device and the root server 102 to achieve real-time data transmission and interaction.
[0040] It can be seen that in the embodiment of the present application, the root server generates a verification requirement according to the device information of the security device, and then the security device sends the first verification data to the root server according to the verification requirement. The root server performs identity verification based on the verification information of the security device to obtain the identity verification result. The identity verification result is supported by the first verification data provided by the security device, which improves the credibility of the identity verification result, thereby improving the security of the security device in the registration process and ensuring the data security of the security device user.
[0041] Figure 2 It is a schematic flowchart of a registration method for a security device provided by an embodiment of the present application. As Figure 2 shown, it includes steps S201 - S205.
[0042] S201: The root server receives the device information sent by the target security device. The device information includes the device identifier of the target security device.
[0043] Specifically, the device information here specifically includes information such as the device identifier and MAC address of the target security device. The device information is specifically sent during the process when the target security device needs to initiate a registration request to the root server and request to access the Internet of Things system where the root server is located.
[0044] S202: The root server determines the first target data type according to the device identifier. The first target data type is one of the data types of multiple data generated during the operation of the target security device.
[0045] Specifically, the root server can determine the first target data type of the target security device based on the device identifier of the target security device. The target data type is one of the data types of multiple data generated during the operation of the target security device. Exemplarily, if the target security device is a temperature sensor, its corresponding first target data type may be the temperature data type, rather than the image data type.
[0046] Further, before determining the first target data type based on the device identifier, the root server may also perform additional verification on the device information of the target security device and the security device information in the local database. If the device information of the target security device is stored in the local database, then S202 and subsequent steps are executed. If the device information of the target security device is not stored in the local database, then the authentication result of the target security device is determined to be failed authentication.
[0047] Optionally, determining the first target data type according to the device identifier includes: determining the device type and device model of the target security device according to the device identifier; determining the first target data type according to the device type and device model of the target security device; if the determination of the device type and device model of the target security device fails according to the device identifier, then determining the presumed device type of the target security device according to the device identifier; determining the second target data type and the third target data type according to the presumed device type; wherein, the second target data type is one of the data types generated during the operation of the security device of the presumed device type, and the third target data type is not the data type generated during the operation of the security device of the presumed device type; generating a second verification requirement according to the second target data type and the third target data type, and sending the second verification requirement to the target security device, where the second verification requirement is used to instruct the target security device to send the second verification data of the second target data type and the third verification data of the third target data type; if the second verification data and the third verification data sent by the target security device are received simultaneously, then determining the authentication result of the target security device is failed authentication; if the second verification data and the third verification data sent by the target security device are not received simultaneously, then determining the first target data type according to the presumed device type.
[0048] Specifically, in the embodiment of the present application, the first target data type of the first target security device is mainly determined by determining the device type and device model of the target security device determined according to the device identifier. Specifically, it can be determined according to the preset correspondence between the device identifier and the device type and device model. Furthermore, the first target data type is determined according to the correspondence between the device type and device model and the data type.
[0049] If the root server cannot match the preset device type library through the device identifier (for example, the device identifier does not contain the standard model code or the communication protocol does not match), then the device type presumption process is started, and the presumed device type is determined according to some features in the device identifier (such as the brand identifier, signal frequency band, or port number). For example, if the device identifier contains the prefix "CAM_" but no complete model information, then the presumed device type is a camera device.
[0050] Based on the presumed device type, the root server extracts the second target data type and the third target data type from a preset data type mapping table. Among them, the second target data type is the data type that the presumed device type will necessarily generate during normal operation (for example, a camera device generates image stream data, and a sensor device generates numerical data), and the third target data type is the data type that the presumed device type physically cannot generate (for example, requiring a camera device to send temperature data, or requiring a temperature sensor to send audio data).
[0051] Subsequently, the root server generates a second verification requirement, indicating that the target security device needs to submit the first verification data of the second target data type and the third target data type at the same time. For example, a device presumed to be an infrared sensor needs to submit the current ambient temperature value (the third target type) and a segment of audio waveform data (the fourth target type). The microprocessor sends the second verification requirement to the target security device through an encrypted communication channel.
[0052] If the target security device returns the second verification data of the second target data type (for example, the infrared sensor returns audio data), the authentication result is directly determined to be failed, and the device is marked as a suspected forged device. If the data of the fourth target data type is not returned (for example, only the temperature value is returned, or the corresponding data cannot be provided), the root server determines the first target data type (not the second target data type or the third target data type) according to the presumed device type for the final verification, and performs encrypted verification or numerical range comparison.
[0053] It can be seen that in this embodiment, through the combination of device type presumption and reverse data type verification, it effectively deals with the scenarios of ambiguous or forged device identifiers, reduces the misjudgment rate, significantly improves the recognition accuracy of counterfeit devices, improves the credibility of the authentication result, and ensures the data security of security device users.
[0054] Optionally, determining the first target data type according to the device type and device model of the target security device specifically includes: determining the device type and device model of the target security device according to the device identifier; if the device type is a sensing device, determining the first target data type according to the device model, where there is a corresponding relationship between the preset device model and multiple data types, the preset device model includes the device model, and the multiple data types include the first target data type; if the device type is a camera device, determining the image data type as the first target data type.
[0055] Specifically, in the embodiments of the present application, the target security devices are divided into sensing devices or image devices. The sensing devices specifically refer to security devices such as smoke alarms, humidity alarms, and smart door locks that cannot generate and transmit image data; the image devices specifically refer to security devices such as cameras and video doorbells that generate image data during operation.
[0056] First, for security devices of the image device type, in this solution, identity verification is mainly performed through the image data they generate. This is because for security devices that need to generate image data, such as security cameras and visual doorbells, they need to generate relevant image data during operation. The cost of forging image data is relatively high and the recognition difficulty is relatively low. The root server can obtain relevant reasonable image parameters (such as frame rate, resolution, etc.) of the generated image data on the premise of knowing the device type and device model, and then perform identity verification on the target security device based on information such as reasonable image parameters to determine the image data type as the first target data type.
[0057] For sensing devices, the root server determines the device type and device model of the target security device according to the device identifier in the device information. The device type specifically includes types such as smoke alarms, humidity alarms, and smart door locks, and the device model specifically includes "DX-001", "DX-001A", "DX-002", etc. Each device model corresponds to different models of security devices of the same type. The data types generated by security devices during operation are related not only to the device type but also to the device model. New models of security devices of the same type may generate more or fewer types of data during operation than old models.
[0058] Therefore, after determining that the device type of the target security device is a sensing device, the root server first determines multiple data types corresponding to the target security device based on the device model of the target security device and the preset corresponding relationship between the device model and multiple data types, and then determines the first target data type from the multiple data types corresponding to the target security device.
[0059] Furthermore, the root server needs to determine one or more first target data types from the multiple data types corresponding to the target security device, and preferably determines the data type with a high degree of relevance to the device type of the target security device as the first target data type. The degree of relevance refers to the degree of association between the data type and the device type of the corresponding target security device. Exemplarily, for a security device of a smoke alarm, the relevance of the smoke concentration data is higher than that of the power data.
[0060] It can be seen that in the embodiment of the present application, the first target data type of the sensing device is screened from multiple data types corresponding to the target security device, and the first target data type of the image device is the image data type; this enables the root server to have data support for the subsequent obtained authentication result, improving the credibility of the authentication result; for the image device, it also reduces the difficulty of authenticating the target security device according to the first verification data, improving the verification efficiency, and thus improving the registration efficiency of the security device.
[0061] S203: The root server generates a first verification requirement for the target security device according to the first target data type, and sends the first verification requirement to the target security device. The first verification requirement is used to instruct the target security device to send the first verification data of the first target data type.
[0062] Specifically, after the root server determines the first target data type of the target security device, it is necessary to generate a first verification requirement for the target security device according to the first target data type. Here, the first verification requirement is used to instruct the target security device to send the first verification data of the first target data type. Specifically, it can require the target security device to send all data within a period of time, or individual data at a specific time point.
[0063] S204: The root server receives the first verification data sent by the target security device according to the first verification requirement, and determines the authentication result of the target security device according to the first verification data.
[0064] Optionally, determining the authentication result of the target security device according to the first verification data includes: determining the device type and device model of the target security device according to the device identifier; determining whether the first verification data is the first target data type; if the first verification data is the first target data type and the device type is a sensing device, determining the reasonable numerical range of the first verification data according to the device model; if the first verification data conforms to the reasonable numerical range, determining the authentication result as verification passed; if the first verification data is the first target data type and the device type is a camera device, determining the reasonable image parameters of the first verification data according to the device model; if the first verification data conforms to the reasonable image parameters, determining the authentication result as verification passed.
[0065] Specifically, in the embodiment of the present application, different verification methods are adopted based on the device type of the target security device. First, the root server will determine whether the first verification data is the first target data type. If the first verification data is not the first target data type, it can be known that the target security device cannot provide relevant data corresponding to its device type as an identity proof, and the root server will directly determine that the authentication result of the target security device fails.
[0066] If the first verification data is of the first target data type and the device type is a sensing device, the root server determines a reasonable numerical range for the first verification data according to the device type. If it conforms to the reasonable numerical range, the identity verification result is determined to be verified passed. It should be noted that the reasonable numerical range here is determined based on the device model and device type provided by the target security device, and the corresponding relationship between the reasonable numerical range, device type, and device model is also stored locally in the root server. Therefore, if the first verification data conforms to the reasonable numerical range, it is determined that the identity of the target security device is legal, and the identity verification result is determined to be verified passed.
[0067] If the first verification data is of the first target data type and the device type is a camera device, the reasonable image parameters of the first verification data are determined according to the device model. Similar to the sensing device, for the camera device, relevant data features also need to be determined based on the device type and device model, that is, the reasonable image parameters here, for identity verification. Specifically, the root server installs various plugins and software locally to analyze the image data, obtains features such as the frame rate, resolution, and watermark information of the first verification data to analyze the first verification data. When it is considered to conform to the reasonable image parameters, it is determined that the identity of the target security device is legal, and the identity verification result is determined to be verified passed.
[0068] Optionally, if the device type is a sensing device, the method further includes: obtaining the environmental information of the target security device, where the environmental information includes at least one of temperature information, season information, weather information, or humidity information, and determining a reasonable numerical range for the first verification data according to the environmental information, device type, and device model.
[0069] Specifically, in this embodiment, for a sensing device deployed in a variable environment (such as an outdoor security temperature and humidity sensor), the dynamically adjusted threshold can filter out environmental noise interference and accurately identify real abnormal data, thereby improving the accuracy of the identity verification result of the root server.
[0070] Optionally, if the device type is a sensor device, the method further includes: if the first verification data is not of the first target data type, determining that the identity verification result is not verified passed; if the first verification data does not conform to the reasonable numerical range, obtaining the verification times of the target security device. If the verification times do not exceed the preset times, generating a second verification requirement, where the second verification requirement is used to instruct the target security device to send the first verification data of the fourth target data type; sending the second verification requirement to the target security device; if the verification times are greater than the preset times, determining that the identity verification result is not verified passed.
[0071] Specifically, in this embodiment, the accuracy of identity authentication of security devices is improved through a hierarchical verification strategy. The root server first quickly screens the basic attributes (data type, numerical range) of the first verification data. If the basic verification fails, the result can be determined without performing complex calculations, thereby reducing system resource consumption.
[0072] For scenarios where the numerical value is abnormal but the data type is compliant, the verification intensity is dynamically adjusted in combination with the number of verification attempts: within the allowed number of attempts, the device is required to provide a fourth target data type with a higher security level (such as multi-factor authentication); if the number of attempts is exhausted, the verification process is immediately terminated to prevent brute force cracking.
[0073] Furthermore, the setting of the reasonable numerical range is based on the physical characteristics of the target security device and the environmental normality. For example, the output value of a light sensor is usually lower than 10 lux at night. If a value higher than 1000 lux is received and the device is not in a strong light environment, it is determined as abnormal. The root server dynamically updates the reasonable numerical range by comparing the data reported by the device with the environmental information of the environment where the target security device is located in real time, avoiding misjudgment caused by sudden environmental changes.
[0074] In addition, the statistics and reset mechanism of the verification times are bound to the device identity. If the target security device does not trigger the verification process within a preset time period (such as 24 hours), the verification times counter automatically resets to zero. If the device is locked due to consecutive failures, the administrator needs to perform a manual unlock through a secure channel to ensure the flexibility of the system defense.
[0075] It can be seen that in the embodiment of this application, for security devices of the sensing device type, through two mechanisms of data numerical range verification and dynamic verification intensity adjustment, while ensuring the identity verification efficiency of security devices of the sensing device type, it effectively resists security threats such as forged data and replay attacks, improves the efficiency of security device registration, and also ensures information security.
[0076] Optionally, if the device type is a camera device, the method further includes: if the data type of the first verification data is not an image data type, determining that the identity verification result is verification failed; if the first verification data does not conform to the reasonable image parameters, obtaining the verification times of the target security device, and if the verification times are not greater than the preset times, generating a third verification requirement, where the third verification requirement is used to instruct the target security device to send the first verification data of the image data type including at least one verification feature, and the verification feature includes a zoom feature or a movement feature; sending the third verification requirement to the target security device; if the verification times are greater than the preset times, determining that the identity verification result is verification failed.
[0077] Specifically, in this embodiment, a multi-level verification mechanism is designed for the characteristics of the imaging device. The root server first filters out spoofing attacks of non-image data (such as forged text or audio data) through data type screening. For image data, the basic legality is further detected through technical parameter verification. For example, a low-resolution image may be a screenshot forgery, and an abnormal frame rate may be a video tampering. If the parameter verification fails but the data type is legal, the verification intensity is dynamically upgraded based on the number of verification attempts: within the allowed number of attempts, the device is required to submit image data containing dynamic behaviors (such as zooming in on a specific QR code or performing a preset trajectory movement). Such features need to be generated by real-time physical operations and are difficult to be forged by static image replay attacks.
[0078] Furthermore, the generation and verification process of the dynamic verification features are combined with image analysis algorithms. For example, the zoom feature needs to verify the focusing accuracy of the device on the target object within a specified time, and the movement feature needs to match the spatio-temporal coordinates of the preset trajectory (such as horizontal translation of 30 cm followed by vertical rotation of 15°). The root server eliminates the influence of image transmission delay through the timestamp compensation algorithm to ensure the temporal coherence of the dynamic behavior. If the dynamic features in the image data returned by the device do not match the spatio-temporal logic required by the instruction, it is directly determined to be invalid.
[0079] In addition, the verification attempt threshold is associated with the device risk level. The preset number threshold for imaging devices in high-risk areas is 1 time, and it can be set to 3 times in ordinary areas. If the device is locked due to continuous failures, it needs to be unlocked manually by the administrator to prevent remote malicious attacks.
[0080] It can be seen that in the embodiment of this application, for security devices of the image device type, through three layers of protection: data type filtering, technical parameter verification, and dynamic behavior verification, while ensuring the rapid response of the imaging device, it effectively resists security threats such as image forgery, replay attacks, and device hijacking, improves the efficiency of security device registration, and also ensures information security.
[0081] S205: If the identity verification result is verification passed, the root server generates the registration information of the target security device in the Internet of Things system and sends the registration information to the target security device.
[0082] Specifically, after determining that the identity verification result is verification passed, the server generates the registration information of the target security device in the Internet of Things system. Here, the registration information specifically includes information such as account, password, and server address. After receiving the registration information, the target security device connects to the communication server through the registration information, thereby realizing asynchronous communication with the root server.
[0083] In addition, the information received by the target security device also includes a message topic, which is used to indicate the purpose, function, or category of each message, thereby preventing problems such as incomplete information, intercepted information, and tampered information during the communication process between the root server, the communication server, and the target security device.
[0084] If the authentication result fails, the root server also needs to implement measures such as blacklisting the device information of the target security device, such as the device ID and IP address, and generating corresponding security logs, and pushing them to the operation and maintenance platform.
[0085] Embodiment 2: In Embodiment 1, a registration method of a root server for a security device is described. Based on this, on the premise that the root server is also connected to a cache device, the embodiment of the present application further provides a more detailed registration method of a security device. Please refer to Figure 3 , Figure 3 which is a schematic flowchart of another registration method of a security device provided by the embodiment of the present application, including steps S301 - S307.
[0086] S301: The root server receives the device information sent by the target security device, and the device information includes the device identifier of the target security device.
[0087] S302: The root server generates query information according to the device identifier and sends the query information to the cache device; wherein, the cache device is used to cache the registration information of the security device, and the query information is used to request the registration information of the target security device in the cache device.
[0088] Specifically, after receiving the device information sent by the target security device and before determining the target data type according to the device identifier, the root server also generates query information according to the device identifier and sends the query information to the cache device. Among them, the cache device is a device used to cache the registration information of security devices that have passed authentication (including information such as device type, model, communication protocol, account, and password), such as a Remote Dictionary Server (Redis) device.
[0089] S303: The root server determines that it has not received the registration information sent by the cache device.
[0090] S304: The root server determines the first target data type according to the device identifier, and the first target data type is one of the data types of multiple data generated by the target security device during operation.
[0091] S305: The root server generates a first verification requirement for the target security device according to the first target data type, and sends the first verification requirement to the target security device. The first verification requirement is used to instruct the target security device to send first verification data of the first target data type.
[0092] S306: The root server receives the first verification data sent by the target security device according to the first verification requirement, and determines the identity verification result of the target security device based on the first verification data.
[0093] S307: If the identity verification result is verified passed, the root server generates registration information of the target security device in the IoT system, and sends the registration information to the target security device.
[0094] For the detailed description of steps S301, S304 - S307, please refer to the relevant description of steps S201 - S205, which will not be elaborated here.
[0095] Optionally, after generating the registration information of the target security device in the IoT system when the identity verification result is verified passed, the method further includes: sending the registration information to the cache device, so that the cache device stores the registration information of the security device.
[0096] Specifically, by way of example, please refer to Figure 4 , Figure 4 FIG. is a schematic structural diagram of an IoT system of a security device provided by an embodiment of the present application, which includes a target security device, a root server, a cache device, and a communication server. It can be seen that the target security device first sends device information to the root server to start the registration process. The root server queries whether there is registration information of the target security device in the cache device according to the device information. When there is registration information in the cache device, the registration information is sent to the target security device, or identity verification is performed according to the device information (for the detailed identity verification process, please refer to the relevant description of the foregoing steps S202 - S204, which will not be elaborated here). After the identity verification is passed, registration information is generated and sent to the target security device, and the registration information is cached in the cache device. The target security device then establishes a communication channel with the communication server according to the registration information to complete the registration.
[0097] In the embodiment of the present application, in addition to sending the registration information to the target security device and storing it in the local cache of the root server, the registration information will also be cached in the cache device.
[0098] This is because the target security device may lose its registration information during system upgrades, factory resets, etc., resulting in the inability to communicate normally with the root server. At this time, the device will resend its device information to the root server for registration. When the root server receives the device information of the target security device again, it can directly obtain the corresponding registration information from the cached devices and send it directly to the security device, thereby reducing the amount of data processing by the root server and improving the processing and transmission efficiency of the root server.
[0099] It can be seen that in the embodiment of the present application, by caching the registration information of the registered security devices in the cache device, the root server can directly send the registration information to the security device when the registered device submits a registration request again, thereby reducing the amount of data processing by the root server and improving the processing and transmission efficiency of the root server.
[0100] Optionally, the root server is respectively connected to the first communication server and the second communication server, and generates the registration information of the target security device in the Internet of Things system, including: generating the first registration information of the target security device in the first communication server and determining the first registration information as the registration information; if a connection failure message sent by the target security device is received, generating the second registration information of the target security device in the second communication server and determining the second registration information as the registration information.
[0101] Please refer to Figure 5 , Figure 5 , which is a communication schematic diagram between a target security device and a root server provided by an embodiment of the present application. It can be seen that the target security device can communicate with the root server through the first communication server or the second communication server. As described above, the target security device needs to establish a connection with the communication server during the registration process. Therefore, when the target security device attempts to establish a connection with the first communication server and fails, it will send a connection failure message to the root server to obtain the second registration information generated by the root server and attempt to establish a connection with the second communication server. Eventually, the target security device will establish a communication connection with the root server through the first communication server or the second communication server.
[0102] Embodiment 3: In Embodiment 1, a registration method for an independent security device to register is described. Based on this, on the premise that the target security device is one of the security devices in a device cluster, the embodiment of the present application also provides another more detailed registration method for the security device. Among them, the device cluster includes multiple security devices of the same type, such as multiple camera devices, multiple temperature sensing devices, etc. The device cluster is installed in the same area, and the multiple security devices in the device cluster can communicate with each other through short-range communication technologies (such as Bluetooth, etc.), so as to implement functions such as image collection, temperature acquisition, and fire warning in a centralized area.
[0103] Please refer to Figure 6 , Figure 6 which is a schematic flowchart of another registration method for a security device provided by an embodiment of the present application, including steps S601 - S605.
[0104] S601: The root server receives device information sent by the target security device. The device information includes the device identifier and the cluster identifier of the target security device. The cluster identifier is used to represent the device cluster to which the target security device belongs.
[0105] S602: If the target security device is the first registered device in the device cluster corresponding to the cluster identifier, the root server determines the first target data type according to the device identifier. The first target data type is one of the data types of multiple types of data generated during the operation of the target security device.
[0106] S603: The root server generates a first verification requirement for the target security device according to the first target data type, and sends the first verification requirement to the target security device. The first verification requirement is used to instruct the target security device to send the first verification data of the first target data type.
[0107] S604: The root server receives the first verification data sent by the target security device according to the first verification requirement, and determines the identity verification result of the target security device according to the first verification data.
[0108] S605: If the identity verification result is verification passed, the root server generates registration information for the target security device in the IoT system, and sends the registration information to the target security device.
[0109] Optionally, if the target security device is not the first registered device in the device cluster to which it belongs, and the device type of the target security device is a sensing device, the method further includes: obtaining reference data sent by the first registered device in the device cluster corresponding to the cluster identifier. The reference data includes data of the fifth target data type generated by the first registered device during the target time period; sending a fifth verification requirement to the target security device. The fifth verification requirement is used to instruct the target security device to send second verification data corresponding to the fifth data type generated during the target time period to the root server; receiving the second verification data sent by the target security device according to the fifth data type; performing identity verification on the target security device according to the reference data and the second verification data.
[0110] Specifically, in this embodiment, the device type of the target security device is a sensing device, and the root server establishes a trusted benchmark based on the reference data of the first registered device in the cluster. Since the first device has been strictly verified through the process in the foregoing steps, its identity has a high degree of credibility. On the premise that there are registered devices, the data of the same time period and the same data type submitted by the target security device to prove that it is in the same physical environment or performing the same task is sufficient to prove the legitimacy of its identity. For example, in an intelligent building cluster, if the first temperature sensor records that the indoor temperature is 15°C at a certain time period, while the target device reports 30°C at the same time period, it may be a forged device or a sensor failure.
[0111] If the similarity between the reference data and the second verification data is greater than the preset similarity, determine that the identity verification result of the target security device is verified.
[0112] It can be seen that in the embodiment of the present application, on the premise that there is a previously registered device in the device cluster where the target security device is located, the target security device is authenticated based on the second verification data and the reference data. Compared with the verification process of the first registered device, the data type of the verification data of the target security device can be directly determined by the data type corresponding to the registered device, reducing steps such as determining the data type and reasonable data range of the target security device, thereby reducing the data processing volume of the root server and improving the verification and registration efficiency of the security device.
[0113] Optionally, if the target security device is not the first registered device in the device cluster to which it belongs, and the device type of the target security device is an image device, the method further includes: obtaining a reference image sent by the first registered device in the device cluster corresponding to the cluster identifier according to the cluster identifier; determining a feature target from the reference image; sending a sixth verification requirement to the target security device, where the sixth verification requirement is used to instruct the target security device to send image data to the root server; receiving the image data sent by the target security device according to the sixth verification requirement; if the image data sent by the target security device according to the sixth verification requirement includes the feature target, determine that the identity verification result of the target security device is verified; if the image data sent by the target security device according to the sixth verification requirement does not include the feature target, determine whether the environmental feature of the image data sent by the target security device according to the sixth verification requirement conforms to the environmental feature of the reference image, and if the environmental feature of the image data sent by the target security device according to the sixth verification requirement conforms to the environmental feature of the reference image, determine that the identity verification result of the target security device is verified.
[0114] Specifically, in the embodiments of the present application, the device type of the target security device is an image device, and the device cluster constructs benchmark verification information through the reference images provided by the first registered device. The characteristic targets specifically refer to specific planar patterns, objects, texts, etc. The characteristic targets are automatically identified from the reference images through a preset deep learning model. For example, the landmark objects or regions in the reference images are located through a target detection algorithm. The environmental characteristic parameters include light intensity, background geometric structure, color distribution, etc. Specifically, they can be converted into multi-dimensional vectors by a feature encoding module for similarity calculation.
[0115] After receiving the sixth verification requirement, the target security device uploads the image data corresponding to the requirement and transmits or encrypts and transmits the image data to the root server. The root server first determines whether there are characteristic targets in the image through a target matching algorithm. If there are, the verification is directly passed; if not, the environmental characteristic analysis process is started to avoid misjudgment caused by temporary occlusion or angle change of the characteristic targets.
[0116] It should be noted that the first registered device needs to collect multiple groups of reference images and upload them to the cloud during the initialization phase. The system selects the image with the highest environmental stability as the benchmark reference image. The environmental characteristic similarity comparison uses the cosine similarity algorithm to judge the environmental consistency by calculating the included angle of the feature vectors of the target image and the reference image. If the similarity is lower than the threshold, it is determined that the target security device may be located in an unauthorized area or there is a risk of tampering, and the verification result is not passed.
[0117] It can be seen that in the embodiments of the present application, through the dual mechanisms of fusing characteristic target matching and environmental characteristic verification, not only the accuracy of device identity verification is ensured, but also the robustness of the system to dynamic environmental changes is improved, effectively preventing illegal devices from accessing the device cluster through spoofing or replay attacks. At the same time, compared with the verification process of the first registered device, steps such as determining the device model of the target security device are reduced, thereby reducing the data processing volume of the root server and improving the verification and registration efficiency of the security device.
[0118] By implementing the method in the above embodiments of the application, it can be seen that the root server performs identity verification based on the verification information of the security device to obtain the identity verification result, improving the credibility of the identity verification result. Through the combination of device type presumption and reverse data type verification, while reducing the misjudgment rate, the recognition accuracy of spoofed devices is significantly improved. Different detection means are adopted for security devices of different device types, which improves the credibility of the identity verification result while ensuring the identity verification efficiency of security devices of the sensing device type. The registration information of the registered security devices is cached in the cache device, reducing the data processing quantity of the root server and improving the processing and transmission efficiency of the root server.
[0119] Based on the description of the above embodiments of the configuration method, the present application further provides a registration device 700 for a security device. The registration device 700 for the security device can be a computer program (including program code) running in Figure 1 one of the root servers 102 shown in Figure 2 and is used to execute the methods shown in Figure 3 and Figure 6 . Please refer to Figure 7 . Figure 7 FIG. is a schematic structural diagram of a registration device for a security device provided by an embodiment of the present application. The registration device 700 for the security device includes: A receiving unit 701, configured to receive device information sent by a target security device, where the device information includes a device identifier of the target security device.
[0120] A determining unit 702, configured to determine a target data type according to the device identifier, where the target data type is one of the data types of multiple types of data generated during the operation of the target security device.
[0121] A sending unit 703, configured to generate a first verification requirement for the target security device according to the target data type, and send the first verification requirement to the target security device, where the first verification requirement is used to instruct the target security device to send first verification data of the target data type.
[0122] A receiving unit 701, configured to receive the first verification data sent by the target security device according to the first verification requirement, and determine an authentication result of the target security device according to the first verification data.
[0123] A sending unit 703, configured to generate registration information of the target security device in the Internet of Things system if the authentication result is authentication passed, and send the registration information to the target security device.
[0124] In a possible embodiment, in terms of determining the first target data type according to the device identifier, the determining unit 702 is further specifically configured to: determine the device type and device model of the target security device according to the device identifier; determine the first target data type according to the device type and device model of the target security device; if the determination of the device type and device model of the target security device fails according to the device identifier, determine the presumed device type of the target security device according to the device identifier; determine the second target data type and the third target data type according to the presumed device type; wherein, the second target data type is one of the data types of various data generated during the operation of the security device of the presumed device type, and the third target data type is not the data type generated during the operation of the security device of the presumed device type; generate a second verification requirement according to the second target data type and the third target data type, and send the second verification requirement to the target security device, and the second verification requirement is used to instruct the target security device to send the second verification data of the second target data type and the third verification data of the third target data type; if the second verification data and the third verification data sent by the target security device are received simultaneously, determine that the identity verification result of the target security device is verification failed; if the second verification data and the third verification data sent by the target security device are not received simultaneously, determine the first target data type according to the presumed device type.
[0125] In a possible embodiment, in terms of determining the identity verification result of the target security device according to the first verification data, the determining unit 702 is further specifically configured to: determine the device type and device model of the target security device according to the device identifier; determine whether the first verification data is of the first target data type; if the first verification data is of the first target data type and the device type is a sensing device, determine the reasonable numerical range of the first verification data according to the device model; if the first verification data conforms to the reasonable numerical range, determine that the identity verification result is verification passed; if the first verification data is of the first target data type and the device type is a camera device, determine the reasonable image parameters of the first verification data according to the device model; if the first verification data conforms to the reasonable image parameters, determine that the identity verification result is verification passed.
[0126] In a possible embodiment, if the device type is a sensor device, the determining unit 702 is further specifically configured to: if the first verification data is not of the first target data type, determine that the identity verification result is verification failed; if the first verification data does not conform to the reasonable numerical range, obtain the verification times of the target security device, if the verification times are not greater than the preset times, generate a second verification requirement, and the second verification requirement is used to instruct the target security device to send the first verification data of the fourth target data type; send the second verification requirement to the target security device; if the verification times are greater than the preset times, determine that the identity verification result is verification failed.
[0127] In a possible embodiment, if the device type is a camera device, the determining unit 702 is further specifically configured to: if the data type of the first verification data is not an image data type, determine that the authentication result is failed authentication; if the first verification data does not conform to reasonable image parameters, obtain the verification times of the target security device, and if the verification times are not greater than the preset times, generate a third verification requirement, where the third verification requirement is used to instruct the target security device to send the first verification data of the image data type including at least one verification feature, and the verification feature includes a zoom feature or a movement feature; send the third verification requirement to the target security device; if the verification times are greater than the preset times, determine that the authentication result is failed authentication.
[0128] In a possible embodiment, before determining the target data type according to the device identifier, the sending unit 703 is further specifically configured to: generate query information according to the device identifier and send the query information to the cache device; where the cache device is used to cache the registration information of the security device, and the query information is used to request the cache device to send the registration information of the target security device; determine that the registration information sent by the cache device is not received.
[0129] In a possible embodiment, after generating the registration information of the target security device in the Internet of Things system if the authentication result is successful authentication, the sending unit 703 is further specifically configured to: send the registration information to the cache device so that the cache device stores the registration information of the security device.
[0130] Based on the description of the above method embodiments and apparatus embodiments, please refer to Figure 8 , Figure 8 which is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Figure 8 The electronic device 800 shown (the electronic device 800 may specifically be a computer device, Figure 1 the root server 102 shown) includes a memory 801, a processor 802, a communication interface 803, and a bus 804. Among them, the memory 801, the processor 802, and the communication interface 803 are communicatively connected to each other through the bus 804.
[0131] The memory 801 may be a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM).
[0132] The memory 801 may store a program. When the program code stored in the memory 801 is executed by the processor 802, the processor 802 and the communication interface 803 are used to execute each step of the security device registration method of the embodiment of the present application.
[0133] The processor 802 may be a general-purpose central processing unit (CPU), a microcontroller, an application specific integrated circuit (ASIC), a graphics processing unit (GPU), or one or more integrated circuits, and is used to execute relevant programs to implement the functions required by the units in the electronic device 800 in the embodiments of the present application, or to execute the registration method of the security device in the method embodiments of the present application.
[0134] The processor 802 may also be an integrated circuit chip with the ability to process signals. In the implementation process, each step of the registration method of the security device in the present application may be completed by the integrated logic circuit in the hardware of the processor 802 or the instructions in software form. The above-mentioned processor 802 may also be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microcontroller or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application may be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by the combination of the hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 801, and the processor 802 reads the information in the memory 801 and combines its hardware to complete the functions required by the units included in the electronic device 800 in the embodiments of the present application, or to execute the registration method of the security device in the method embodiments of the present application.
[0135] The communication interface 803 uses a transceiver device such as, but not limited to, a transceiver to implement the communication between the electronic device 800 and other devices or communication networks. For example, data may be obtained through the communication interface 803.
[0136] The bus 804 may include a path for transmitting information between various components of the electronic device 800 (for example, the memory 801, the processor 802, the communication interface 803).
[0137] It should be noted that although Figure 8The illustrated electronic device 800 only shows the memory 801, the processor 802, and the communication interface 803. However, in the specific implementation process, those skilled in the art should understand that the electronic device 800 also includes other components necessary for normal operation. At the same time, according to specific needs, those skilled in the art should understand that the electronic device 800 may also include hardware components for implementing other additional functions. In addition, those skilled in the art should understand that the electronic device 800 may also only include the components necessary for implementing the embodiments of the present application, and does not necessarily include Figure 8 all the components shown in
[0138] An embodiment of the present application also provides a chip, which includes a processor and a data interface. The processor reads the instructions stored on the memory through the data interface to implement the registration method of the security device described above.
[0139] Optionally, as an implementation, the chip may further include a memory. Instructions are stored in the memory, and the processor is configured to execute the instructions stored on the memory. When the instructions are executed, the processor is configured to execute the registration method of the security device described above.
[0140] An embodiment of the present application also provides a computer-readable storage medium. Instructions are stored in the computer-readable storage medium. When it runs on a computer or a processor, it causes the computer or the processor to execute one or more steps in any of the above methods.
[0141] An embodiment of the present application also provides a computer program product containing instructions. When the computer program product runs on a computer or a processor, it causes the computer or the processor to execute one or more steps in any of the above methods.
[0142] Those skilled in the art will appreciate that the functions described in connection with the various illustrative logical blocks, modules, and algorithm steps disclosed herein can be implemented in hardware, software, firmware, or any combination thereof. If implemented in software, the functions described by the various illustrative logical blocks, modules, and steps can be stored or transmitted as one or more instructions or code on a computer-readable medium and executed by a hardware-based processing unit. The computer-readable medium can include a computer-readable storage medium corresponding to a tangible medium such as a data storage medium, or a communication medium including any medium that facilitates transfer of a computer program from one place to another (e.g., based on a communication protocol). In this way, the computer-readable medium generally can correspond to (1) a non-transitory tangible computer-readable storage medium, or (2) a communication medium such as a signal or carrier wave. The data storage medium can be any available medium that can be accessed by one or more computers or one or more processors to retrieve instructions, code, and / or data structures for implementing the techniques described in this application. A computer program product can include a computer-readable medium.
[0143] By way of example, and not limitation, such computer-readable storage media can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, flash memory, or any other medium that can be used to store the desired program code in the form of instructions or data structures and that can be accessed by a computer. Also, any connection is properly termed a computer-readable medium. For example, if instructions are transmitted using coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of the medium. However, it should be understood that the computer-readable storage media and data storage media do not include connections, carrier waves, signals, or other transient media, but rather are directed to non-transitory tangible storage media. As used herein, disk and disc include compact disc (CD), laser disc, optical disc, digital versatile disc (DVD), and Blu-ray disc, where disks generally reproduce data magnetically, while discs reproduce data optically using lasers. Combinations of the above should also be included within the scope of computer-readable media.
[0144] Instructions may be executed by one or more processors, such as one or more digital signal processors (DSPs), general microcontrollers, application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other equivalent integrated or discrete logic circuitry. Thus, as used herein, the term “processor” may refer to any one of the foregoing structures or any other structure suitable for implementing the techniques described herein. Additionally, in some aspects, the functionality described for the various illustrative logical blocks, modules, and steps described herein may be provided within dedicated hardware and / or software modules configured for encoding and decoding, or incorporated in a combined codec. Moreover, the techniques may be implemented entirely in one or more circuits or logic elements.
[0145] The techniques of this application may be implemented in a variety of devices or apparatuses, including wireless handsets, integrated circuits (ICs) or a group of ICs (e.g., a chipset). Various components, modules, or units are described in this application to emphasize functional aspects of the devices for performing the disclosed techniques, but need not be implemented by different hardware units. In fact, as described above, the various units may be combined in an encoding hardware unit with suitable software and / or firmware, or provided by interoperating hardware units, including one or more processors as described above.
[0146] Those skilled in the art can clearly understand that, for convenience and brevity of description, the specific working processes of the systems, apparatuses, and units described above can refer to the corresponding step processes in the foregoing method embodiments, and will not be elaborated herein.
[0147] It should be understood that in the description of this application, unless otherwise specified, " / " means that the objects associated before and after are in an "or" relationship. For example, A / B can represent A or B; where A and B can be singular or plural. Also, in the description of this application, unless otherwise specified, "a plurality of" means two or more than two. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of a single item or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple. Additionally, for the convenience of clearly describing the technical solutions of the embodiments of this application, in the embodiments of this application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and roles. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and terms such as "first" and "second" do not necessarily mean different. At the same time, in the embodiments of this application, words such as "exemplary" or "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplary" or "for example" is intended to present relevant concepts in a specific manner for easy understanding.
[0148] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the division of the unit is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. The couplings, direct couplings, or communication connections shown or discussed with each other can be through some interfaces, and the indirect couplings or communication connections of devices or units can be in electrical, mechanical, or other forms.
[0149] The unit described as a separated component may or may not be physically separated, and the component shown as a unit may or may not be a physical unit, that is, it can be located in one place, or it can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0150] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted through the computer-readable storage medium. The computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a read-only memory (ROM), a random access memory (RAM), a magnetic medium, such as a floppy disk, a hard disk, a magnetic tape, a magnetic disk, or an optical medium, such as a digital versatile disc (DVD), or a semiconductor medium, such as a solid state disk (SSD), etc.
[0151] As described above, it is only the specific implementation manner of the embodiments of the present application, but the protection scope of the embodiments of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the embodiments of the present application should be covered by the protection scope of the embodiments of the present application. Therefore, the protection scope of the embodiments of the present application should be subject to the protection scope of the claims.
[0152] The device embodiments described above are merely illustrative. The units and modules described as separate components may or may not be physically separated. Additionally, some or all of the units and modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative effort.
[0153] The above description is only the specific implementation manner of the present application. It should be noted that for those of ordinary skill in the technical field, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A registration method for a security device, characterized in that, Applied to a root server, the method includes: Receiving device information sent by a target security device, where the device information includes the device identifier of the target security device; Determining a first target data type according to the device identifier, where the first target data type is one of the data types of multiple types of data generated by the target security device during operation; Generating a first verification requirement for the target security device according to the first target data type, and sending the first verification requirement to the target security device, where the first verification requirement is used to instruct the target security device to send first verification data of the first target data type; Receiving the first verification data sent by the target security device according to the first verification requirement, and determining the identity verification result of the target security device according to the first verification data; If the identity verification result is verification passed, generating registration information of the target security device in the Internet of Things system, and sending the registration information to the target security device.
2. The method according to claim 1, wherein The determining the first target data type according to the device identifier includes: Determining the device type and device model of the target security device according to the device identifier; Determining the first target data type according to the device type and device model of the target security device; If the determination of the device type and device model of the target security device fails according to the device identifier, determining the presumed device type of the target security device according to the device identifier; Determining a second target data type and a third target data type according to the presumed device type; where the second target data type is one of the data types of multiple types of data generated by a security device of the presumed device type during operation, and the third target data type is not a data type generated by a security device of the presumed device type during operation; Generating a second verification requirement according to the second target data type and the third target data type, and sending the second verification requirement to the target security device, where the second verification requirement is used to instruct the target security device to send second verification data of the second target data type and third verification data of the third target data type; If the second verification data and the third verification data sent by the target security device are received simultaneously, determining that the identity verification result of the target security device is verification failed; If the second verification data and the third verification data sent by the target security device are not received simultaneously, determining the first target data type according to the presumed device type.
3. The method according to claim 1, characterized in that, The determining the identity verification result of the target security device according to the first verification data includes: Determining the device type and device model of the target security device according to the device identifier; Determining whether the first verification data is the first target data type; If the first verification data is the first target data type and the device type is a sensing device, determining a reasonable numerical range of the first verification data according to the device model; If the first verification data conforms to the reasonable numerical range, determining that the identity verification result is verification passed; If the first verification data is of the first target data type and the device type is a camera device, determine reasonable image parameters for the first verification data according to the device model; If the first verification data conforms to the reasonable image parameters, determine that the authentication result is passed.
4. The method according to claim 3, wherein If the device type is a sensor device, the method further includes: If the first verification data is not of the first target data type, determine that the authentication result is not passed; If the first verification data does not conform to the reasonable numerical range, obtain the verification times of the target security device. If the verification times are not greater than the preset times, generate a second verification requirement, where the second verification requirement is used to instruct the target security device to send the first verification data of the fourth target data type; Send the second verification requirement to the target security device; If the verification times are greater than the preset times, determine that the authentication result is not passed.
5. The method according to claim 3, characterized in that, If the device type is a camera device, the method further includes: If the data type of the first verification data is not an image data type, determine that the authentication result is not passed; If the first verification data does not conform to the reasonable image parameters, obtain the verification times of the target security device. If the verification times are not greater than the preset times, generate a third verification requirement, where the third verification requirement is used to instruct the target security device to send the first verification data of the image data type including at least one verification feature, and the verification feature includes a scaling feature or a moving feature; Send the third verification requirement to the target security device; If the verification times are greater than the preset times, determine that the authentication result is not passed.
6. The method according to any one of claims 1-5, characterized in that, Before determining the target data type according to the device identifier, the method further includes: Generate query information according to the device identifier and send the query information to the cache device; where the cache device is used to cache the registration information of the security device, and the query information is used to request the cache device to send the registration information of the target security device; Determine that the registration information sent by the cache device is not received.
7. The method according to claim 6, characterized in that After generating the registration information of the target security device in the Internet of Things system if the authentication result is passed, the method further includes: Send the registration information to the cache device so that the cache device stores the registration information of the security device.
8. A registration device for a security device, characterized in that, The registration device of the security device is used to execute the registration method of the security device, and the registration device of the security device includes: A receiving unit, configured to receive device information sent by a target security device, where the device information includes the device identifier of the target security device; A determining unit, configured to determine a target data type according to the device identifier, where the target data type is one of the data types of multiple data generated during the operation of the target security device; A sending unit, configured to generate a first verification requirement for the target security device according to the target data type, and send the first verification requirement to the target security device, where the first verification requirement is used to instruct the target security device to send first verification data of the target data type; A receiving unit, configured to receive the first verification data sent by the target security device according to the first verification requirement, and determine an identity verification result of the target security device according to the first verification data; A sending unit, configured to generate registration information of the target security device in the Internet of Things system if the identity verification result is verification passed, and send the registration information to the target security device.
9. An electronic device, characterized in that, It includes a processor, a memory, a communication interface, and one or more programs, where the one or more programs are stored in the memory and configured to be executed by the processor, and the programs include instructions for performing the steps in the method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program for electronic data exchange, where the computer program causes a computer to execute the method according to any one of claims 1-7.
Citation Information
Patent Citations
Methods, systems, and computer readable media for discovering network function service producers in hierarchical network
CN116743840A
Control method and device of security and protection equipment, electronic equipment and storage medium
CN119449865A
Access request response method and apparatus, and electronic device
WO2021218859A1
Cited By
Elevator accessory defect recognition and analysis system based on visual analysis
CN121180810A
Method for determining expired equipment information of security and protection equipment registration system and related device
CN121309130A