Data flow control method and device and data presentation method and device of Internet of Things equipment

By importing data flow rules in IoT devices, the problem of insufficient data flow control of IoT devices is solved, targeted data presentation and security control are realized, and data value utilization and privacy protection are improved.

CN120378467APending Publication Date: 2025-07-25ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510494682.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-18
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

Existing IoT devices lack effective data flow control, resulting in data being unable to generate greater value, and there are problems such as data abuse, privacy leakage and conflicts of interest.

Method used

Data flow rules are determined through terminal devices, including the data consumer identification and consumption field names, and imported them into the Internet of Things device to achieve targeted presentation and security control of IoT data.

Benefits of technology

It realizes the targeted circulation and secure presentation of IoT data, protects data security, and users can better enjoy the value of data and reduces the risk of privacy leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378467A_ABST
    Figure CN120378467A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data flow control method and device and a data presentation method and device for Internet of Things equipment. A specific implementation mode of the data flow control method of the Internet of Things equipment is executed by terminal equipment, and the method comprises the steps that a data flow rule is determined according to first input of a first user, and the data flow rule comprises a plurality of data consumer identifiers and field names of corresponding consumption fields; and importing the data flow rule into a first Internet of Things device bound to the terminal device for storage, so that the first Internet of Things device shows corresponding data to a data consumer corresponding to each data consumer identifier based on the data flow rule.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of this specification relate to the technical field of the Internet of Things, and in particular, to a method and device for controlling data flow and presenting data of Internet of Things devices. Background Art

[0002] With the continuous progress of intelligent technologies, more and more Internet of Things (IoT) devices are endowed with data connection capabilities, which greatly facilitates users' lives. Taking an IoT device being a vehicle as an example, users can easily use a smartphone to perform various controls and information queries on the vehicle through digital key technology. During the process of using IoT devices, users can generate a large amount of IoT data, and this data has great value. At present, due to the lack of effective data flow control, this data not only cannot generate greater value, but may even bring problems such as data abuse, privacy leakage, and interest conflicts. In view of the above problems, there is an urgent need for a method for controlling data flow and presenting data of IoT devices. Summary of the Invention

[0003] The embodiments of this specification describe a method and device for controlling data flow and presenting data of IoT devices, which can achieve users' control over the data flow of IoT data, enable the targeted presentation of IoT data, and protect the security of IoT data.

[0004] According to a first aspect, there is provided a method for controlling data flow of an IoT device, which is executed by a terminal device and includes: determining a data flow rule according to a first input of a first user, where the data flow rule includes several data consumer identifiers and the field names of corresponding consumption fields; importing and binding the data flow rule to a first IoT device bound to the terminal device for storage, so that the first IoT device presents corresponding data to data consumers corresponding to each data consumer identifier based on the data flow rule.

[0005] According to a second aspect, there is provided a method for presenting data of an IoT device, which is executed by a first IoT device, where the first IoT device stores a data flow rule set and imported through the terminal device of the owner, and the data flow rule includes several data consumer identifiers and the field names of corresponding consumption fields, including a first data consumer identifier and a corresponding first field name; the method includes: generating first presentation data based on the collected IoT data and the data flow rule, where the first presentation data includes the field value corresponding to the first field name; sending the first presentation data to a first data consumer corresponding to the first data consumer identifier.

[0006] According to a third aspect, there is provided a data flow control device for an Internet of Things device, which is deployed on a terminal device and includes: a determination unit configured to determine a data flow rule according to a first input of a first user, wherein the data flow rule includes a plurality of data consumer identifiers and the field names of corresponding consumption fields; an import unit configured to import the data flow rule into a first Internet of Things device bound to the terminal device for storage, so that the first Internet of Things device can present corresponding data to data consumers corresponding to the respective data consumer identifiers based on the data flow rule.

[0007] According to a fourth aspect, there is provided a data presentation device for an Internet of Things device, which is deployed on a first Internet of Things device. Among them, the first Internet of Things device stores a data flow rule set and imported through the terminal device of the owner. The data flow rule includes a plurality of data consumer identifiers and the field names of corresponding consumption fields, including a first data consumer identifier and a corresponding first field name. The device includes: a generation unit configured to generate first presentation data based on the collected Internet of Things data and the data flow rule, wherein the first presentation data includes the field value corresponding to the first field name; a sending unit configured to send the first presentation data to a first data consumer corresponding to the first data consumer identifier.

[0008] According to a fifth aspect, there is provided a computer-readable storage medium, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the method described in any implementation manner of the first aspect or the second aspect.

[0009] According to a sixth aspect, there is provided a terminal device, including a memory and a processor, characterized in that the memory stores executable code, and when the processor executes the executable code, the method described in any implementation manner of the first aspect is implemented.

[0010] According to a seventh aspect, there is provided an Internet of Things device, including a memory and a processor, characterized in that the memory stores executable code, and when the processor executes the executable code, the method described in any implementation manner of the second aspect is implemented.

[0011] According to the data flow control, data presentation methods and devices for Internet of Things (IoT) devices provided by the embodiments of this specification, a terminal device can determine a data flow rule based on a first input of a first user. The data flow rule may include several data consumer identifiers and the field names of the corresponding consumption fields, including a first data consumer identifier and the corresponding first field name. Subsequently, the terminal device can import and bind the data flow rule to a first IoT device bound to the terminal device. Based on this, the first IoT device can generate first presentation data based on the collected IoT data and the data flow rule. The first presentation data includes the field value corresponding to the first field name. Thereafter, the first IoT device can send the first presentation data to the first data consumer corresponding to the first data consumer identifier. Thus, the first user realizes the flow control of the IoT data collected by the first IoT device, enabling the IoT data to be presented in a targeted manner and protecting the data security of the IoT data. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 FIG. shows a schematic diagram of an application scenario to which the embodiments of this specification can be applied;

[0013] Figure 2 FIG. shows a schematic diagram of a distributed identity authentication system applicable to the embodiments of this application;

[0014] Figure 3 FIG. shows a schematic diagram of a terminal device, a first IoT device, and a data consumer creating a DID;

[0015] Figure 4 FIG. shows a flowchart of a data flow control method for an IoT device according to an embodiment;

[0016] Figure 5 FIG. shows a flowchart of a data presentation method for an IoT device according to an embodiment;

[0017] Figure 6 FIG. shows a schematic block diagram of a data flow control device for an IoT device according to an embodiment;

[0018] Figure 7 FIG. shows a schematic block diagram of a data presentation device for an IoT device according to an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0019] The following will further describe in detail the technical solutions provided in this specification in conjunction with the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the relevant invention and do not limit the invention. In addition, it should be noted that for the convenience of description, only the parts related to the relevant invention are shown in the drawings. It should be noted that, without conflict, the embodiments of this specification and the features in the embodiments can be combined with each other.

[0020] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0021] For example, when responding to receiving an active request from the user, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server, or a storage medium that performs the operations of the technical solutions of the present disclosure according to the prompt message.

[0022] As an optional but non-limiting implementation manner, for example, the manner of sending a prompt message to the user in response to receiving an active request from the user may be in the form of a pop-up window, and the prompt message may be presented in text in the pop-up window. In addition, the pop-up window may also carry selection controls for the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0023] It can be understood that the above process of notifying and obtaining the user's authorization is only illustrative and does not limit the implementation manner of the present disclosure. Other manners that meet the relevant laws and regulations can also be applied to the implementation manner of the present disclosure.

[0024] As mentioned above, a vast amount of Internet of Things data has great value. Taking the Internet of Things device as a vehicle as an example, the data generated by the vehicle has great value in aspects such as insurance purchase, vehicle maintenance, traffic optimization, and environmental monitoring. Specifically, in terms of insurance purchase, by providing driving behavior data to insurance institutions and analyzing this data, the insurance institutions can dynamically adjust insurance rates to achieve personalized premiums for each person. In terms of vehicle maintenance, by providing vehicle performance data to repair shops, potential and existing faults can be detected and targeted maintenance plans can be provided. In terms of traffic optimization, by sharing vehicle location and speed data with traffic management and navigation institutions, route planning can be optimized and congestion can be alleviated. In terms of environmental monitoring, by providing vehicle environmental sensor data to meteorological departments, air quality and weather conditions can be monitored.

[0025] Although Internet of Things (IoT) data has great value, due to the lack of effective data transfer control, IoT data not only fails to generate greater value but may even lead to problems such as data abuse, privacy leakage, and conflicts of interest. Specifically, most of the existing data transfer methods for IoT data are formulated by device manufacturers and service providers based on their own interests. As the producers and owners of data, users have weak awareness of data transfer, bear a high risk of privacy leakage, and cannot fully enjoy the value generated by the data. For example, considering data security, there may be security issues during the data transfer process, resulting in data leakage. Another example is that considering privacy protection, the location and behavior data of IoT devices may disclose personal privacy, and personal information collected by service providers (such as phone numbers, etc.) requires even more privacy protection. Another example is that considering user authorization, collecting IoT device data without user authorization poses compliance problems. Another example is that considering data right confirmation, in some scenarios, there is a lack of user identification in IoT device data, making it impossible to effectively associate with user data, and thus the value is limited.

[0026] Therefore, the embodiments of this specification provide a method for controlling data transfer and presenting data of IoT devices, which can achieve the control of the transfer of IoT data collected by a first user for a first IoT device, enable the targeted presentation of IoT data, and protect the data security of IoT data. As Figure 1 shown, Figure 1 FIG. shows a schematic diagram of an application scenario to which the embodiments of this specification can be applied. In Figure 1 the shown application scenario, the terminal device 101 used by user Bob can determine a data transfer rule according to the first input of user Bob. The data transfer rule may include several data consumer identifiers and the field names of the corresponding consumption fields. Then, the terminal device 101 can import and bind the data transfer rule to the first IoT device 102 bound to the terminal device 101 for storage, so that the first IoT device 102 can present the corresponding data to the data consumers corresponding to each data consumer identifier based on the data transfer rule. For example, assuming that the data transfer rule includes a first data consumer identifier and the corresponding first field name, the first IoT device 102 can generate first presentation data based on the collected IoT data and the data transfer rule, and the first presentation data includes the field value corresponding to the first field name. Then, the first IoT device 102 can send the first presentation data to the first data consumer 103 corresponding to the first data consumer identifier.

[0027] Before executing the method described in this embodiment, for the convenience of managing and identifying each participating party and participating device, the identity information of each participating party and participating device can be pre-registered and authenticated. For example, a centralized method can be adopted for management. For instance, an identity verification mechanism managed and controlled by a single authoritative institution or service provider. In this method, the user's identity information and authentication process are both centrally processed by a central entity. Another example is that a distributed identity authentication method can also be adopted for identity management. Distributed identity authentication is a decentralized identity management solution that allows individuals or organizations to own and control their own identity and data information.

[0028] The user-centric distributed identity authentication system is the latest trend in the development of digital identities. It uses blockchain technology, cryptographic algorithms, and new identity authentication technologies, etc., to achieve distributed identity authentication and identity authorization management that protects user privacy. This method not only has a high level of security and privacy protection capabilities, but also can span different digital applications and services to achieve secure, compliant, and trustworthy interoperability of digital identities and identity-related data.

[0029] For the convenience of subsequent understanding, here, a distributed identity authentication system applicable to the embodiments of this application is introduced. As Figure 2 shown, Figure 2 shows a schematic diagram of a distributed identity authentication system applicable to the embodiments of this application.

[0030] Figure 2 In the shown distributed identity authentication system, it may include an Identity Provider (IDP) 201, an ISSUER 202, a DID (Decentralized Identifier) identity holder 203, and a Service Provider (SP) 204. Among them, the identity service provider IDP 201 can interact with the blockchain.

[0031] Specifically, the identity service provider IDP201 can provide DID registration services for various institutions and users in the distributed identity authentication system. It mainly participates in the institution entry and user registration process, provides DID creation and distributed identification document chain services for institutions and users, and can also provide DID alias management and other services. Here, institutions or individuals in the distributed identity authentication system can register DID through the identity service provider IDP201, and upload the distributed identity document containing the identity public key to the blockchain through the identity service provider IDP201 for evidence storage. After the user actively applies, the credential issuer 202 can issue a verifiable credential (VC) to the user side for encrypted storage. When the user needs to present relevant credentials in a specific business scenario, after the user's authorization, the verifiable credential can be assembled and issued on the user side into a verifiable presentation (VP) and submitted to the business service provider 204. Here, through encryption, decryption, signing, signature verification and other security technologies, the verifiable credential VC can be converted into a verifiable presentation VP, which has good security and privacy. The business service provider 204 can obtain the public keys of the user and the credential issuer 202, and perform user authorization verification of the verifiable expression and identity verification of the credential issuer 202 in turn. After the verification is passed, it can further determine that the declaration content meets the business scenario requirements and provide scenario services.

[0032] based on Figure 2 In the distributed identity authentication system shown in the embodiment of the present application, the terminal device corresponding to the first IoT device owner (in this example, referred to as the first user), the first IoT device, and the data consumer can pre-create a DID. Figure 3 As shown, Figure 3 A schematic diagram showing the creation of a DID by a terminal device, a first IoT device, and a data consumer is shown.

[0033] The process of creating a DID by the first IoT device, the terminal device, and the data consumer may include the following (1), (2), and (3), specifically:

[0034] (1), the terminal device can use various asymmetric encryption algorithms to generate a first public key, and send the generated first public key to the identity service provider IDP, and receive and store the first user identifier returned by the identity service provider IDP, where the first user identifier is generated by the identity service provider IDP based on the first public key. For example, the identity service provider IDP can perform a hash calculation on the first public key and use the calculation result as the first user identifier. In addition, the identity service provider IDP can also be used to associate the first user identifier and the first public key and store them in the blockchain.

[0035] It can be understood that the terminal device can also import the first user identifier into the first Internet of Things device for storage, so as to bind the first Internet of Things device to the terminal device. For example, the first user identifier can be imported into the first Internet of Things device through a short-range communication protocol. As an example, the short-range communication protocol can include, but is not limited to, Bluetooth, NFC (Near Field Communication), RFID (Radio-Frequency Identification), and so on.

[0036] (2), the first Internet of Things device can also generate a second public key using various asymmetric encryption algorithms, and send the generated second public key to the Identity Service Provider (IDP), receive and store the first device identifier returned by the Identity Service Provider (IDP), where the first device identifier can be generated by the Identity Service Provider (IDP) based on the second public key of the first Internet of Things device. In addition, the Identity Service Provider (IDP) can also associate and store the first device identifier and the second public key of the first Internet of Things device in the blockchain.

[0037] (3), each data consumer can generate a third public key using various asymmetric encryption algorithms, and send the generated third public key to the Identity Service Provider (IDP), receive and store the data consumer identifier returned by the Identity Service Provider (IDP), where the data consumer identifier can be generated by the Identity Service Provider (IDP) based on the third public key of the data consumer. In addition, the Identity Service Provider (IDP) can also associate and store the data consumer identifiers of each data consumer and their respective corresponding third public keys in the blockchain. It can be understood that the data consumers in this example can act as service providers in the Figure 2 distributed identity authentication system shown.

[0038] Continue to refer to Figure 4 , Figure 4 shows a flowchart of a data flow control method for an Internet of Things device according to an embodiment. It can be understood that this method can be executed by a terminal device used by the owner of the first Internet of Things device (in this example, referred to as the first user). The above-mentioned first Internet of Things device can be various Internet of Things devices, including but not limited to household appliances, vehicles, etc. The above-mentioned terminal devices can include but not limited to smart phones, tablet computers, smart watches, laptop computers, etc. As Figure 4 shown, the data flow control method for this Internet of Things device can include the following steps 401 and 402, specifically:

[0039] Step 401, determine a data flow rule according to the first input of the first user.

[0040] In this embodiment, the terminal device can receive a first input from a first user. This first input can be used to configure a data flow rule, which may include several data consumer identifiers and the field names of the corresponding consumption fields. In this example, a data consumer can refer to a party that uses Internet of Things (IoT) data. Taking an IoT device as a vehicle as an example, data consumers that use the data generated by the vehicle may include vehicle insurance institutions, vehicle repair shops, traffic management and navigation institutions, and so on. Since the IoT data required by different data consumers may not be the same, different data flow rules can be configured for different data consumers. The first input can include the data consumer identifier and the field name of the corresponding consumption field. Here, the first user can input the first input in various ways. For example, the first input can be input in text form.

[0041] In some implementation manners, before step 401, the above-mentioned data flow control method for IoT devices may further include the following steps 1)-3), specifically:

[0042] Step 1), obtain the data usage rules corresponding to at least one alternative data consumer respectively.

[0043] In this implementation manner, the data usage rules corresponding to the alternative data consumers may include the data fields that are expected to be consumed. Taking the first IoT device as a vehicle and the alternative data consumer as an insurance institution as an example, the first user can use the vehicle control APP (Application) installed in the terminal device to obtain the data usage rules corresponding to the insurance institution from the server corresponding to the vehicle control APP. The data usage rules include the data fields that the insurance institution hopes to consume. It can be understood that the server corresponding to the vehicle control APP can pre-collect the data usage rules of each insurance institution.

[0044] As an example, the data usage rules corresponding to the alternative data consumers may further include the user benefits provided after obtaining the data of the corresponding data fields. Continuing with the example of the first IoT device being a vehicle and the alternative data consumer being an insurance institution, the insurance institution can configure different user benefits for different data fields in order to encourage users to authorize the presentation of more data fields. For example, if the user authorizes the presentation of data fields A, B, C, there is a 20% discount when purchasing insurance. If the user authorizes the presentation of data fields A, B, C, D, there is a 30% discount when purchasing insurance.

[0045] Step 2), display the data usage rules of at least one alternative data consumer on the first page.

[0046] In this implementation manner, the terminal device can display the data usage rules of at least one alternative data consumer obtained in the first page. For example, the data usage rules of each alternative data consumer can be displayed in the first page for the first user to select.

[0047] Step 3), receive a first input.

[0048] In this implementation manner, the first user can input the first input by selecting items in the first page. Through this implementation manner, the first user can input the first input by selecting the data items displayed in the first page, improving the efficiency of information input.

[0049] Step 402, import and bind the data flow rule to the first Internet of Things device bound to the terminal device for storage.

[0050] In this embodiment, the terminal device can import and bind the data flow rule to the first Internet of Things device bound to the terminal device for storage through various methods (for example, wired method, wireless method, cloud platform transfer, etc.). For example, the terminal device can import the data flow rule to the first Internet of Things device through a short-range communication protocol. Based on the stored data flow rule, the first Internet of Things device can present the corresponding data to the corresponding data consumer for each data consumer identifier.

[0051] In some implementation manners, the above data flow control method for the Internet of Things device may further include Figure 4 The following steps 1) and 2) not shown in the figure, specifically:

[0052] Step 1), the terminal device sends each data consumer identifier to the identity service provider and receives the returned third public keys of each.

[0053] In this implementation manner, the third public key can be obtained by the identity service provider from the blockchain query.

[0054] Step 2), import each third public key into the first Internet of Things device for the first Internet of Things device to use the third public key for data encryption.

[0055] Through this implementation manner, the third public keys of the corresponding data consumers of each data consumer identifier can be imported into the first Internet of Things device in advance for the first Internet of Things device to encrypt the presented data when presenting it to the data consumer, protecting data security.

[0056] Through Figure 4The method shown can enable the first Internet of Things device to store data transfer rules. To implement the presentation of Internet of Things data, the embodiments of this specification also provide a method for presenting data of an Internet of Things device, which can enable targeted data presentation of Internet of Things data and protect the data security of Internet of Things data.

[0057] Continue to refer to Figure 5 , Figure 5 shows a flowchart of a method for presenting data of an Internet of Things device according to an embodiment. Here, the first Internet of Things device may store data transfer rules set and imported through the owner's terminal device, and the data transfer rules may be imported into the first Internet of Things device by the terminal device through the Figure 4 method shown. In this example, the data transfer rules may include several data consumer identifiers and the field names of the corresponding consumption fields, including the first data consumer identifier and the corresponding first field name. It can be understood that Figure 5 the method for presenting data of the Internet of Things device shown can be executed by the first Internet of Things device, and the above-mentioned first Internet of Things device may be various Internet of Things devices, including but not limited to household appliances, vehicles, etc. As Figure 5 shown, the method for presenting data of this Internet of Things device may include the following steps 501 and 502, specifically:

[0058] Step 501, generate first presentation data based on the collected Internet of Things data and data transfer rules.

[0059] In this embodiment, the data transfer rules may include the first data consumer identifier and the first field name corresponding to the first data consumer identifier, where the first data consumer identifier may refer to any one of several data consumer identifiers. During operation, the first Internet of Things device can collect various Internet of Things data. Based on the collected Internet of Things data and the pre-stored data transfer rules, first presentation data can be generated, and the first presentation data may include the field value corresponding to the first field name. For example, the first Internet of Things device can screen out the field value corresponding to the first field name from the Internet of Things data as the first presentation data.

[0060] It can be understood that, in order to ensure data security, the first Internet of Things device can generate first presentation data in a secure element or a Trusted Execution Environment (TEE). Among them, the secure element can include an SE chip (Secure Element Chip), and the SE chip is independent of the main processor and can provide a secure environment to execute sensitive operations such as encryption and key management. The TEE can provide an isolated secure area in the main processor for executing sensitive code and processing sensitive data. By using the SE chip or the TEE to generate the first presentation data, it can be ensured that even if the first Internet of Things device is damaged, sensitive information such as Internet of Things data and first presentation data will not be leaked.

[0061] In some implementation manners, the above first presentation data may further include at least one of the following: a first device identifier of the first Internet of Things device, a first user identifier, and device information of the first Internet of Things device. Among them, the first user identifier is a user identifier pre-stored by the first Internet of Things device, and the device information of the first Internet of Things device may be various information related to the first Internet of Things device, including but not limited to: the identifier, picture, production number, production date, manufacturer, etc. of the first Internet of Things device.

[0062] Step 502, send the first presentation data to the first data consumer corresponding to the first data consumer identifier.

[0063] In this embodiment, the first Internet of Things device can send the first presentation data generated in step 501 to the first data consumer corresponding to the first data consumer identifier through various methods (such as wired method, wireless method, cloud platform transfer, etc.) for the first data consumer to use the data and provide corresponding user rights and interests for the user. It can be understood that, in order to obtain more comprehensive data, more user data can also be obtained and used based on the first user identifier. For example, taking the first Internet of Things device as a vehicle, vehicle violation data of the first user can be obtained from the traffic management agency, and personal credit information of the first user can be obtained from the user credit management agency, etc. As an example, the first Internet of Things device can send the first presented data in plaintext to the first data consumer.

[0064] In some implementation manners, in order to protect the data security of the first presentation data, the first Internet of Things device can also encrypt the first presentation data and then send it to the first data consumer. As an example, the above step 502 may specifically include the following contents a) and b), specifically:

[0065] a), obtain the third public key corresponding to the first data consumer identifier, and use the third public key to encrypt the first presentation data to obtain the first ciphertext.

[0066] As an implementation, the first Internet of Things device may pre-store a third public key corresponding to the first data consumer identifier. Based on this, for the step a) above, obtaining the third public key corresponding to the first data consumer identifier can be specifically carried out as follows: The first Internet of Things device can obtain the third public key corresponding to the first data consumer identifier from local storage.

[0067] As another implementation, the first Internet of Things device does not store the third public key corresponding to the first data consumer identifier. Based on this, for the step a) above, obtaining the third public key corresponding to the first data consumer identifier can be specifically carried out as follows: The first Internet of Things device can send the first data consumer identifier to the identity service provider and receive the third public key returned by the identity service provider. The third public key can be obtained by the identity service provider from the blockchain query.

[0068] b), sending the first ciphertext to the first data consumer for the first data consumer to decrypt and obtain the first presented data.

[0069] Through this implementation, the first Internet of Things device can encrypt and send the first presented data to the first data consumer, thus protecting the data security of the first presented data.

[0070] In some implementations, the first Internet of Things device may include an internet-connected vehicle. Based on this, the Internet of Things data may include at least one of the following: throttle status data, vehicle speed data, driving mileage data. The first data consumer may include one of the following: vehicle insurance service provider, vehicle repair service provider.

[0071] According to an embodiment of another aspect, a data flow control device for an Internet of Things device is provided. The data flow control device for the Internet of Things device may be deployed on a terminal device. The terminal device may include, but is not limited to, a smart phone, a tablet computer, a smart watch, a laptop computer, and so on.

[0072] Figure 6 Shows a schematic block diagram of a data flow control device for an Internet of Things device according to an embodiment. As Figure 6 shown, the data flow control device 600 for the Internet of Things device includes: a determination unit 601 configured to determine a data flow rule according to a first input of a first user, where the data flow rule includes several data consumer identifiers and the field names of corresponding consumption fields; an import unit 602 configured to import and bind the data flow rule to a first Internet of Things device bound to the terminal device for storage, so that the first Internet of Things device can present corresponding data to data consumers corresponding to each data consumer identifier based on the data flow rule.

[0073] In some alternative implementation manners of this embodiment, the above device 600 further includes: an obtaining unit (not shown in the figure), configured to obtain the data usage rules corresponding to at least one alternative data consumer, where the data usage rules include the data fields that are expected to be consumed; a display unit (not shown in the figure), configured to display the data usage rules of the at least one alternative data consumer on a first page; a receiving unit (not shown in the figure), configured to receive the above first input, which is generated by selecting items on the above first page.

[0074] In some alternative implementation manners of this embodiment, the above data usage rules further include the user rights and interests provided after obtaining the data of the corresponding data fields.

[0075] In some alternative implementation manners of this embodiment, the device 600 further includes: a sending unit (not shown in the figure), configured to send the generated first public key to an identity service provider, and receive the returned first user identifier, where the first user identifier is generated by the identity service provider based on the first public key; a storage unit (not shown in the figure), configured to import the first user identifier into the first Internet of Things device for storage, so as to bind the first Internet of Things device to the terminal device.

[0076] In some alternative implementation manners of this embodiment, the identity service provider is configured to associatively store the first user identifier and the first public key in a blockchain, and associatively store the first device identifier of the first Internet of Things device and the second public key corresponding to the first Internet of Things device in the blockchain, and associatively store each data consumer identifier and its corresponding third public key in the blockchain.

[0077] In some alternative implementation manners of this embodiment, the device 600 further includes: an identifier sending unit (not shown in the figure), configured to send each data consumer identifier to the identity service provider, and receive each of the above third public keys returned by the identity service provider, where the third public keys are obtained by the identity service provider by querying the blockchain; a third public key importing unit (not shown in the figure), configured to import each of the above third public keys into the first Internet of Things device for the first Internet of Things device to use the third public keys for data encryption.

[0078] According to an embodiment of another aspect, a data presentation device for an Internet of Things (IoT) device is provided. The data presentation device for the IoT device can be deployed on a first IoT device, and the first IoT device can be various IoT devices, including but not limited to household appliances, vehicles, and the like. Data transfer rules set and imported through the owner's terminal device are stored in the first IoT device. The data transfer rules include a number of data consumer identifiers and the field names of the corresponding consumption fields, including a first data consumer identifier and the corresponding first field name.

[0079] Figure 7 FIG. shows a schematic block diagram of a data presentation device for an IoT device according to an embodiment. As Figure 7 shown, the data presentation device 700 for the IoT device includes: a generation unit 701 configured to generate first presentation data based on the collected IoT data and the data transfer rules, where the first presentation data includes the field value corresponding to the first field name; and a presentation unit 702 configured to send the first presentation data to a first data consumer corresponding to the first data consumer identifier.

[0080] In some alternative implementation manners of this embodiment, the presentation unit 702 includes: a third public key acquisition unit (not shown in the figure) configured to acquire the third public key corresponding to the first data consumer identifier and use the third public key to encrypt the first presentation data to obtain a first ciphertext; and a first ciphertext sending unit (not shown in the figure) configured to send the first ciphertext to the first data consumer for the first data consumer to decrypt and obtain the first presentation data.

[0081] In some alternative implementation manners of this embodiment, the third public key corresponding to the first data consumer identifier is pre-stored in the first IoT device, and the third public key acquisition unit is further configured to acquire the third public key corresponding to the first data consumer identifier from the local.

[0082] In some alternative implementation manners of this embodiment, the third public key acquisition unit is further configured to send the first data consumer identifier to an identity service provider and receive the returned third public key, and the third public key is obtained by the identity service provider from the blockchain query.

[0083] In some alternative implementation manners of this embodiment, the first presentation data further includes at least one of the following: a first device identifier, a first user identifier, and device information of the first IoT device, where the first user identifier is a user identifier pre-stored in the first IoT device.

[0084] In some alternative implementation manners of this embodiment, the above-mentioned first Internet of Things device includes a connectable vehicle; the above-mentioned Internet of Things data includes at least one of the following: throttle state data, vehicle speed data, driving mileage data; the above-mentioned first data consumer includes one of the following: vehicle insurance service provider, vehicle maintenance service provider.

[0085] According to an embodiment of another aspect, there is also provided a computer-readable storage medium, on which a computer program is stored. When the above-mentioned computer program is executed in a computer, the computer is made to execute Figure 4 or Figure 5 the described method.

[0086] According to an embodiment of still another aspect, there is also provided a terminal device, including a memory and a processor. It is characterized in that an executable code is stored in the above-mentioned memory. When the above-mentioned processor executes the above-mentioned executable code, the Figure 4 described method is implemented.

[0087] According to an embodiment of still another aspect, there is also provided an Internet of Things device, including a memory and a processor. It is characterized in that an executable code is stored in the above-mentioned memory. When the above-mentioned processor executes the above-mentioned executable code, the Figure 5 described method is implemented.

[0088] Those of ordinary skill in the art should further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those of ordinary skill in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0089] The steps of the methods or algorithms described in combination with the embodiments disclosed herein can be implemented by hardware, software modules executed by a processor, or a combination of the two. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the technical field.

[0090] The specific embodiments described above further elaborate on the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only for the specific embodiments of the present invention and is not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for controlling data flow of an Internet of Things device, which is executed by a terminal device, includes: Determine a data flow rule according to a first input of a first user, where the data flow rule includes a plurality of data consumer identifiers and the field names of corresponding consumption fields; Import the data flow rule into a first Internet of Things device bound to the terminal device for storage, so that the first Internet of Things device can present corresponding data to data consumers corresponding to each data consumer identifier based on the data flow rule.

2. The method according to claim 1, wherein, The method further includes: Obtain the data usage rules corresponding to at least one alternative data consumer, where the data usage rules include the data fields that the data consumer hopes to consume; Display the data usage rules of the at least one alternative data consumer on a first page; Receive the first input, which is generated by selecting items on the first page.

3. The method according to claim 2, wherein, The data usage rules further include the user rights provided after obtaining the data of the corresponding data field.

4. The method according to claim 1, wherein, The method further includes: Send the generated first public key to an identity service provider, and receive the first user identifier returned by it, where the first user identifier is generated by the identity service provider based on the first public key; Import the first user identifier into the first Internet of Things device for storage, so as to bind the first Internet of Things device to the terminal device.

5. The method according to claim 4, wherein The identity service provider is used to associate and store the first user identifier and the first public key in a blockchain, and associate and store the first device identifier of the first Internet of Things device and the second public key corresponding to the first Internet of Things device in the blockchain, and associate and store each data consumer identifier and its corresponding third public key in the blockchain.

6. The method according to claim 5, wherein, The method further includes: Send each data consumer identifier to the identity service provider, and receive the respective third public keys returned by it, where the third public keys are obtained by the identity service provider by querying the blockchain; Import each of the third public keys into the first Internet of Things device for the first Internet of Things device to use the third public key for data encryption.

7. A method for presenting data of an Internet of Things device, which is executed by a first Internet of Things device, wherein, The first Internet of Things device stores a data flow rule set and imported through the terminal device of the owner, where the data flow rule includes a plurality of data consumer identifiers and the field names of corresponding consumption fields, including a first data consumer identifier and a corresponding first field name; the method includes: Generate first presentation data based on the collected Internet of Things data and the data flow rule, where the first presentation data includes the field value corresponding to the first field name; Send the first presentation data to a first data consumer corresponding to the first data consumer identifier.

8. The method according to claim 7, wherein, Sending the first presentation data to a first data consumer corresponding to the first data consumer identifier includes: Obtain the third public key corresponding to the first data consumer identifier, and use the third public key to encrypt the first presentation data to obtain a first ciphertext; Send the first ciphertext to the first data consumer for the first data consumer to decrypt and obtain the first presentation data.

9. The method according to claim 8, wherein The first Internet of Things device pre-stores a third public key corresponding to the first data consumer identifier, and obtaining the third public key corresponding to the first data consumer identifier includes: Obtaining the third public key corresponding to the first data consumer identifier from the local.

10. The method according to claim 8, wherein, Obtaining the third public key corresponding to the first data consumer identifier includes: Sending the first data consumer identifier to an identity service provider and receiving the returned third public key, which is obtained by the identity service provider from the blockchain query.

11. The method according to claim 7, wherein, The first presented data further includes at least one of the following: a first device identifier, a first user identifier, device information of the first Internet of Things device, where the first user identifier is a user identifier pre-stored by the first Internet of Things device.

12. The method according to claim 7, wherein, The first Internet of Things device includes an internet-connected vehicle; the Internet of Things data includes at least one of the following: throttle status data, vehicle speed data, driving mileage data; the first data consumer includes one of the following: a vehicle insurance service provider, a vehicle repair service provider.

13. A data flow control device for an Internet of Things device, deployed on a terminal device, includes: A determination unit configured to determine a data flow rule according to a first input of a first user, where the data flow rule includes several data consumer identifiers and field names of corresponding consumption fields; An import unit configured to import and bind the data flow rule to a first Internet of Things device bound to the terminal device for storage, so that the first Internet of Things device presents corresponding data to data consumers corresponding to each data consumer identifier based on the data flow rule.

14. A data presentation device for an Internet of Things device, deployed in a first Internet of Things device, wherein, The first Internet of Things device stores a data flow rule set and imported through the terminal device of the owner. The data flow rule includes several data consumer identifiers and field names of corresponding consumption fields, including a first data consumer identifier and a corresponding first field name; the device includes: A generation unit configured to generate first presented data based on the collected Internet of Things data and the data flow rule, where the first presented data includes a field value corresponding to the first field name; A presentation unit configured to send the first presented data to a first data consumer corresponding to the first data consumer identifier.

15. A computer-readable storage medium, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the method according to any one of claims 1-6 or 7-12.

16. A terminal device, comprising a memory and a processor, characterized in that The memory stores executable code, and when the processor executes the executable code, the method according to any one of claims 1-6 is implemented.

17. An Internet of Things device, comprising a memory and a processor, characterized in that, The memory stores executable code, and when the processor executes the executable code, the method according to any one of claims 7-12 is implemented.