Remote equipment control method and equipment based on Internet of Things equipment, and medium

Through the management-side encryption processing, edge layer forwarding and remote device control methods executed by the device-side, combined with fingerprint verification and bucket management, the security and management problems of traditional HTTP protocol are solved, and efficient and secure remote device control is achieved.

CN120455504APending Publication Date: 2025-08-08SHANDONG INSPUR ULTRA HD INTELLIGENT TECH CO LTD

Patent Information

Application Number
CN202510530570.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

Traditional HTTP protocols are susceptible to man-in-the-middle attacks in remote device control, lack encryption mechanisms, incomplete monitoring of device status, lack of unified storage and management mechanisms, making it difficult to achieve closed-loop management of instructions and execution results.

Method used

The management side is encrypted and processed control instructions, and the edge layer forwards through preset transmission protocols, executes and feedbacks the results on the device side. Combining fingerprint verification and multi-layer security protection, the bucket management instructions and results are used to support visual display.

Benefits of technology

It realizes efficient, secure, flexible and automated management of remote control of IoT devices, improves system maintainability and scalability, ensures security of command transmission, reduces communication delay, reduces storage costs, and improves data management efficiency and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455504A_ABST
    Figure CN120455504A_ABST
Patent Text Reader

Abstract

The invention discloses a remote equipment control method and equipment based on Internet of Things equipment, and a medium, and the method comprises the steps: a management end generates a control instruction, carries out the encryption processing of the control instruction, and transmits the encrypted control instruction to an edge layer; the edge layer forwards the encrypted control instruction through a preset transmission protocol; and the device end receives the control instruction forwarded by the edge layer, and performs execution according to the control instruction to obtain an execution result. According to the invention, security is guaranteed by encryption, authority control and the like; the instructions and results are managed through a storage bucket, and optimization functions such as regular file deletion and classified storage are achieved; safety measures such as fingerprint verification are also provided, meanwhile, result visual display is supported, and the overall scheme is comprehensive, safe and efficient.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of remote control technology, and in particular to a remote device control method, device, and medium based on an Internet of Things device. Background Art

[0002] Remote control refers to remote management, whereby administrators can remotely dial in via a computer network or connect to the Internet. Device control can be achieved by calling HTTP interfaces via the HTTP protocol. For example, specific HTTP requests can be sent to control device power status and adjust parameters. However, traditional HTTP protocols are susceptible to man-in-the-middle attacks, lack effective encryption mechanisms, provide incomplete device status monitoring, and lack a unified storage and management mechanism, making closed-loop management of commands and execution results difficult. Summary of the Invention

[0003] In order to solve the above problems, the present application proposes a remote device control method based on Internet of Things devices, which is applied to a remote device control system based on Internet of Things devices, the system including a management end, an edge layer, and a device end; the method includes: the management end generates a control instruction, encrypts the control instruction, and sends the encrypted control instruction to the edge layer; the edge layer forwards the encrypted control instruction through a pre-set transmission protocol; the device end receives the control instruction forwarded by the edge layer, and executes it according to the control instruction to obtain an execution result.

[0004] In one example, a control instruction is generated and the control instruction is encrypted, specifically including: the management end determines a preset instruction format, determines the control instruction according to the instruction format, and the control instruction includes fingerprint information, operation type, and address information; determines a preset encryption algorithm, and encrypts the control instruction according to the encryption algorithm.

[0005] In one example, the method also includes: the edge layer determines a pre-set instruction topic, and publishes the control instruction to the corresponding instruction topic through the transmission protocol; determines the edge gateway of the edge layer, records the instruction status corresponding to the control instruction through the edge gateway, and sends the recorded instruction status to a pre-set task queue.

[0006] In one example, the method also includes: the device side monitors the instruction topic to obtain metadata corresponding to the control instruction; determines a pre-set storage bucket, and downloads instruction parameters from the storage bucket according to the metadata; executes according to the instruction parameters, obtains a file of the execution result, and uploads the file to the storage bucket.

[0007] In one example, the method further includes: the management end monitoring the storage bucket through a preset communication mechanism to obtain event information corresponding to the execution result; and visually displaying the execution result through a preset visualization component.

[0008] In one example, the method further includes: determining a pre-signed address through the storage bucket and determining a validity period of the address; determining multiple roles and determining access control permissions corresponding to the multiple roles to read or write the storage bucket according to the access control permissions.

[0009] In one example, the method further includes: determining an instruction file through the storage bucket, determining a file identifier of the instruction file, the file identifier including a creation date, and periodically deleting the instruction file according to a preset storage period and the creation date; determining a result file through the storage bucket, and determining a diagnosis type corresponding to the result file, classifying the result file according to the diagnosis type, and saving the classified result file.

[0010] In one example, the method further includes: determining the MAC address hash value and EDID verification code of the device end, determining fingerprint verification information based on the MAC address hash value and the EDID verification code, and performing fingerprint verification based on the fingerprint verification information.

[0011] On the other hand, the present application also proposes a remote device control device based on an Internet of Things device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the remote device control device based on the Internet of Things device to execute: a method as described in any one of the above examples.

[0012] On the other hand, the present application also proposes a non-volatile computer storage medium storing computer-executable instructions, wherein the computer-executable instructions are configured to perform the method described in any one of the above examples.

[0013] This application comprehensively implements efficient, secure, flexible, and automated remote control management for IoT devices. The system is divided into a management side, an edge layer, and a device side, with clearly defined responsibilities. The management side is responsible for command generation and encryption, the edge layer is responsible for command forwarding and status recording, and the device side is responsible for command execution and result feedback, improving system maintainability and scalability. The management side encrypts control commands and combines them with fingerprint verification information to ensure secure command transmission and execution, preventing tampering or illegal execution. The edge layer forwards commands via a preset transmission protocol and supports command topic publishing and monitoring, enabling fast and accurate command transmission and reducing communication latency. Storage buckets are used to store command parameters and execution results, supporting pre-signed address access and access control permission management to ensure data security and flexible access. Storage buckets support automatic cleanup and classified storage of command and result files, reducing storage costs and improving data management efficiency. The management side displays execution results through visual components, intuitively presenting device status and operation effects, improving user experience and decision-making efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0015] Figure 1 This is a flow chart of a remote device control method based on an Internet of Things device in an embodiment of the present application;

[0016] Figure 2 This is a structural diagram of a remote device control system based on an Internet of Things device in an embodiment of the present application;

[0017] Figure 3 This is a schematic diagram of a remote device control device based on an Internet of Things device in an embodiment of the present application. DETAILED DESCRIPTION

[0018] To make the purpose, technical solutions, and advantages of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the specific embodiments of this application and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0019] The following describes in detail the technical solutions provided by various embodiments of the present application in conjunction with the accompanying drawings.

[0020] like Figure 1As shown, in order to solve the above problems, the embodiment of the present application provides a remote device control method based on an IoT device, which is applied to a remote device control system based on an IoT device. The system includes a management end, an edge layer, and a device end. The method includes:

[0021] S101: The management terminal generates a control instruction, encrypts the control instruction, and sends the encrypted control instruction to the edge layer.

[0022] The management end generates a structured JSON format instruction. The instruction content must include a unique device identifier, i.e., a device fingerprint, for accurate identification of the target device; a specific operation type, such as device restart, firmware upgrade, parameter configuration, etc., to clarify the instruction execution action; and an object address in the MinIO object storage service, which points to the resource location where the relevant data or files are stored, so that the device can obtain the required resources when performing the operation. Subsequently, to ensure that the instruction is not stolen or tampered with during transmission, the management end uses the AES-256 encryption algorithm to encrypt the instruction body. AES-256, with its high-strength encryption performance, can effectively resist various cryptanalysis attacks. At the same time, to further enhance security, the system will set up a key rotation mechanism, that is, automatically changing the encryption key every 30 seconds. Even if the key is leaked within a certain period of time, the attacker cannot use the key to effectively decrypt the subsequently transmitted instructions, thereby maximizing the security of instruction transmission.

[0023] S102: The edge layer forwards the encrypted control instruction through a preset transmission protocol.

[0024] The edge layer publishes the generated encrypted instructions to the designated topic path using MQTT's QoS level 2. The path format is cmd / ${productKey} / ${deviceName}, where ${productKey} represents the product identifier, used to distinguish different types or series of products; ${deviceName} represents the name or unique identifier of the specific device, ensuring that the instructions are accurately located to the target device. QoS level 2, the highest quality of service level in the MQTT protocol, provides "at least once" and "only once" delivery guarantees. This means that not only are messages reliably transmitted to the recipient, but the recipient also confirms receipt, preventing duplication or loss of messages, thus providing strong protection for instruction transmission.

[0025] To address potential device offline conditions or network instability, the edge gateway takes on the important responsibility of recording command status. Once a command is issued, the edge gateway monitors its transmission status in real time and records relevant information, such as the command ID, release time, and target device, as well as the current execution status (sent, pending, or confirmed), in an offline task queue. This allows the device to retrieve unfinished commands from the offline task queue and resend them to the device once it comes back online, ensuring their execution and improving the robustness and reliability of the entire system.

[0026] S103: The device receives the control instruction forwarded by the edge layer, and executes according to the control instruction to obtain an execution result.

[0027] Android devices launch an efficient and reliable MQTT message listening service, continuously monitoring and dynamically monitoring a preset MQTT topic. This topic acts as an information hub, carrying metadata about various commands issued by the management end. Command metadata often includes key information such as the command's unique identifier, a brief description, the associated task type, version number, and the mapping between the command and storage resources. While this information doesn't include specific operational parameters, it provides guidance for the Android device to subsequently retrieve complete commands and accurately execute tasks.

[0028] After an Android device successfully captures the command metadata in the MQTT topic, it quickly initiates a request to the MinIO bucket (the command bucket) based on the storage path and access credentials specified in the metadata, accurately locating the complete command parameter file corresponding to the current command in the commands bucket. MinIO, with its high performance, high scalability, and S3 protocol compatibility, ensures that command parameter files can be downloaded to the Android device in an efficient and stable manner. These complete command parameter files contain all the details required for the device to execute the task, such as specific operation steps, configuration parameters, input data, execution conditions, and expected result format, and are the core basis for the Android device to correctly execute the task.

[0029] After receiving the complete command parameters, the Android device executes the task in an orderly manner, strictly following the requirements in the parameter file and invoking its own hardware resources, system interfaces, and related applications. During task execution, the device monitors the execution status in real time, handles any exceptions, and records detailed execution logs. Upon task completion, the Android device organizes and packages the execution results according to the command requirements, generating a well-formatted result file. This result file may contain important information such as the task's success or failure status, actual output data, performance metrics, error logs, and the task completion timestamp. The Android device then leverages MinIO's powerful storage capabilities to upload the generated result file to the "results" bucket. Storing result files in the "results" bucket not only enables centralized data management and long-term preservation, but also provides solid data support for subsequent data analysis, audit tracking, troubleshooting, and task replay, establishing a complete closed loop from command issuance to execution and result feedback.

[0030] In one embodiment, the management client establishes an efficient, real-time, two-way communication channel using WebSocket technology to monitor event notifications from the MinIO distributed object storage system. With its superior performance, high scalability, and high compatibility with the S3 protocol, MinIO has become a key component in the system for storing various types of data, such as task instructions and execution results. When a task is completed and results are generated on an Android device or other execution node, these result files are promptly uploaded to MinIO's designated storage bucket. When MinIO receives new file uploads, modifications, or deletions, it triggers corresponding event notifications and pushes these event information to the management client in real time via a pre-configured WebSocket connection. Event notifications contain rich details, such as the operation type, the file name involved, the storage bucket information, and the operation timestamp, providing key data for the management client to fully understand system dynamics.

[0031] After receiving event notifications from MinIO, the management client parses and processes this data, extracting key information related to task execution results. To present this abstract data to managers in an intuitive and easy-to-understand manner, enabling them to quickly make decisions and assess system health, the management client uses the highly customizable Highcharts component for data visualization. Highcharts offers a wide variety of chart types, such as bar charts, line charts, pie charts, and scatter plots, allowing for flexible selection based on different data characteristics and presentation requirements. For example, a bar chart can be used to visually compare the success rates of different tasks, while a line chart can be used to clearly present the changing trends in task execution time. Through the powerful rendering capabilities of the Highcharts component, the management client can transform previously dull data into vivid charts, allowing managers to clearly grasp the overall status of task execution, the changing trends of key indicators, and potential problems, thereby providing strong data support for system optimization and business decision-making.

[0032] In one embodiment, the storage bucket contains three primary storage paths: minio-bucket / commands / , minio-bucket / results / , and minio-bucket / diagnostics / . The commands / directory stores commands, with each command file named using a device ID and timestamp combination, such as ${deviceID} / ${timestamp}.json. The results / directory stores execution results, with each result file also named using a device ID and timestamp combination, such as ${deviceID} / ${timestamp}.log. The diagnostics / directory is specifically used to store device diagnostic data. This structure clearly separates commands, execution results, and device diagnostic information, facilitating data organization and management.

[0033] In one embodiment, access to storage buckets utilizes a role-based access control (RBAC) policy, assigning hierarchical permissions to different roles. Operators, as system administrators, have higher permissions, allowing them to read and write to the instruction bucket, upload and update instruction parameter files, and manage instruction storage. Devices, as task execution nodes, are granted read-only access to the instruction bucket to ensure they receive the correct instructions. They also have write access to the result bucket, allowing them to upload execution results and record task completion. Auditors, responsible for oversight and auditing, have read access to the result bucket, allowing them to read and inspect uploaded execution result files and verify the results and status of task execution. Furthermore, to further enhance system security, pre-signed URLs are set with a 15-minute expiration window, ensuring access to designated resources within a limited window and mitigating potential security risks. This hierarchical role-based permission management and pre-signed URL expiration policy establish a solid security defense for the system, ensuring data security and compliance throughout the entire process of instruction storage, task execution, and result feedback.

[0034] In one embodiment, for instruction files, taking into account their timeliness and the rational use of storage resources, the system sets strict lifecycle management rules, that is, after the instruction file is successfully released to the device and the corresponding task process is completed, it will be retained in the storage system for 7 days. During this 7-day validity period, the instruction file can be consulted for subsequent audits, replays, and abnormal situation handling to ensure the traceability of system operations. Once the 7-day retention period is exceeded, the system will automatically trigger the deletion mechanism to clean up expired instruction files through preset scheduled tasks or triggers to free up storage space, ensure the efficient operation of the storage system, and avoid waste of storage resources and performance degradation due to the long-term accumulation of useless files.

[0035] As for the result files, since they contain key information after the device executes the task, such as task execution status, output data, performance indicators, etc., they are of great significance for system optimization, troubleshooting and data analysis. Therefore, the system adopts a more refined management method, classifying and archiving result files according to diagnostic type. Specifically, the system will classify them into different folders or tags based on the diagnostic information recorded in the result files, such as task type, execution environment, device status, etc., such as "Network Diagnosis Results", "Hardware Fault Diagnosis Results", "Performance Optimization Diagnosis Results", etc. This classification and archiving method not only facilitates subsequent rapid retrieval and positioning, but also provides data analysts with a structured data source, supporting them to carry out in-depth data mining and analysis, thereby providing a strong basis for continuous optimization and improvement of the system. At the same time, classification and archiving also help to quickly focus on the relevant types of diagnostic results when facing complex system problems, improving the efficiency of problem troubleshooting and resolution.

[0036] In one embodiment, a dual verification mechanism is adopted in the device authentication link. The MAC address is the physical address of the network device and is globally unique, but there is a risk of information leakage when using the plaintext MAC address for authentication directly. Therefore, the system first hashes the MAC address of the device to generate a hash value of fixed length, which not only retains the uniqueness of the MAC address, but also enhances the security of the data and prevents the MAC address from being maliciously stolen during transmission and storage. The EDID check code is mainly for devices with display functions. It contains detailed parameter information related to the device display, such as resolution, refresh rate, manufacturer identification, etc. By calculating the check code of the EDID data, the authenticity of the device can be further verified to ensure that the connected device meets the display specifications and performance standards required by the system. Combining the MAC address hash value with the EDID check code to form a device fingerprint greatly improves the accuracy and security of device identification, and effectively prevents illegal devices from impersonating legitimate devices to access the system.

[0037] The system generates time-sensitive tokens based on the HMAC-SHA256 algorithm. HMAC is an authentication mechanism that combines a hash function and a secret key to provide data integrity and authentication. SHA256, as a hash function, offers high strength and collision resistance, ensuring the uniqueness and security of the token. When generating a dynamic token, the system uses a pre-shared key, combined with the current timestamp, device ID, and other information, to calculate the token value using the HMAC-SHA256 algorithm. This token is time-sensitive and typically has a short validity period, such as several minutes or tens of minutes. Each time a device initiates an authentication request, it must carry a currently valid dynamic token. Upon receiving an authentication request, the system uses the same key and algorithm, combining the timestamp, device ID, and other information in the request to recalculate the token value and compare it with the token value carried by the device. Authentication is successful only if the two match and the token is within its validity period. This dynamic token mechanism effectively prevents replay attacks, ensures the uniqueness and freshness of each authentication request, and further enhances the security of device authentication.

[0038] In one embodiment, the system has built a multi-level security protection. For the MQTT communication channel, TLS1.3 protocol encryption is used. This protocol has features such as forward secrecy and simplified handshake process. It can resist attacks such as replay and man-in-the-middle, and ensure the confidentiality and integrity of data transmission in the channel. For the instruction body that carries the core instructions, AES-256-GCM mode is used for encryption. The GCM mode has both encryption and authentication functions and can process data efficiently. At the same time, an independent key rotation strategy is implemented for each device, and the keys for the devices are replaced regularly. Even if the key of a device is leaked, the risk can be minimized to protect the security of data transmission in all directions.

[0039] In one embodiment, to ensure the integrity and reliability of data transmission and storage, the system adopts a dual integrity verification mechanism. For the instruction file, a unique hash value is generated using the MD5 verification algorithm. The hash value is calculated and compared at the file generation end and the receiving end respectively. If the values are consistent, it indicates that the file has not been tampered with or damaged during the transmission process, ensuring that the instruction content arrives accurately. For the result file, ECDSA, the elliptic curve digital signature algorithm, is used to implement a digital signature. The sender signs the file with a private key, and the receiver verifies it with the corresponding public key. Leveraging the advantages of elliptic curve encryption, the integrity and authenticity of the result file can be efficiently verified while ensuring security, effectively preventing data from being maliciously tampered with.

[0040] like Figure 3 As shown, the embodiment of the present application further provides a remote device control device based on an Internet of Things device, including:

[0041] at least one processor; and,

[0042] a memory communicatively connected to at least one processor; wherein,

[0043] The memory stores instructions that can be executed by at least one processor, and the instructions are executed by at least one processor to enable a remote device control device based on an Internet of Things device to execute: the method described in any one of the above embodiments.

[0044] An embodiment of the present application further provides a non-volatile computer storage medium storing computer executable instructions, wherein the computer executable instructions are configured to perform the method described in any one of the above embodiments.

[0045] In the 1990s, technological improvements could be clearly distinguished as either hardware improvements (for example, improvements to circuit structures like diodes, transistors, and switches) or software improvements (improvements to process flows). However, with the advancement of technology, many process flow improvements today can now be considered direct improvements to hardware circuit structures. Designers almost always create the corresponding hardware circuit structure by programming the improved process flow into the hardware circuit. Therefore, it cannot be said that a process flow improvement cannot be implemented using hardware modules. For example, a programmable logic device (PLD), such as a field programmable gate array (FPGA), is an integrated circuit whose logical function is determined by user programming. Designers can "integrate" a digital system on a PLD through their own programming, without having to hire a chip manufacturer to design and manufacture a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly done using "logic compiler" software. This is similar to the software compiler used when developing programs. Before compilation, the original code must also be written in a specific programming language, called a hardware description language (HDL). There is not just one HDL, but many, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art will also understand that by simply programming the method flow in one of these hardware description languages and then programming it into an integrated circuit, a hardware circuit that implements the logic method flow can be easily obtained.

[0046] The controller can be implemented in any suitable manner. For example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that in addition to implementing the controller in a purely computer-readable program code format, the controller can be implemented in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be considered as structures within the hardware component. Or even, the devices for implementing various functions can be considered as both software modules that implement the method and structures within the hardware component.

[0047] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.

[0048] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0049] The various embodiments in this application are described in a progressive manner. Similar portions between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the device and medium embodiments are generally similar to the method embodiments, so their descriptions are relatively simple. For relevant portions, refer to the descriptions of the method embodiments.

[0050] The devices and media provided in the embodiments of the present application correspond one-to-one to the methods. Therefore, the devices and media also have similar beneficial technical effects to their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the devices and media will not be repeated here.

[0051] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0052] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0053] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0054] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0055] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0056] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.

[0057] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0058] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0059] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.

Claims

1. A remote device control method based on an Internet of Things device, characterized in that: The method is applied to a remote device control system based on an Internet of Things device, the system including a management end, an edge layer, and a device end; the method includes: The management end generates a control instruction, encrypts the control instruction, and sends the encrypted control instruction to the edge layer; The edge layer forwards the encrypted control instruction through a preset transmission protocol; The device side receives the control instruction forwarded by the edge layer, and executes according to the control instruction to obtain an execution result.

2. The method according to claim 1, characterized in that Generate a control instruction and encrypt the control instruction, specifically including: The management terminal determines a preset instruction format, and determines the control instruction according to the instruction format, wherein the control instruction includes fingerprint information, operation type, and address information; A preset encryption algorithm is determined, and the control instruction is encrypted according to the encryption algorithm.

3. The method according to claim 1, characterized in that The method further comprises: The edge layer determines a preset instruction topic, and publishes the control instruction to the corresponding instruction topic through the transmission protocol; An edge gateway of the edge layer is determined, an instruction state corresponding to the control instruction is recorded by the edge gateway, and the recorded instruction state is sent to a preset task queue.

4. The method according to claim 3, characterized in that The method further comprises: The device monitors the command topic to obtain metadata corresponding to the control command; Determine a preset storage bucket, and download instruction parameters from the storage bucket according to the metadata; The command is executed according to the instruction parameters, and a file of the execution result is obtained, and the file is uploaded to the storage bucket.

5. The method according to claim 4, characterized in that The method further comprises: The management end monitors the storage bucket through a preset communication mechanism to obtain event information corresponding to the execution result; The execution results are visually displayed through pre-set visualization components.

6. The method according to claim 4, characterized in that The method further comprises: Determining a pre-signed address through the storage bucket and determining a validity period of the address; Determine multiple roles and access control permissions corresponding to the multiple roles, so as to read or write the storage bucket according to the access control permissions.

7. The method according to claim 4, characterized in that The method further comprises: Determining a command file through the storage bucket, determining a file identifier of the command file, the file identifier including a creation date, and regularly deleting the command file according to a preset storage period and the creation date; The result file is determined through the storage bucket, and the diagnosis type corresponding to the result file is determined. The result file is classified according to the diagnosis type, and the classified result file is saved.

8. The method according to claim 1, characterized in that The method further comprises: Determine the MAC address hash value and the EDID verification code of the device end, determine fingerprint verification information according to the MAC address hash value and the EDID verification code, and perform fingerprint verification according to the fingerprint verification information.

9. A remote device control device based on an Internet of Things device, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the remote device control device based on the Internet of Things device to execute: the method according to any one of claims 1 to 8.

10. A non-volatile computer storage medium storing computer executable instructions, characterized in that: The computer executable instructions are configured to: perform the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Power Internet of Things terminal control instruction encryption and decryption system and method

    CN113225371A

  • Data management equipment based on logistics edge gateway and control method thereof

    CN114390051A

  • Processing system for Internet of Things data

    CN117743471A

  • Internet of Things equipment credible control method and system, electronic equipment and storage medium

    CN117914558A

  • System and method for a decentralized portable information container supporting privacy protected digital information credentialing, remote administration, local validation, access control and remote instruction signaling utilizing blockchain distributed ledger and container wallet technologies

    US20210374693A1

Cited By

  • Internet of Things equipment control method and equipment, and storage medium

    CN122316795A