Service access control method, system and device, computer equipment, readable storage medium and program product
Through the collaborative work of the first device and the access control unit, the user location is verified using dynamic devices and user identification, which solves the problem of service providers obtaining accurate and reliable user locations in non-controlled networks and improves the security and efficiency of communication services.
Patent Information
- Application Number
- CN202510881858.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-09-19
AI Technical Summary
When the network accessed by the user is not controlled by the communication service provider, it is difficult for the service provider to obtain accurate and reliable user locations, affecting the security and reliability of the communication service.
The first device trusted by the service provider network reports the first location information to the access control unit, and the first device perceives and reports the second location information of the second device. The access control unit determines the credibility of the user location based on the distance, and sends service access permission information when the preset conditions are met, and uses dynamic device and user identification for verification.
It realizes the credibility verification of user location in different network access scenarios, improves the security and efficiency of communication services, and reduces the possibility of data falsification.
Smart Images

Figure CN120676358A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a service access control method, system, apparatus, computer equipment, computer-readable storage medium, and computer program product. Background Art
[0002] With the development of communication technology, data network-based communication services such as voice communication, video calls, and instant messaging have gradually become widely used. Users can access and use these communication services through network communication. However, when the network a user accesses is not controlled by the service provider, it is difficult for the service provider to obtain accurate and reliable user locations, affecting the security and reliability of the communication service. Summary of the Invention
[0003] Based on this, it is necessary to provide a service access control method, system, apparatus, computer equipment, computer-readable storage medium and computer program product.
[0004] In a first aspect, the present application provides a service access control method, comprising:
[0005] Sending a dynamic device identifier and an accessible user identifier to the first device;
[0006] When receiving an identification acquisition request from a second device, sending the accessible device identification and the dynamic user identification to the second device;
[0007] Receiving first location information sent by the first device, and receiving a user identity and second location information of the second device sent by the first device; the user identity and the second location information are received by the first device from the second device; the dynamic device identifier of the first device matches the accessible device identifier of the second device, and the accessible user identifier of the first device matches the dynamic user identifier of the second device;
[0008] When the distance between the first location information and the second location information meets a preset distance condition, near-domain identification success information including the user identity identifier is sent to the first device, and service access permission information including the user identity identifier is sent to the service provider.
[0009] In one embodiment, after receiving the first location information sent by the first device, and receiving the user identity and second location information of the second device sent by the first device, it includes: when the distance between the first location information and the second location information does not meet the preset distance condition, sending near-domain identification failure information containing the user identity to the first device, and sending service access cancellation information containing the user identity to the service provider.
[0010] In one embodiment, after sending the access permission information including the user identity to the service provider, it also includes: receiving the updated first location information sent by the first device, and receiving the user identity and updated second location information of the second device sent by the first device; if the distance between the updated first location information and the updated second location information meets the preset distance condition, sending the near-domain identification success information to the first device; if the updated first location information and the updated second location information do not meet the preset distance condition, sending the near-domain identification failure information including the user identity to the first device, and sending the service access cancellation information including the user identity to the service provider.
[0011] In one embodiment, sending the dynamic device identifier and the accessible user identifier to the first device includes: regularly sending the updated dynamic device identifier and the updated accessible user identifier to the first device; after receiving the identifier acquisition request from the second device, it also includes: sending the updated accessible device identifier and the updated dynamic user identifier to the second device.
[0012] In a second aspect, the present application provides a service access control method, comprising:
[0013] Sending first location information to the access control unit;
[0014] Receiving a dynamic device identifier and an accessible user identifier from an access control unit;
[0015] Publishing the dynamic device identification in a shared network environment;
[0016] receiving a dynamic user identifier sent by a second device located in the same shared network environment;
[0017] If there is an accessible user identifier that matches the dynamic user identifier, sending a location acquisition request to the second device;
[0018] receiving second location information from the second device;
[0019] Sending the user identity of the second device and the second location information to the access control unit;
[0020] Upon receiving the near-domain identification success information containing the user identity identifier, service accessibility information is sent to the second device; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information meets a preset distance condition; the service accessibility information is used to indicate that the second device can access the service provider.
[0021] In one embodiment, the method further includes: upon receiving near-domain identification failure information containing the user identity identifier, sending service inaccessibility information to the second device; the near-domain identification failure information is sent by the access control unit when it is determined that the distance between the first location information and the second location information does not meet a preset distance condition; the service inaccessibility information is used to indicate that the second device cannot access the service provider.
[0022] In one embodiment, after sending the service accessibility information to the second device, it also includes: regularly sending a location acquisition request to the second device; receiving updated second location information from the second device; regularly sending the updated first location information to the access control unit, and regularly sending the user identity of the second device and the updated second location information to the access control unit.
[0023] In a third aspect, the present application provides a service access control method, comprising:
[0024] Sending an identification acquisition request to the access control unit;
[0025] Receiving the accessible device identifier and the dynamic user identifier sent by the access control unit;
[0026] Upon receiving a dynamic device identifier issued by a first device in a shared network environment, determining whether the dynamic device identifier matches the accessible device identifier;
[0027] If the dynamic device identifier matches the accessible device identifier, sending the dynamic user identifier to the first device;
[0028] sending second location information to the first device upon receiving a location acquisition request sent by the first device; the location acquisition request is sent by the first device after determining that there is an accessible user identifier matching the dynamic user identifier; the accessible user identifier is received by the first device from the access control unit;
[0029] Receive service accessibility information from the first device; the service accessibility information is sent by the first device after receiving near-domain identification success information from the access control unit; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information of the first device meets a preset distance condition.
[0030] In one embodiment, after receiving the service accessibility information from the first device, the method further includes: receiving a location acquisition request sent by the first device; and sending updated second location information to the first device.
[0031] In one of the embodiments, the method further includes: regularly sending the identification acquisition request to the access control unit; and receiving the updated accessible device identification and the updated dynamic user identification sent by the access control unit.
[0032] In a fourth aspect, the present application further provides a service access control system, comprising: an access control unit, a first device, and a second device;
[0033] The access control unit is configured to send a dynamic device identifier and an accessible user identifier to the first device;
[0034] The first device is configured to receive the dynamic device identifier and the accessible user identifier;
[0035] The second device is configured to send an identification acquisition request to the access control unit;
[0036] The access control unit is further configured to receive the identification acquisition request; and send the accessible device identification and the dynamic user identification to the second device;
[0037] The second device is further configured to receive the accessible device identifier and the dynamic user identifier;
[0038] The first device is further configured to publish the dynamic device identifier in a shared network environment;
[0039] The second device is further configured to receive the dynamic device identifier; and if the dynamic device identifier matches the accessible device identifier, send the dynamic user identifier to the first device;
[0040] The first device is further configured to receive the dynamic user identifier; and if there is an accessible user identifier that matches the dynamic user identifier, send a location acquisition request to the second device;
[0041] The second device is further configured to receive the location acquisition request; and send second location information to the first device;
[0042] The first device is further configured to send the first location information to the access control unit; and receive the second location information; and send the user identity of the second device and the second location information to the access control unit;
[0043] The access control unit is further configured to receive the first location information, the user identity identifier, and the second location information; and when the distance between the first location information and the second location information meets a preset distance condition, send a near-domain identification success message including the user identity identifier to the first device, and send a service access permission message including the user identity identifier to the service provider;
[0044] The first device is further configured to receive the near-domain identification success information; and send service accessibility information to the second device;
[0045] The second device is further configured to receive the service accessibility information.
[0046] In a fifth aspect, the present application further provides a service access control device, including:
[0047] A first sending module, configured to send a dynamic device identifier and an accessible user identifier to the first device;
[0048] A second sending module is configured to send the accessible device identifier and the dynamic user identifier to the second device when receiving an identifier acquisition request from the second device;
[0049] a receiving module, configured to receive first location information sent by the first device, and receive a user identity identifier and second location information of the second device sent by the first device; the user identity identifier and the second location information are received by the first device from the second device; the dynamic device identifier of the first device is consistent with the accessible device identifier of the second device, and the accessible user identifier of the first device includes the dynamic user identifier of the second device;
[0050] The third sending module is used to send near-domain identification success information containing the user identity identifier to the first device when the distance between the first location information and the second location information meets a preset distance condition, and to send service access permission information containing the user identity identifier to the service provider.
[0051] In a sixth aspect, the present application further provides a service access control device, including:
[0052] A first sending module, configured to send first location information to the access control unit;
[0053] A first receiving module is used to receive a dynamic device identifier and an accessible user identifier from an access control unit;
[0054] A second sending module, configured to publish the dynamic device identification in a shared network environment;
[0055] A second receiving module, configured to receive a dynamic user identifier sent by a second device located in the same shared network environment;
[0056] a third sending module, configured to send a location acquisition request to the second device if there is an accessible user identifier matching the dynamic user identifier;
[0057] a third receiving module, configured to receive second location information from the second device;
[0058] A fourth sending module, configured to send the user identity of the second device and the second location information to the access control unit;
[0059] The fifth sending module is used to send service accessibility information to the second device when receiving the near-domain identification success information containing the user identity identifier; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information meets the preset distance condition; the service accessibility information is used to indicate that the second device can access the service provider.
[0060] In a seventh aspect, the present application further provides a service access control device, including:
[0061] A first sending module, configured to send an identification acquisition request to the access control unit;
[0062] A first receiving module is configured to receive an accessible device identifier and a dynamic user identifier sent by the access control unit;
[0063] an identification matching module, configured to, upon receiving a dynamic device identification issued by a first device in a shared network environment, determine whether the dynamic device identification matches the accessible device identification;
[0064] A second sending module, configured to send the dynamic user identifier to the first device if the dynamic device identifier matches the accessible device identifier;
[0065] a third sending module, configured to send second location information to the first device upon receiving a location acquisition request sent by the first device; the location acquisition request is sent by the first device after determining that there is an accessible user identifier matching the dynamic user identifier; the accessible user identifier is received by the first device from the access control unit;
[0066] The second receiving module is used to receive service accessibility information from the first device; the service accessibility information is sent by the first device after receiving the near-domain identification success information from the access control unit; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information of the first device meets a preset distance condition.
[0067] In an eighth aspect, the present application further provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0068] Sending a dynamic device identifier and an accessible user identifier to the first device;
[0069] When receiving an identification acquisition request from a second device, sending the accessible device identification and the dynamic user identification to the second device;
[0070] Receiving first location information sent by the first device, and receiving a user identity and second location information of the second device sent by the first device; the user identity and the second location information are received by the first device from the second device; the dynamic device identifier of the first device is consistent with the accessible device identifier of the second device, and the accessible user identifier of the first device includes the dynamic user identifier of the second device;
[0071] When the distance between the first location information and the second location information meets a preset distance condition, near-domain identification success information including the user identity identifier is sent to the first device, and service access permission information including the user identity identifier is sent to the service provider.
[0072] In a ninth aspect, the present application further provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0073] Sending first location information to the access control unit;
[0074] Receiving a dynamic device identifier and an accessible user identifier from an access control unit;
[0075] Publishing the dynamic device identification in a shared network environment;
[0076] receiving a dynamic user identifier sent by a second device located in the same shared network environment;
[0077] If there is an accessible user identifier that matches the dynamic user identifier, sending a location acquisition request to the second device;
[0078] receiving second location information from the second device;
[0079] Sending the user identity of the second device and the second location information to the access control unit;
[0080] Upon receiving the near-domain identification success information containing the user identity identifier, service accessibility information is sent to the second device; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information meets a preset distance condition; the service accessibility information is used to indicate that the second device can access the service provider.
[0081] In a tenth aspect, the present application further provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0082] Sending an identification acquisition request to the access control unit;
[0083] Receiving the accessible device identifier and the dynamic user identifier sent by the access control unit;
[0084] Upon receiving a dynamic device identifier issued by a first device in a shared network environment, determining whether the dynamic device identifier matches the accessible device identifier;
[0085] If the dynamic device identifier matches the accessible device identifier, sending the dynamic user identifier to the first device;
[0086] sending second location information to the first device upon receiving a location acquisition request sent by the first device; the location acquisition request is sent by the first device after determining that there is an accessible user identifier matching the dynamic user identifier; the accessible user identifier is received by the first device from the access control unit;
[0087] Receive service accessibility information from the first device; the service accessibility information is sent by the first device after receiving near-domain identification success information from the access control unit; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information of the first device meets a preset distance condition.
[0088] In an eleventh aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the following steps are implemented:
[0089] Sending a dynamic device identifier and an accessible user identifier to the first device;
[0090] When receiving an identification acquisition request from a second device, sending the accessible device identification and the dynamic user identification to the second device;
[0091] Receiving first location information sent by the first device, and receiving a user identity and second location information of the second device sent by the first device; the user identity and the second location information are received by the first device from the second device; the dynamic device identifier of the first device is consistent with the accessible device identifier of the second device, and the accessible user identifier of the first device includes the dynamic user identifier of the second device;
[0092] When the distance between the first location information and the second location information meets a preset distance condition, near-domain identification success information including the user identity identifier is sent to the first device, and service access permission information including the user identity identifier is sent to the service provider.
[0093] In a twelfth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the following steps are implemented:
[0094] Sending first location information to the access control unit;
[0095] Receiving a dynamic device identifier and an accessible user identifier from an access control unit;
[0096] Publishing the dynamic device identification in a shared network environment;
[0097] receiving a dynamic user identifier sent by a second device located in the same shared network environment;
[0098] If there is an accessible user identifier that matches the dynamic user identifier, sending a location acquisition request to the second device;
[0099] receiving second location information from the second device;
[0100] Sending the user identity of the second device and the second location information to the access control unit;
[0101] Upon receiving the near-domain identification success information containing the user identity identifier, service accessibility information is sent to the second device; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information meets a preset distance condition; the service accessibility information is used to indicate that the second device can access the service provider.
[0102] In a thirteenth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the following steps are implemented:
[0103] Sending an identification acquisition request to the access control unit;
[0104] Receiving the accessible device identifier and the dynamic user identifier sent by the access control unit;
[0105] Upon receiving a dynamic device identifier issued by a first device in a shared network environment, determining whether the dynamic device identifier matches the accessible device identifier;
[0106] If the dynamic device identifier matches the accessible device identifier, sending the dynamic user identifier to the first device;
[0107] sending second location information to the first device upon receiving a location acquisition request sent by the first device; the location acquisition request is sent by the first device after determining that there is an accessible user identifier matching the dynamic user identifier; the accessible user identifier is received by the first device from the access control unit;
[0108] Receive service accessibility information from the first device; the service accessibility information is sent by the first device after receiving near-domain identification success information from the access control unit; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information of the first device meets a preset distance condition.
[0109] In a fourteenth aspect, the present application further provides a computer program product, including a computer program, which, when executed by a processor, implements the following steps:
[0110] Sending a dynamic device identifier and an accessible user identifier to the first device;
[0111] When receiving an identification acquisition request from a second device, sending the accessible device identification and the dynamic user identification to the second device;
[0112] Receiving first location information sent by the first device, and receiving a user identity and second location information of the second device sent by the first device; the user identity and the second location information are received by the first device from the second device; the dynamic device identifier of the first device is consistent with the accessible device identifier of the second device, and the accessible user identifier of the first device includes the dynamic user identifier of the second device;
[0113] When the distance between the first location information and the second location information meets a preset distance condition, near-domain identification success information including the user identity identifier is sent to the first device, and service access permission information including the user identity identifier is sent to the service provider.
[0114] In a fifteenth aspect, the present application further provides a computer program product, including a computer program, which, when executed by a processor, implements the following steps:
[0115] Sending first location information to the access control unit;
[0116] Receiving a dynamic device identifier and an accessible user identifier from an access control unit;
[0117] Publishing the dynamic device identification in a shared network environment;
[0118] receiving a dynamic user identifier sent by a second device located in the same shared network environment;
[0119] If there is an accessible user identifier that matches the dynamic user identifier, sending a location acquisition request to the second device;
[0120] receiving second location information from the second device;
[0121] Sending the user identity of the second device and the second location information to the access control unit;
[0122] Upon receiving the near-domain identification success information containing the user identity identifier, service accessibility information is sent to the second device; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information meets a preset distance condition; the service accessibility information is used to indicate that the second device can access the service provider.
[0123] In a sixteenth aspect, the present application further provides a computer program product, including a computer program, which, when executed by a processor, implements the following steps:
[0124] Sending an identification acquisition request to the access control unit;
[0125] Receiving the accessible device identifier and the dynamic user identifier sent by the access control unit;
[0126] Upon receiving a dynamic device identifier issued by a first device in a shared network environment, determining whether the dynamic device identifier matches the accessible device identifier;
[0127] If the dynamic device identifier matches the accessible device identifier, sending the dynamic user identifier to the first device;
[0128] sending second location information to the first device upon receiving a location acquisition request sent by the first device; the location acquisition request is sent by the first device after determining that there is an accessible user identifier matching the dynamic user identifier; the accessible user identifier is received by the first device from the access control unit;
[0129] Receive service accessibility information from the first device; the service accessibility information is sent by the first device after receiving near-domain identification success information from the access control unit; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information of the first device meets a preset distance condition.
[0130] The above-mentioned service access control method, system, apparatus, computer device, computer-readable storage medium, and computer program product, through which a first device trusted by the service provider network reports first location information to the access control unit, and the first device perceives and reports the second location information of a second device requiring service access to the access control unit, enables the access control unit to determine whether the user location of the second device is credible based on the distance between the first location information and the second location information and a preset distance condition, thereby ensuring the authenticity and validity of the location of the user requiring service access in different network access scenarios. Subsequently, when the access control unit determines that the distance between the first location information and the second location information meets the preset distance condition, it sends service access permission information to the service provider and returns near-domain identification success information to the first device. The first device then sends service accessibility information to the second device, thereby notifying the service provider and the second device of service accessibility, respectively, which is conducive to the safe and efficient implementation of subsequent communication services. At the same time, in this solution, by having the access control unit send the dynamic device identifier and accessible user identifier to the first device, and send the accessible device identifier and dynamic user identifier to the second device, it is possible to utilize mutual verification between the dynamic device identifier and the accessible device identifier, as well as the accessible user identifier and the dynamic user identifier, to reduce the possibility of data falsification and help improve the credibility of the user location during service access. Therefore, this application can implement credibility verification of user location in different network access scenarios, which is conducive to the secure and efficient development of communication services. BRIEF DESCRIPTION OF THE DRAWINGS
[0131] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments of the present application or related technical descriptions. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying any creative work.
[0132] Figure 1 FIG1 is a schematic diagram of the architecture of a service access control system in one embodiment;
[0133] Figure 2 FIG1 is a schematic diagram of a processing flow of a service access control system in one embodiment;
[0134] Figure 3 A schematic flow chart of a service access control method according to an embodiment;
[0135] Figure 4 is a flow chart of a service access control method in another embodiment;
[0136] Figure 51 is a flow chart of a service access control method in another embodiment;
[0137] Figure 6 is a structural block diagram of a service access control device in one embodiment;
[0138] Figure 7 is a structural block diagram of a service access control device in another embodiment;
[0139] Figure 8 is a structural block diagram of a service access control device in yet another embodiment;
[0140] Figure 9 is a diagram of the internal structure of a computer device in one embodiment;
[0141] Figure 10 FIG. 4 is a diagram showing the internal structure of a computer device in another embodiment. DETAILED DESCRIPTION
[0142] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0143] In an exemplary embodiment, Figure 1 As shown, a service access control system is provided, which may include: an access control unit, a first device, and a second device.
[0144] For example, the service access control system provided in the embodiments of the present application can be used to control access to communication services based on data networks. The access control unit can be a server provided by an operator providing communication services, the first device can be a server or terminal provided / trusted by the operator, and the second device can be a terminal used by a user who needs to access and use communication services. The access control unit can be connected to a service provider, and the service provider can be a network element set up by the operator for providing communication services. The first device and the second device can be in the same shared network environment, which can use the operator network providing the communication service or not.
[0145] The terminals referred to in this application may include, but are not limited to, various personal computers, laptops, smartphones, tablets, drones, low-altitude aircraft, IoT devices, and portable wearable devices. IoT devices may include smart speakers, smart TVs, smart air conditioners, smart car devices, projectors, and the like. Portable wearable devices may include smart watches, smart bracelets, head-mounted devices, and the like. Head-mounted devices may include virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, and the like. The servers referred to in this application may include independent physical servers, server clusters or distributed systems consisting of multiple physical servers, or cloud servers providing cloud computing services.
[0146] The access control unit is configured to send a dynamic device identifier and an accessible user identifier to the first device.
[0147] Specifically, the access control unit may store device information for one or more first devices, user information for one or more accessible users, and a correspondence between each first device and each accessible user. The first device may be a trusted device registered with the access control unit, and the accessible user may be a user who has pre-registered to use the communication service. For example, each first device may correspond to one or more accessible users, and each accessible user may correspond to one or more trusted devices.
[0148] The access control unit may dynamically generate a dynamic device identifier uniquely corresponding to each first device, and dynamically generate a dynamic user identifier uniquely corresponding to each accessible user. The access control unit may then send the dynamic device identifier and accessible user identifier corresponding to each first device. The accessible user identifier may be the dynamic user identifier of the accessible user corresponding to the first device.
[0149] The first device is configured to receive a dynamic device identifier and an accessible user identifier.
[0150] The first device may receive a dynamic device identifier and an accessible user identifier from the access control unit, wherein the dynamic device identifier may be used to identify the first device itself, and each accessible user identifier may be used to indicate an accessible user corresponding to the first device.
[0151] The second device is configured to send an identification acquisition request to the access control unit.
[0152] The second device may send an identification acquisition request to the access control unit to request acquisition of a dynamic user identification for identifying a user using the second device, so as to obtain an accessible device identification for identifying the first device corresponding to the second device.
[0153] The access control unit is further configured to receive an identification acquisition request; and send an accessible device identification and a dynamic user identification to the second device.
[0154] After receiving the identification acquisition request from the second device, the access control unit may send the corresponding accessible device identification and dynamic user identification to the second device. Each accessible device identification sent to the second device may be a dynamic device identification of a first device corresponding to the second device.
[0155] The second device is further configured to receive an accessible device identifier and a dynamic user identifier.
[0156] The second device may receive the accessible device identifier and the dynamic user identifier from the access control unit.
[0157] The first device is further configured to publish a dynamic device identification in a shared network environment.
[0158] After receiving the dynamic device identification, the first device may broadcast the dynamic device identification in a shared network environment. For example, the shared network environment may be a local area network where the first device and the second device are located.
[0159] The second device is further configured to receive a dynamic device identifier; and if the dynamic device identifier matches the accessible device identifier, send the dynamic user identifier to the first device.
[0160] The second device may receive a dynamic device identifier broadcast in a shared network environment, and compare the dynamic device identifier with an accessible device identifier received from the access control unit.
[0161] When the dynamic device identifier matches the accessible device identifier (for example, the dynamic device identifier is consistent with one of the accessible device identifiers received by the second device), it can be determined that the first device that issued the dynamic device identifier has a corresponding relationship with the second device. The second device can then send its own dynamic user identifier to the first device.
[0162] The first device is further configured to receive a dynamic user identifier; and if there is an accessible user identifier that matches the dynamic user identifier, send a location acquisition request to the second device.
[0163] The first device may receive a dynamic user identifier from the second device, and compare the dynamic user identifier with the accessible user identifier received from the access control unit.
[0164] When the dynamic user identifier matches an accessible user identifier (for example, the dynamic user identifier is consistent with one of the accessible user identifiers received by the first device), it can be determined that the second device that sent the dynamic user identifier has a corresponding relationship with the first device. The first device can then send a location acquisition request to the second device to request the second device's location information.
[0165] The second device is further configured to receive a location acquisition request and send second location information to the first device.
[0166] After receiving the location acquisition request from the first device, the second device may send its own second location information to the first device.
[0167] The first device is further configured to send the first location information to the access control unit; and receive the second location information; and send the user identity identifier and the second location information of the second device to the access control unit.
[0168] The first device may send its own first location information to the access control unit. After receiving the second location information from the second device, the first device may also send the user identity of the second device and the second location information to the access control unit.
[0169] Among them, the user identity of the second device can be an identity used by the user of the second device to register for the use of communication services, such as but not limited to an international mobile subscriber identity code, a mobile phone number, etc. Exemplarily, the second device can send its user identity and the second location information to the first device, so that the first device can receive the user identity at the same time as receiving the second location information of the second device. Exemplarily, the second device can also provide the user identity to the first device through prior interaction with the first device, and the first device can store the correspondence between each accessible user identity and the user identity, so that after receiving the dynamic user identity of the second device, it can obtain the corresponding user identity according to the accessible user identity that matches it.
[0170] It is understandable that the first device may send the first location information to the access control unit, and may send the second location information and the user identity identifier to the access control unit synchronously or asynchronously.
[0171] The access control unit is also used to receive the first location information, as well as the user identity and the second location information; when the distance between the first location information and the second location information meets the preset distance condition, it sends the near-domain identification success information containing the user identity to the first device, and sends the service access permission information containing the user identity to the service provider.
[0172] The access control unit may receive the first location information from the first device and may also receive the user identity and the second location information corresponding to the second device sent by the first device.
[0173] The access control unit may calculate the distance between the first location information and the second location information and determine whether the distance satisfies a preset distance condition. For example, the preset distance condition may be that the distance between the first location information and the second location information is less than a preset distance threshold (e.g., 50 meters). When the distance between the first location information and the second location information satisfies the preset distance condition, it can be determined that the second device is in close proximity to the trusted first device and is in the same network environment, thereby confirming that the user location of the second device has passed the credibility check.
[0174] If it is determined that the distance between the first location information and the second location information meets the preset distance condition, the access control unit may send a proximity identification success message containing the user identity to the first device. This information may be used to notify the first device that the user location of the second device corresponding to the user identity has passed the credibility verification and that subsequent registration and access to communication services can be performed.
[0175] At the same time, the access control unit may also send service access permission information including the user identity to the service provider. The service access permission information may be used to notify the service provider that the user location of the second device corresponding to the user identity has passed the credibility verification, so that the service provider may allow the user using the second device to register for and access the communication service.
[0176] The first device is further configured to receive near-domain identification success information; and send service accessibility information to the second device.
[0177] After receiving the near-field identification success information from the access control unit, the first device can obtain the user identity from it and send service access information to the second device corresponding to the user identity. The service access information can be used to indicate that the second device can register for and access the communication service.
[0178] The second device is further configured to receive service accessibility information.
[0179] The second device may receive the service accessibility information from the first device. It is understood that after receiving the service accessibility information, the second device may initiate registration for the communication service and subsequently access and use the service.
[0180] In this embodiment, a first device trusted by the service provider's network reports first location information to the access control unit, and the first device senses and reports the second location information of a second device requiring service access to the access control unit. This allows the access control unit to determine whether the user location of the second device is trustworthy based on the distance between the first and second location information and a preset distance condition, thereby ensuring the authenticity and validity of the location of the user requiring service access in different network access scenarios. Subsequently, upon determining that the distance between the first and second location information meets the preset distance condition, the access control unit sends service access permission information to the service provider and returns a near-field identification success message to the first device. The first device then sends service accessibility information to the second device, thereby notifying the service provider and the second device of the service accessibility, respectively. This facilitates the secure and efficient delivery of subsequent communication services. Furthermore, in this solution, by sending a dynamic device identifier and an accessible user identifier to the first device, and sending an accessible device identifier and a dynamic user identifier to the second device, the access control unit can utilize mutual verification between the dynamic device identifier and the accessible device identifier, as well as the accessible user identifier and the dynamic user identifier, to reduce the possibility of data falsification and improve the credibility of the user location during service access. Therefore, this application can realize the credibility verification of user location in different network access scenarios, which is conducive to the safe and efficient development of communication services.
[0181] In an exemplary embodiment, after receiving the first location information sent by the first device, and receiving the user identity and second location information of the second device sent by the first device, the access control unit can also be used to: when the distance between the first location information and the second location information does not meet the preset distance condition, send a near-domain identification failure message containing the user identity to the first device, and send a service access cancellation message containing the user identity to the service provider.
[0182] Specifically, after receiving the first location information and the second location information, the access control unit may calculate the distance between the first location information and the second location information and determine whether the distance satisfies a preset distance condition. If the distance does not satisfy the preset distance condition (e.g., the distance is greater than or equal to a preset distance threshold), it may be determined that the user location of the second device has failed the credibility check.
[0183] Thus, the access control unit can send a near-field identification failure message containing the user identity to the first device. This information can be used to notify the first device that the user location of the second device corresponding to the user identity has failed the credibility check and is unable to register for and access subsequent communication services.
[0184] At the same time, the access control unit may also send a service access cancellation message containing the user identity to the service provider. The service access cancellation message may be used to notify the service provider that the user location of the second device corresponding to the user identity has failed the credibility check, so that the service provider may cancel the registration information of the user of the second device.
[0185] The first device may also be configured to send service inaccessible information to the second device when receiving the near domain identification failure information including the user identity identifier.
[0186] After receiving the near-field identification failure information from the access control unit, the first device can obtain the user identity from the information and send service inaccessibility information to the second device corresponding to the user identity. The service accessibility information can be used to indicate that the second device cannot register for and access the communication service.
[0187] The second device may also be used to receive service inaccessible information.
[0188] The second device may receive service inaccessibility information from the first device.
[0189] In this embodiment, when the access control unit determines that the distance between the first location information and the second location information does not meet the preset distance condition, it sends a near-domain identification failure message to the first device and sends a service access cancellation message to the service provider. This can prevent a second device with an unreliable user location from accessing the service provider and using the corresponding communication service, thereby improving the security and reliability of the communication service.
[0190] In an exemplary embodiment, after sending the service accessibility information to the second device, the first device is further configured to periodically send a location acquisition request to the second device.
[0191] Specifically, after the first device sends the service accessibility information to the second device, the second device can initiate registration for the communication service and subsequently access and use the service. To continuously ensure the reliability of the user's location during service use, in this embodiment, the relative distance between the first device and the second device can be updated and confirmed.
[0192] After sending the service accessibility information to the second device, the first device may periodically send a location acquisition request to the second device according to a preset time interval (for example, every 1 minute).
[0193] The second device is further configured to receive a location acquisition request sent by the first device; and send updated second location information to the first device.
[0194] After receiving the location acquisition request sent by the first device, the second device may send its latest second location information to the first device.
[0195] The first device is further configured to receive updated second location information from the second device; periodically send the updated first location information to the access control unit; and periodically send the user identity of the second device and the updated second location information to the access control unit.
[0196] The first device may periodically send its own updated first location information to the access control unit. Simultaneously, upon receiving updated second location information from the second device, the first device may also send the user identity of the second device and the updated second location information to the access control unit.
[0197] It is understandable that the first device may send the updated first location information to the access control unit, and may send the updated second location information and the user identity to the access control unit synchronously or asynchronously.
[0198] The access control unit is further used to receive the updated first location information, as well as the user identity and updated second location information of the second device; if the distance between the updated first location information and the updated second location information meets the preset distance condition, near-domain identification success information is sent to the first device; if the updated first location information and the updated second location information do not meet the preset distance condition, near-domain identification failure information containing the user identity is sent to the first device, and service access cancellation information containing the user identity is sent to the service provider.
[0199] The access control unit may receive updated first location information sent by the first device; and may also receive a user identity corresponding to the second device and updated second location information sent by the first device. The access control unit may then calculate the distance between the most recently received first location information and the second location information, and determine whether the distance satisfies a preset distance condition.
[0200] If the distance satisfies the preset distance condition, it can be determined that the user location of the second device is still close to the location of the trusted first device, thereby confirming that the user location of the second device still passes the credibility check. Therefore, the access control unit can again send service access permission information including the user identity identifier to the first device.
[0201] If the distance does not meet the preset distance condition, it can be determined that the user location of the second device is far away from the trusted location of the first device, and thus it can be determined that the user location has failed the credibility check and cannot be used for subsequent registration and access to the communication service. Therefore, the access control unit can send a near-field identification failure message containing the user identity to the first device, and send a service access cancellation message containing the user identity to the service provider.
[0202] In this embodiment, after the location of the second device is verified, the first device continuously reports the latest first location information and continuously requests the second device to obtain the latest second location information, and then sends it to the access control unit. This enables the access control unit to timely grasp the latest relative distance between the first device and the second device, realize continuous monitoring of the credibility of the user location of the second device, and promptly stop the device's access to the service provider when it is determined that the location of the second device is unreliable.
[0203] In an exemplary embodiment, the access control unit is further configured to periodically send an updated dynamic device identifier and an updated accessible user identifier to the first device.
[0204] Specifically, the access control unit may periodically update the dynamic device identifier of each first device and the dynamic user identifier of each accessible user at a preset time interval (e.g., every 30 minutes). Subsequently, the access control unit may send the updated dynamic device identifier and updated accessible user identifier corresponding to each first device to each first device.
[0205] The first device is further configured to receive an updated dynamic device identifier and an updated accessible user identifier.
[0206] The second device is further configured to periodically send an identification acquisition request to the access control unit.
[0207] The second device may periodically send an identification acquisition request to the access control unit according to a preset time interval (for example, every 30 minutes) to obtain an updated accessible device identification and an updated dynamic user identification.
[0208] The access control unit is further configured to receive an identification acquisition request and send the updated accessible device identification and the updated dynamic user identification to the second device.
[0209] The access control unit may send the corresponding updated accessible device identifier and updated dynamic user identifier to the second device after receiving the identifier acquisition request from the second device.
[0210] In this embodiment, by having the access control unit periodically update the dynamic device identifier corresponding to each first device and update the dynamic user identifier corresponding to each accessible user, and periodically issuing the updated dynamic device identifier and updated accessible user identifier to the first device, and having the second device periodically request the access control unit to obtain the updated accessible device identifier and updated dynamic user identifier, dynamic updating of the device identifier and user identifier can be achieved, which is beneficial to avoiding data falsification caused by reasons such as identifier leakage.
[0211] The following is an illustrative description of the processing of the service access control system in conjunction with a specific service access scenario.
[0212] Specifically, if Figure 2 As shown, the service access control system in this embodiment can be applied to access control for Voice over Internet Protocol (VoIP) services. The second device can be a terminal used by a user who has pre-subscribed to the VoIP service. The access control unit can be connected to a VoIP service provider, which can be an IP Multimedia Subsystem (IMS).
[0213] Among them, such as Figure 2 As shown, the processing process of the service access control system in this embodiment may include:
[0214] Step 1: The first device initiates registration with the access control unit.
[0215] Step 2: The access control unit completes the registration of the first device.
[0216] Step 3: The access control unit sends a registration success message to the first device.
[0217] Step 4: The first device periodically sends the first location information to the access control unit.
[0218] Step 5: The access control unit periodically sends the dynamic device identifier and the accessible user identifier to the first device.
[0219] Step 6: The second device periodically sends an identification acquisition request to the access control unit.
[0220] Step 7: After receiving the identifier acquisition request from the second device, the access control unit sends the dynamic user identifier and the accessible device identifier to the second device.
[0221] Step 8: The first device publishes a dynamic device identifier in the shared network environment.
[0222] Step 9: After receiving the dynamic device identifier in the shared network environment, if the second device determines that the dynamic device identifier matches the accessible device identifier, the second device sends the dynamic user identifier to the first device.
[0223] Step 10: After receiving the dynamic user identifier of the second device, the first device queries whether there is an accessible user identifier that matches the dynamic user identifier.
[0224] Step 11: After determining that there is an accessible user identifier that matches the dynamic user identifier, the first device sends a location acquisition request to the second device.
[0225] Step 12: After receiving the location acquisition request, the second device sends second location information to the first device.
[0226] Step 13: After receiving the second location information, the first device sends the user identity identifier and the second location information of the second device to the access control unit.
[0227] Step 14: After receiving the first location information and the second location information, the access control unit calculates the distance between the first location information and the second location information.
[0228] Step 15: When the access control unit determines that the distance is less than the preset threshold, it determines that the distance meets the preset distance condition.
[0229] Step 16: The access control unit sends a near-domain identification success message including the user identity identifier to the first device.
[0230] Step 17: After receiving the near-field identification success information, the first device sends service accessibility information to the second device.
[0231] Step 18: The access control unit sends service access permission information including the user identity to the IMS.
[0232] In step 19, the second device initiates service registration with the IMS and accesses the service, which may be a VoIP service.
[0233] Step 20: The access control unit, the first device, and the second device periodically repeat the operations of steps 11 to 17.
[0234] In step 21, if the access control unit determines that the distance between the first location information and the second location information is less than a preset threshold, the access control unit determines that the distance does not meet the preset distance condition. The access control unit may also determine that the distance between the first device and the second device does not meet the preset distance condition if the second location information sent by the first device is not received within a preset time period.
[0235] Step 22: The access control unit sends near-domain identification failure information including the user identity identifier to the first device.
[0236] Step 23: After receiving the near-field identification failure information, the first device sends a service inaccessible information to the second device.
[0237] Step 24: The access control unit sends a service access cancellation message including the user identity to the IMS.
[0238] In this embodiment, by utilizing a trusted first device to upload first location information to the access control unit and sensing the second location information of a second device in real time, and by having the access control unit determine the user location credibility of the second device based on the distance between the first and second location information, authenticated users can normally register with the service provider and use the corresponding communication services. If the access control unit does not receive the second location information reported by the first device within the identification and determination validity period, or if the distance between the second location information and the first location information exceeds a distance threshold, the access control unit determines that the user of the second device has left the coverage area of the first device and notifies the service provider to cancel the user's registration. This prevents users with untrusted locations from continuing to use communication services, thereby improving the reliability and security of communication services. Furthermore, by regularly updating dynamic device and user identifiers, as well as continuously updating and verifying the first and second location information, this solution effectively prevents the possibility of data falsification and continuously verifies the credibility of the user's location during the use of communication services. Therefore, this embodiment is applicable to a variety of network access scenarios, such as at sea, onboard, and for emergency communications. Even if the second device is not connected through the operator's network, it can still obtain accurate and reliable user locations and smoothly provide communication services.
[0239] Based on the same inventive concept, the embodiment of the present application also provides a microservice communication strategy processing method. The implementation solution for solving the problem provided by this method is similar to the implementation solution recorded in the above-mentioned system embodiment. Therefore, the specific limitations in one or more microservice communication strategy processing method embodiments provided below can be referred to the above limitations on the microservice communication strategy processing system, and will not be repeated here.
[0240] In an exemplary embodiment, Figure 3As shown, a service access control method is provided, which is applied to Figure 1 The access control unit in the example is used to illustrate the process, which includes the following steps:
[0241] Step S301: Send a dynamic device identifier and an accessible user identifier to a first device.
[0242] Step S302: When receiving an identification acquisition request from a second device, the accessible device identification and the dynamic user identification are sent to the second device.
[0243] Step S303, receiving the first location information sent by the first device, and receiving the user identity and second location information of the second device sent by the first device; the user identity and the second location information are received by the first device from the second device; the dynamic device identifier of the first device matches the accessible device identifier of the second device, and the accessible user identifier of the first device matches the dynamic user identifier of the second device.
[0244] Step S304: When the distance between the first location information and the second location information meets a preset distance condition, a near-field identification success message including the user identity is sent to the first device, and a service access permission message including the user identity is sent to the service provider.
[0245] In an exemplary embodiment, after receiving the first location information sent by the first device, and receiving the user identity and second location information of the second device sent by the first device, it includes: when the distance between the first location information and the second location information does not meet the preset distance condition, sending a near-domain identification failure message containing the user identity to the first device, and sending a service access cancellation message containing the user identity to the service provider.
[0246] In an exemplary embodiment, after sending access permission information including a user identity identifier to a service provider, the method further includes: receiving updated first location information sent by a first device, and receiving the user identity identifier and updated second location information of a second device sent by the first device; if the distance between the updated first location information and the updated second location information meets a preset distance condition, sending near-domain identification success information to the first device; if the updated first location information and the updated second location information do not meet the preset distance condition, sending near-domain identification failure information including the user identity identifier to the first device, and sending service access cancellation information including the user identity identifier to the service provider.
[0247] In an exemplary embodiment, sending a dynamic device identifier and an accessible user identifier to a first device includes: periodically sending an updated dynamic device identifier and an updated accessible user identifier to the first device; after receiving an identifier acquisition request from a second device, further including: sending an updated accessible device identifier and an updated dynamic user identifier to the second device.
[0248] In an exemplary embodiment, Figure 4 As shown, a service access control method is provided. This embodiment applies the method to Figure 1 Taking the first device in the example as an example, the following steps are included:
[0249] Step S401: Send first location information to an access control unit.
[0250] Step S402: Receive a dynamic device identifier and an accessible user identifier from an access control unit.
[0251] Step S403: publishing a dynamic device identifier in a shared network environment.
[0252] Step S404: Receive a dynamic user identifier sent by a second device located in the same shared network environment.
[0253] Step S405: If there is an accessible user identifier that matches the dynamic user identifier, a location acquisition request is sent to the second device.
[0254] Step S406: Receive second location information from the second device.
[0255] Step S407: Send the user identity and the second location information of the second device to the access control unit.
[0256] Step S408: When the near-domain identification success information containing the user identity identifier is received, the service accessibility information is sent to the second device; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information meets the preset distance condition; the service accessibility information is used to indicate that the second device can access the service provider.
[0257] In an exemplary embodiment, the method further includes: upon receiving near-domain identification failure information containing a user identity identifier, sending service inaccessibility information to the second device; the near-domain identification failure information is sent by the access control unit when it is determined that the distance between the first location information and the second location information does not meet a preset distance condition; the service inaccessibility information is used to indicate that the second device cannot access the service provider.
[0258] In an exemplary embodiment, after sending service accessibility information to the second device, the method further includes: periodically sending a location acquisition request to the second device; receiving updated second location information from the second device; periodically sending updated first location information to the access control unit, and periodically sending a user identity identifier and updated second location information of the second device to the access control unit.
[0259] In an exemplary embodiment, Figure 5 As shown, a service access control method is provided. This embodiment applies the method to Figure 1 The second device in the example is used as an example to illustrate the process, including the following steps:
[0260] Step S501: Send an identification acquisition request to the access control unit.
[0261] Step S502: Receive the accessible device identifier and dynamic user identifier sent by the access control unit.
[0262] Step S503: upon receiving the dynamic device identification issued by the first device in the shared network environment, determining whether the dynamic device identification matches the accessible device identification.
[0263] Step S504: If the dynamic device identifier matches the accessible device identifier, the dynamic user identifier is sent to the first device.
[0264] Step S505: Upon receiving a location acquisition request sent by the first device, second location information is sent to the first device; the location acquisition request is sent by the first device after determining that there is an accessible user identifier that matches the dynamic user identifier; the accessible user identifier is received by the first device from the access control unit.
[0265] Step S506, receiving service accessibility information from the first device; the service accessibility information is sent by the first device after receiving the near-domain identification success information from the access control unit; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information of the first device meets the preset distance condition.
[0266] In an exemplary embodiment, after receiving the service accessibility information from the first device, the method further includes: receiving a location acquisition request sent by the first device; and sending updated second location information to the first device.
[0267] In an exemplary embodiment, the method further includes: periodically sending an identification acquisition request to the access control unit; and receiving an updated accessible device identification and an updated dynamic user identification sent by the access control unit.
[0268] It should be understood that, although the various steps in the flowcharts involved in the above embodiments are displayed in sequence according to the instructions of the arrows, these steps are not necessarily performed in sequence in the order indicated by the arrows. Unless clearly stated herein, the execution of these steps is not strictly limited in order, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times, and the execution order of these steps or stages is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of the steps or stages in other steps or other steps. It is understandable that the various steps in different embodiments can be freely combined as needed, and the various non-contradictory schemes formed by the combination all fall within the scope of protection of this application.
[0269] Based on the same inventive concept, embodiments of the present application also provide a service access control device for implementing the aforementioned service access control method. The implementation solution provided by this device is similar to the implementation solution described in the aforementioned method. Therefore, the specific limitations in one or more service access control device embodiments provided below can be found in the above-mentioned limitations on the service access control method and will not be further elaborated here.
[0270] In an exemplary embodiment, Figure 6 As shown, a service access control device 600 is provided, including:
[0271] A first sending module 601 is configured to send a dynamic device identifier and an accessible user identifier to a first device;
[0272] The second sending module 602 is configured to send the accessible device identifier and the dynamic user identifier to the second device upon receiving an identifier acquisition request from the second device;
[0273] a receiving module 603 configured to receive first location information sent by the first device, and receive a user identity identifier and second location information of the second device sent by the first device; the user identity identifier and the second location information are received by the first device from the second device; the dynamic device identifier of the first device matches the accessible device identifier of the second device, and the accessible user identifier of the first device matches the dynamic user identifier of the second device;
[0274] The third sending module 604 is used to send near-domain identification success information containing the user identity identifier to the first device when the distance between the first location information and the second location information meets a preset distance condition, and to send service access permission information containing the user identity identifier to the service provider.
[0275] In an exemplary embodiment, the device also includes: a fourth sending module, which is used to send near-domain identification failure information containing the user identity identifier to the first device when the distance between the first location information and the second location information does not meet the preset distance condition, and send service access cancellation information containing the user identity identifier to the service provider.
[0276] In an exemplary embodiment, the device also includes: a first receiving module for receiving the updated first location information sent by the first device, and receiving the user identity and updated second location information of the second device sent by the first device; a fifth sending module for sending the near-domain identification success information to the first device if the distance between the updated first location information and the updated second location information meets the preset distance condition; a sixth sending module for sending near-domain identification failure information containing the user identity to the first device if the updated first location information and the updated second location information do not meet the preset distance condition, and sending service access cancellation information containing the user identity to the service provider.
[0277] In an exemplary embodiment, the first sending module 601 is used to: periodically send an updated dynamic device identifier and an updated accessible user identifier to the first device; the device also includes: a seventh sending module, used to send an updated accessible device identifier and an updated dynamic user identifier to the second device.
[0278] In an exemplary embodiment, Figure 7 As shown, a service access control device 700 is provided, including:
[0279] A first sending module 701 is configured to send first location information to an access control unit;
[0280] A first receiving module 702 is configured to receive a dynamic device identifier and an accessible user identifier from an access control unit;
[0281] A second sending module 703 is configured to publish the dynamic device identification in a shared network environment;
[0282] A second receiving module 704 is configured to receive a dynamic user identifier sent by a second device located in the same shared network environment;
[0283] A third sending module 705 is configured to send a location acquisition request to the second device if there is an accessible user identifier matching the dynamic user identifier;
[0284] A third receiving module 706 is configured to receive second location information from the second device;
[0285] A fourth sending module 707 is configured to send the user identity of the second device and the second location information to the access control unit;
[0286] The fifth sending module 708 is used to send service accessibility information to the second device when receiving the near-domain identification success information containing the user identity identifier; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information meets the preset distance condition; the service accessibility information is used to indicate that the second device can access the service provider.
[0287] In an exemplary embodiment, the device also includes: a sixth sending module, used to send service inaccessibility information to the second device when receiving near-domain identification failure information containing the user identity identifier; the near-domain identification failure information is sent by the access control unit when it is determined that the distance between the first location information and the second location information does not meet a preset distance condition; the service inaccessibility information is used to indicate that the second device cannot access the service provider.
[0288] In an exemplary embodiment, the apparatus further includes: a seventh sending module for periodically sending a location acquisition request to the second device; a fourth receiving module for receiving updated second location information from the second device; and an eighth sending module for periodically sending the updated first location information to the access control unit, and periodically sending the user identity identifier and updated second location information of the second device to the access control unit.
[0289] In an exemplary embodiment, Figure 8 As shown, a service access control device 800 is provided, including:
[0290] A first sending module 801 is configured to send an identification acquisition request to an access control unit;
[0291] A first receiving module 802 is configured to receive an accessible device identifier and a dynamic user identifier sent by the access control unit;
[0292] An identification matching module 803 is configured to, upon receiving a dynamic device identification issued by a first device in a shared network environment, determine whether the dynamic device identification matches the accessible device identification;
[0293] A second sending module 804 is configured to send the dynamic user identifier to the first device if the dynamic device identifier matches the accessible device identifier;
[0294] a third sending module 805 configured to send second location information to the first device upon receiving a location acquisition request sent by the first device; the location acquisition request is sent by the first device after determining that there is an accessible user identifier matching the dynamic user identifier; the accessible user identifier is received by the first device from the access control unit;
[0295] The second receiving module 806 is used to receive service accessibility information from the first device; the service accessibility information is sent by the first device after receiving the near-domain identification success information from the access control unit; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information of the first device meets a preset distance condition.
[0296] In an exemplary embodiment, the apparatus further includes: a third receiving module, configured to receive a location acquisition request sent by the first device; and a fourth sending module, configured to send updated second location information to the first device.
[0297] In an exemplary embodiment, the apparatus further includes: a fifth sending module, configured to periodically send the identification acquisition request to the access control unit; and a fourth receiving module, configured to receive the updated accessible device identification and the updated dynamic user identification sent by the access control unit.
[0298] Each module in the above-mentioned service access control device can be implemented in whole or in part through software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of the processor in the computer device in hardware form, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each of the above modules.
[0299] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 9As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store data such as dynamic device identification, accessible user identification, dynamic user identification, accessible device identification, etc. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a service access control method is implemented.
[0300] In an exemplary embodiment, a computer device is provided. The computer device may be a terminal, and its internal structure diagram may be as shown in FIG. Figure 10 As shown. The computer device includes a processor, memory, an input / output interface, a communication interface, a display unit, and an input device. The processor, memory, and input / output interface are connected via a system bus, and the communication interface, display unit, and input device are connected to the system bus via the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals via wired or wireless means, and the wireless means can be implemented via Wi-Fi, a mobile cellular network, near field communication (NFC), or other technologies. When executed by the processor, the computer program implements a service access control method. The display unit of the computer device is used to form a visually visible image, and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covering the display screen, or a button, trackball or touchpad set on the computer device casing, or an external keyboard, touchpad or mouse.
[0301] Those skilled in the art will understand that Figure 9 or Figure 10The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0302] In one embodiment, a computer device is further provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.
[0303] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0304] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0305] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0306] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), quantum computing-based data processing logic devices, artificial intelligence (AI) processors, and the like.
[0307] The technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0308] The above embodiments merely illustrate several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.
Claims
1. A service access control method, characterized in that: The method comprises: Sending a dynamic device identifier and an accessible user identifier to the first device; When receiving an identification acquisition request from a second device, sending the accessible device identification and the dynamic user identification to the second device; Receiving first location information sent by the first device, and receiving a user identity and second location information of the second device sent by the first device; the user identity and the second location information are received by the first device from the second device; the dynamic device identifier of the first device matches the accessible device identifier of the second device, and the accessible user identifier of the first device matches the dynamic user identifier of the second device; When the distance between the first location information and the second location information meets a preset distance condition, near-domain identification success information including the user identity identifier is sent to the first device, and service access permission information including the user identity identifier is sent to the service provider.
2. The method according to claim 1, characterized in that After receiving the first location information sent by the first device and receiving the user identity identifier and second location information of the second device sent by the first device, the method further includes: When the distance between the first location information and the second location information does not meet the preset distance condition, near-domain identification failure information including the user identity identifier is sent to the first device, and service access cancellation information including the user identity identifier is sent to the service provider.
3. The method according to claim 1, characterized in that After sending the access permission information including the user identity to the service provider, the method further includes: receiving the updated first location information sent by the first device, and receiving the user identity and updated second location information of the second device sent by the first device; If the distance between the updated first location information and the updated second location information meets the preset distance condition, sending the near-field recognition success information to the first device; If the updated first location information and the updated second location information do not meet the preset distance condition, a near-domain identification failure message including the user identity is sent to the first device, and a service access cancellation message including the user identity is sent to the service provider.
4. The method according to claim 1, wherein The sending the dynamic device identifier and the accessible user identifier to the first device includes: Periodically sending an updated dynamic device identifier and an updated accessible user identifier to the first device; After receiving the identification acquisition request from the second device, the method further includes: The updated accessible device identifier and the updated dynamic user identifier are sent to the second device.
5. A service access control method, characterized in that: The method comprises: Sending first location information to the access control unit; Receiving a dynamic device identifier and an accessible user identifier from an access control unit; Publishing the dynamic device identification in a shared network environment; receiving a dynamic user identifier sent by a second device located in the same shared network environment; If there is an accessible user identifier that matches the dynamic user identifier, sending a location acquisition request to the second device; receiving second location information from the second device; Sending the user identity of the second device and the second location information to the access control unit; Upon receiving the near-domain identification success information containing the user identity identifier, service accessibility information is sent to the second device; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information meets a preset distance condition; the service accessibility information is used to indicate that the second device can access the service provider.
6. The method according to claim 5, characterized in that The method further comprises: Upon receiving near-domain identification failure information containing the user identity identifier, service inaccessibility information is sent to the second device; the near-domain identification failure information is sent by the access control unit when it is determined that the distance between the first location information and the second location information does not meet a preset distance condition; the service inaccessibility information is used to indicate that the second device cannot access the service provider.
7. The method according to claim 5, characterized in that After sending the service accessibility information to the second device, the method further includes: Periodically sending a location acquisition request to the second device; receiving updated second location information from the second device; The updated first location information is periodically sent to the access control unit, and the user identity of the second device and the updated second location information are periodically sent to the access control unit.
8. A service access control method, characterized in that: The method comprises: Sending an identification acquisition request to the access control unit; Receiving an accessible device identifier and a dynamic user identifier sent by the access control unit; Upon receiving a dynamic device identifier issued by a first device in a shared network environment, determining whether the dynamic device identifier matches the accessible device identifier; If the dynamic device identifier matches the accessible device identifier, sending the dynamic user identifier to the first device; sending second location information to the first device upon receiving a location acquisition request sent by the first device; the location acquisition request is sent by the first device after determining that there is an accessible user identifier matching the dynamic user identifier; the accessible user identifier is received by the first device from the access control unit; Receive service accessibility information from the first device; the service accessibility information is sent by the first device after receiving near-domain identification success information from the access control unit; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information of the first device meets a preset distance condition.
9. The method according to claim 8, characterized in that After receiving the service accessibility information from the first device, the method further includes: receiving a location acquisition request sent by the first device; The updated second location information is sent to the first device.
10. The method according to claim 8, characterized in that The method further comprises: Periodically sending the identification acquisition request to the access control unit; The updated accessible device identifier and the updated dynamic user identifier sent by the access control unit are received.
11. A service access control system, characterized in that: The system includes: an access control unit, a first device, and a second device; The access control unit is configured to send a dynamic device identifier and an accessible user identifier to the first device; The first device is configured to receive the dynamic device identifier and the accessible user identifier; The second device is configured to send an identification acquisition request to the access control unit; The access control unit is further configured to receive the identification acquisition request; and send the accessible device identification and the dynamic user identification to the second device; The second device is further configured to receive the accessible device identifier and the dynamic user identifier; The first device is further configured to publish the dynamic device identifier in a shared network environment; The second device is further configured to receive the dynamic device identifier; and if the dynamic device identifier matches the accessible device identifier, send the dynamic user identifier to the first device; The first device is further configured to receive the dynamic user identifier; and if there is an accessible user identifier that matches the dynamic user identifier, send a location acquisition request to the second device; The second device is further configured to receive the location acquisition request; and send second location information to the first device; The first device is further configured to send the first location information to the access control unit; and receive the second location information; and send the user identity of the second device and the second location information to the access control unit; The access control unit is further configured to receive the first location information, the user identity identifier, and the second location information; and when the distance between the first location information and the second location information meets a preset distance condition, send a near-domain identification success message including the user identity identifier to the first device, and send a service access permission message including the user identity identifier to the service provider; The first device is further configured to receive the near-domain identification success information; and send service accessibility information to the second device; The second device is further configured to receive the service accessibility information.
12. A service access control device, characterized in that: The device comprises: A first sending module, configured to send a dynamic device identifier and an accessible user identifier to the first device; A second sending module is configured to send the accessible device identifier and the dynamic user identifier to the second device when receiving an identifier acquisition request from the second device; a receiving module, configured to receive first location information sent by the first device, and receive a user identity identifier and second location information of the second device sent by the first device; the user identity identifier and the second location information are received by the first device from the second device; the dynamic device identifier of the first device is consistent with the accessible device identifier of the second device, and the accessible user identifier of the first device includes the dynamic user identifier of the second device; The third sending module is used to send near-domain identification success information containing the user identity identifier to the first device when the distance between the first location information and the second location information meets a preset distance condition, and to send service access permission information containing the user identity identifier to the service provider.
13. A service access control device, characterized in that: The device comprises: A first sending module, configured to send first location information to the access control unit; A first receiving module is used to receive a dynamic device identifier and an accessible user identifier from an access control unit; A second sending module, configured to publish the dynamic device identification in a shared network environment; A second receiving module, configured to receive a dynamic user identifier sent by a second device located in the same shared network environment; a third sending module, configured to send a location acquisition request to the second device if there is an accessible user identifier matching the dynamic user identifier; a third receiving module, configured to receive second location information from the second device; A fourth sending module, configured to send the user identity of the second device and the second location information to the access control unit; The fifth sending module is used to send service accessibility information to the second device when receiving the near-domain identification success information containing the user identity identifier; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information meets the preset distance condition; the service accessibility information is used to indicate that the second device can access the service provider.
14. A service access control device, characterized in that: The device comprises: A first sending module, configured to send an identification acquisition request to the access control unit; A first receiving module is configured to receive an accessible device identifier and a dynamic user identifier sent by the access control unit; an identification matching module, configured to, upon receiving a dynamic device identification issued by a first device in a shared network environment, determine whether the dynamic device identification matches the accessible device identification; A second sending module, configured to send the dynamic user identifier to the first device if the dynamic device identifier matches the accessible device identifier; a third sending module, configured to send second location information to the first device upon receiving a location acquisition request sent by the first device; the location acquisition request is sent by the first device after determining that there is an accessible user identifier matching the dynamic user identifier; the accessible user identifier is received by the first device from the access control unit; The second receiving module is used to receive service accessibility information from the first device; the service accessibility information is sent by the first device after receiving the near-domain identification success information from the access control unit; the near-domain identification success information is sent by the access control unit when it is determined that the distance between the first location information and the second location information of the first device meets a preset distance condition.
15. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 10 are implemented.
16. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.
17. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.