Computer network equipment remote control system for Internet of Things
By introducing a device-side security agent module and a two-way digital certificate authentication mechanism of the cloud control platform into the IoT remote control system, combined with a policy management engine and an adaptive learning unit, the security and adaptability issues of the IoT remote control system are solved, achieving highly secure and intelligent remote control.
Patent Information
- Application Number
- CN202511225821.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2025-11-11
AI Technical Summary
Existing IoT remote control systems lack a security-in-depth architecture, making communication vulnerable to man-in-the-middle attacks. Device status information is not effectively used to build dynamic security strategies, resulting in poor adaptability and an inability to meet the high standards required in the IoT environment.
By adopting a two-way digital certificate authentication mechanism between the device-side security agent module and the cloud control platform, combined with a policy management engine and an adaptive learning unit, encrypted communication and dynamic control policies are realized. Communication security is ensured through a certificate authentication center, and control policies are optimized using an adaptive learning unit.
It significantly improves the security level and adaptability of IoT device control networks, enhances the reliability and intelligence of the system, and reduces operational risks and inefficiencies caused by rigid strategies.
Smart Images

Figure CN120934873A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet of Things (IoT) technology, specifically to a remote control system for computer network devices used in the Internet of Things. Background Technology
[0002] With the widespread application of IoT technology, remote control of massive network devices has become commonplace. Existing remote control systems mostly focus on implementing the control function itself, and usually transmit commands through a simple client-server model. They generally lack a deep security protection architecture, and their communication process mostly uses basic identity authentication and plaintext or weak encryption transmission methods, which are difficult to resist network threats such as man-in-the-middle attacks and command tampering, and have significant security vulnerabilities.
[0003] Meanwhile, such systems typically centralize control logic in the cloud, with the device only serving as an instruction execution terminal. This results in low intelligence, and the device status information and surrounding environment data are not effectively used to build dynamic security strategies. Consequently, the system has poor adaptability when facing new attacks or complex network environments, and cannot meet the high standards of real-time performance, reliability, and security required for device control in the Internet of Things (IoT) environment. Therefore, there is an urgent need for a remote control system for computer network devices used in the IoT. Summary of the Invention
[0004] The purpose of this invention is to provide a remote control system for computer network devices used in the Internet of Things (IoT).
[0005] To achieve the above objectives, the present invention provides the following technical solution: a remote control system for computer network devices used in the Internet of Things (IoT), comprising a remote control system, wherein the remote control system includes:
[0006] The device-side security agent module is deployed on the controlled network device to collect device operating status data and environmental data, and execute instructions from the cloud control platform.
[0007] The cloud control platform is connected to the device-side security agent module via network communication and is used to receive, store, and process device operating status data and environmental data.
[0008] The cloud control platform includes a policy management engine and a certificate authentication center. The policy management engine generates device control policies based on data processing results. The certificate authentication center provides digital certificate support for two-way authentication between the device-side security agent module and the cloud control platform, ensuring that the communication link complies with network security protocols. The device-side security agent module receives and executes the authenticated control policy instructions, thereby achieving remote and secure control of network devices.
[0009] As a further aspect of the present invention: the device-side security agent module includes a data acquisition unit, a secure communication unit, and an instruction execution unit. The data acquisition unit is used to collect device operating status data and surrounding environment data. The secure communication unit establishes an encrypted communication connection with the cloud control platform based on a digital certificate. The instruction execution unit is used to parse and execute the authenticated control instructions received by the secure communication unit.
[0010] As a further aspect of the present invention, the strategy management engine further includes an adaptive learning unit, which dynamically adjusts the parameters of the device control strategy based on historical device operating status data and environmental data to form an adaptive control strategy.
[0011] As a further aspect of the present invention: the communication between the cloud control platform and the device-side security agent module adopts a two-way certificate authentication mechanism. When establishing a connection, both parties exchange and verify digital certificates issued by the certificate authentication center. Data transmission can only proceed after the verification is successful.
[0012] As a further aspect of the present invention: after the secure communication connection of the two-way certificate authentication mechanism is established, all transmitted data is encrypted, and each session uses a different session key for encryption.
[0013] As a further aspect of the present invention: the remote control system further includes a user terminal, which is communicatively connected to the cloud control platform and is used to display device status, environmental data and policy execution logs to the user, and to receive control commands issued by the user. The control commands issued by the user are verified and encapsulated by the policy management engine and then sent to the device-side security agent module.
[0014] As a further aspect of the present invention: the communication interface between the user terminal and the cloud control platform is a controlled application programming interface, and access to the interface requires identity authentication and permission verification.
[0015] As a further aspect of the present invention, the remote control system further includes a security audit module, which is used to record all control commands, operation behaviors and remote control system events, generate audit logs, and provide real-time alarms for abnormal operation behaviors.
[0016] As a further aspect of the present invention: when the controlled network device first accesses the remote control system, it needs to register with the certificate authentication center and apply for a unique identity and digital certificate. Devices that fail to register cannot establish a communication connection with the cloud control platform.
[0017] Compared with the prior art, the beneficial effects of the present invention by adopting the above technical solution are as follows:
[0018] 1. This invention establishes an independent certificate authentication center and implements a two-way digital certificate authentication mechanism between the device and the cloud platform, thereby constructing a highly reliable communication foundation that complies with network security protocols. This design fundamentally eliminates the risk of unauthorized device access and man-in-the-middle attacks, ensuring the integrity, confidentiality, and authenticity of control commands and status data during transmission, and significantly improving the security level of the entire IoT device control network.
[0019] 2. By introducing a strategy management engine and an adaptive learning unit, this invention achieves intelligent and dynamic control strategies. The remote control system can comprehensively analyze equipment operating status and environmental data, continuously optimize control strategy parameters, and make control decisions not only based on preset rules, but also adapt to real-time operating conditions and historical patterns. This design improves the system's adaptability and decision accuracy in the face of complex and ever-changing network environments, while reducing operational risks or inefficiencies caused by rigid strategies, and enhancing the reliability and intelligence level of the entire remote control system. Attached Figure Description
[0020] Figure 1 This is a diagram of the overall system architecture of the present invention;
[0021] Figure 2 This is a flowchart illustrating the device registration and certification process of the present invention.
[0022] Figure 3 This is a flowchart of the data acquisition and instruction execution process of the present invention;
[0023] Figure 4 This is a flowchart of the user instruction issuance process of the present invention;
[0024] Figure 5 A flowchart is provided for establishing secure communication in this invention. Detailed Implementation
[0025] The specific embodiments of the present invention will be further described below with reference to the accompanying drawings. It should be noted that the description of these embodiments is for the purpose of helping to understand the present invention, but does not constitute a limitation of the present invention.
[0026] Furthermore, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.
[0027] Please see the appendix Figure 1 - Appendix Figure 5 The present invention provides a remote control system for computer network devices used in the Internet of Things (IoT), comprising:
[0028] The device-side security agent module is deployed on the controlled network device to collect device operating status data and environmental data, and execute instructions from the cloud control platform.
[0029] The cloud control platform connects to the device-side security agent module via network communication and is used to receive, store, and process device operating status data and environmental data.
[0030] The cloud control platform includes a policy management engine and a certificate authentication center. The policy management engine generates device control policies based on data processing results, while the certificate authentication center provides digital certificate support for two-way authentication between the device-side security agent module and the cloud control platform, ensuring that the communication link complies with network security protocols. The device-side security agent module receives and executes the authenticated control policy instructions, achieving remote and secure control of network devices.
[0031] In one embodiment of the present invention: the device-side security agent module includes a data acquisition unit, a secure communication unit, and an instruction execution unit. The data acquisition unit is used to collect device operating status data and surrounding environment data. The secure communication unit establishes an encrypted communication connection with the cloud control platform based on a digital certificate. The instruction execution unit is used to parse and execute the authenticated control instructions received by the secure communication unit.
[0032] In one embodiment of the present invention, the strategy management engine further includes an adaptive learning unit, which dynamically adjusts the parameters of the device control strategy based on historical device operating status data and environmental data to form an adaptive control strategy.
[0033] In one embodiment of the present invention: the communication between the cloud control platform and the device-side security agent module adopts a two-way certificate authentication mechanism. When establishing a connection, the two parties exchange and verify the digital certificate issued by the certificate authentication center. Data transmission can only be carried out after the verification is successful.
[0034] In one embodiment of the present invention: after a secure communication connection is established by the two-way certificate authentication mechanism, all transmitted data is encrypted, and each session uses a different session key for encryption.
[0035] In one embodiment of the present invention: the remote control system further includes a user terminal, which is communicatively connected to the cloud control platform and is used to display device status, environmental data and policy execution logs to the user, and to receive control commands issued by the user. The control commands issued by the user are verified and encapsulated by the policy management engine and then sent to the device-side security agent module.
[0036] In one embodiment of the present invention: the communication interface between the user terminal and the cloud control platform is a controlled application programming interface, and access to the interface requires identity authentication and permission verification.
[0037] In one embodiment of the present invention, the remote control system further includes a security audit module, which is used to record all control commands, operation behaviors and remote control system events, generate audit logs, and provide real-time alarms for abnormal operation behaviors.
[0038] In one embodiment of the present invention: when a controlled network device first accesses the remote control system, it needs to register with the certificate authentication center and apply for a unique identity and digital certificate. Devices that fail to register cannot establish a communication connection with the cloud control platform.
[0039] Example 1: A Secure Network Device Management System Based on Two-Way Certificate Authentication
[0040] The core of the system implementation lies in the deployment of the device-side security proxy module. This module is embedded in the operating system or firmware of the aforementioned network devices as lightweight software, achieving deep integration and low invasiveness. Its built-in data acquisition unit acts as a "sensory nerve," continuously collecting and preprocessing two main categories of data at high frequency:
[0041] One is the device operating status data, which covers comprehensive performance and health indicators such as CPU and memory utilization, port real-time throughput and error frame statistics, session connection count, routing table status, hardware temperature, fan speed, and power status.
[0042] Secondly, there is the equipment environment data. By connecting the built-in or external sensors of the equipment, the precise temperature and humidity, smoke detection, cabinet door magnetic switch status, and UPS power supply voltage of the computer room where the equipment is located can be obtained. This massive amount of fine-grained real-time data is the basis for subsequent intelligent analysis and decision-making.
[0043] To ensure the absolute security of these sensitive data and subsequent control commands transmitted over the public internet or leased network, the secure communication unit employs a two-way certificate authentication mechanism supported by the system's embedded Certificate Authority (CA). Before each controlled network device goes online for the first time, it must complete mandatory registration with the central Certificate Authority, apply for and obtain a globally unique identifier and a bound X.509 format digital certificate. Similarly, the cloud control platform itself also holds a server certificate issued by the CA. At the beginning of any communication connection between the device agent and the cloud platform (such as HTTPS, MQTT over TLS), both parties must exchange and strictly verify the validity of each other's certificates (including verifying the issuer, validity period, Certificate Revocation List, etc.). This process fundamentally eliminates the risk of unauthorized device impersonation and "man-in-the-middle-attack," ensuring a trusted starting point for the communication link. After verification, both parties encrypt all business data (status data and control commands) in the transmission end-to-end based on the negotiated high-strength, one-time-use key, ensuring the confidentiality and integrity of the information.
[0044] As the "brain" of the system, the cloud control platform receives, stores, and processes massive amounts of status and environmental data from tens of thousands of devices. One of its core components, the policy management engine, performs real-time analysis of the data based on a preset set of rules. For example, the engine can set the following rules:
[0045] If the CPU utilization of a core switch is detected to be consistently above 85% and accompanied by memory utilization above 90%, the device is deemed to be at risk of overload.
[0046] If the cabinet temperature sensor reading exceeds 40 degrees Celsius for a continuous period, a high temperature alarm will be triggered. Based on these analysis results, the policy management engine can automatically generate preliminary control policy instructions, such as issuing instructions to overloaded switches to dynamically adjust their routing policies and divert some non-critical business traffic to the less loaded backup links.
[0047] Alternatively, a command can be sent to the intelligent PDU to temporarily increase the cooling power of the cabinet;
[0048] Control commands generated by the policy engine or initiated by the administrator are sent to the target device through a secure communication link. The command execution unit of the device-side security agent is responsible for receiving, parsing, and finally executing the commands. The execution results and changes in the device status after the commands take effect are captured by the data acquisition unit and reported to the cloud, thus forming a complete closed-loop automated control loop of "monitoring-analysis-decision-execution-feedback". This enables refined and automated remote security management and control of distributed network devices, greatly improving the efficiency and reliability of network operation and maintenance.
[0049] Example 2: Evolution of Intelligent Operation and Maintenance Integrating Adaptive Learning and Security Auditing
[0050] Based on the secure and controllable network described in Example 1, the advanced nature and intelligence of this system are further enhanced by the adaptive learning unit and independent security audit module in the policy management engine, demonstrating the system's self-evolution and continuous security assurance capabilities in long-term operation.
[0051] The adaptive learning unit is the key to the system’s intelligent operation and maintenance. It is no longer limited to executing preset static rules, but introduces machine learning algorithms to deeply mine and recognize patterns in the long-term, massive equipment operation status data and environmental data accumulated in the historical database of the cloud control platform.
[0052] For example, by analyzing the traffic data of all routers in the network over the past year, the unit may accurately learn the business traffic pattern model of different branches, different workdays / holidays, and even different time periods of the day. Based on this, the system can achieve predictive operation and maintenance and dynamic strategy adjustment.
[0053] A typical application is this: the system learns that a certain core node experiences periodic bandwidth shortages due to a surge in video conferencing traffic every weekday afternoon from 4 pm to 6 pm. Therefore, the adaptive learning unit dynamically adjusts the parameters of relevant policies in the policy management engine to form an adaptive control policy. At 3:45 pm every day, it proactively pre-configures the Quality of Service (QoS) policy for this node, temporarily increasing the priority bandwidth guarantee for video conferencing applications, thereby smoothly passing through traffic peaks and avoiding network congestion and a decline in user experience. This shift from "post-event remediation" to "pre-event prediction" significantly enhances the network's adaptability and resilience in the face of complex and ever-changing business demands.
[0054] Meanwhile, user terminals (such as the monitoring screen of the network operation and maintenance center or the web console of the engineer) provide administrators with a window to interact with this intelligent system. Authorized administrators can log in to the system through a secure and controlled API interface (access requires strict identity authentication and permission verification) to view the real-time health status of all network devices, historical trend charts, automated policy execution logs, and predictive insights generated by the adaptive learning unit. Administrators can not only passively receive information, but also actively issue advanced control commands, such as initiating a remote deep packet inspection (DPI) diagnostic or manually triggering a device configuration backup. These commands do not go directly to the device, but must first be submitted to the cloud control platform, where the policy management engine performs compliance verification and security encapsulation (ensuring that the command format is correct and the administrator has the right to perform this operation), before being sent to the command execution unit of the target device through a secure channel. This process ensures both flexibility and the security and controllability of the operation.
[0055] All the above operations, whether automatically generated policy instructions, manually issued control commands by administrators, or even device status changes and authentication events, are recorded without omission by the security audit module. This module acts like a faithful "black box," generating detailed, tamper-proof audit logs. The logs include the operation time, operation subject (system or user ID), operation object, operation content, source IP address, and final execution result. More importantly, the audit module has built-in abnormal behavior detection rules, enabling real-time analysis of the logs. Once an abnormal pattern is detected, such as a low-privilege account attempting to execute high-risk instructions, frequent configuration changes during non-working hours, or repeated authentication failures of a device, the system will immediately trigger a real-time alarm, notifying security personnel via SMS, email, or a work order system. This provides a crucial final line of defense for the entire remote control system, meeting the auditable and traceable requirements for high-level network security operations.
[0056] In summary, this invention constructs a highly secure and automated remote control foundation through Embodiment 1, and realizes the intelligent evolution and in-depth security defense of the system through Embodiment 2, fully demonstrating a panoramic view of a remote control system that is both secure and reliable as well as intelligent and efficient for modern computer network equipment.
[0057] Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make possible changes and modifications without departing from the spirit and scope of the present invention. Therefore, any modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the content of the technical solution of the present invention shall fall within the protection scope defined by the claims of the present invention.
Claims
1. A remote control system for computer network devices used in the Internet of Things (IoT), comprising a remote control system, characterized in that: The remote control system includes: The device-side security agent module is deployed on the controlled network device to collect device operating status data and environmental data, and execute instructions from the cloud control platform. The cloud control platform is connected to the device-side security agent module via network communication and is used to receive, store, and process device operating status data and environmental data. The cloud control platform includes a policy management engine and a certificate authentication center. The policy management engine generates device control policies based on data processing results. The certificate authentication center provides digital certificate support for two-way authentication between the device-side security agent module and the cloud control platform, ensuring that the communication link complies with network security protocols. The device-side security agent module receives and executes the authenticated control policy instructions, thereby achieving remote and secure control of network devices.
2. The remote control system for computer network equipment for the Internet of Things according to claim 1, characterized in that: The device-side security agent module includes a data acquisition unit, a secure communication unit, and an instruction execution unit. The data acquisition unit is used to collect device operating status data and surrounding environment data. The secure communication unit establishes an encrypted communication connection with the cloud control platform based on a digital certificate. The instruction execution unit is used to parse and execute the authenticated control instructions received by the secure communication unit.
3. The remote control system for computer network equipment for the Internet of Things according to claim 1, characterized in that: The strategy management engine also includes an adaptive learning unit, which dynamically adjusts the parameters of the device control strategy based on historical device operating status data and environmental data to form an adaptive control strategy.
4. The remote control system for computer network equipment for the Internet of Things according to claim 1, characterized in that: The communication between the cloud control platform and the device-side security agent module adopts a two-way certificate authentication mechanism. When establishing a connection, both parties exchange and verify digital certificates issued by the certificate authentication center. Data transmission can only proceed after the verification is successful.
5. A remote control system for computer network equipment for the Internet of Things according to claim 4, characterized in that: After the secure communication connection of the two-way certificate authentication mechanism is established, all transmitted data is encrypted, and a different session key is used for encryption in each session.
6. A remote control system for computer network equipment for the Internet of Things according to claim 3, characterized in that: The remote control system also includes a user terminal, which is communicatively connected to the cloud control platform. The user terminal is used to display device status, environmental data and policy execution logs to the user, and to receive control commands issued by the user. The control commands issued by the user are verified and encapsulated by the policy management engine and then sent to the device-side security agent module.
7. A remote control system for computer network equipment for the Internet of Things according to claim 6, characterized in that: The communication interface between the user terminal and the cloud control platform is a controlled application programming interface (API), and access to the interface requires identity authentication and permission verification.
8. A remote control system for computer network equipment for the Internet of Things according to claim 1, characterized in that: The remote control system also includes a security audit module, which is used to record all control commands, operation behaviors and remote control system events, generate audit logs, and provide real-time alarms for abnormal operation behaviors.
9. A remote control system for computer network equipment for the Internet of Things according to claim 1, characterized in that: When the controlled network device first connects to the remote control system, it needs to register with the certificate authentication center and apply for a unique identity and digital certificate. Devices that fail to register will not be able to establish a communication connection with the cloud control platform.
Citation Information
Patent Citations
Security remote control system and method for industrial equipment
CN108390851A
Intelligent control system for museum
CN118567244A
Air purification system for clean workshop
CN119573198A
Security for network computing environment using centralized security system
US10419931B1
Cited By
Household gas detection device
CN121384852A