Internet of Things terminal control method, electronic equipment and storage medium
The two-layer authorization and review mechanism that interacts with user devices through physical tags solves the problems of poor user experience and low security in existing technologies, and achieves high security and convenient operation and maintenance of device control, which is suitable for rapid business expansion in diverse scenarios.
Patent Information
- Application Number
- CN202511042302.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-28
- Publication Date
- 2025-11-21
AI Technical Summary
In smart buildings, campuses, or parking lots, existing technologies rely on physical cards, remote controls, or single-function native apps for device control and access management. This results in poor user experience, low security, and difficulty in expanding new services. It also presents problems such as the need for multiple media to carry, frequent switching, high update costs, and weak security protection.
It uses physical tags to interact with user devices, generates user request information through tag number and user token, and performs two-layer authorization review. It first judges access permissions and then verifies control permissions. The communication method is reverse access to avoid direct exposure to the public network. The physical tag is decoupled from the business and supports rapid function upgrades.
It improves user experience and control security, simplifies operation and maintenance processes, supports rapid business expansion, and is suitable for diverse scenarios such as buildings, campuses, industrial parks, parking lots, and hospitals.
Smart Images

Figure CN121000412A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of permission management, and more particularly to an Internet of Things terminal control method, an electronic device and a storage medium. BACKGROUND
[0002] In the scenarios of intelligent buildings, campuses or parking lots, device control and access control management have long relied on physical cards, remote controls or single-function native Apps. This mode has the following problems: ① multiple types of media need to be carried at all times; ② frequent switching between multiple Apps leads to fragmented experience; ③ when new services are added, cards need to be reissued or independent Apps need to be developed, which results in long update cycles and high costs; and ④ on-site devices often need to expose public network ports, and security protection is weak. These greatly affect user experience and device control security.
[0003] Therefore, the present application is proposed. SUMMARY
[0004] The present application is proposed in consideration of the above problems. According to one aspect of the present application, an Internet of Things terminal control method is provided, comprising: Upon receiving user request information, determining target function configuration information corresponding to a target tag number in a tag configuration database, wherein the tag configuration database stores a plurality of tag numbers and function configuration information corresponding to the tag numbers one by one, the user request information is generated by a user device triggering a physical tag, the user request information includes the target tag number of the physical tag and a user token, and the physical tag is a tag corresponding to a target Internet of Things terminal; Determining whether a current user has access permission to a function configuration interface corresponding to the target function configuration information according to at least the user token; When the current user has the access permission, sending a script address of the function configuration interface to the user device, and the user device displays the function configuration interface upon receiving the script address; Upon receiving control information, determining whether the current user has control permission to execute a target control instruction according to the user token, the target control instruction being a control instruction corresponding to the control information, and the control information being generated by the user device in response to a triggering operation on a specific page element in the function configuration interface; When the current user has the control permission, issuing the target control instruction to the target Internet of Things terminal to control the target Internet of Things terminal to execute the target control instruction.
[0005] Exemplarily, before the determining whether the current user has the access permission to the function configuration interface corresponding to the target function configuration information, the method further comprises: determining whether the user token is valid; The step of determining whether the current user has access to the function configuration interface corresponding to the target function configuration information is performed when the identification of the user token is valid.
[0006] Exemplarily, the determination of whether the user token is valid comprises: determining whether the identification of the user token is stored in the identification blacklist; When the identification of the user token is not stored in the identification blacklist, it is determined that the user token is valid.
[0007] Exemplarily, after the user equipment generates the control information, the function configuration interface displays prompt information; or the user equipment generates and sends the control information when the waiting time length after the generation of the control information reaches a first preset time length and no cancellation instruction is received, or the user equipment generates and sends the control information after the trigger operation duration of the specific page element reaches a second preset time length.
[0008] Exemplarily, within a third preset time length after the target control instruction is issued to the target IoT terminal, the function configuration interface displays a revocation page element for revoking the control information. The user equipment generates a revocation instruction in response to a trigger operation on the revocation page element; and the method further comprises: when the revocation instruction is received, controlling the target IoT terminal to perform an action opposite to the target control instruction.
[0009] Exemplarily, the determination of whether the current user has access to the function configuration interface corresponding to the target function configuration information at least according to the user token comprises: determining whether the current user has the access right according to the user token and the current time.
[0010] Exemplarily, the determination of whether the current user has the access right according to the user token and the current time comprises: determining whether user information in the user token is in a label access control list; when the user information is in the label access control list, determining whether the current time is within a permitted time period; when the current time is within the permitted time period, determining whether the current user has the access right.
[0011] Exemplarily, after the target IoT terminal is controlled to execute the target control instruction, the method further comprises: Record the execution time of the target control instruction, the execution result, the user information in the user token, and the target tag number.
[0012] According to yet another aspect of the present application, there is provided an electronic device comprising a processor and a memory having stored therein a computer program, the processor being configured to execute the computer program to implement the method as described above.
[0013] According to still another aspect of the present application, there is provided a computer readable storage medium having stored therein a computer program / instructions which, when executed by a processor, implement the method as described above.
[0014] In the above technical solution, the user device does not directly communicate with the target device, and the user device no longer exposes a public network address. This reverse access communication mode helps to improve control security. Through double-layer authorization auditing of access rights and control rights, it is first determined whether the user can see the function configuration interface, and then it is verified whether the user has control rights of the specific instruction. This double-layer authorization system can further improve the control security. In addition, the method is simple to use and has a low operation threshold. The user only needs to complete the operation of triggering the physical tag, which can greatly improve the user experience. At the same time, the physical tag of the method is only associated with the tag number and is not directly coupled with a specific business page. In this case, when the user changes the business requirements, the user only needs to associate the tag number of the physical tag with the new business, without the need to re-produce the physical tag (such as reprinting a two-dimensional code or re-burning an NFC), thereby enabling the on-site rapid online of new functions. In summary, the method is simple to use, has high communication security, and is convenient for operation and maintenance, and can be applied to multiple scenarios such as buildings, campuses, industrial parks, parking lots, and hospitals, and has a wide application prospect.
[0015] The above description is only a summary of the technical solutions of the present application. In order to more clearly understand the technical means of the present application, the content of the specification can be implemented, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific embodiments of the present application are described below. BRIEF DESCRIPTION OF DRAWINGS
[0016] The above and other objects, features and advantages of the present application will become more apparent from the following detailed description of embodiments of the present application taken in conjunction with the accompanying drawings. The drawings provided in the specification and the contents of the specification form a part of the detailed description of the application and serve to explain the application together with the embodiments of the application, but do not constitute a limitation on the application. In the drawings, the same reference numerals generally represent the same components or steps.
[0017] Figure 1 a schematic flowchart of a method for controlling an Internet of Things terminal according to an embodiment of the present application is shown; Figure 2 A schematic block diagram of an electronic device according to an embodiment of the present application is shown. DETAILED DESCRIPTION
[0018] In order to make the objects, technical solutions and advantages of the present application more obvious, the following will describe the example embodiments of the present application in detail with reference to the drawings. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments of the present application, and it should be understood that the present application is not limited to the example embodiments described herein. Based on the embodiments of the present application described in the present application, all other embodiments obtained by those skilled in the art without creative labor should fall within the protection scope of the present application.
[0019] As described above, in the current intelligent building, campus or parking lot and other scenarios, device control and access management have long relied on physical cards, remote controls or single-function native apps, which have poor user experience, low security and are not easy to expand new businesses. In some related technologies, direct code scanning or NFC web page is used for access management, but this method still has the defect of poor security. Specifically, the current direct code scanning or NFC web page still has the following shortcomings: Weak authentication: only jump to static page, not connected with enterprise identity provider (IdP); Coarse authority: two-dimensional code / NFC tag is often bound to a single function, and cannot be finely controlled according to user roles, white lists or time periods; Risk of misoperation: lack of secondary confirmation or audit log, and mis-scanning or malicious scanning can easily trigger sensitive instructions; Security exposure: the browser needs to be directly connected to the on-site device, and the device port exposure becomes an attack entry.
[0020] As can be seen, there is an urgent need for a device control method with strong security, good user experience and convenient business expansion. In view of this, the present application provides a method for controlling an Internet of Things terminal, an electronic device and a storage medium. The method is simple to use, has high communication security and is convenient for operation and maintenance. The method, electronic device and storage medium are described in detail below.
[0021] According to an aspect of an embodiment of the present application, a method for controlling an Internet of Things terminal is provided. Figure 1 A schematic flowchart of a method for controlling an Internet of Things terminal according to an embodiment of the present application is shown. As shown in Figure 1 The method can include the following steps S110, S120, S130, S140 and S150.
[0022] At step S110, when receiving the user request information, target function configuration information corresponding to the target tag number is determined in a tag configuration database, wherein the tag configuration database stores a plurality of tag numbers and function configuration information corresponding to the tag numbers one by one, the user request information is generated by a user equipment triggering a physical tag, and the user request information includes a target tag number of the physical tag and a user token, and the physical tag is a tag corresponding to a target thing terminal.
[0023] In the scheme of the embodiment, the physical tag can be any one or several of a two-dimensional code, NFC, BLE beacon, etc. The user can scan the two-dimensional code by using the user equipment or interact through the NFC and BLE beacon to trigger the physical tag. The user equipment can include but is not limited to a mobile phone, a tablet computer, a smart watch, etc., and the present application does not limit this. Thus, the "one scan / one touch / one approach" can reach the service, which helps to improve the user experience.
[0024] In the embodiment, the physical tag is the trigger entry. The physical tag can provide parameters including a target tag number, a specified service page, a service context (which can carry additional information such as a room number and a parking lot number), an international language code, etc., which are not described in detail.
[0025] After triggering the physical tag, the user equipment can obtain the tag number (i.e., the target tag number) of the physical tag. It can be understood that each physical tag has a unique tag number, which can be a 64-bit UUID or a device code. For example, the tag number can be "a3f8-…". After obtaining the target tag number, the user equipment can combine the target tag number and the user token into user request information and send it to a cloud device (hereinafter referred to as a cloud) for executing the method of the embodiment.
[0026] Optionally, the user token can be used to store the identity information of the user, which includes but is not limited to the user's name, the user's type, the user's account, etc. In some schemes of the embodiment, the cloud can interface with enterprise SSO, username-password and SMS one-time password, and when the user accesses for the first time through the user equipment, the login can be completed according to the configuration guide, and the user token (which can be a JWT token) is issued after successful login.
[0027] In the embodiment, the target function configuration information corresponding to the target tag number can be found by searching in a tag configuration database (TagDB) according to the target tag number. In some embodiments, before determining the target function configuration information corresponding to the target tag number, the method can further include the following steps: judging whether the necessary parameters in the user request information exist and are within a safe range in length; and determining the target function configuration information corresponding to the target tag number is performed when the necessary parameters in the user request information exist and are within a safe range in length. The necessary parameters in the user request information include the target tag number and the user token, and when any one of the parameters is missing or the length of the parameters is obviously unreasonable, it is difficult to make subsequent judgments. In this case, an error code 400 can be directly returned.
[0028] In some embodiments, the method can further include the following steps: returning error information to the user equipment when the target tag number does not exist in the tag configuration database. In the embodiment, the TagDB can be queried according to the target tag number, and if the number is not recorded in the TagDB, error information can be directly returned to the user. The error information can be an error code 404. In a specific implementation, when the error information is returned, prompt information can also be returned at the same time, and the prompt information can be "function not open".
[0029] In some embodiments, the user request information can include an application parameter, which is used to specify a business page (i.e., TagApp). In the embodiment, after determining the target function configuration information corresponding to the target tag number, the method can further include the following steps: judging whether the application parameter is included in the target function configuration information; if not, an error code 403 is directly returned; and if yes, the execution is continued.
[0030] In the embodiment, the physical tag is decoupled from the TagApp, and an operator can load different versions of the TagApp according to needs by tag group or user group, so as to smoothly upgrade.
[0031] In some embodiments, after determining the target function configuration information corresponding to the target tag number, the method can further include the following steps: judging whether the target function configuration information is marked as no authentication is required, and when the target function configuration information is marked as no authentication is required, directly sending the script address of the corresponding function configuration interface to the user equipment, and issuing the target control instruction to the target Internet of Things terminal according to the received control information. When the target function configuration information is marked as authentication is required, the subsequent step S120 can be continued. In this embodiment, for some low-risk functions, they can be directly marked as no authentication is required, and for sensitive functions such as opening and closing doors, they can be marked as authentication is required. Thus, when the user uses low-risk functions, the response can be faster. This can further improve the user experience while ensuring security.
[0032] In step S120, whether the current user has access to the function configuration interface corresponding to the target function configuration information is determined according to at least the user token.
[0033] After determining the target function configuration information, whether the current user has access can be determined according to the user token. As described above, the user token stores the identity information of the user. In some embodiments, the identity information can be matched with the tag-level access control list (TagACL) in TagDB. If the user has no access, the page is directly returned as unavailable. Otherwise, step S130 is continued.
[0034] In step S130, when the current user has access, the script address of the function configuration interface is sent to the user equipment, and the user equipment displays the function configuration interface when receiving the script address.
[0035] In some embodiments, the script address of the function configuration interface and the metadata required to run the function configuration interface can be sent to the user equipment at the same time, so that the user equipment can quickly load the script and render the interface.
[0036] In step S140, when receiving the control information, whether the current user has control authority to execute the target control instruction is determined according to the user token, the target control instruction being the control instruction corresponding to the control information, and the control information being generated by the user equipment in response to the trigger operation on a specific page element in the function configuration interface.
[0037] In this embodiment, the function configuration interface can have at least one page element. These page elements can exist in the form of virtual buttons. For example, the function configuration interface can have an “open door” button. When the user clicks this button, the user equipment can generate corresponding control information in response to the trigger operation and send it to the cloud.
[0038] In some embodiments, after receiving the control information, the current user can be first matched with the identity information stored in the user token according to the device-level access control list (Device ACL) to determine whether the current user has the right to use the control instruction corresponding to the control information. When the current user does not have the control right, the operation right can be directly returned. Otherwise, step S150 is continued.
[0039] In step S150, when the current user has the control right, the target control instruction is issued to the target IoT terminal to control the target IoT terminal to execute the target control instruction.
[0040] The target IoT terminal can include an IoT device such as a door access. In the present embodiment, the target IoT terminal can return execution information (execution success or execution failure) after executing the target control instruction. The cloud can send the execution information to the user device after receiving the execution information, so that the user can know the execution situation.
[0041] In some embodiments, the communication between the user device and the cloud, the cloud and the target IoT terminal can be encrypted by TLS1.3. At the same time, the minimum open port is exposed to the outside only 443 (HTTPS) and 22 (SSH operation and maintenance); Kafka traffic is limited to intranet access. Thus, the control security can be further improved.
[0042] In the above technical solution, the user device and the target IoT device do not communicate directly, and the user device no longer exposes the public network address. This reverse access communication method helps to improve the control security; through the double-layer authorization audit of access right and control right, it is first determined whether the user can see the function configuration interface, and then it is verified whether the user has the control right of the specific instruction. This double-layer authorization system can further improve the control security. In addition, the method is simple to use and has low operation threshold. The user only needs to complete the operation of triggering the physical tag, which can greatly improve the user experience. At the same time, the physical tag of the method is only associated with the tag number and is not directly coupled with the specific business page. In this case, when the user changes the business demand, the physical tag (such as reprinting the two-dimensional code or reprogramming the NFC) does not need to be re-made. Only the tag number of the physical tag needs to be associated with the new business, which can quickly online new functions in the field. In short, the method is simple to use, has high communication security and is easy to maintain, and can be applied to multi-scenarios such as buildings, campuses, industrial parks, parking lots, hospitals, etc., and has a wide application prospect.
[0043] Exemplarily, before determining whether the current user has the access right to the function configuration interface corresponding to the target function configuration information, the method further comprises: determining whether the user token is valid; and the step of determining whether the current user has the access right to the function configuration interface corresponding to the target function configuration information is executed when the identity of the user token is valid.
[0044] In the scheme of this example, the validity of the user token can be determined first. For example, it is determined whether the user information in the user token is in a blacklist, or whether the identity of the user token is valid. In this way, access from unauthorized users can be further avoided, security is improved, and meaningless steps can be avoided, and response efficiency is improved.
[0045] Exemplarily, determining whether the user token is valid comprises: determining whether the identity of the user token is stored in the identity blacklist; and determining that the user token is valid when the identity of the user token is not stored in the identity blacklist.
[0046] In some embodiments, a one-time identity for the user token can be generated at the same time as the user token is generated. In addition, the identity of the user token that no longer has the right can be stored in the identity blacklist. For example, after a student graduates, the identity of the user token of the student can be stored in the identity blacklist. The one-time identity can be a jti identifier.
[0047] The above technical solution can effectively prevent replay attacks and improve the control security of the Internet of Things terminal by starting the identity of the user token and performing blacklist checking on the identity of the user token.
[0048] Exemplarily, after the user equipment generates the control information, the function configuration interface displays prompt information; the user equipment sends the control information when the waiting time length after the control information is generated reaches a first preset time length and no cancellation instruction is received, or the user equipment generates and sends the control information after the trigger operation duration of a specific page element reaches a second preset time length.
[0049] The time lengths of the first preset time length and the second preset time length can be set as needed, for example, the first preset time length can be 5s, and the second preset time length can be 1.5s. The present application does not limit this.
[0050] In some embodiments, the user equipment sends the control information when the waiting time length after the control information is generated reaches a first preset time length and no cancellation instruction is received. In this embodiment, the user equipment can display a countdown and a cancel button on the device interface after generating the control information. If the user does not trigger the cancel button after the countdown reaches the first preset time length, the control information can be sent.
[0051] In some embodiments, the user device can generate and send the control information when the trigger operation duration of the specific page element reaches a second preset time length. For example, the control information can be generated and sent when the trigger operation duration of the specific page element reaches 1.5s (i.e., the user long-presses the specific page element for 1.5s).
[0052] The above technical solution determines whether to send the control information by accumulating the waiting time length or the accumulated trigger time length. This local secondary confirmation manner can effectively reduce the false triggering, thereby improving the control accuracy.
[0053] For example, within a third preset time length after the target control instruction is issued to the target IoT terminal, the function configuration interface displays a revocation page element (which can be referred to as a revocation button) for revoking the control information. The user device generates a revocation instruction in response to a trigger operation on the revocation page element. The method further includes: when the revocation instruction is received, controlling the target IoT terminal to perform an action opposite to the target control instruction.
[0054] The third preset time length can be set according to actual needs, and will not be described here.
[0055] In this embodiment, the revocation button can be provided within the third preset time length after the target control instruction is issued, and quick rollback is allowed. For example, in this embodiment, the third preset time length is 5s, and the target control instruction is to open the door. When the open-door instruction is issued to the target IoT device, the user can click the revocation button within 5s to revoke the target control instruction. The target IoT terminal can stop opening the door and execute the close-door instruction when the revocation instruction is received.
[0056] The above technical solution can revoke the execution of the target control instruction within the third preset time length after the target control instruction is issued. Thus, false operations can be further avoided.
[0057] For example, the method of determining whether the current user has access to the function configuration interface corresponding to the target function configuration information according to the user token includes: determining whether the current user has access according to the user token and the current time.
[0058] In this embodiment, different allowed access times can also be set for each user or each type of user. For example, students can be set to have access to the function configuration interface for controlling the access control of the dormitory door within 08:00-22:00. This combined time and user token confirmation manner can be more convenient for managing the access rights of different users, achieving more fine-grained permission control, and thus can adapt to more complex usage requirements.
[0059] According to the user token and the current time, it is determined whether the current user has access rights, including: judging whether the user information in the user token is in the tag access control list; when the user information is in the tag access control list, judging whether the current time is in the allowed time period; when the current time is in the allowed time period, determining whether the current user has access rights.
[0060] In the scheme of the present example, the allowed time period corresponding to each user information can also be recorded in the tag access control list. When it is determined that the user information is in the tag access control list, it can be further judged whether the current time is in the allowed time period. This scheme is simple to implement and can achieve more fine-grained permission management.
[0061] Exemplarily, after the target control terminal controlled by the target control instruction, the method further comprises: recording the execution time, execution result, user information in the user token, and target label number of the target control instruction.
[0062] In the scheme of the present example, the execution time, execution result, user information in the user token, and target label number of each execution can be recorded in the log table, which can facilitate the operation and maintenance personnel to search and trace according to the user or device dimension, thereby reducing the complexity of operation and maintenance operation.
[0063] In some embodiments, a structured response (error code, error information, tracking number) can also be generated for all exceptions, and the tracking number is written into the log to facilitate problem tracing.
[0064] The application is described in detail below through a specific embodiment. In this embodiment, the target IoT terminal is a smart campus access control. In this embodiment, a student Li touches the access control tag with his mobile phone NFC at the entrance of the experimental building; the system parses the tag number T-123 and automatically fills in app=DoorCtrl, arg=Room=A101, and uploads the user request information composed of these information and the user token. After receiving the user request information, the corresponding configuration can be found in TagDB according to the tag number T-123 in it, and it is determined that login is required and the TagApp is "access control". Since Li has logged in through the campus SSO, the browser is attached with a valid JWT token. Then, it is checked that the role of Li is "student", and TagACL allows students to access the door from 08:00 to 22:00, and it is determined to pass, and the script address of the access control TagApp and the device ID=A1 (laboratory access controller) are returned to the mobile phone. After the mobile phone is loaded, the "open door" button is presented. After Li clicks "open door", the page popup of the mobile phone counts down for five seconds for confirmation; after confirmation, the request gateway sends the control information (i.e. control information) after uploading. After receiving the control information, the DeviceACL is checked to confirm that Li has the "open door" permission for the device A1 in the current time period, and then the "open door" instruction is pushed to the device A1 through the WebSocket long connection; the device returns "Success" after execution. The cloud returns the success status to the front end (i.e. the mobile phone of the user), and the page prompts "the door has been opened", and records the audit log at the same time. If Li makes a mistake, he can click "revoke" within five seconds, and the cloud initiates the "close door" instruction to the device A1 and records it.
[0065] In this embodiment, the following system deployment can be used: API gateway, identity authentication service, tag service, ACL engine, reverse gateway and front-end container are arranged using Docker Compose. The images are pushed to the private warehouse through the CI / CD pipeline, and the test, pre-release and production environment are upgraded one key.
[0066] After testing, the average delay from scanning the tag to executing the device in the access control scenario is <1.2 seconds, and the 90th percentile is <1.8 seconds, which can meet the demand of instant control within seconds.
[0067] According to another aspect of the embodiment of the application, an electronic device is also provided. Figure 2 A schematic block diagram of an electronic device according to an embodiment of the application is shown. As Figure 2As shown, the electronic device 200 includes a processor 210 and a memory 220. The memory 220 stores a computer program, which the processor 210 executes to implement the method described above.
[0068] According to another aspect of the present invention, a computer-readable storage medium is also provided. The storage medium stores a computer program / instructions that, when executed by a processor, implement the method described above. The storage medium may, for example, include a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a portable compact disc read-only memory (CD-ROM), a USB memory, or any combination of the above storage media. The computer-readable storage medium may be any combination of one or more computer-readable storage media.
[0069] Those skilled in the art will readily understand the implementation structure, working principle, and beneficial effects of electronic devices and computer-readable storage media by reading the above methods. For the sake of brevity, further details will not be elaborated here.
[0070] Although exemplary embodiments have been described herein with reference to the accompanying drawings, it should be understood that the above exemplary embodiments are merely illustrative and are not intended to limit the scope of the invention. Various changes and modifications can be made therein by those skilled in the art without departing from the scope and spirit of the invention. All such changes and modifications are intended to be included within the scope of the invention as claimed in the appended claims.
[0071] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0072] In the several embodiments provided by this invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed.
[0073] Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of the invention may be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.
[0074] Similarly, it is to be understood that the embodiments of the present application can be alternately grouped together in a single embodiment, figure, or description of an embodiment for conciseness and to aid in the understanding of one or more of the various aspects of the present application. This method of grouping is not, however, to be interpreted as reflecting an intention that the claimed application requires more features than are explicitly recited in each of the claims. Rather, it is to be understood that the inventive aspect lies in the fact that a corresponding technical problem can be solved with less features than all of the features of a disclosed single embodiment. Thus, the claims following, fully intend to embrace each and every alternative of the application, as fairly, legally, equitably and otherwise encompassed by said claims. Each claim is hereby incorporated into the specification as an additional embodiment to the extent that the subject matter of the claim forms a potentially distinct embodiment and is not merely redundant in relation to the embodiments presented in the specification.
[0075] Those skilled in the art will appreciate that all features described herein (including all accompanying claims, abstract and drawings), and steps of any method or processes disclosed herein can be combined in any combination, except where features are mutually exclusive. Each feature disclosed in this specification (including any accompanying claims, abstract and drawings) can be replaced by alternative features serving the same, equivalent or a similar purpose, unless expressly stated otherwise.
[0076] Furthermore, those skilled in the art will recognize that references in the specification to "one embodiment", "an embodiment", "an example embodiment", mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. The appearances of the phrase "in one embodiment" in various places in the specification are not necessarily all referring to the same embodiment, nor are they necessarily referring to a single, "one embodiment".
[0077] Various component embodiments of the present application can be implemented in hardware, or as software modules running in one or more processors, or in combinations thereof. Those skilled in the art will appreciate that a microprocessor or digital signal processor (DSP) can be used in practice to implement some or all of the functions of some of the modules in the electronic devices according to embodiments of the present application. The present application can also be implemented as a program (e.g., computer program and computer program product) for executing any or all of the methods described herein on a computer. Such a program implementing the present application can be stored on a computer readable medium, or can be in the form of one or more signals. Such a signal can be downloaded from an Internet website, or provided on a carrier program, or in any other form.
[0078] It should be noted that the above-mentioned embodiments illustrate rather than limit the application, and that those skilled in the art will be able to design many alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word 'comprising' does not exclude the presence of elements or steps other than those listed in a claim. The word 'a' or 'an' preceding an element does not exclude the presence of a plurality of such elements. The application can be implemented by means of both hardware and software, and any combination thereof. In a unitary claim, several devices or sub-claims can be joined by means of the expression 'and / or'. The use of the term 'at least' followed by a list of one or more items should be interpreted as including at least one of the items but it does not exclude the presence of others not specified in the list. The use of the term 'one' or 'the' in relation to an element or step of the application should not be construed as excluding the presence of additional such elements or steps nor should the use of the term 'first','second' and 'third' etc. mean that the elements so designated need to be in a given order and / or locations.
[0079] The above description is only specific embodiments or specific implementations of the present application, and the protection scope of the present application is not limited thereto. Any skilled person in the art can easily think of changes or replacements within the technical range disclosed by the present application, and all of them should be covered within the protection scope of the present application. The protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method of controlling an IoT terminal, characterized by, The method comprises the following steps: Upon receiving a user request information, determining target function configuration information corresponding to a target tag number in a tag configuration database, wherein the tag configuration database stores a plurality of tag numbers and function configuration information corresponding to the tag numbers one by one, the user request information is generated by a user equipment triggering a physical tag, the user request information comprises the target tag number of the physical tag and a user token, and the physical tag is a tag corresponding to a target IoT terminal; According to at least the user token, determining whether a current user has access permission to a function configuration interface corresponding to the target function configuration information; When the current user has the access permission, sending a script address of the function configuration interface to the user equipment, and the user equipment displays the function configuration interface upon receiving the script address; Upon receiving control information, determining whether the current user has control permission to execute a target control instruction according to the user token, the target control instruction being a control instruction corresponding to the control information, and the control information being generated by the user equipment in response to a triggering operation on a specific page element in the function configuration interface; When the current user has the control permission, issuing the target control instruction to the target IoT terminal to control the target IoT terminal to execute the target control instruction. 2.The method according to claim 1, wherein, Before the step of determining whether the current user has the access permission to the function configuration interface corresponding to the target function configuration information, the method further comprises: Determining whether the user token is valid; The step of determining whether the current user has the access permission to the function configuration interface corresponding to the target function configuration information is executed when the identity of the user token is valid. 3.The method according to claim 2, wherein, The step of determining whether the user token is valid comprises: Judging whether the identity of the user token is stored in an identity blacklist; When the identity of the user token is not stored in the identity blacklist, determining that the user token is valid. 4.The method of claim 1, wherein, After the user equipment generates the control information, the function configuration interface displays prompt information; the user equipment sends the control information when a waiting time length after generating the control information reaches a first preset time length and no cancellation instruction is received, or the user equipment generates and sends the control information after a triggering operation duration of the specific page element reaches a second preset time length. 5.The method of claim 1, wherein, Within a third preset time length after the target control instruction is issued to the target IoT terminal, the function configuration interface displays a revocation page element for revoking the control information; The user equipment generates a revocation instruction in response to a triggering operation on the revocation page element; the method further comprises: upon receiving the revocation instruction, controlling the target IoT terminal to perform an action opposite to the target control instruction. 6.The method of claim 1, wherein, The step of determining whether the current user has the access permission to the function configuration interface corresponding to the target function configuration information according to at least the user token comprises: According to the user token and a current time, determining whether the current user has the access permission. 7.The method of claim 6, wherein, The determining whether the current user has the access right according to the user token and the current time comprises: determining whether user information in the user token is in a tag access control list; when the user information is in the tag access control list, determining whether the current time is in an allowed time period; when the current time is in the allowed time period, determining whether the current user has the access right.
8. The method according to any one of claims 1 to 7, characterized in that, After the controlling the target IoT terminal to execute the target control instruction, the method further comprises: recording execution time of the target control instruction, execution result, user information in the user token, and the target tag number.
9. An electronic device, comprising: The device comprises a processor and a memory, and the memory stores a computer program, and the processor is configured to execute the computer program to implement the method according to any one of claims 1-8.
10. A computer-readable storage medium, characterized in that, The device stores a computer program / instruction, and the computer program / instruction is executed by the processor to implement the method according to any one of claims 1-8.