Authority management method and device, electronic equipment and readable storage medium

By monitoring and adjusting the functional permission status of third-party cloud platforms, and dynamically managing user permissions, the problem of dynamic permission management for third-party cloud platforms controlling device functions is solved, thereby improving the efficiency and security of permission management.

CN121098539APending Publication Date: 2025-12-09GREE ELECTRIC APPLIANCE INC OF ZHUHAI +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511117177.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-11
Publication Date
2025-12-09

AI Technical Summary

Technical Problem

Existing technologies cannot effectively manage the dynamic permissions of devices controlled by third-party cloud platforms, resulting in control failures and low efficiency in permission management.

Method used

By monitoring the functional permission status of the target third-party cloud platform, permissions are dynamically adjusted, including determining the execution success rate and the number of response commands, establishing connections to control smart devices, and determining permission levels based on user accounts, thus integrating the permission management of multiple third-party cloud platforms.

Benefits of technology

It enables dynamic permission management of device functions controlled by third-party cloud platforms, improving the efficiency and security of permission management and ensuring the privacy of user data and the stability of devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098539A_ABST
    Figure CN121098539A_ABST
Patent Text Reader

Abstract

The invention discloses an authority management method and device, electronic equipment and a readable storage medium, and the method is applied to the technical field of smart home. Determining a first function permission of a current third-party cloud platform corresponding to the third-party application software and a second function permission of the current third-party cloud platform; the first function permission is in an open state; the second function authority is in a closed state; monitoring a third function permission, corresponding to the second function permission, of the target third-party cloud platform; the second function is the same as the third function; and establishing connection with the target third-party cloud platform under the condition that the third function permission of the target third-party cloud platform is in the open state, so as to control the second function of the intelligent equipment through the target third-party cloud platform. According to the invention, dynamic authority management can be carried out on the equipment function controlled by the third-party cloud platform, and the authority management efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of smart home technology, specifically relating to a permission management method, device, electronic device, and readable storage medium. Background Technology

[0002] By allocating, controlling, supervising, and adjusting various permissions such as access rights, operation rights, and data viewing rights for smart furniture devices, it is possible to ensure that smart furniture devices are used legally, safely, and orderly, and to prevent problems such as privacy leaks, device malfunctions, and security risks caused by unauthorized access or misoperation.

[0003] Most current IoT devices support control via different cloud platforms. For example, Mijia supports control of devices from manufacturers such as AUX and Midea.

[0004] However, when using large units, due to the different naming rules, protocol rules and device permissions of various third-party platforms, various control failures and reporting failures may occur, making it impossible to achieve dynamic permission management of device functions controlled by third-party cloud platforms, thereby reducing the efficiency of permission management. Summary of the Invention

[0005] The purpose of this application is to provide a permission management method, device, electronic device, and readable storage medium, which can solve the problem in related technologies that it is impossible to dynamically manage the permissions of devices controlled by third-party cloud platforms.

[0006] In a first aspect, embodiments of this application provide a permission management method, the method comprising:

[0007] When controlling a smart device through a third-party application, the first functional permission and the second functional permission of the current third-party cloud platform corresponding to the third-party application are determined; the first functional permission is in an enabled state; the second functional permission is in a disabled state.

[0008] The system monitors the target third-party cloud platform and the third function permission corresponding to the second function permission; the target third-party cloud platform is a third-party cloud platform other than the current third-party cloud platform; the second function and the third function are the same function.

[0009] When the third function permission of the target third-party cloud platform is enabled, a connection is established with the target third-party cloud platform to control the second function of the smart device through the target third-party cloud platform.

[0010] Optionally, the third functional permission corresponding to the second functional permission of the third-party cloud platform monitoring the target includes:

[0011] Obtain the execution status of the target third-party cloud platform corresponding to the third function corresponding to the second function permission;

[0012] The third function permission is determined based on the execution status.

[0013] Optionally, determining the third function permission based on the execution state includes:

[0014] Based on the execution status, determine the execution success rate within the preset period;

[0015] If the execution success rate is greater than or equal to a preset threshold, the third function permission of the target third-party cloud platform is determined to be enabled.

[0016] If the execution success rate is less than the preset threshold, the third function permission of the target third-party cloud platform is determined to be closed.

[0017] Optionally, after determining that the third-party function permission of the target third-party cloud platform is closed when the execution success rate is less than the preset threshold, the method further includes:

[0018] The number of response commands from the target third-party cloud platform is determined by activating the command traffic corresponding to the third function.

[0019] If the number of response commands is greater than or equal to a preset value, the third function permission is enabled.

[0020] If the number of response commands is less than a preset value, the third function permission remains in the off state.

[0021] Optionally, after determining that the third-party function permission of the target third-party cloud platform is disabled, the method further includes:

[0022] Receive a list of third functions whose third function permissions are disabled; the list of third functions includes device function identifiers;

[0023] The object model corresponding to the target third-party cloud platform is updated based on the third function list, and the smart device is controlled based on the object model.

[0024] Optionally, before controlling the smart device via a third-party application, the method further includes:

[0025] User permissions are determined based on user accounts; these permissions include super administrator permissions, administrator permissions, and regular user permissions; super administrator permissions are greater than administrator permissions; and administrator permissions are greater than regular user permissions.

[0026] Optionally, the method further includes:

[0027] In the event of a permission conflict with the third-party cloud platform, determine the permission order of the third-party cloud platform;

[0028] The smart device is controlled according to the permission sequence.

[0029] Optionally, determining the permission order of the third-party cloud platform includes:

[0030] Determine the first priority order of the vendor's cloud platform permissions and the third-party cloud platform permissions; the vendor's cloud platform permissions are greater than the third-party cloud platform permissions; or...

[0031] Determine the authorization time for multiple third-party cloud platforms;

[0032] The second permission order is determined based on the authorization time.

[0033] The permission order of the third-party cloud platform is determined based on either the first permission sorting or the second permission sorting.

[0034] Secondly, embodiments of the present invention disclose an access control device, the device comprising:

[0035] The determination module is used to determine the first functional permission and the second functional permission of the current third-party cloud platform corresponding to the third-party application software when controlling the smart device through the third-party application software; the first functional permission is in an enabled state; and the second functional permission is in a disabled state.

[0036] The monitoring module is used to monitor the target third-party cloud platform and the third function permission corresponding to the second function permission; the target third-party cloud platform is a third-party cloud platform other than the current third-party cloud platform; the second function and the third function are the same function;

[0037] The connection module is used to establish a connection with the target third-party cloud platform when the third function permission of the target third-party cloud platform is enabled, so as to control the second function of the smart device through the target third-party cloud platform.

[0038] Optionally, the monitoring module includes:

[0039] The acquisition module is used to acquire the execution status of the target third-party cloud platform and the third function corresponding to the second function permission;

[0040] The determination submodule is used to determine the third function permission based on the execution status.

[0041] Optionally, the determining submodule includes:

[0042] The first determining submodule is used to determine the execution success rate within a preset period based on the execution status; if the execution success rate is greater than or equal to a preset threshold, determine that the third function permission of the target third-party cloud platform is enabled; if the execution success rate is less than the preset threshold, determine that the third function permission of the target third-party cloud platform is disabled.

[0043] Optionally, the first determining submodule includes:

[0044] The first sub-determination sub-module is used to enable the instruction traffic corresponding to the third function and determine the number of response instructions from the target third-party cloud platform;

[0045] The enabling module is used to enable the third function permission when the number of response commands is greater than or equal to a preset value.

[0046] The module is used to keep the third function permission in a closed state when the number of response commands is less than a preset value.

[0047] Optionally, the device further includes:

[0048] The receiving module is configured to receive a list of third functions whose third function permissions are disabled; the list of third functions includes device function identifiers;

[0049] The update module is used to update the object model corresponding to the target third-party cloud platform based on the third function list, and to control the smart device based on the object model.

[0050] Optionally, the device further includes:

[0051] The second determination submodule is used to determine user permissions based on the user account; the user permissions include super administrator permissions, administrator permissions, and ordinary user permissions; the super administrator permissions are greater than the administrator permissions; the administrator permissions are greater than the ordinary user permissions.

[0052] Optionally, the device further includes:

[0053] The third determination submodule is used to determine the permission order of the third-party cloud platform in the event of a permission conflict with the third-party cloud platform.

[0054] The control module is used to control the smart device according to the permission sequence.

[0055] Optionally, the third determining submodule includes:

[0056] The third sub-determination module is used to determine a first permission order between the manufacturer's cloud platform permissions and the third-party cloud platform permissions; wherein the manufacturer's cloud platform permissions are greater than the third-party cloud platform permissions; or, determine the authorization time of multiple third-party cloud platforms; determine a second permission order based on the authorization time; and determine the permission order of the third-party cloud platforms based on the first permission order or the second permission order.

[0057] Thirdly, embodiments of the present invention also disclose an electronic device, which includes a processor, a memory, a communication interface, and a communication bus. The processor, the memory, and the communication interface communicate with each other through the communication bus. The memory is used to store executable instructions, which cause the processor to execute the aforementioned permission management method.

[0058] Fourthly, embodiments of the present invention also disclose a readable storage medium, which, when the instructions in the readable storage medium are executed by the processor of an electronic device, enables the electronic device to execute the aforementioned permission management method.

[0059] This application provides a permission management method, comprising: when controlling a smart device through a third-party application, determining the first functional permission and the second functional permission of the current third-party cloud platform corresponding to the third-party application; the first functional permission is enabled; the second functional permission is disabled; monitoring the third functional permission of the target third-party cloud platform corresponding to the second functional permission; the target third-party cloud platform is another third-party cloud platform besides the current third-party cloud platform; the second and third functions are the same function; when the third functional permission of the target third-party cloud platform is enabled, establishing a connection with the target third-party cloud platform to control the second function of the smart device through the target third-party cloud platform. This application can achieve dynamic permission management of device functions controlled by third-party cloud platforms by merging the permissions of multiple third-party cloud platforms; it supports dynamic permission adjustment of users, devices, and functions, thereby improving the efficiency of permission management. Attached Figure Description

[0060] Figure 1 This is a flowchart illustrating the steps of a permission management method provided in an embodiment of this application;

[0061] Figure 2 This is a schematic diagram of permission management provided in an embodiment of this application;

[0062] Figure 3 This is a schematic diagram illustrating a dynamic adjustment of function permissions provided in an embodiment of this application;

[0063] Figure 4This is a schematic diagram illustrating a permission check provided in an embodiment of this application;

[0064] Figure 5 This is a logical block diagram of a permission management device provided in an embodiment of this application;

[0065] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0066] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. All other embodiments obtained by those skilled in the art based on the embodiments of this application are within the scope of protection of this application.

[0067] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0068] Method Implementation Examples

[0069] The permission management method provided in this application will be described in detail below with reference to the accompanying drawings, through specific embodiments and application scenarios.

[0070] Reference Figure 1 The diagram illustrates a flowchart of the steps of a permission management method provided in an embodiment of this application, such as... Figure 1 As shown, the method specifically includes steps S101 and S103:

[0071] Step S101: When controlling a smart device through a third-party application, determine the first functional permission and the second functional permission of the current third-party cloud platform corresponding to the third-party application; the first functional permission is enabled; the second functional permission is disabled.

[0072] Step S102: Monitor the target third-party cloud platform and the third function permission corresponding to the second function permission; the target third-party cloud platform is a third-party cloud platform other than the current third-party cloud platform; the second function and the third function are the same function;

[0073] Step S103: With the third function permission of the target third-party cloud platform enabled, establish a connection with the target third-party cloud platform to control the second function of the smart device through the target third-party cloud platform.

[0074] When controlling smart devices through third-party applications, the first functional permission and the second functional permission of the current third-party cloud platform corresponding to the third-party application are determined; the first functional permission is enabled; and the second functional permission is disabled.

[0075] For example, when attempting to perform a specific operation through a third-party application, the system first verifies whether the software has obtained the necessary authorization. As a bridge between the user and the smart device, the enabling or disabling of the third-party application's functions is directly related to the user's permission settings on the current third-party cloud platform. If the third-party application has the corresponding first function permission enabled, it means the user has authorized the software to perform operations related to the first function; conversely, if the second function permission is disabled, it indicates that the user has not authorized the software to perform operations related to the second function. This permission management mechanism aims to protect user privacy and data security, preventing unauthorized software from accessing or controlling smart devices.

[0076] Smart devices refer to devices that can connect to the internet, interact with third-party applications via specific communication protocols, and perform corresponding operations based on instructions sent by these applications. These devices include, but are not limited to, smart home devices (such as smart light bulbs, smart sockets, smart cameras, and smart door locks), smart wearable devices (such as smartwatches and smart bracelets), and smart home appliances (such as smart TVs, smart refrigerators, and smart washing machines). Smart devices establish connections with third-party cloud platforms through built-in communication modules, allowing users to remotely control and manage these devices through third-party applications, thereby achieving a smart and convenient lifestyle experience.

[0077] A third-party cloud platform refers to an intermediary service platform independent of smart devices and third-party applications. This platform acts as a bridge between smart devices and third-party applications, receiving operation instructions from the applications and forwarding them to the smart devices for execution via specific communication protocols. Simultaneously, the third-party cloud platform also bears the crucial responsibility of managing and verifying user permissions, ensuring that only authorized applications can access and control smart devices. By introducing a third-party cloud platform, not only is the security and reliability of smart devices improved, but users are also provided with a more flexible and convenient smart living experience.

[0078] The first functional permission refers to the user's operational permissions for smart devices. This permission allows users to perform basic operations and controls on smart devices through third-party applications, such as turning the device on and off, adjusting settings, and checking its status. This is the foundational permission for intelligent control of smart home devices, smart wearables, and smart appliances, ensuring that users can easily manage and use these devices.

[0079] The second functional permission refers to the permission to access and analyze data from smart devices. This permission allows authorized applications to obtain operational data from smart devices and perform further analysis and processing. For example, health monitoring applications can obtain data such as heart rate and step count from smart bracelets to provide users with health advice; smart home applications can collect energy consumption data from smart devices in the home to help users optimize energy use.

[0080] For example, when the second function permission is disabled, the smart device's data will not be accessed or analyzed by any third-party applications, thus protecting user privacy and data security and ensuring that the smart device's data will only be accessed with the user's explicit authorization. When users do not want third-party applications to access their smart device's operational data, they can set the second function permission to disabled, thereby effectively preventing data leakage and abuse. At the same time, this also provides users with more flexible and controllable permission management options, allowing them to freely adjust access permissions to smart devices according to their needs and preferences.

[0081] For example, the "enabled" state refers to the state where the first functional permission is activated. In this state, the smart device allows authorized application software to access its operational data and perform corresponding analysis and processing.

[0082] The "Off" state refers to the state where secondary function permissions are not activated. In this state, the smart device will strictly restrict access requests from any third-party applications, ensuring that user privacy and data security are not violated. Unless the user actively enables secondary function permissions, the smart device's data will not be accessed or analyzed by any unauthorized applications. This "Off" state provides users with a safe and private smart device usage environment, effectively avoiding the risks of data leakage and misuse.

[0083] Monitor the target third-party cloud platform and the third function permission corresponding to the second function permission; the target third-party cloud platform is a third-party cloud platform other than the current third-party cloud platform; the second function and the third function are the same function.

[0084] The monitoring of third-party function permissions aims to ensure that the flow of user data between different third-party cloud platforms is strictly controlled. When a target third-party cloud platform requests access to a specific function of a smart device, the system first checks whether the cloud platform has been authorized with third-party function permissions. If the target cloud platform has not obtained the corresponding authorization, the smart device will reject its access request.

[0085] The target third-party cloud platform is any cloud platform other than the current one. To ensure user data security, the system will monitor access requests from the target third-party cloud platform in real time and respond according to preset permission policies. If the target third-party cloud platform does not obtain the corresponding access permissions, the system will automatically block its access path to prevent data leakage or unauthorized use.

[0086] For example, for the current third-party cloud platform, its corresponding first function includes function A - switch, function B - fan speed, and function C - temperature. The second function includes function D - up and down swing. The third function corresponding to function D is found in the target third-party cloud platform. In the application (APP) corresponding to the current third-party cloud platform, if function D needs to be controlled by voice or command, it is possible to monitor whether the target third-party cloud platform has granted permission for function D. If permission for function D is granted, the permissions of the two third-party cloud platforms can be merged, and then control can be achieved by issuing commands.

[0087] With the third-party cloud platform's third-party function permission enabled, a connection is established with the target third-party cloud platform to control the second function of the smart device through the target third-party cloud platform.

[0088] Specifically, with the target third-party cloud platform's third-party function permissions enabled, a connection is established with the platform. Then, based on a pre-defined mapping, user control commands issued to the target third-party cloud platform are converted into a command format recognizable by the smart device. This conversion process ensures command compatibility across different platforms, enabling users to control smart devices through the target third-party cloud platform. Simultaneously, the system monitors the connection status and command execution results in real time. If a connection interruption or command execution failure is detected, an exception handling procedure is immediately triggered to ensure the stability and reliability of user operations.

[0089] For example, on a target third-party cloud platform with an established connection, the system receives user control commands for the secondary functions of the smart device. These commands may originate from user actions on the corresponding app interface of the target third-party cloud platform, such as clicking buttons or adjusting sliders, or they may be commands input through a smart device such as a voice assistant. Upon receiving these commands, the system first verifies the legality of the commands and the user's permissions, ensuring that only users with the appropriate permissions can control the smart device.

[0090] In embodiments of this invention, by integrating the permissions of multiple third-party cloud platforms, dynamic permission management of device functions controlled by these platforms is achieved. This dynamic permission management mechanism can flexibly respond to changes in user needs for smart device functions in different scenarios. Specifically, the system dynamically adjusts the user's permission scope on each third-party cloud platform based on the user's identity, role, and preset policies. For example, home users may only need to be granted basic permissions to control smart home devices, such as turning lights on and off and adjusting air conditioning temperatures; while professional administrators may need to be granted higher-level permissions to remotely configure and troubleshoot smart devices. This permission integration and dynamic management not only improves the convenience and flexibility of user operations but also effectively ensures the security and stability of smart devices.

[0091] In an optional embodiment of the present invention, the third functional permission corresponding to the second functional permission of the monitoring target third-party cloud platform may specifically include the following steps:

[0092] Step S1021: Obtain the execution status of the target third-party cloud platform and the third function corresponding to the second function permission;

[0093] Step S1022: Determine the third function permission based on the execution status.

[0094] Obtain the execution status of the target third-party cloud platform and the third function corresponding to the second function permission.

[0095] The execution status of the third function corresponding to the second function permission can be obtained by monitoring relevant interfaces or log information of the target third-party cloud platform. This execution status reflects the actual operation of the third function on the target third-party cloud platform. For example, if the third function is a data reading function, the execution status can include parameters such as the success rate of data reading and the reading speed. Based on the different execution statuses, it can be further determined whether the third function permission is abnormal or needs to be adjusted.

[0096] Determine the third function permission based on the execution status.

[0097] For example, if the execution status shows that the third function is operating normally, the third function permission can be considered valid; if the execution status is abnormal, such as a high data read failure rate, the third function permission may need to be reviewed or adjusted. Implementing this step helps ensure that the function permissions on the third-party cloud platform match the actual application needs, improving the accuracy and flexibility of permission management.

[0098] In embodiments of the present invention, in commercial environments, different roles often require different functionalities, and depending on the privacy agreement, manufacturers may grant different permissions to different third parties. Specifically, manufacturers can grant different functional permissions to different third parties according to the specific terms of the privacy agreement, thereby ensuring data security and compliance. In this way, permission management in commercial environments becomes more flexible, efficient, and secure.

[0099] In an optional embodiment of the present invention, determining the third functional permission based on the execution state may specifically include the following steps:

[0100] Step S10221: Determine the execution success rate within a preset period based on the execution status;

[0101] Step S10222: If the execution success rate is greater than or equal to a preset threshold, determine that the third-party function permission of the target third-party cloud platform is enabled;

[0102] Step S10223: If the execution success rate is less than a preset threshold, determine that the third-party function permission of the target third-party cloud platform is closed.

[0103] Determine the execution success rate within a preset period based on the execution status.

[0104] The preset period refers to a fixed time range set during the execution status assessment. Within this time range, the execution status of the wireless module or third-party cloud platform is recorded and analyzed, including key indicators such as task completion and resource utilization efficiency. The setting of the preset period must consider the actual operating conditions and needs of the system to ensure the accuracy and effectiveness of the assessment results. By setting a reasonable preset period, the system can more accurately reflect the actual operating status of the wireless module or third-party cloud platform, providing strong support for subsequent access control.

[0105] For example, the execution success rate is a crucial indicator of the success rate of a wireless module or third-party cloud platform in executing a specific task or function within a preset period. It reflects the stability and reliability of the system and serves as an important basis for access control decisions. The execution success rate is calculated by determining the proportion of successfully executed tasks to the total number of tasks within the preset period. A higher success rate indicates more stable system performance and higher task completion quality. In managing the execution success rate, a preset threshold is set. When the actual execution success rate is greater than or equal to this threshold, the third-party cloud platform's access permissions are considered to remain enabled to fully utilize its functionality. Conversely, when the actual execution success rate is lower than this threshold, the third-party cloud platform's access permissions are disabled to ensure overall system performance and security. This dynamic management approach ensures both system flexibility and the rationality and security of access control usage.

[0106] If the success rate is greater than or equal to the preset threshold, the third-party cloud platform's third-party function permissions are enabled.

[0107] The preset thresholds are set based on historical data analysis and system performance evaluation. These thresholds reflect the expected task execution success rate under normal operating conditions. To ensure the rationality and effectiveness of the preset thresholds, the system is periodically updated and optimized to adapt to constantly changing operating environments and task requirements. Furthermore, the preset threshold settings also consider the system's fault tolerance and redundancy design to ensure that the system maintains a certain level of stability and reliability when facing unexpected situations or abnormal tasks.

[0108] For example, in the success rate management process, the specific time, reason, and success rate data before and after each permission adjustment can be recorded. This data is stored in a dedicated log file for administrators to query and analyze later. Through in-depth analysis of historical data, administrators can understand the system's operating status, identify potential problems, and adjust and optimize preset thresholds accordingly. Furthermore, a visualization interface is provided to display the trend of success rate changes in charts, allowing administrators to more intuitively understand the system's performance.

[0109] If the success rate is less than a preset threshold, the third-party cloud platform's third-party function permissions will be disabled.

[0110] For example, to ensure the accuracy and efficiency of access control, when the actual execution success rate is detected to be lower than a preset threshold, the system will immediately trigger an early warning mechanism, send a notification to the administrator, and automatically begin disabling the third-party function permissions of the target third-party cloud platform. This process is automated, designed to minimize human intervention and improve response speed and accuracy. Simultaneously, to ensure the thoroughness and security of permission disabling, the system will also perform a series of verification and confirmation steps after executing the permission disabling operation to ensure that the permissions have been correctly disabled, preventing the risk of permission leakage or abuse due to operational errors or system anomalies.

[0111] In an embodiment of the present invention, upon obtaining a device's functional permission with a probability of successful execution, the status of the target third-party cloud platform's third functional permission is determined based on the success rate (execution success rate) and a preset threshold. Specifically, this permission management method first calculates the success rate (execution success rate) by monitoring and analyzing the device's functional execution data. Subsequently, the system compares the calculated success rate with a preset threshold. If the success rate is higher than or equal to the preset threshold, the system determines that the target third-party cloud platform's third functional permission should remain enabled to maintain normal system functionality and performance. Conversely, if the success rate is lower than the preset threshold, the system automatically adjusts the target third-party cloud platform's third functional permission to disabled based on preset rules and logic to avoid potential performance degradation or security risks. This dynamic adjustment mechanism ensures the flexibility and adaptability of the system's permission management, enabling intelligent decision-making based on different scenarios and needs.

[0112] In an optional embodiment of the present invention, after determining that the third-party function permission of the target third-party cloud platform is closed when the execution success rate is less than a preset threshold, the specific steps may include the following:

[0113] Step S10224: Enable the command traffic corresponding to the third function and determine the number of response commands from the target third-party cloud platform;

[0114] Step S10225: If the number of response commands is greater than or equal to a preset value, enable the third function permission;

[0115] Step S10226: If the number of response commands is less than a preset value, keep the third function permission in the closed state.

[0116] Enable the command traffic corresponding to the third function to determine the number of response commands from the target third-party cloud platform.

[0117] For example, network data traffic generated by commands sent to a third-party function of a target third-party cloud platform during permission management operations. By monitoring this command traffic and analyzing the target third-party cloud platform's response to the corresponding commands, it is possible to further determine whether the third-party function permission should be enabled or kept disabled. This mechanism helps improve the flexibility and accuracy of permission management, ensuring that the permission management of the third-party cloud platform can be effectively executed in complex network environments.

[0118] The number of response commands from the target third-party cloud platform can be used as a key criterion for determining whether third-party function permissions are enabled. A preset threshold value can be used, determined based on factors such as the actual application scenario, security requirements, and the performance of the third-party cloud platform. When the number of response commands reaches or exceeds this threshold, it can be determined that the target third-party cloud platform's request for third-party functions is valid, and therefore, third-party function permissions are automatically enabled. Conversely, if the number of response commands is below the threshold, it may indicate that the target third-party cloud platform's current state is not suitable for enabling third-party functions, or that there are potential security risks; therefore, third-party function permissions can be kept disabled. This dynamic permission management mechanism based on the number of response commands can flexibly adjust permission status according to actual conditions, improving system security and stability.

[0119] If the number of response commands is greater than or equal to a preset value, enable the third function permission.

[0120] For example, in some application scenarios, the preset value might be set to 100. This means that only when the number of response commands issued by the third-party cloud platform reaches or exceeds 100 will the system consider the third-party cloud platform's request for third-party functions valid and automatically enable the third-party function permissions accordingly. In other scenarios, the preset value might be a range, such as between 50 and 150. As long as the number of response commands falls within this range, the system will also consider the request valid and enable permissions. The setting of the preset value needs to comprehensively consider factors such as actual application needs, security, and the performance of the third-party cloud platform to ensure the accuracy and flexibility of permission management.

[0121] For example, if the preset value is 100 and the number of response commands issued by the third-party cloud platform is 150, then the request from the third-party cloud platform for the third-party function is considered valid, and the third-party function permission is automatically enabled. Alternatively, if the preset value is between 50 and 150 and the number of response commands is 139, then the request can be considered valid and the permission can be enabled.

[0122] If the number of response commands is less than the preset value, keep the third function permission in the off state.

[0123] Specifically, if the number of response commands is less than a preset value, the third-party function permission will remain disabled.

[0124] For example, if the preset value is 100 and the number of response commands issued by the third-party cloud platform is 50, then the request from the third-party cloud platform for the third-party function is considered invalid, and the third-party function permission is automatically kept closed. Alternatively, if the preset value is between 50 and 150 and the number of response commands is 39, then the request can be considered invalid and the third-party function permission can be kept closed.

[0125] For example, the system also records the request history of the third-party cloud platform, including request time, request content, and the number of response commands, for subsequent data analysis, auditing, or anomaly detection. This design not only enhances the rigor of access control but also improves the system's security and traceability.

[0126] In an embodiment of the present invention, when the success rate is less than a preset threshold, after determining that the third-party function permission of the target third-party cloud platform is closed, the traffic of this function is opened every X time intervals to check whether the service already supports the third-party platform. This achieves cross-validation of permission management. The X time intervals can be a preset time interval, such as hourly, daily, or weekly, and the specific time interval can be set according to actual needs. By opening the traffic of this function every X time intervals, the system can automatically detect whether the service already supports the target third-party cloud platform, thereby achieving cross-validation of permission management. If the service already supports the third-party cloud platform, the system can automatically enable the third-party function permission so that the third-party cloud platform can use the function normally. If the service still does not support the third-party cloud platform, the system will continue to keep the third-party function permission closed until the service supports the third-party cloud platform. This design not only improves the flexibility and automation of permission management but also helps to promptly identify and resolve potential problems, ensuring the stability and security of the system.

[0127] In an optional embodiment of the present invention, after determining that the third-party function permission of the target third-party cloud platform is closed, the step may specifically include the following steps:

[0128] Step S10227: Receive a list of third functions whose third function permissions are disabled; the list of third functions includes device function identifiers;

[0129] Step S10228: Update the object model corresponding to the target third-party cloud platform based on the third function list, and control the smart device based on the object model.

[0130] Receive a list of third functions whose third function permissions are disabled; the list of third functions includes device function identifiers.

[0131] The third-party function list refers to key information that identifies specific device functions that are disabled on the target third-party cloud platform. This list details the device function identifiers corresponding to all disabled third-party functions; these identifiers are unique and accurately point to specific functions on the smart device. By parsing the third-party function list, the system can precisely understand which functions are disabled, thus making corresponding adjustments when updating the object model. This process ensures that the control permissions of the smart device remain synchronized with the actual permission status of the target third-party cloud platform, effectively avoiding operational errors or security risks caused by permission mismatches.

[0132] A device function identifier refers to a unique code identifying each specific function on a smart device. In the management and control system of smart devices, every function—whether it's turning a light on / off, adjusting the temperature, or any other operation—is assigned a unique device function identifier. This identifier acts like a "ID number" for the function, ensuring that the system can accurately identify and operate the corresponding function. When a device function identifier appears in the third-party function list, it means that the function is set to a disabled state on the target third-party cloud platform. By comparing device function identifiers, the system can quickly locate and disable the corresponding function on the smart device, thereby achieving precise control and management of the smart device's functions.

[0133] The system updates the object model corresponding to the target third-party cloud platform based on the third function list, and controls the smart devices based on the object model.

[0134] In this context, the object model corresponding to the target third-party cloud platform refers to an abstract description of the functions and attributes of smart devices, defining the manifestation and control methods of smart devices on the cloud platform. On the target third-party cloud platform, each smart device has a corresponding object model. This object model records in detail all the functions, attributes, and states of the smart device, serving as the foundation for the cloud platform's management and control of the smart device.

[0135] When the list of third-party functions changes, the system updates the object model on the target third-party cloud platform based on the latest list information. This process includes adding new functions to the object model or removing functions that have been set to be disabled. By updating the object model, the cloud platform can reflect the latest functional status of smart devices in real time, ensuring that the control and management of smart devices are always consistent with the actual situation.

[0136] For example, in the process of controlling smart devices based on object models, the system first parses the third-party function list to determine the current function set of the smart device. Then, based on this function set, the system finds the corresponding object model on the target third-party cloud platform and updates it. The update operation may include modifying attribute definitions in the object model, adjusting function descriptions, or updating status information. Once the object model is successfully updated, the cloud platform can execute corresponding control commands to the smart device based on the new object model. For example, if the smart device adds a brightness adjustment function, the cloud platform can send a brightness adjustment command to the smart device through the updated object model to achieve remote control. This object model-based control method not only improves the flexibility of smart device management but also ensures the communication efficiency and accuracy between the cloud platform and the smart device.

[0137] In embodiments of this invention, if the probability of a function's execution remains 0 for an extended period after a service update, it indicates that the manufacturer has disabled permissions for certain users to access that function's commands. In this case, a blacklist can be returned to the third-party cloud-connected object model. Upon receiving this blacklist, the third-party cloud platform can automatically remove these disabled functions from the list of available functions for users. This way, when users attempt to use these disabled functions, the system will immediately report that the function is unavailable, preventing users from performing ineffective operations. Simultaneously, the system can record this change information, providing data support for future function restoration or permission re-enabling. This approach not only improves the user experience but also ensures the real-time performance and accuracy of smart device functions, effectively maintaining the stability and reliability of smart device management.

[0138] In one optional embodiment of the present invention, the step of controlling the smart device through third-party application software may specifically include the following steps:

[0139] Step S105: Determine user permissions based on user account; user permissions include super administrator permissions, administrator permissions, and ordinary user permissions; super administrator permissions are greater than administrator permissions; administrator permissions are greater than ordinary user permissions.

[0140] In this context, a user account refers to the account information created when a user registers and logs in to a third-party cloud platform. This account information not only identifies the user but also determines their operational permissions on the cloud platform. For example, a super administrator account can perform advanced management operations, including but not limited to adding, deleting, and modifying device configurations; an administrator account may have management permissions for specific devices or functions; while a regular user account may only have permissions to view device status or perform limited control operations. By clearly defining user accounts and their corresponding permissions, the cloud platform can achieve granular management of smart devices, ensuring that only authorized users can perform the corresponding operations.

[0141] User permissions refer to the level and scope of a user's operations on a third-party cloud platform. These permissions are assigned based on user accounts and are designed to ensure that different users can access and control the corresponding smart device functions according to their roles and needs.

[0142] Super administrator privileges, as the highest level of user privileges, grant users comprehensive management and control over the entire third-party cloud platform. Users with this privilege can not only perform advanced management operations such as adding, deleting, and modifying device configurations, but also access all functional areas and data of the cloud platform for in-depth analysis and decision-making. Furthermore, super administrators have the authority to create, modify, and delete other user accounts and assign them appropriate permission levels, thereby ensuring the security and efficient operation of the cloud platform.

[0143] Administrator privileges are the second most important user level after super administrator privileges. Users with administrator privileges are typically responsible for managing a specific area or function of the cloud platform. They can perform most device management operations, such as adding devices, modifying configurations, and monitoring status, but they cannot access all functional areas and data of the cloud platform, nor can they create, modify, or delete other user accounts. Administrator privileges are designed to balance users' control over devices with the security of the cloud platform, ensuring its efficient operation under orderly management. Administrators must also regularly report cloud platform usage and potential security vulnerabilities to the super administrator so that the super administrator can make timely adjustments and decisions.

[0144] Ordinary user permissions represent the most basic permission level on the cloud platform. Users with this permission typically can only access certain functional areas and data of the cloud platform, performing basic device queries and operations. They cannot perform advanced device management operations, such as device deletion, configuration modification, or status monitoring, nor can they access the core functional areas and sensitive data of the cloud platform. Furthermore, ordinary users do not have the right to create, modify, or delete other user accounts, nor can they assign permissions to other users. The purpose of setting ordinary user permissions is to ensure the basic usage needs of the cloud platform while ensuring its security and data privacy. By restricting the scope of ordinary user operations, the cloud platform can effectively prevent unauthorized access and data leaks, thereby maintaining the stable operation of the entire platform.

[0145] In embodiments of this invention, users are automatically categorized into roles based on their network configuration accounts: Super Administrator (with all permissions), Administrator (with group permissions), and Regular User (with personal permissions). Once a user completes device network configuration, they are assumed to have all permissions for that device. Super Administrators can manage the cloud platform comprehensively, including user management, device management, data management, and security policy formulation. Administrators are responsible for device management within specific groups, such as device allocation, status monitoring, and permission adjustments, but must adhere to the overall security policy set by the Super Administrator. When a user is categorized as a Regular User, their permissions are limited to the use and operation of their personal device and cannot affect other users or devices.

[0146] In an optional embodiment of the present invention, the permission management method may specifically include the following steps:

[0147] Step S107: In the event of a permission conflict with a third-party cloud platform, determine the permission order of the third-party cloud platform;

[0148] Step S108: Control the smart devices according to the permission order.

[0149] In the event of permission conflicts with a third-party cloud platform, determine the permission order of the third-party cloud platform.

[0150] When multiple cloud platforms request control of the same smart device, permission conflicts may occur. To resolve these conflicts, the system needs a mechanism to determine which cloud platform has higher privileges, thus deciding which platform should control the smart device. The process of determining permission conflicts may involve evaluating and comparing the privileges of each cloud platform to ensure that a reasonable decision can be made when a conflict occurs.

[0151] For example, in practical applications, the order of permissions for third-party cloud platforms may be determined based on various factors, including but not limited to the cloud platform's security, reliability, user trust, and the cooperative relationship between the vendor and the cloud platform. To ensure the secure operation of smart devices and the user experience, systems typically pre-define a set of permission ordering rules. In these rules, vendor cloud platforms are often granted higher permissions to protect the device's original functionality and data security. When a permission conflict arises between a third-party cloud platform and a vendor cloud platform, the system uses these pre-determined rules to determine which cloud platform's request should be executed first. This mechanism helps maintain the stable operation of smart devices in complex cloud environments while ensuring the security and privacy of user data.

[0152] Control smart devices according to the order of permissions.

[0153] For example, the system first identifies the cloud platforms currently connected to the smart device and determines the permission levels of each cloud platform according to preset permission sorting rules. Once a permission conflict is detected, a decision-making process is automatically executed. This process comprehensively considers multiple factors, such as the cloud platform's authorization time, security records, historical performance, and user feedback, to determine which cloud platform's instructions better align with the overall security policy and user experience requirements. Through this mechanism, the smart device can respond appropriately in complex cloud environments, ensuring normal device functionality while avoiding data leaks or device malfunctions caused by permission conflicts.

[0154] In embodiments of the present invention, in the event of a permission conflict, arbitration and multi-parameter weighted decision-making are used to determine the permission order, ensuring that smart devices can operate efficiently and securely in collaborative work across multiple cloud platforms. In this way, smart devices can automatically adjust their response strategies when facing complex cloud environments, prioritizing the execution of cloud platform instructions that both meet security standards and enhance user experience. This not only improves the intelligence level of the devices but also brings users a smoother and more secure smart living experience.

[0155] In an optional embodiment of the present invention, determining the permission order of the third-party cloud platform may specifically include the following steps:

[0156] Step S1071: Determine the priority order of the vendor's cloud platform permissions and the third-party cloud platform permissions; the vendor's cloud platform permissions are greater than the third-party cloud platform permissions; or,

[0157] Step S1072: Determine the authorization time for multiple third-party cloud platforms;

[0158] Step S1073: Determine the second permission order based on the authorization time;

[0159] Step S1074: Determine the permission order of the third-party cloud platform based on the first permission sorting or the second permission sorting.

[0160] Determine the priority order of vendor cloud platform permissions and third-party cloud platform permissions; vendor cloud platform permissions are greater than third-party cloud platform permissions.

[0161] As the original manufacturer of the equipment, the vendor's cloud platform has control over the device. This control includes, but is not limited to, initial device configuration, firmware updates, and access to critical data. The vendor's cloud platform's permissions are designed to ensure the secure operation and efficient maintenance of the device. In complex cloud environments, when multiple cloud platforms need to access and control the same device, the vendor's cloud platform's permissions should have higher priority than those of third-party cloud platforms. This is because the vendor's cloud platform better understands the device's needs and limitations, enabling it to make more reasonable and secure decisions. Furthermore, the vendor's cloud platform has the final right to interpret the device data, which helps provide authoritative judgment and solutions in the event of data disputes or security issues.

[0162] For example, third-party cloud platforms typically offer specific services or applications that may exceed the capabilities of the vendor's cloud platform. For instance, a third-party cloud platform might focus on data analytics, remote monitoring, or user interface optimization. By authorizing a third-party cloud platform to access device data, users can enjoy more diverse and customized services.

[0163] For example, the permissions of third-party cloud platforms can be flexibly adjusted according to actual needs. For instance, in some situations, users may need to temporarily elevate the permissions of a third-party cloud platform to quickly respond to urgent needs or conduct specific tests. In such cases, the vendor's cloud platform can temporarily adjust the permissions of the third-party cloud platform according to preset rules and procedures to meet the user's actual needs.

[0164] The primary authority order prioritizes the vendor's cloud platform over third-party cloud platforms. This order ensures the vendor's cloud platform maintains its dominant position in data security, device management, and final interpretation. As the original manufacturer or primary supplier of the equipment, the vendor's cloud platform has a deeper understanding and control over the device data. Therefore, when data disputes or security issues arise, the vendor's cloud platform can provide more authoritative judgments and solutions based on its expertise and experience. Simultaneously, this authority order helps protect user interests, preventing data leaks or device damage caused by third-party cloud platforms abusing their authority or misoperating their systems.

[0165] Determine the authorization time for multiple third-party cloud platforms.

[0166] For example, determining the authorization period for multiple third-party cloud platforms requires comprehensive consideration of several factors. First, the authorization period should align with the user's actual needs, ensuring that the third-party cloud platform can fully meet those needs within the authorization period. Simultaneously, to avoid risks arising from permission abuse or misoperation, the authorization period should not be excessively long; a reasonable validity period should be set based on specific circumstances. Furthermore, a regular review and update mechanism should be established to continuously track and evaluate the authorization status of third-party cloud platforms, ensuring that it consistently meets the user's expectations and interests. By comprehensively considering these factors, an authorization period strategy that both meets actual needs and possesses risk prevention capabilities can be developed.

[0167] The second permission order is determined based on the authorization time.

[0168] The second permission ranking should be set based on the authorization time. Specifically, newly authorized third-party cloud platforms can be granted relatively high permission levels to reflect trust in their long-term cooperation and stable services. For third-party cloud platforms authorized several months ago, their permissions should be appropriately restricted to reduce potential risks. This permission ranking mechanism not only helps maintain system security and stability but also incentivizes third-party cloud platforms to provide better services in order to earn longer authorization periods and higher permission levels.

[0169] The order of permissions for third-party cloud platforms is determined based on either the first or second permission order.

[0170] For example, in the event of a permission conflict between a manufacturer's cloud platform and a third-party cloud platform, since the manufacturer's cloud platform has greater permissions than the third-party cloud platform, the manufacturer's cloud platform controls the functions of the smart device first, and then the third-party cloud platform controls the functions of the smart device. In the event of a permission conflict between multiple third-party cloud platforms, the permission order of the multiple third-party cloud platforms is determined according to the authorization time of each third-party cloud platform.

[0171] In embodiments of this invention, if a vendor's cloud service exists, permissions are primarily granted based on the vendor's cloud service. Further decisions are made based on role weight, platform weight (vendor > third-party cloud), and the most recent authorization time (e.g., if Huawei and Xiaomi are authorized simultaneously, but Xiaomi is the most recently authorized, it has a higher weight). When multiple third-party cloud platforms coexist with a vendor's cloud platform, the system first identifies and assigns the highest permission level to the vendor's cloud platform. This is because vendor cloud platforms typically have a deeper understanding and control over smart devices, enabling them to provide more professional services. Subsequently, the system further subdivides permissions based on role weight and platform weight. Here, platform weight follows the principle of vendor priority over third-party cloud, ensuring the vendor's cloud platform's dominant position in permission allocation. When platform weights are comparable, the system refers to the most recent authorization time as the decision-making basis. For example, if Huawei and Xiaomi are authorized simultaneously, and Xiaomi is the most recently authorized cloud platform, the system will assign a relatively higher weight to Xiaomi's cloud platform. This mechanism aims to encourage third-party cloud platforms to gain more trust and higher permission levels by providing timely and efficient services.

[0172] In embodiments of the present invention, in a commercial environment, dynamic permission management is implemented for device functions controlled by a third-party cloud platform. Dynamic adjustment of permissions for users, devices, and functions is supported.

[0173] In a convenient commercial environment, it enables users to manage their access permissions to unit functions and matches corresponding device access permissions based on different user permissions and third-party cloud platform integration permissions. Compared with the traditional device access permission management method of IoT cloud integration, it increases the privacy of device use and the administrator's access management of third-party cloud platforms and devices used by users, and can make dynamic adjustments during use.

[0174] For example, device access permissions can be for a single function. Taking air conditioning equipment as an example, for some third-party clouds (such as Huawei Cloud), the manufacturer only opens up four basic functions: on / off, fan speed, mode, and temperature. For other third-party clouds (such as Xiaomi), more advanced functions such as sleep, health mode, and silent mode are opened up.

[0175] Specifically, it can dynamically adjust the permissions of users, third-party cloud platforms, and certain devices and functions based on different users, third-party cloud platform interfaces, different device control methods, and control execution results.

[0176] Reference Figure 2 This illustration shows a permission management diagram provided by an embodiment of this application, such as... Figure 2 As shown, this is used to describe the permission relationships between administrators, users, and devices.

[0177] Reference Figure 3This illustration shows a schematic diagram of a dynamic adjustment of function permissions provided in an embodiment of this application, such as... Figure 3 As shown, after the device is configured to the network, users can issue commands through a third-party cloud platform and check whether the third-party cloud platform has the necessary permissions based on the manufacturer's cloud integration service. If no permissions are granted, the process will return directly. At the same time, after the device is configured to the network, users have basic functional permissions for the device and can control the device according to the control commands. If control fails, permissions can be adjusted.

[0178] For example, the function command can be the user's voice command, such as: turn on the air conditioner; the command to be issued refers to the cloud-to-cloud connection protocol, such as: (taking Xiaomi's protocol as an example);

[0179] For example, code that dynamically adjusts function permissions may include the following:

[0180] / / Message Status

[0181] HTTP / 1.1 200 OK

[0182] Content-Type: application / json

[0183] Content-Length: 167

[0184] {

[0185] / / This ID is generated by the Xiaomi IoT platform, and the requestId in the message response and information request must be consistent.

[0186] "requestId":"xxxx",

[0187] / / This ID is sent by the Xiaomi IoT platform; the intent in the message response and information request must be consistent.

[0188] "intent":"get-devices",

[0189] "devices":[

[0190] {

[0191] / / did, or DeviceID, is a unique identifier for a device. It must be a string, cannot contain periods, and cannot exceed 40 characters. This did is set by the developer.

[0192] "did":"AAAA",

[0193] / / Device type: After defining product functions on the Xiaomi IoT Developer Platform, developers can obtain the product type version through the "View JSON" function.

[0194] "type":"urn:miot-spec:device:lightbulb:00000007:philips",

[0195] / / Product name, this field is set by the developer.

[0196] "name":"Xiaobai"

[0197] },

[0198] {

[0199] / / did, or DeviceID, is a unique identifier for a device. It must be a string, cannot contain periods, and cannot exceed 40 characters. This did is set by the developer.

[0200] "did":"AAAB",

[0201] / / Device type: After defining product functions on the Xiaomi IoT Developer Platform, developers can obtain the product's Type information through the "View JSON" function in the function definition interface.

[0202] "type":"urn:miot-spec:device:lightbulb:00000007:philips",

[0203] / / Product name, this field is set by the developer.

[0204] "name":"Xiao Hei"

[0205] } ]

[0207] }

[0208] Reference Figure 4 The diagram illustrates a permission check provided in an embodiment of this application. Figure 4 As shown, when a user requests to operate device X, the permissions of device X are checked. The manufacturer's cloud grants different functional permissions to different third-party clouds, which is the "explicit permission" here. If there is no explicit permission, the group inherited permission is checked. If the group permission allows, the corresponding operation is performed. If there is a conflict of group permissions, the conflict resolution strategy is applied to decide according to role / time priority, update the permission cache and execute.

[0209] For example, the device network configuration is set up on the manufacturer's cloud, and control and status synchronization are achieved through cloud-to-cloud interaction. The manufacturer's cloud grants different functional permissions to different third-party clouds, which is the "explicit permission" mentioned here.

[0210] It should be noted that all devices can connect to the internet, can issue commands from the cloud, and can report status and other data; device manufacturers and third parties have cooperated through cloud-to-cloud integration, and users can control devices and view device status through third-party apps; device manufacturers can dynamically adjust the permissions of commands requested from third parties.

[0211] For example, taking Xiaomi and Huawei as third-party cloud platforms and Gree as manufacturers, assuming that the user has completed the network configuration of Gree devices and authorized the account to Xiaomi Cloud and Huawei Cloud, the user can control the devices through Xiaomi, Huawei, Gree+ and other apps.

[0212] Based on the user's network configuration account, the user's role is automatically classified as follows: Super Administrator - with all permissions, Administrator - with group permissions, and Regular User - with personal permissions. After the user completes the device network configuration, it is assumed that the user has all permissions for this device (except for the confidential permissions required by the manufacturer).

[0213] For example, in a commercial environment, different functions are often required for different roles for a certain device's XX function, and depending on the privacy agreement, the manufacturer will grant different permissions to different third parties.

[0214] When manufacturers connect to third-party cloud platforms via cloud-to-cloud integration and iterate on them, conflicts may arise between IoT device models (e.g., Huawei's device model may not support certain device functions during continuous updates). Alternatively, during the development of control standard protocols, manufacturers may evaluate and decide to no longer open certain functions for certain devices (possibly related to user privacy data, leading to the decision to disable the function). In such cases, the third-party cloud platform may fail to call the function of that product category model.

[0215] At this point, the cloud-connected interface is monitored, and different request commands are retrieved (such as get-prop to obtain device attributes, i.e., current on / off status, mode status, etc.). The return results of the commands, the success / failure of the command execution, and the success / failure of the return result after the command execution are recorded. Finally, the success rate of execution and return is statistically analyzed. If the execution success rate is lower than a certain threshold within a certain period of time, the execution success rate of devices and users is monitored. It is possible that a certain user has an extremely low success rate for operating a certain device, but other users or other platforms have a high success rate.

[0216] In cases where the device model conflicts with the vendor's standard cloud protocol, the user's permission for a specific operation function on that device is disabled, restricting their control command issuance authority for a certain period. Because the device model from the vendor or third-party cloud may be updated, there's a probability that a specific function on the device will execute successfully. If, after the vendor updates its service, the probability of this function's execution remains 0 for an extended period, it indicates that the vendor has closed permissions for certain users to that function's command, and a blacklist can be returned to the device model connected to the third-party cloud. If there's a consistent probability of successful execution, it suggests that control might succeed through one third-party platform but fail through another. In this case, the vendor's service should disable the function for that user and that platform, and allow traffic for that function at intervals of X to check if the service now supports the third-party platform. This allows for cross-validation of permission management.

[0217] Permission decisions can be made through arbitration and multi-parameter weighting. That is, if a vendor's cloud service exists, the permissions of the vendor's cloud service take precedence; then, the decision is made based on role weight, platform weight (vendor > third-party cloud), and the most recent authorization time (for example, if Huawei and Xiaomi are authorized at the same time, but Xiaomi is the most recent authorization, then the weight is higher).

[0218] In addition to user control permissions for individual devices, users can be automatically grouped by administrators or services based on their identities. For example, in a commercial environment, ordinary security personnel in an office building may only have viewing permissions for cameras, administrators may adjust camera angles, and only super administrators may have the authority to add, delete, modify, and query devices. In traditional IoT cloud integration environments, all permissions are often assigned at the device level during network configuration, which may raise privacy and security concerns for users. Furthermore, during device control, manufacturers may not support the common object models of third-party cloud platforms, leading to control failures and impacting user experience. This solution dynamically adjusts function-level permissions, facilitating the management of certain functions and user permissions in commercial cloud integration environments.

[0219] For example, in a security system, ordinary security guards have the right to view cameras, organizers can set the position and angle of the cameras, and administrators can view and delete video recordings. Even if an individual's role is not updated in some third-party cloud during the authorization process, they can still control the system according to their original permissions.

[0220] In summary, this invention provides a permission management method, which includes: when controlling a smart device through third-party application software, determining the first functional permission and the second functional permission of the current third-party cloud platform corresponding to the third-party application software; the first functional permission is in an enabled state; the second functional permission is in a disabled state; monitoring the third functional permission of the target third-party cloud platform corresponding to the second functional permission; the target third-party cloud platform is another third-party cloud platform besides the current third-party cloud platform; the second and third functions are the same function; when the third functional permission of the target third-party cloud platform is enabled, establishing a connection with the target third-party cloud platform to control the second function of the smart device through the target third-party cloud platform. This application can achieve dynamic permission management of device functions controlled by third-party cloud platforms by merging the permissions of multiple third-party cloud platforms; it supports dynamic permission adjustment of users, devices, and functions, thus improving the efficiency of permission management.

[0221] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0222] Device Examples

[0223] like Figure 5 As shown, Figure 5 This paper illustrates a logical block diagram of a permission management device according to an embodiment of the present application. The device includes:

[0224] The determining module 501 is used to determine the first functional permission and the second functional permission of the current third-party cloud platform corresponding to the third-party application software when controlling the smart device through the third-party application software; the first functional permission is in an enabled state; the second functional permission is in a disabled state.

[0225] Monitoring module 502 is used to monitor the target third-party cloud platform and the third function permission corresponding to the second function permission; the target third-party cloud platform is a third-party cloud platform other than the current third-party cloud platform; the second function and the third function are the same function;

[0226] The connection module 503 is used to establish a connection with the target third-party cloud platform when the third function permission of the target third-party cloud platform is enabled, so as to control the second function of the smart device through the target third-party cloud platform.

[0227] Optionally, the monitoring module includes:

[0228] The acquisition module is used to acquire the execution status of the target third-party cloud platform and the third function corresponding to the second function permission;

[0229] The determination submodule is used to determine the third function permission based on the execution status.

[0230] Optionally, the determining submodule includes:

[0231] The first determining submodule is used to determine the execution success rate within a preset period based on the execution status; if the execution success rate is greater than or equal to a preset threshold, determine that the third function permission of the target third-party cloud platform is enabled; if the execution success rate is less than the preset threshold, determine that the third function permission of the target third-party cloud platform is disabled.

[0232] Optionally, the first determining submodule includes:

[0233] The first sub-determination sub-module is used to enable the instruction traffic corresponding to the third function and determine the number of response instructions from the target third-party cloud platform;

[0234] The enabling module is used to enable the third function permission when the number of response commands is greater than or equal to a preset value.

[0235] The module is used to keep the third function permission in a closed state when the number of response commands is less than a preset value.

[0236] Optionally, the device further includes:

[0237] The receiving module is configured to receive a list of third functions whose third function permissions are disabled; the list of third functions includes device function identifiers;

[0238] The update module is used to update the object model corresponding to the target third-party cloud platform based on the third function list, and to control the smart device based on the object model.

[0239] Optionally, the device further includes:

[0240] The second determination submodule is used to determine user permissions based on the user account; the user permissions include super administrator permissions, administrator permissions, and ordinary user permissions; the super administrator permissions are greater than the administrator permissions; the administrator permissions are greater than the ordinary user permissions.

[0241] Optionally, the device further includes:

[0242] The third determination submodule is used to determine the permission order of the third-party cloud platform in the event of a permission conflict with the third-party cloud platform.

[0243] The control module is used to control the smart device according to the permission sequence.

[0244] Optionally, the third determining submodule includes:

[0245] The third sub-determination module is used to determine a first permission order between the manufacturer's cloud platform permissions and the third-party cloud platform permissions; wherein the manufacturer's cloud platform permissions are greater than the third-party cloud platform permissions; or, determine the authorization time of multiple third-party cloud platforms; determine a second permission order based on the authorization time; and determine the permission order of the third-party cloud platforms based on the first permission order or the second permission order.

[0246] In summary, the permission management device provided in this application, when controlling a smart device through third-party application software, determines the first functional permission and the second functional permission of the current third-party cloud platform corresponding to the third-party application software; the first functional permission is in an enabled state; the second functional permission is in a disabled state; it monitors the third functional permission of the target third-party cloud platform corresponding to the second functional permission; the target third-party cloud platform is another third-party cloud platform besides the current third-party cloud platform; the second and third functions are the same function; when the third functional permission of the target third-party cloud platform is enabled, it establishes a connection with the target third-party cloud platform to control the second function of the smart device through the target third-party cloud platform. This application can achieve dynamic permission management of device functions controlled by third-party cloud platforms by merging the permissions of multiple third-party cloud platforms; it supports dynamic permission adjustment of users, devices, and functions, thus improving the efficiency of permission management.

[0247] As the apparatus embodiment is basically similar to the method embodiment, it is described in a relatively simple manner. For relevant details, please refer to the description of the method embodiment.

[0248] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0249] Regarding the processor in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be elaborated upon here.

[0250] Reference Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. Figure 6 As shown, the electronic device includes: a processor, a memory, a communication interface, and a communication bus. The processor, the memory, and the communication interface communicate with each other through the communication bus. The memory is used to store executable instructions, which cause the processor to execute the permission management method of the aforementioned embodiment.

[0251] The processor can be a CPU, a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable devices, transistor logic devices, hardware components, or any combination thereof. The processor can also be a combination that implements computational functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0252] The communication bus may include a path for transmitting information between the memory and the communication interface. The communication bus may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 The symbol is represented by only one line, but this does not mean that there is only one bus or one type of bus.

[0253] The memory may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0254] This invention also provides a non-transitory computer-readable storage medium that, when instructions in the storage medium are executed by a processor of an electronic device (server or terminal), enables the processor to perform... Figure 1The permission management method shown.

[0255] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0256] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0257] Embodiments of the present invention are described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, as well as combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0258] These computer program instructions may also be stored in a computer-readable storage medium capable of directing a computer or other programmable data processing terminal device to operate in a predictive manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0259] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0260] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.

[0261] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0262] The present invention has provided a detailed description of a permission management method, apparatus, electronic device, and storage medium. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, those skilled in the art will recognize that there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A method for managing access permissions, characterized in that, The method includes: When controlling a smart device through a third-party application, the first functional permission and the second functional permission of the current third-party cloud platform corresponding to the third-party application are determined; the first functional permission is enabled; and the second functional permission is disabled. The system monitors the target third-party cloud platform and the third function permission corresponding to the second function permission; the target third-party cloud platform is a third-party cloud platform other than the current third-party cloud platform; the second function and the third function are the same function. When the third function permission of the target third-party cloud platform is enabled, a connection is established with the target third-party cloud platform to control the second function of the smart device through the target third-party cloud platform.

2. The method according to claim 1, characterized in that, The third functional permissions corresponding to the second functional permissions of the third-party cloud platform monitoring target include: Obtain the execution status of the target third-party cloud platform corresponding to the third function corresponding to the second function permission; The third function permission is determined based on the execution status.

3. The method according to claim 2, characterized in that, Determining the third function permission based on the execution status includes: Based on the execution status, determine the execution success rate within the preset period; If the execution success rate is greater than or equal to a preset threshold, the third function permission of the target third-party cloud platform is determined to be enabled. If the execution success rate is less than the preset threshold, the third function permission of the target third-party cloud platform is determined to be closed.

4. The method according to claim 3, characterized in that, After determining that the third-party function permission of the target third-party cloud platform is closed when the execution success rate is less than the preset threshold, the method further includes: The number of response commands from the target third-party cloud platform is determined by activating the command traffic corresponding to the third function. If the number of response commands is greater than or equal to a preset value, the third function permission is enabled. If the number of response commands is less than a preset value, the third function permission remains in the off state.

5. The method according to claim 3, characterized in that, After determining that the third-party function permission of the target third-party cloud platform is disabled, the method further includes: Receive a list of third functions whose third function permissions are disabled; the list of third functions includes device function identifiers; The object model corresponding to the target third-party cloud platform is updated based on the third function list, and the smart device is controlled based on the object model.

6. The method according to claim 1, characterized in that, Before controlling the smart device via a third-party application, the method further includes: User permissions are determined based on user accounts; these permissions include super administrator permissions, administrator permissions, and regular user permissions; super administrator permissions are greater than administrator permissions; and administrator permissions are greater than regular user permissions.

7. The method according to claim 1, characterized in that, The method further includes: In the event of a permission conflict with the third-party cloud platform, determine the permission order of the third-party cloud platform; The smart device is controlled according to the permission sequence.

8. The method according to claim 7, characterized in that, The process of determining the permission order of the third-party cloud platform includes: Determine the first priority order of the vendor's cloud platform permissions and the third-party cloud platform permissions; the vendor's cloud platform permissions are greater than the third-party cloud platform permissions; or... Determine the authorization time for multiple third-party cloud platforms; The second permission order is determined based on the authorization time. The permission order of the third-party cloud platform is determined based on either the first permission sorting or the second permission sorting.

9. A permission management device, characterized in that, The device includes: The determination module is used to determine the first functional permission and the second functional permission of the current third-party cloud platform corresponding to the third-party application software when controlling the smart device through the third-party application software; the first functional permission is in an enabled state; and the second functional permission is in a disabled state. The monitoring module is used to monitor the target third-party cloud platform and the third function permission corresponding to the second function permission; the target third-party cloud platform is a third-party cloud platform other than the current third-party cloud platform; the second function and the third function are the same function; The connection module is used to establish a connection with the target third-party cloud platform when the third function permission of the target third-party cloud platform is enabled, so as to control the second function of the smart device through the target third-party cloud platform.

10. The apparatus according to claim 9, characterized in that, The monitoring module includes: The acquisition module is used to acquire the execution status of the target third-party cloud platform and the third function corresponding to the second function permission; The determination submodule is used to determine the third function permission based on the execution status.

11. An electronic device, characterized in that, The electronic device includes a processor, a memory, a communication interface, and a communication bus, wherein the processor, the memory, and the communication interface communicate with each other through the communication bus; The memory is used to store executable instructions that cause the processor to execute the permission management method as described in any one of claims 1 to 8.

12. A readable storage medium, characterized in that, When the instructions in the readable storage medium are executed by the processor of the electronic device, the processor is enabled to perform the access control method as described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Device abnormal behavior alarm method and device and platform information query method and device

    CN106559259A

  • Interconnection and intercommunication system and interconnection and intercommunication method for smart home equipment

    CN113783760A

  • Cross-platform communication system of Internet of Things and intelligent equipment and communication method thereof

    CN114900384A

  • Equipment control method and device, storage medium and electronic device

    CN115103033A

  • Control method and device of third-party equipment, electronic equipment and medium

    CN117478449A