A method and system for suspension and dynamic binding of home internet of things device permissions
Through a three-tier binding model of device-home-user and a cloud service platform, efficient and secure dynamic binding of IoT device permissions is achieved, solving the problems of complex operation and insufficient security in existing technologies, and improving user experience and efficiency of permission handover.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- XIAMEN LEELEN TECH CO LTD
- Filing Date
- 2025-11-25
- Publication Date
- 2026-07-21
AI Technical Summary
Existing IoT device permission management is complex, time-consuming, and insecure in scenarios with frequent user changes, resulting in a poor user experience and failing to meet the needs of short-term rental scenarios for efficient and rapid permission handover.
It adopts a three-tier binding model of device-home-user, and realizes the suspension and dynamic binding of home permissions through a cloud service platform, including unbinding, status setting, permission credential generation and binding. New users can obtain control of all devices by scanning a code or reading credentials for verification.
It achieves continuity and convenience in device configuration, significantly reduces manpower and time costs, ensures the integrity and security of permission transfer, and is suitable for high-frequency change scenarios.
Smart Images

Figure CN121441668B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of Internet of Things (IoT) device management technology, and specifically relates to a method and system for suspending and dynamically binding permissions for home IoT devices. Background Technology
[0002] With the rapid development of Internet of Things (IoT) technology and the popularization of the smart home concept, various smart devices, such as smart door locks, smart lighting, environmental sensors, and smart appliances, have been widely used in residential, short-term rental apartments, and hotels, greatly improving the convenience and comfort of living. In these application scenarios, how to efficiently and securely manage the control permissions of IoT devices, especially when users frequently change, has become a key technical issue.
[0003] Currently, the common approach to managing control permissions for these smart devices is a one-to-one or one-to-many direct binding model between user accounts and specific devices. When it's necessary to change the user of a device, such as when a tenant in a short-term rental apartment moves out and a new tenant moves in, or when property ownership is transferred, existing technology typically employs the following procedure: First, the original user or system administrator must log into the management backend and manually unbind each device to sever the control relationship between the original user and the device; then, the new user must complete the rebinding process with these devices one by one through the corresponding application (APP).
[0004] Chinese invention patent application CN107274278A discloses a rental system based on an Internet of Things (IoT) smart lock, comprising: an identity information input terminal for inputting user identity information, i.e., user characteristic information, to complete user registration; an IoT smart lock for allowing legitimate users to enter the rental property during a specified time period according to instructions and information issued by the system; a cloud processing platform for storing user characteristic information input by the user at the identity information input terminal and authorizing the IoT smart lock to allow legitimate users to enter the rental property during a specified time period; and a user client for supporting online rental.
[0005] However, the above solutions have the following significant shortcomings in practical applications, especially in scenarios with high user mobility: Based on the direct device-user binding model, permission transfer must be performed device-by-device. In a residential environment with dozens or even hundreds of smart devices, the process of unbinding and binding devices one by one is extremely complex and time-consuming, with high manual intervention costs, failing to meet the needs of short-term rentals and other scenarios for efficient and rapid permission handover. After device rebinding is completed, data such as scene configurations, scheduled tasks, and personalized settings linked to the devices in the original residential environment are usually lost when the original user is unbound. After a new user moves in, a significant amount of time needs to be spent reconfiguring all devices, severely impacting the continuity and convenience of the user experience. When the residence is vacant, current technology cannot provide a mechanism to securely decouple and suspend control of the entire residence from a specific user account, awaiting convenient takeover by the next authorized user. This rigid binding relationship is prone to security vulnerabilities due to operational omissions and cannot meet the needs of modern property management for flexible and dynamic permission transfers. Summary of the Invention
[0006] This invention provides a method and system for suspending and dynamically binding permissions for home IoT devices, aiming to solve the problems of complexity, time consumption, insufficient security, and poor user experience in the existing IoT device permission handover process.
[0007] To address the aforementioned technical problems, this invention proposes a method for suspending and dynamically binding permissions for home IoT devices, comprising the following steps: In response to the first user's suspension request, a target residential entity is unbound from the first user, and the state of the target residential entity is set to suspended; Receive the device identifier uploaded by the second user, query the residential entity to which the device identifier belongs, and determine whether the corresponding residential entity is in a suspended state; If the corresponding residential entity is in a suspended state, generate an associated residential permission credential and guide the second user to obtain and upload the residential permission credential. After the uploaded home access credentials are verified, the second user is bound to the corresponding home entity and the status of the corresponding home entity is restored to normal, so that the second user gains control over all IoT devices under the corresponding home entity.
[0008] Preferably, the home access credentials have a preset validity period.
[0009] Preferably, after the uploaded home access credentials are verified, the method further includes a step of invalidating the home access credentials used in this instance.
[0010] Preferably, the home access credentials are sent to a designated display device within the target home entity for display.
[0011] Preferably, the step of the second user uploading the device identifier specifically involves: scanning the QR code on the IoT device through the user terminal to obtain and upload the device identifier.
[0012] Preferably, the step of guiding the second user to obtain and upload the home access credentials includes: the cloud service platform sending an instruction to the second user's terminal, prompting the user to read the home access credentials.
[0013] Preferably, the IoT devices, residential entities, and users adopt a three-tier binding relationship: one or more IoT devices are pre-belonging to a residential entity, and users obtain control rights over all IoT devices under that residential entity by binding with that residential entity.
[0014] Preferably, the unbinding, status setting, permission code generation, status judgment and binding steps are all executed by the cloud service platform.
[0015] Preferably, the home access credentials are presented in the form of QR codes, near-field communication, Bluetooth Low Energy broadcasting, letters, numbers, or combinations of letters, numbers, and characters.
[0016] On the other hand, the present invention also proposes a system for suspending and dynamically binding permissions for home IoT devices, the system being used to implement the suspension and dynamic binding method as described in the first aspect of the present invention, comprising: The suspension processing module is used to respond to the suspension request of the first user, unbind a target residential entity from the first user, and set the state of the target residential entity to suspension. The status query module is used to receive the device identifier uploaded by the second user, query the residential entity to which the device identifier belongs, determine whether the corresponding residential entity is in a suspended state, and generate an associated residential permission credential. The binding execution module is used to receive and verify the home access credentials uploaded by the second user when it is determined that the corresponding home entity is in a suspended state. After successful verification, the second user is bound to the corresponding home entity, and the status of the corresponding home entity is restored to normal.
[0017] Compared with the prior art, the present invention has the following technical effects: 1. In the suspension and dynamic binding method proposed in this invention, the configuration information for various scenarios is bound to the residential entity rather than the user. Therefore, when the ownership of the residence is transferred, the new user can fully inherit these preset configurations, realizing a move-in ready smart home experience, ensuring the continuity of service and experience, and greatly improving user satisfaction and convenience.
[0018] 2. The suspension and dynamic binding method proposed in this invention presents a three-layer binding model of device-home-user, shifting the focus of access control from complex individual devices to a single home entity. Existing users can suspend their homes with a single click, while new users can instantly gain control of all devices under the home through a simple two-step process of scanning / reading and verification. This completely changes the cumbersome process of unbinding and rebinding devices one by one in existing technologies, reducing what might have been a manual operation taking tens of minutes or even hours to an automated process of less than a minute. It is particularly suitable for scenarios with frequent user changes, such as short-term rental apartments and hotels, significantly reducing labor and time costs.
[0019] 3. The suspension and dynamic binding method proposed in this invention ensures the integrity of permission transfer through overall operation of the residential entity. Once suspended, the original user and all devices under that residential entity will be completely and cleanly decoupled. Simultaneously, the introduced residential permission credentials are time-sensitive and one-time use, requiring the new user's physical presence to obtain them. This combination of digital authorization and physical verification effectively prevents permissions from being remotely and illegally stolen, ensuring the security of the handover process.
[0020] 4. The suspension and dynamic binding method proposed in this invention introduces a suspended state for residences, logically decoupling residence control from any specific user, allowing it to safely remain in a suspended, unclaimed state. This flexible state machine management mechanism perfectly solves the problem of permission ownership during physical space vacancy, which is impossible to achieve with the traditional device-user fixed binding model. It provides a highly flexible, dynamic, and automated permission transfer solution for modern properties, especially emerging business models such as shared accommodation and long-term rental apartments. Attached Figure Description
[0021] Figure 1 This is a flowchart illustrating the suspension and dynamic binding method described in this invention. Detailed Implementation
[0022] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below in conjunction with specific embodiments of the present application and with reference to the accompanying drawings.
[0023] Before providing a detailed description of the embodiments of this application, some of the nouns and terms involved in the embodiments of this application will be explained first. The nouns and terms involved in the embodiments of this application are subject to the following interpretations.
[0024] Residence: refers to a separate physical space unit served by IoT devices, such as an apartment, a hotel room, or an office. In the embodiments of this application, it is a logical entity.
[0025] Home Suspended Status: This refers to a special logical state of a home, in which the home is not bound to any user account, allowing new users to acquire ownership of it through a specific process.
[0026] Home Ownership Credentials: A time-sensitive digital credential dynamically generated by the cloud service platform when a home enters a suspended state, used to authorize new users to acquire ownership of the home.
[0027] The three-tiered binding relationship between devices, homes, and users refers to a data model where IoT devices are initially associated with a home entity, while users have control over that home entity, thereby indirectly controlling all devices under it.
[0028] Example 1 This embodiment describes a method for suspending and dynamically binding permissions for home IoT devices. In this embodiment, a three-tiered binding relationship is adopted between IoT devices, the home entity, and the user: one or more IoT devices are pre-assigned to a home entity, and the user gains control permissions for all IoT devices under that home entity by binding to it. The specific method is as follows... Figure 1 As shown, it includes the following steps one through four: Step one: In response to the first user's suspension request, unbind a target residential entity from the first user and set the target residential entity's status to suspended. The core purpose of this step is to allow the current legitimate user (the first user) to proactively and securely release control of a residential entity from their personal account, placing it into a pending, vacant state.
[0029] In a specific application scenario, for example, tenant A (the first user) of a short-term rental apartment is preparing to check out. The operation process for this step is as follows: Tenant A opens the smart home application (APP) installed on their smartphone and enters the management page. This page displays the currently linked apartment (i.e., the target residence). Tenant A clicks the "Check Out" or "Suspend Residence" button on the interface. After clicking, the APP sends a suspension request to the cloud service platform. This request includes at least Tenant A's UserID and the HomeID of the residence to be suspended.
[0030] Upon receiving the request, the cloud service platform will first verify the user's permissions to confirm that the user initiating the request, A, is indeed the legitimate user currently bound to the home ID. After successful verification, the platform will execute the following series of automated operations: In the system's user-home mapping data table (e.g., a table named user_home_mapping), delete or mark the association record of the user ID and home ID as invalid. After this operation is completed, tenant A's APP will lose control over all devices in the apartment, and these devices will no longer be displayed in their device list.
[0031] In the home information data table (e.g., a table named home_info), find the record corresponding to the home ID and update the value of its status field from normal or occupied to pending. This status serves as a key criterion for determining whether a new user can be bound to the account.
[0032] Through step one, the control of the apartment that originally belonged to tenant A was completely and securely suspended.
[0033] Step two involves receiving the device identifier uploaded by the second user, querying the residential entity to which the device identifier belongs, and determining whether the corresponding residential entity is in a suspended state. The purpose of this step is to allow the newly registered user (the second user) to initiate a query request to the cloud service platform through simple interaction with any physical device in the environment. Based on this, the cloud platform identifies the user's residential entity and verifies whether the entity is in a bindable suspended state, thereby triggering the subsequent permission handover process.
[0034] The second step of uploading the device identifier by the user is as follows: the user terminal scans the QR code on the IoT device to obtain and upload the device identifier.
[0035] Following the scenario in step one, new tenant B (the second user) has moved into the apartment and needs to gain control of all smart devices within the apartment. The process is as follows: Tenant B opens the same smart home app on their smartphone. Because they are a new user or lack permission for the home, their device list is empty. The app's homepage displays a tutorial prompting the user to add a new home or scan for devices to bind, or read a specified NFC tag or receive a specified BLE broadcast.
[0036] Tenant B can find any IoT device in the apartment that displays their identity. This could be a smart gateway on the wall, a smart switch panel, or a smart speaker in the living room. This identity display is like the device's ID card, uniquely assigned and printed on the device's casing at the factory, or written to a permanent NFC tag. The information encoded within it is the device's unique identifier (Device ID), such as a UUID or the device's MAC address.
[0037] Tenant B uses the app's built-in scanning or NFC reading function to scan the QR code or NFC tag on the smart gateway. After successfully decoding, the app obtains this unique device identifier. The app then packages this device identifier together with Tenant B's UserID and sends it to a designated interface on the cloud service platform via a network protocol request.
[0038] After receiving a request from tenant B's terminal, the cloud service platform executes the following key logic: The platform first queries the device-home binding relationship data table. It uses the device ID uploaded in the request as an index to find which home entity (HomeID) the device belongs to. Since all devices are pre-bound to this apartment (home entity) by the administrator during initial installation, the platform can accurately query the corresponding home ID.
[0039] After successfully obtaining the home ID, the platform will then query the home information data table (home_info table). It uses this home ID to retrieve detailed information about the home, focusing on its status field. Scenario 1: If the home's status is "Pending," this indicates that the home is in the correct state, awaiting a new user to bind it, and the cloud verification is successful. Scenario 2: If the status is "Normal" or "Occupied," this means that the home may have already been bound by another user, or the original user did not perform a "Pending" operation. In this case, the cloud will return an error message to tenant B's app, such as "This home has been occupied and cannot be bound."
[0040] Step 3: If the corresponding residential entity is in a suspended state, an associated residential access credential is generated, guiding the second user to obtain and upload the credential. After confirming in the cloud that the residential entity is in a bindable suspended state, this step guides the new user (the second user) to obtain and submit credentials to claim control through a secure interaction based on physical presence proof. In this embodiment of the invention, the residential access credential can be generated through authorization operations in the backend of the apartment or hotel management system when the second user checks in, and an expiration time can be set according to the user's expected check-in time.
[0041] In this embodiment, the home access credentials, which are in the form of QR codes, barcodes, or alphanumeric codes, are sent to a designated display device within the target home entity for display.
[0042] If the platform detects situation one as described in step two, it will invoke its internal security credential generation module to generate a unique, random, and difficult-to-crack home access credential for the suspended home entity. This credential is essentially a string of characters that can be encoded according to different application scenarios. In this embodiment, the home access credential has a preset validity period; that is, when generating the credential, the system sets a preset validity period, such as 4 hours or 24 hours. The cloud records the generation time and expiration time of the credential. Once the validity period expires, the credential will automatically become invalid and can no longer be used for binding, thus ensuring security. The credential is also unique, uniquely associated with this suspension operation and the home ID.
[0043] After the credentials are generated in the cloud, a method is needed to make them accessible to the next user (the second user). The home access credential can be displayed as a QR code, Near Field Communication (NFC), Bluetooth Low Energy (BLE) broadcast, letters, numbers, or combinations of letters, numbers, and characters. For home access credentials in the form of numbers, letters, and characters (such as minus signs, underscores, etc.), it can be one or more combinations of numbers, letters, and characters.
[0044] The most common form is presenting it as a QR code, barcode, or alphanumeric combination. The cloud service platform encodes the generated credential string into a QR code image, or uses the string itself directly. Subsequently, the platform pushes the QR code image data or string of text to one or more designated display devices deployed within the residence via IoT communication protocols (such as MQTT or HTTP). These devices can be: smart TV screens, smart gateways or control panels with screens, e-ink labels, etc. After receiving the data, the device will clearly display the QR code, barcode, or a verification code like "A9B3-C8D7" on its screen, waiting for new users to obtain it.
[0045] If a device supporting NFC reading and writing is installed in the home (such as a smart door lock or an NFC tag on a wall panel), the cloud platform can send the generated authorization credentials to the device through the gateway, and the device will then write the credentials into its NFC chip. New users can then simply tap their phones together to obtain the credentials.
[0046] If the home gateway or a smart device (such as a smart speaker) supports BLE broadcasting, the cloud platform can instruct the device to launch a specific BLE broadcast service. The broadcast signal packet carries the generated authorization credentials. The new user's mobile app can discover and parse these credentials by scanning nearby Bluetooth signals.
[0047] The step of guiding the second user to obtain and upload the home access credentials includes: the cloud service platform sending an instruction to the second user's terminal, prompting the user to read the home access credentials.
[0048] Continuing from step two, the new tenant B's (the second user) mobile app has successfully triggered the cloud-based suspended status verification. After confirming the home's status as suspended, the cloud does not immediately perform the binding process. Instead, it first returns a clear response to tenant B's mobile app. This response not only informs the app that the status verification has passed, but more importantly, it carries a command to guide the app to the next step. For example, it might display a status code indicating "Verification successful, please continue"; an action command; or a user-facing prompt text, such as: "Welcome! Please scan the QR code on the TV screen to activate your home," etc.
[0049] Upon receiving this instruction, the APP interface on Tenant B's mobile phone can trigger an interface switch, changing from the device scanning interface to an interface specifically for scanning home access credentials, and displaying corresponding text prompts to guide Tenant B to find and scan the permission QR code that was displayed on the smart TV or other device in step one, or to read the specified NFC tag or BLE broadcast.
[0050] Guided by the app, tenant B began searching for the "residential access pass" within the apartment. Depending on how the pass was presented in step one, tenant B's actions varied accordingly.
[0051] Tenant B sees a QR code displayed on the smart TV screen in the living room. He / She holds up his / her phone and uses the scanning tool provided on the app's interface to scan the QR code. The app's camera captures the image and decodes it, extracting a unique string. The app prompts, "Please gently touch the back of your phone to the NFC area on the door lock." Tenant B follows the prompt, bringing his / her phone close to the smart lock's sensor area. The phone's NFC module automatically reads the authorization credential string stored in the door lock's NFC chip. The TV screen displays a line of code, such as "B4X9-2P7G," and the app interface correspondingly presents an input box, prompting, "Please enter the activation code displayed on the screen." Tenant B manually enters the code into the app.
[0052] Regardless of which method was used, the app ultimately succeeded in obtaining the string of home access credentials.
[0053] After obtaining the credentials, the app will immediately package them together with tenant B's UserID and the previously obtained HomeID, and upload them to the cloud service platform through a secure API interface to request final binding.
[0054] This completes the current step. The new user has successfully submitted proof of their legal right to control the home to the cloud through a closed-loop process that combines online guidance and offline physical interaction.
[0055] Step four: After the uploaded home access credentials are verified, the second user is bound to the corresponding home entity, and the status of the corresponding home entity is restored to normal. This grants the second user control over all IoT devices under the corresponding home entity. This step is the final stage and deliverable of the entire process. After receiving the access credentials uploaded by the new user (the second user), the cloud service platform will perform the final verification and authorization operations, officially completing the transfer of home control.
[0056] Understandably, this is the final checkpoint to ensure handover security. The cloud will strictly verify the uploaded authorization credentials: consistency check, comparing the credential string uploaded by tenant B with the credential generated in step one and associated with that home ID stored internally on the server; the two must be completely identical; timeliness check, checking if the credential is within its preset validity period; the system will compare the current time with the credential's expiration timestamp; if it has expired, the verification fails; uniqueness check, checking if the credential has already been used. The credential data record will have a flag indicating whether it has been used (is_used), which defaults to false. If this flag is true, it means the credential has been consumed, and the verification fails.
[0057] Following the scenario in step three, the cloud service platform has received a binding request from the new tenant B (the second user)'s terminal, containing their UserID, HomeID, and home access credentials. The platform will execute the following automated process: To prevent the credentials from being reused or intercepted and replayed by others, this embodiment includes a step of invalidating the currently used home access credentials after the uploaded home access credentials have been verified. The system will immediately update the status of the access credentials, setting the "is_used" flag to true. In this way, the credentials have completed their historical mission and are immediately invalidated.
[0058] Then, in the system's user-home mapping table (user_home_mapping), a new record is created, linking tenant B's user ID with the apartment's home ID, officially establishing tenant B as the new owner of the home. In the home information table (home_info), the status field of the home ID is changed from suspended to normal or occupied, indicating that the home has ended its suspended state and returned to a normal controlled state.
[0059] After completing the above background operations, the cloud will return a response indicating successful binding to Tenant B's APP. Upon receiving the success response, Tenant B's APP will immediately refresh its main interface. The APP will then request a list of all devices under that home ID from the cloud. Thanks to the device-home-user three-layer binding relationship adopted in this invention, the cloud only needs to distribute the control permission information of all IoT devices (such as lights, air conditioners, curtains, door locks, etc.) belonging to that home ID to Tenant B's APP based on the new binding relationship.
[0060] Tenant B's phone screen will display the control cards for all smart devices in the apartment. He / she can immediately begin full control of the entire home without any manual, device-by-device addition and configuration. Thus, a complete, secure, and efficient dynamic transfer of home access is completed.
[0061] In steps one through four above, the unbinding, status setting, permission code generation, status judgment, and binding steps are all executed by the cloud service platform. The cloud service platform acts as the central control hub and the only trusted third party. This embodiment centralizes all core business logic, status management, and security decisions in the cloud, thereby ensuring the robustness, security, and consistency of the process.
[0062] Specifically, the key steps of unbinding, status setting, permission code generation, status judgment, and binding are all uniformly executed by the cloud service platform. The implementation is as follows: The cloud platform maintains the status of each residential entity. Whether it's unbinding and setting the status of the first user, or binding and restoring the status of the second user, the cloud drives and records this status flow. The generation, storage, timeliness management, and final verification and expiration of residential permission credentials are all completed within the cloud server; this ensures that credentials cannot be forged by the client and that their lifecycle is strictly controlled. When a second user's address request is received, the cloud performs a status judgment, deciding whether to reject the request or guide the user to perform permission verification. This centralized decision-making mechanism avoids complex logical judgments on the device or user app side, simplifying terminal design. Whether it's terminating the relationship between the first user and the residential entity, or establishing the relationship between the second user and the residential entity, it involves direct operations on the core relationship table in the cloud database. This centralized management of data relationships is the foundation for realizing changes in residential ownership, and thus achieving batch transfer of permissions for all devices under it.
[0063] In summary, the user terminal APP and IoT devices themselves only act as the initiators and executors of instructions, while all core calculations and decisions involving permission changes, status management and security verification are reliably executed by the cloud service platform, thus constituting the efficient and secure technical architecture of this invention.
[0064] Example 2 This embodiment is a system for suspending and dynamically binding permissions for home IoT devices. The system is used to implement the suspension and dynamic binding method as described in Embodiment 1, including: The suspension processing module is used to respond to the suspension request of the first user, unbind a target residential entity from the first user, and set the state of the target residential entity to suspension. The status query module is used to receive the device identifier uploaded by the second user, query the residential entity to which the device identifier belongs, determine whether the corresponding residential entity is in a suspended state, and generate an associated residential permission credential. The binding execution module is used to receive and verify the home access credentials uploaded by the second user when it is determined that the corresponding home entity is in a suspended state. After successful verification, the second user is bound to the corresponding home entity, and the status of the corresponding home entity is restored to normal.
[0065] The above description is only a preferred embodiment of the present invention. It should be noted that those skilled in the art can make several modifications and improvements without departing from the inventive concept of the present invention, and these all fall within the protection scope of the present invention.
Claims
1. A method for suspending and dynamically binding permissions for home IoT devices, characterized in that, Includes the following steps: In response to the first user's suspension request, a target residential entity is unbound from the first user, and the state of the target residential entity is set to suspended; Receive the device identifier uploaded by the second user, query the residential entity to which the device identifier belongs, and determine whether the corresponding residential entity is in a suspended state; If the corresponding residential entity is in a suspended state, generate an associated residential access credential with a preset validity period, and guide the second user to obtain and upload the residential access credential. After the uploaded home access credentials are verified, the home access credentials used in this instance become invalid. The second user is then bound to the corresponding home entity, and the status of the corresponding home entity is restored to normal. This allows the second user to gain control over all IoT devices under the corresponding home entity.
2. The method according to claim 1, characterized in that, The residential access credentials are sent to a designated display device within the target residential entity for display.
3. The method according to claim 1, characterized in that, The second step of uploading the device identifier by the user is as follows: the user terminal scans the QR code on the IoT device to obtain and upload the device identifier.
4. The method according to claim 1, characterized in that, The step of guiding the second user to obtain and upload the home access credentials includes: the cloud service platform sending an instruction to the second user's terminal, prompting the user to read the home access credentials.
5. The method according to claim 1, characterized in that, The IoT devices, residential entities, and users are linked by a three-tiered binding relationship: one or more IoT devices are pre-assigned to a residential entity, and users gain control over all IoT devices under that residential entity by binding themselves to it.
6. The method according to claim 1, characterized in that, The unbinding, status setting, permission code generation, status judgment, and binding steps are all executed by the cloud service platform.
7. The method according to claim 1, characterized in that, The home access credentials are presented in the form of QR codes, near-field communication, Bluetooth Low Energy broadcast, letters, numbers, and combinations of letters, numbers, and characters.
8. A system for suspending and dynamically binding permissions for home IoT devices, characterized in that, The system is used to implement the suspension and dynamic binding method as described in any one of claims 1-7, including: The suspension processing module is used to respond to the suspension request of the first user, unbind a target residential entity from the first user, and set the state of the target residential entity to suspension. The status query module is used to receive the device identifier uploaded by the second user, query the residential entity to which the device identifier belongs, determine whether the corresponding residential entity is in a suspended state, and generate an associated residential permission credential. The binding execution module is used to receive and verify the home access credentials uploaded by the second user when it is determined that the corresponding home entity is in a suspended state. After successful verification, the second user is bound to the corresponding home entity, and the status of the corresponding home entity is restored to normal.