Equipment control system, method and device, electronic equipment and storage medium

By using dynamic multi-factor authentication and access control, the problem that static security policies cannot adapt to dynamic environments in IoT device control is solved, thereby improving system security and adaptability, and making it suitable for device control systems of IoT devices.

CN121603253APending Publication Date: 2026-03-03CHINA MOBILE INTERNET CO LTD +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511649648.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-12
Publication Date
2026-03-03

AI Technical Summary

Technical Problem

The control and security management of IoT devices rely on static security policies, which cannot adapt to the dynamic IoT environment, thus limiting the improvement of overall system performance.

Method used

The system employs dynamic execution of multi-factor authentication and access control. Through authentication enhancement and access control modules, it dynamically adjusts authentication weights and generates comprehensive authentication results based on context information, and combines network analysis to generate dynamic access control policies.

Benefits of technology

It improves system security and access control adaptability, enables dynamic adaptation of the authentication process and dynamic access control policies, and enhances the flexibility and security of device management in the Internet of Things environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121603253A_ABST
    Figure CN121603253A_ABST
Patent Text Reader

Abstract

The invention provides an equipment control system, method and device, electronic equipment and a storage medium, and relates to the field of data communication, and the system comprises an authentication enhancement module and an access control module; wherein the authentication enhancement module is used for responding to a received access request, dynamically executing multi-factor authentication on context information based on the access request, generating a comprehensive authentication result, and sending the comprehensive authentication result to the access control module; the access control module is used for carrying out network analysis on the dynamic factors to obtain a network analysis result, generating a dynamic access control strategy based on the received comprehensive authentication result and the network analysis result, and sending the dynamic access control strategy to the target equipment, so that the target equipment executes access control based on the dynamic access control strategy; by dynamically executing multi-factor authentication and access control, the dynamic adaptation between the authentication process and the dynamic access control strategy is realized, and the adaptability of access control is enhanced while the system security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of data communication, and more particularly to a device control system, method and apparatus, electronic device and storage medium. Background Technology

[0002] In recent years, IoT technology has developed rapidly, and the number of connected devices has continued to grow. In application scenarios such as smart homes, industrial IoT, and smart cities, users have put forward higher requirements for the convenience and security of device management and control. At the same time, the IoT environment is also facing increasingly complex security threats.

[0003] In related technologies, the control and security management of IoT devices rely on static security policies or pre-set static rules. However, there is an inherent contradiction between the static nature of security policies and the dynamic nature of the IoT environment, which limits the improvement of the overall system performance. Summary of the Invention

[0004] This disclosure provides a device control system, method and apparatus, electronic device and storage medium to solve the problems of static security policies and lack of dynamic adaptability of access control in the control of Internet of Things (IoT) devices in related technologies. By dynamically executing multi-factor authentication and access control, the authentication process and dynamic access control policies are dynamically adapted, which improves system security and enhances the adaptability of access control.

[0005] According to a first aspect of this disclosure, a device control system is provided, the system comprising: an authentication enhancement module and an access control module; wherein... The authentication enhancement module is used to respond to a received access request, dynamically perform multi-factor authentication based on the access request and context information, generate a comprehensive authentication result, and send the comprehensive authentication result to the access control module. The access control module is used to perform network analysis on dynamic factors, obtain network analysis results, generate a dynamic access control policy based on the received comprehensive authentication result and the network analysis results, and send the dynamic access control policy to the target device so that the target device can perform access control based on the dynamic access control policy.

[0006] In some embodiments of this disclosure, the authentication enhancement module is further configured to: Collect the context information; The authentication weights of the multi-factor authentication and the authentication scores corresponding to the authentication weights are dynamically adjusted based on the context information to obtain the adjustment result; The comprehensive authentication result is generated based on the near-field authentication result obtained by the near-field automatic authentication and binding module, the message platform authentication result, and the adjustment result. The near-field authentication result is used to characterize the result of the terminal and the target device completing the initial authentication binding through near-field communication, and the message platform authentication result is used to characterize the result of the terminal initiating identity authentication through the message platform.

[0007] In some embodiments of this disclosure, the context information includes geographical location, current time, device status, and identity information; The authentication weights of the multi-factor authentication include the geographical location factor corresponding to the geographical location, the time factor corresponding to the current time, the device status factor corresponding to the device status, and the identity authentication factor corresponding to the identity recognition information. The authentication enhancement module is also used for: The geographic location factor is calculated based on the distance difference between the current location and the preset safe location and the duration of stay at the current location; The time factor is obtained by calculation based on daily cycle changes, weekly cycle changes, and time decay. The device status factor is calculated based on the current security score, version difference, and update time. The identity authentication factor is calculated based on the identity recognition information entropy, usage duration, and replacement frequency.

[0008] In some embodiments of this disclosure, the authentication score corresponding to the authentication weight includes the geographical location score corresponding to the geographical location factor, the time score corresponding to the time factor, the device status score corresponding to the device status factor, and the identity authentication score corresponding to the identity authentication factor. The authentication enhancement module is also used for: The geographical location score is obtained by calculating the geographical location factor based on the first scoring function corresponding to the geographical location factor; The time factor is calculated based on the second scoring function corresponding to the time factor to obtain the time score; The equipment status factor is calculated based on the third scoring function corresponding to the equipment status factor to obtain the equipment status score; The identity authentication score is obtained by calculating based on the fourth scoring function corresponding to the identity authentication factor.

[0009] In some embodiments of this disclosure, the authentication enhancement module is further configured to: Determine the reliability scores of the near-field authentication result and the message platform authentication result, and fuse the near-field authentication result, the message platform authentication result, the reliability score corresponding to the near-field authentication result, and the reliability score corresponding to the message platform authentication result through an authentication fusion function to obtain a fusion result; If both the near-field authentication result and the message platform authentication result are confirmed to be successful, a small positive factor is introduced into the fusion result to improve the fusion score.

[0010] In some embodiments of this disclosure, the comprehensive authentication result includes a credibility authentication score and authentication strength, and the authentication enhancement module is further configured to: The weighted and fused authentication score is subjected to nonlinear normalization to obtain the credibility authentication score; The credibility authentication score is transformed to obtain the authentication strength.

[0011] In some embodiments of this disclosure, the access control module is further configured to: Network analysis is performed on the dynamic factors to obtain the network analysis results. Based on the received comprehensive authentication results and the network analysis results, an access permission score is generated. The dynamic factors include at least network topology and device relationships. The access permission score is optimized to obtain an optimized access permission score, and a dynamic access control policy is generated based on the optimized access permission score.

[0012] In some embodiments of this disclosure, the access control module is further configured to: The access permission score is optimized by introducing a time decay factor and historical interaction similarity to obtain the optimized access permission score; The optimized access permission scores are divided into different access control levels based on predefined thresholds, and a dynamic access control policy is determined based on the access control levels.

[0013] In some embodiments of this disclosure, the system further includes: a device risk prediction and anomaly detection module; used for: Monitor the status information of the target device; wherein the status information includes at least one of device performance indicators, environmental parameters, functional status, and network behavior; Analyze the time-series data of the status information to determine whether there are any anomalies in the status information; If it is determined that the status information is abnormal, an abnormal prompt message corresponding to the status information is generated, and the abnormal prompt message is sent to the terminal through the message platform.

[0014] In some embodiments of this disclosure, the system further includes: a multi-device collaborative management module and a message card generation module; wherein, The multi-device collaborative management module is used to respond to a control command sent by the terminal and coordinate the collaborative work of at least two target devices based on the control command. The multi-device collaborative management module is further configured to send the collaborative status information to the message card generation module; wherein, the collaborative status information includes at least the connection status and task requirements; The access control module is also used to send access permission information to the message card generation module; The message card generation module is used to receive the collaboration status information and the access permission information, generate a personalized message card based on the collaboration status information, the access permission information and historical interaction data, and send the personalized message card to the terminal.

[0015] In some embodiments of this disclosure, the message card generation module is further configured to: The terminal interacts with the target device via the personalized message card to obtain historical interaction data; The historical interaction data is sent to the authentication enhancement module, the access control module, the device risk prediction and anomaly detection module, and the message card generation module so that each module can be optimized and adjusted.

[0016] In some embodiments of this disclosure, the system further includes: a near-field automatic authentication and binding module; used for: A secure binding relationship is established between the terminal and the target device, and a near-field authentication token is generated; wherein, the near-field authentication token includes at least a communication device identifier, a timestamp, and a session key; The near-field authentication token is stored in the terminal and the target device so that the terminal and the target device can establish a trust relationship.

[0017] According to a second aspect of this disclosure, a device control method is provided, comprising: In response to a received access request, multi-factor authentication is dynamically performed based on the access request and context information to generate a comprehensive authentication result; A network analysis is performed on dynamic factors to obtain network analysis results. Based on the comprehensive authentication results and the network analysis results, a dynamic access control policy is generated and sent to the target device so that the target device can perform access control based on the dynamic access control policy.

[0018] In some embodiments of this disclosure, the step of responding to a received access request and dynamically performing multi-factor authentication based on the access request and context information to generate a comprehensive authentication result includes: Collect the context information; The authentication weights of the multi-factor authentication and the authentication scores corresponding to the authentication weights are dynamically adjusted based on the context information to obtain the adjustment result; The system obtains the near-field authentication result and the message platform authentication result, and generates the comprehensive authentication result based on the near-field authentication result, the message platform authentication result, and the adjustment result; wherein, the near-field authentication result is used to characterize the result of the terminal and the target device completing the initial authentication binding through near-field communication, and the message platform authentication result is used to characterize the result of the terminal initiating identity authentication through the message platform.

[0019] In some embodiments of this disclosure, the context information includes geographic location, current time, device status, and identity information; the authentication weight of the multi-factor authentication includes a geographic location factor corresponding to the geographic location, a time factor corresponding to the current time, a device status factor corresponding to the device status, and an identity authentication factor corresponding to the identity information; the authentication weight of the multi-factor authentication and the authentication score corresponding to the authentication weight are dynamically adjusted according to the context information to obtain an adjustment result, including: The geographic location factor is calculated based on the distance difference between the current location and the preset safe location and the duration of stay at the current location; The time factor is obtained by calculation based on daily cycle changes, weekly cycle changes, and time decay. The device status factor is calculated based on the current security score, version difference, and update time. The identity authentication factor is calculated based on the identity recognition information entropy, usage duration, and replacement frequency.

[0020] In some embodiments of this disclosure, the authentication score corresponding to the authentication weight includes a geographical location score corresponding to the geographical location factor, a time score corresponding to the time factor, a device status score corresponding to the device status factor, and an identity authentication score corresponding to the identity authentication factor; determining the authentication score based on the authentication weight includes: The geographical location score is obtained by calculating the geographical location factor based on the first scoring function corresponding to the geographical location factor; The time factor is calculated based on the second scoring function corresponding to the time factor to obtain the time score; The equipment status factor is calculated based on the third scoring function corresponding to the equipment status factor to obtain the equipment status score; The identity authentication score is obtained by calculating based on the fourth scoring function corresponding to the identity authentication factor.

[0021] In some embodiments of this disclosure, after obtaining the near-field authentication result and the messaging platform authentication result, the following steps are included: Determine the reliability scores of the near-field authentication result and the message platform authentication result, and fuse the near-field authentication result, the message platform authentication result, the reliability score corresponding to the near-field authentication result, and the reliability score corresponding to the message platform authentication result through an authentication fusion function to obtain a fusion result; If both the near-field authentication result and the message platform authentication result are confirmed to be successful, a small positive factor is introduced into the fusion result to improve the fusion score.

[0022] In some embodiments of this disclosure, the comprehensive authentication result includes a credibility authentication score and an authentication strength. Determining the credibility authentication score and the authentication strength based on the authentication score includes: The weighted and fused authentication score is subjected to nonlinear normalization to obtain the credibility authentication score; The credibility authentication score is transformed to obtain the authentication strength.

[0023] In some embodiments of this disclosure, the step of performing network analysis on dynamic factors to obtain network analysis results, and generating dynamic access control policies based on the comprehensive authentication results and the network analysis results, includes: Network analysis is performed on the dynamic factors to obtain the network analysis results. Based on the received comprehensive authentication results and the network analysis results, an access permission score is generated. The dynamic factors include at least network topology and device relationships. The access permission score is optimized to obtain an optimized access permission score, and a dynamic access control policy is generated based on the optimized access permission score.

[0024] In some embodiments of this disclosure, optimizing the access permission score to obtain an optimized access permission score, and generating a dynamic access control policy based on the optimized access permission score, includes: The access permission score is optimized by introducing a time decay factor and historical interaction similarity to obtain the optimized access permission score; The optimized access permission scores are divided into different access control levels based on predefined thresholds, and a dynamic access control policy is determined based on the access control levels.

[0025] In some embodiments of this disclosure, after sending the dynamic access control policy to the target device, the method further includes: Monitor the status information of the target device; wherein the status information includes at least one of device performance indicators, environmental parameters, functional status, and network behavior; Analyze the time-series data of the status information to determine whether there are any anomalies in the status information; If it is determined that the status information is abnormal, an abnormal prompt message corresponding to the status information is generated, and the abnormal prompt message is sent to the terminal through the message platform.

[0026] In some embodiments of this disclosure, after sending the dynamic access control policy to the target device, the method further includes: In response to receiving a control command from a terminal, coordinate the collaborative operation of the at least two target devices based on the control command; The collaboration status information and access permission information are sent to the message card generation module; wherein, the collaboration status information includes at least the connection status and task requirements; Based on the collaborative status information, the access permission information, and historical interaction data, a personalized message card is generated and sent to the terminal.

[0027] In some embodiments of this disclosure, after generating a personalized message card based on the collaborative status information, the access permission information, and historical interaction data, and sending the personalized message card to the terminal, the method further includes: The terminal interacts with the target device via the personalized message card to obtain historical interaction data; The historical interaction data is sent to the authentication enhancement module, access control module, device risk prediction and anomaly detection module, and message card generation module so that each module can be optimized and adjusted.

[0028] In some embodiments of this disclosure, before responding to a received access request and dynamically performing multi-factor authentication based on the access request to generate a comprehensive authentication result, the method further includes: A secure binding relationship is established between the terminal and the target device, and a near-field authentication token is generated; wherein, the near-field authentication token includes at least a communication device identifier, a timestamp, and a session key; The near-field authentication token is stored in the terminal and the target device so that the terminal and the target device can establish a trust relationship.

[0029] According to a third aspect of this disclosure, a device control apparatus is provided, comprising: An execution unit is used to respond to a received access request, dynamically perform multi-factor authentication based on the access request and context information, and generate a comprehensive authentication result. The first generation unit is used to perform network analysis on dynamic factors, obtain network analysis results, and generate dynamic access control policies based on the comprehensive authentication results and the network analysis results. The first sending unit is used to send the dynamic access control policy to the target device so that the target device can perform access control based on the dynamic access control policy.

[0030] In some embodiments of this disclosure, the execution unit includes: The acquisition module is used to acquire the context information; The adjustment module is used to dynamically adjust the authentication weights of the multi-factor authentication and the authentication scores corresponding to the authentication weights based on the context information, so as to obtain the adjustment result; The acquisition module is used to obtain near-field authentication results and message platform authentication results; The first generation module is used to generate the comprehensive authentication result based on the near-field authentication result, the message platform authentication result, and the adjustment result.

[0031] In some embodiments of this disclosure, the adjustment module includes: The first calculation submodule is used to calculate the geographic location factor based on the distance difference between the current location and the preset safe location and the duration of stay at the current location; The second calculation submodule is used to calculate the time factor based on daily cycle changes, weekly cycle changes, and time decay. The third calculation submodule is used to calculate the device status factor based on the current security score, version difference, and update time. The fourth calculation submodule is used to calculate the identity authentication factor based on the identity recognition information entropy, usage duration, and replacement frequency.

[0032] In some embodiments of this disclosure, the execution unit further includes a first determining module, the first determining module comprising: The fifth calculation submodule is used to calculate the geographic location factor based on the first scoring function corresponding to the geographic location factor after the adjustment module dynamically adjusts the authentication weight of the multi-factor authentication and the authentication score corresponding to the authentication weight according to the context information and obtains the adjustment result; The sixth calculation submodule is used to calculate the time factor based on the second scoring function corresponding to the time factor to obtain the time score; The seventh calculation submodule is used to calculate the equipment status factor based on the third scoring function corresponding to the equipment status factor to obtain the equipment status score; The eighth calculation submodule is used to calculate the identity authentication score based on the fourth scoring function corresponding to the identity authentication factor.

[0033] In some embodiments of this disclosure, the execution unit further includes: The second determining module is used to determine the reliability scores of the near-field authentication results and the message platform authentication results after the obtaining module obtains the near-field authentication results and the message platform authentication results, and to fuse the near-field authentication results, the message platform authentication results, the reliability scores corresponding to the near-field authentication results and the message platform authentication results corresponding to the message platform authentication results through an authentication fusion function to obtain a fusion result; An introduction module is used to improve the fusion score by introducing a small positive factor into the fusion result when both the near-field authentication result and the message platform authentication result are successfully authenticated.

[0034] In some embodiments of this disclosure, the comprehensive authentication result includes a credibility authentication score and authentication strength, and the apparatus further includes a determining unit, which includes: The first processing module is used to perform non-linear normalization processing on the weighted and fused authentication score to obtain the credibility authentication score. The second processing module is used to transform the credibility authentication score to obtain the authentication strength.

[0035] In some embodiments of this disclosure, the first generation unit includes: The second generation module is used to perform network analysis on the dynamic factors, obtain the network analysis results, and generate access permission scores based on the received comprehensive authentication results and the network analysis results; wherein, the dynamic factors include at least network topology and device relationships; The third generation module is used to optimize the access permission score to obtain an optimized access permission score, and generate a dynamic access control policy based on the optimized access permission score.

[0036] In some embodiments of this disclosure, the third generation module includes: A submodule is introduced to optimize the access permission score by incorporating a time decay factor and historical interaction similarity, thereby obtaining the optimized access permission score. The determination submodule is used to divide the optimized access permission score into different access control levels according to a predefined threshold, and to determine a dynamic access control policy based on the access control level.

[0037] In some embodiments of this disclosure, the apparatus further includes: The monitoring unit is used to monitor the status information of the target device after the first sending unit sends the dynamic access control policy to the target device; wherein the status information includes at least one of device performance indicators, environmental parameters, functional status and network behavior; The analysis unit is used to analyze the time-series data of the status information and determine whether there is any abnormality in the status information; The second generation unit is used to generate an abnormality prompt message corresponding to the status information when it is determined that there is an abnormality in the status information, and send the abnormality prompt message to the terminal through a message platform.

[0038] In some embodiments of this disclosure, the apparatus further includes: The coordination unit is configured to coordinate the collaborative work of at least two target devices based on the control command received from the terminal after the first sending unit sends the dynamic access control policy to the target device. The second sending unit is used to send the collaboration status information and access permission information to the message card generation module; wherein, the collaboration status information includes at least the connection status and task requirements; The third generation unit is used to generate personalized message cards based on the collaborative status information, the access permission information, and historical interaction data, and send the personalized message cards to the terminal.

[0039] In some embodiments of this disclosure, the apparatus further includes: An interaction unit is used to generate a personalized message card based on the collaborative status information, the access permission information, and historical interaction data by the third generation unit, and send the personalized message card to the terminal. After that, the terminal interacts with the target device through the personalized message card to obtain historical interaction data. The third sending unit is used to send the historical interaction data to the authentication enhancement module, access control module, device risk prediction and anomaly detection module, and message card generation module so that each module can be optimized and adjusted.

[0040] In some embodiments of this disclosure, the apparatus further includes: An establishment unit is configured to establish a secure binding relationship between the terminal and the target device and generate a near-field authentication token before the execution unit, in response to a received access request, dynamically performs multi-factor authentication based on the access request and generates a comprehensive authentication result; wherein the near-field authentication token includes at least a communication device identifier, a timestamp, and a session key; A storage unit is used to store the near-field authentication token to the terminal and the target device so that the terminal and the target device can establish a trust relationship.

[0041] According to a fourth aspect of this disclosure, an electronic device is provided, comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method described in the second aspect of the preceding embodiments.

[0042] According to a fifth aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are configured to cause the computer to perform the method described in the second aspect of the preceding description.

[0043] According to a sixth aspect of this disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the method described in the second aspect of the foregoing.

[0044] In summary, this disclosure provides a device control system, method, apparatus, electronic device, and storage medium. The system includes an authentication enhancement module and an access control module. The authentication enhancement module, in response to a received access request, dynamically performs multi-factor authentication based on the context information, generates a comprehensive authentication result, and sends the comprehensive authentication result to the access control module. The access control module performs network analysis on dynamic factors, obtains network analysis results, generates a dynamic access control policy based on the received comprehensive authentication result and network analysis results, and sends the dynamic access control policy to the target device so that the target device can execute access control based on the dynamic access control policy. By dynamically executing multi-factor authentication and access control, dynamic adaptation between the authentication process and the dynamic access control policy is achieved, improving system security while enhancing the adaptability of access control.

[0045] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent from the following description. Attached Figure Description

[0046] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein: Figure 1 This is a schematic diagram of the structure of a device control system provided in an embodiment of the present disclosure; Figure 2 This is a schematic diagram of another device control system provided in an embodiment of the present disclosure; Figure 3 This is an interactive architecture diagram of a device control system provided in an embodiment of the present disclosure; Figure 4 This is a schematic flowchart of a device control method provided in an embodiment of the present disclosure; Figure 5 This is a schematic flowchart illustrating another device control method provided in an embodiment of this disclosure; Figure 6 This is a schematic flowchart illustrating another device control method provided in an embodiment of this disclosure; Figure 7 This is a schematic flowchart illustrating another device control method provided in an embodiment of this disclosure; Figure 8 This is a schematic flowchart illustrating another device control method provided in an embodiment of this disclosure; Figure 9 This is a schematic flowchart illustrating another device control method provided in an embodiment of this disclosure; Figure 10 This is a schematic flowchart illustrating another device control method provided in an embodiment of this disclosure; Figure 11 This is a schematic flowchart illustrating another device control method provided in an embodiment of this disclosure; Figure 12 This is a schematic flowchart illustrating another device control method provided in an embodiment of this disclosure; Figure 13 A schematic diagram illustrating an anomaly notification of a device control method provided in an embodiment of this disclosure; Figure 14 This is a schematic flowchart illustrating another device control method provided in an embodiment of this disclosure; Figure 15 This is a schematic diagram of a message card for a device control method provided in an embodiment of the present disclosure; Figure 16 This is a schematic flowchart illustrating another device control method provided in an embodiment of this disclosure; Figure 17 This is a schematic flowchart illustrating another device control method provided in an embodiment of this disclosure; Figure 18An interaction diagram illustrating a device control method provided in an embodiment of this disclosure; Figure 19 This is a schematic diagram of the structure of a device control apparatus provided in an embodiment of the present disclosure; Figure 20 This is a schematic diagram of another device control apparatus provided in an embodiment of the present disclosure; Figure 21 A schematic block diagram of an example electronic device provided for embodiments of this disclosure. Detailed Implementation

[0047] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0048] The following description, with reference to the accompanying drawings, describes an embodiment of the device control system, method, apparatus, electronic device, and storage medium.

[0049] Figure 1 This is a schematic diagram of the structure of a device control system provided in an embodiment of the present disclosure.

[0050] like Figure 1 As shown, the system includes: an authentication enhancement module 11 and an access control module 12; wherein, The authentication enhancement module 11 is used to respond to the received access request, dynamically perform multi-factor authentication based on the access request and context information, generate a comprehensive authentication result, and send the comprehensive authentication result to the access control module 12.

[0051] In some embodiments, an access request may be initiated by a user through a terminal to request access to or control a target device. Context information refers to various real-time status information related to the access request, such as the geographical location of the terminal initiating the access request, the current time of the access request, the operating status of the target device, and the user's identity information. Dynamically executing multi-factor authentication refers to adjusting the factors involved in the authentication and their weights in the authentication process according to different context information. Multi-factor authentication includes, but is not limited to, geographical location factors, time factors, device status factors, and identity authentication factors extracted based on context information. The comprehensive authentication result is an overall evaluation result of the authentication process, a quantitative value used to characterize the authentication credibility, and an indicator used to reflect the authentication strictness. When the authentication enhancement module 11 receives an access request, it collects the context information related to the access request, selects appropriate multi-factor authentication based on the context information, dynamically adjusts the weights of each multi-factor authentication, obtains a comprehensive authentication result by executing multi-factor authentication, and then transmits the comprehensive authentication result to the access control module 12. It should be noted that the above examples are merely illustrative and do not limit the specific content.

[0052] The access control module 12 is used to perform network analysis on dynamic factors, obtain network analysis results, generate a dynamic access control policy based on the received comprehensive authentication result and the network analysis results, and send the dynamic access control policy to the target device so that the target device can perform access control based on the dynamic access control policy.

[0053] In some embodiments, dynamic factors refer to network-related dynamic information that affects device access permissions. Dynamic factors include at least network topology and device relationships. Network topology refers to the connection method and layout of each device node in the Internet of Things, and device relationships refer to the degree of association or dependency between different devices. Network analysis results are information obtained after analyzing dynamic factors (such as the location of devices in the network, the connection strength between devices, etc.). After receiving the comprehensive authentication result, the access control module 12 performs network analysis on the dynamic factors to obtain network analysis results. Then, combining the comprehensive authentication result and the network analysis result, it calculates and determines the access permissions of different access subjects to the target device, and then generates a dynamic access control policy. The dynamic access control policy is used to specify the types and scope of operations that access subjects can perform on the target device. After the access control module 12 sends the generated dynamic access control policy to the target device, the target device will respond to the access request according to the dynamic access control policy, allowing or restricting the corresponding access operations.

[0054] Through the above structure, the authentication enhancement module 11 dynamically performs multi-factor authentication based on context information, enabling the authentication process to adapt to different scenario changes and improving the adaptability and reliability of authentication; the access control module 12 combines the comprehensive authentication results and network analysis results to generate dynamic access control policies, enabling access control to be adjusted according to the authentication situation and network dynamic factors, realizing flexible management and control of target devices, and meeting the needs of device control in the Internet of Things environment in terms of security and dynamic adaptability.

[0055] In summary, this disclosure provides a device control system, which includes an authentication enhancement module and an access control module. The authentication enhancement module, in response to a received access request, dynamically performs multi-factor authentication based on the context information, generates a comprehensive authentication result, and sends the comprehensive authentication result to the access control module. The access control module performs network analysis on dynamic factors, obtains network analysis results, generates a dynamic access control policy based on the received comprehensive authentication result and network analysis results, and sends the dynamic access control policy to the target device so that the target device can execute access control based on the dynamic access control policy. By dynamically executing multi-factor authentication and access control, dynamic adaptation between the authentication process and the dynamic access control policy is achieved, improving system security while enhancing the adaptability of access control.

[0056] Figure 2 A schematic diagram of the structure of a device control system provided in an embodiment of this disclosure is further shown.

[0057] like Figure 2 As shown, the authentication enhancement module 11 is further configured to: Collect the aforementioned context information.

[0058] In some embodiments, context information can be collected through built-in sensors or associated services of the terminal and target device; for example, geographical location can be obtained through the terminal's GPS module, base station positioning, or WiFi positioning; the current time can be obtained through the clock module of the terminal or system; device status can be extracted from the target device's operation logs, etc.; identification information includes, but is not limited to, the terminal's SIM card information, device unique identifier, etc.; the collection process can be triggered when an access request is initiated, acquiring context information in real time and transmitting it to the authentication enhancement module 11. It should be noted that the above examples are merely illustrative and do not limit the specific content.

[0059] The authentication weights of the multi-factor authentication and the authentication scores corresponding to the authentication weights are dynamically adjusted based on the context information to obtain the adjustment results.

[0060] In some embodiments, authentication weight refers to the degree of influence of each authentication factor in multi-factor authentication, and authentication score refers to the quantitative value calculated based on the authentication factors. Dynamic adjustment can be implemented based on preset rules or preset algorithms. For example, when the terminal's geographical location deviates significantly from a preset security zone, the weight of the geographical location factor is increased; when the target device has recently undergone security updates, the weight of the device status factor is increased, etc. The adjustment result includes the adjusted authentication weight and the corresponding authentication score, which are used to generate a comprehensive authentication result. It should be noted that the above examples are merely illustrative and do not limit the specific content.

[0061] Based on the near-field authentication result, the message platform authentication result, and the adjustment result obtained by the near-field automatic authentication and binding module 16, the comprehensive authentication result is generated; wherein, the near-field authentication result is used to characterize the result of the terminal and the target device completing the initial authentication binding through near-field communication, and the message platform authentication result is used to characterize the result of the terminal initiating identity authentication through the message platform.

[0062] In some embodiments, when the authentication enhancement module 11 dynamically performs multi-factor authentication and generates a comprehensive authentication result based on context information, the algorithm used is the "Context-Aware Dynamic Weight Fusion Authentication Algorithm (CADWFAA)". The idea of ​​this algorithm is to dynamically adjust the weight of each authentication factor according to the current context and use a non-linear function to enhance security. The calculation formula is shown in Formula 1.

[0063]

[0064] Where σ(x) is the sigmoid function, calculated using the formula: The function's purpose is to... The calculated results are mapped to the (0,1) interval to achieve nonlinear normalization and ensure that this part of the results is within a uniform quantization range; This represents a weighted sum of four authentication factors, which correspond to the geographic location factor, time factor, device status factor, and identity authentication factor, respectively. These factors correspond one-to-one with the geographic location (L), current time (T), device status (D), and identity recognition information (S) in the context information. It is the dynamic weight of the i-th authentication factor, a function of the context information C, used to dynamically adjust the influence of each authentication factor in the overall authentication based on the current context; It is the scoring function for the i-th authentication factor, used to generate a quantitative score for the corresponding authentication factor, specifically including geographic location score, time score, device status score and identity authentication score; It is the input value of the i-th authentication factor, corresponding to the original feature data of each authentication factor.

[0065] This is the authentication fusion item, used to merge the near-field authentication result and the message platform authentication result. N is the near-field authentication result provided by the Near-Field Automatic Authentication and Binding Module (NFAAB), with a value of 0 or 1 (0 indicates authentication failure, 1 indicates authentication success); M is the identity authentication result provided by the 5G message platform, also with a value of 0 or 1 (0 indicates authentication failure, 1 indicates authentication success). It is the reliability score of the near-field authentication method, with a value ranging from 0 to 1. The specific value is defined by the business scenario and is used to characterize the trustworthiness of the near-field authentication method. It is a reliability score for the 5G messaging platform authentication method, with a value range of 0 to 1. It is defined by the business scenario and is used to characterize the credibility of the 5G messaging platform authentication method.

[0066] The CAWDFAA formula achieves context-aware adjustment of the weights of each authentication factor through dynamic weight allocation. It also integrates multi-dimensional information such as geographical location, current time, device status, and identity recognition information, and combines the dual-source results of near-field authentication and 5G messaging platform authentication. Finally, it obtains a comprehensive authentication score through non-linear normalization processing using the sigmoid function. This design enables the authentication system to flexibly adapt to different IoT scenarios, balance the influence of multi-dimensional authentication factors, and effectively improve the accuracy, security, and robustness of authentication, thereby addressing various security threats in the complex and ever-changing IoT environment.

[0067] Through the above structure, the authentication enhancement module 11 can obtain context information in real time and dynamically adjust authentication parameters, and generate a comprehensive authentication result by combining multi-source authentication results, thereby improving the flexibility and accuracy of the authentication process and enabling authentication to adapt to the security needs of different scenarios.

[0068] Please continue reading. Figure 2 The context information includes geographic location, current time, device status, and identity recognition information; the authentication weight of the multi-factor authentication includes the geographic location factor corresponding to the geographic location, the time factor corresponding to the current time, the device status factor corresponding to the device status, and the identity authentication factor corresponding to the identity recognition information. The authentication enhancement module 11 is also used for: The geographic location factor is calculated based on the distance difference between the current location and the preset safe location, as well as the duration of stay at the current location.

[0069] In some embodiments, when the authentication enhancement module 11 calculates the geolocation factor, it first uses a context influence function. Quantify the geographical location-related characteristics, as shown in Formula 2.

[0070]

[0071] in, The distance between the current position and the preset safe position is used to characterize the positional difference in the spatial dimension; This is a distance influence factor, used to adjust the degree of influence of distance differences on geographic location trust. The duration of the user's stay at the current location. As a time-related factor, the two are... These items collectively reflect the user's dwell time characteristics at the current location over time; subsequently, the weights of the geographic location factor are calculated using the dynamic weight formula shown in Formula 3.

[0072]

[0073] in, These are parameters that can be iteratively adjusted according to business needs, used to characterize the importance of geolocation factors in multi-factor authentication. Right now This dynamic weighting formula integrates the contextual influence of the geographic location factor with the influence of other certification factors to determine its weight in the overall certification process, thus forming the geographic location factor.

[0074] The time factor is obtained by calculation based on daily cycle changes, weekly cycle changes, and time decay.

[0075] In some embodiments, when the authentication enhancement module 11 calculates the time factor, it first uses the context influence function. Integrate the time dimension features, as shown in Formula 4.

[0076]

[0077] Where T represents the current hour (0-23). To preset a safe time point, The term simulates the daily cycle using a cosine function, mapping the time differences within a day to a value in the range of 0-1; W represents the current day of the week (0-6). To set the nearest day of the week corresponding to the preset safe time, Similarly, the cyclical changes are simulated; ΔT is the normalized time interval since the last certification (normalized to the range of 0-1). The time decay factor, The item reflects the characteristics of time decay; then, Substituting into the dynamic weight formula, the corresponding As an iterable parameter characterizing the importance of the time factor, the weight of the time factor is calculated by combining the influence function of other certification factors, thus forming the time factor.

[0078] The device status factor is calculated based on the current security score, version differences, and update time.

[0079] In some embodiments, when the authentication enhancement module 11 calculates the device state factor, it first uses the context influence function. Integrate device safety features, as shown in Formula 5.

[0080]

[0081] in, The current safety score of the device. As a benchmark security score, As a safety score influencing factor, The term is the Sigmoid function, which quantifies the current security state; This is the current version number of the device. This is the latest security version number. Version difference influencing factors The impact of version differences in item quantification; This refers to the time since the device was last updated. To update the time impact factor, The timeliness of quantitative updates will be affected; subsequently, Substituting into the dynamic weight formula, the corresponding As an iterable parameter characterizing the importance of equipment status factors, the weights of equipment status factors are calculated by combining the influence functions of other certification factors, thus forming equipment status factors.

[0082] The identity authentication factor is calculated based on the identity recognition information entropy, usage duration, and replacement frequency.

[0083] In some embodiments, the identification information is SIM card information. When the authentication enhancement module 11 calculates the authentication factor, it first uses a context influence function. Integrate SIM card features, as shown in Formula 6.

[0084]

[0085] Where H(S) is the hash value of the SIM card identification number. For the safe hash threshold, The hash matching degree influence factor. The term is the Sigmoid function, which quantifies information entropy (credibility). For SIM card usage time, As a time-related factor, The initial penalty factor for the new card. Item quantification for stability; This refers to the number of recent replacements. To change the frequency influence factor, The frequency of item replacement has an impact; subsequently, Substituting into the dynamic weight formula, the corresponding An iterable parameter characterizing the importance of the SIM card authentication factor is used to calculate the weight of the authentication factor by combining it with the influence function of other authentication factors, thus forming the authentication factor.

[0086] Through the above structure, the authentication enhancement module 11 integrates the key features of the corresponding dimension for each authentication factor through a dedicated context influence function, and relies on a unified dynamic weight formula combined with business-adjustable parameters to realize the dynamic allocation of the weight of each factor. This design ensures that the calculation of each authentication factor closely follows the actual context and can flexibly adjust the importance ratio according to business needs, providing accurate and dynamic quantitative basis for multi-factor authentication and improving the adaptability and accuracy of multi-factor authentication in complex IoT environments.

[0087] Please continue reading. Figure 2 The authentication score corresponding to the authentication weight includes the geographical location score corresponding to the geographical location factor, the time score corresponding to the time factor, the device status score corresponding to the device status factor, and the identity authentication score corresponding to the identity authentication factor. The authentication enhancement module 11 is also used for: The geographical location score is obtained by calculating the geographical location factor based on the first scoring function corresponding to the geographical location factor.

[0088] In some embodiments, the first scoring function is a dedicated calculation function for geographic location scoring, as shown in Formula 7.

[0089]

[0090] This function quantifies the security characteristics of geolocation factors, providing geolocation-dimensional scoring input for the CADWFAA algorithm; where, The distance between the current position and the preset safe position is used to characterize the positional deviation in the spatial dimension; This is the distance influence factor, used to adjust the degree of influence of distance deviation on the score. The item maps the distance deviation to a value in the 0-1 range using an exponential function, thereby achieving spatial similarity assessment. The duration of the user's stay at the current location. As a time-related factor, The term quantifies the user's dwell time at the current location over time using an exponential function; the longer the dwell time, the closer the value of this term is to 1. When calculating, the authentication enhancement module 11 incorporates the parameters corresponding to the geographic location factor ( , , , Substituting this into the first scoring function, we can directly obtain the geographic location score.

[0091] The time factor is calculated based on the second scoring function corresponding to the time factor to obtain the time score.

[0092] In some embodiments, the second scoring function is a time-specific scoring function, as shown in Formula 8.

[0093]

[0094] Used to quantify the behavioral characteristics of the time factor, providing the time dimension scoring input for the weighted summation term of the CADWFAA algorithm; where T is the current hour (range 0-23). The nearest time point in the preset usable time period. The term simulates the periodic changes in time within a 24-hour day using a cosine function, mapping time differences to values ​​between -1 and 1, and then... Convert to a daily cycle score in the 0-1 range. This is the daily cycle adjustment factor, used to adjust the degree of influence of daily cycle changes on the score; W is the current day of the week (value range 0-6). To preset the nearest day of the week for when it will be available, Similarly, the time-periodic changes over a 7-day week are simulated, and then converted into a weekly cycle score in the 0-1 range using the corresponding Sigmoid function. For the periodic adjustment factor; the authentication enhancement module 11 will adjust the parameters (T, ...) corresponding to the time factor. , W , Substitute the values ​​into the second scoring function to obtain the time score.

[0095] The equipment status score is obtained by calculating the equipment status factor based on the third scoring function corresponding to the equipment status factor.

[0096] In some embodiments, the third scoring function is a dedicated calculation function for device status scoring, as shown in Formula 9.

[0097]

[0098] in, This is used to quantify the safety characteristics of equipment state factors, providing equipment-level scoring input for the weighted summation term of the CADWFAA algorithm; among which, The current security score for IoT devices. As a benchmark security score, As a factor influencing the safety score, The item is a Sigmoid function, which maps the difference between the current safety score and the baseline score to a value in the range of 0-1, thereby quantifying the safety status of the device. This is the current version number of the device. This is the latest security version number. As a factor affecting version differences, The item maps version differences to values ​​in the 0-1 range through linear adjustment; the smaller the version difference, the closer the value of the item is to 1. The authentication enhancement module 11 maps the parameters corresponding to the device status factors ( , , , , , Substitute the values ​​into the third scoring function to obtain the equipment status score.

[0099] The identity authentication score is obtained by calculating based on the fourth scoring function corresponding to the identity authentication factor.

[0100] In some embodiments, the identity authentication factor is specifically the SIM card identity authentication factor, and the fourth scoring function is a dedicated calculation function for SIM card identity recognition scoring, as shown in Formula 10.

[0101]

[0102] Used to quantify the trustworthy features of SIM card identity authentication factors, providing the identity dimension scoring input for the weighted summation term of the CADWFAA algorithm; where H(S) is the hash value of the SIM card identity code. The preset safe hash threshold, The factors influencing hash matching degree The term is the Sigmoid function, which maps the SIM card information entropy (hash value difference) to a value in the range of 0-1, thereby quantifying the credibility of SIM card information; For SIM card usage time, For the time-influence factor parameter, The initial penalty factor parameter for the new SIM card. The term quantifies the stability of SIM card usage using an exponential function; the longer the usage time, the closer the value of this term is to 1. The authentication enhancement module 11 will assign parameters (H(S)) corresponding to the SIM card identity authentication factor. , , , , Substitute the values ​​into the fourth scoring function to obtain the identity authentication score.

[0103] Through the above structure, the authentication enhancement module 11 configures a dedicated scoring function for each authentication factor, quantifies the feature parameters of each factor into a unified score in the 0-1 range, and works in conjunction with the dynamic weights of each factor to provide accurate multi-dimensional quantitative input for the CADWFAA algorithm.

[0104] Please continue reading. Figure 2 The authentication enhancement module 11 is further configured to: Determine the reliability scores of the near-field authentication result and the message platform authentication result, and fuse the near-field authentication result, the message platform authentication result, the reliability score corresponding to the near-field authentication result, and the reliability score corresponding to the message platform authentication result through an authentication fusion function to obtain a fusion result.

[0105] In some embodiments, the authentication fusion function used by the authentication enhancement module 11 is: As shown in Formula 11.

[0106]

[0107] Wherein, N is the near-field authentication result provided by the near-field automatic authentication and binding module, with a value of 0 (authentication failed) or 1 (authentication successful); M is the user identity authentication result provided by the 5G messaging platform, with a value of 0 (authentication failed) or 1 (authentication successful). The reliability score for the near-field authentication method ranges from 0 to 1 and is defined by the business scenario. It is used to characterize the trustworthiness of the near-field authentication method. The reliability score for the 5G messaging platform authentication method ranges from 0 to 1 and is also defined by the business scenario. It is used to characterize the trustworthiness of the messaging platform authentication method. It is a small positive number (e.g., 0.01), its purpose is to avoid the denominator ( + + If N is zero, the validity of the function calculation is guaranteed, and the fusion result is adjusted under specific conditions; the authentication enhancement module 11 will, during calculation, acquire the N, M, ... , and preset Substituting into the formula, we can directly obtain the quantitative value of the fused two authentication results, which is the fused result.

[0108] If both the near-field authentication result and the message platform authentication result are confirmed to be successful, a small positive factor is introduced into the fusion result to improve the fusion score.

[0109] In some embodiments, when both the near-field authentication result N and the message platform authentication result M are 1 (i.e., both authentications are successful), the authentication fusion function... middle The value of the item is *1*1= This makes the molecular part "1* +1* + The denominator is " + + At this point, the fusion result is "( + + ) / ( + + =1”; compared to not introduced The situation (i.e.) When =0, the fusion result is "( + ) / ( + Although both are numerically 1, )=1”, The existence of this term, through the addition of an extra term in the numerator, achieves a positive incentive for successful dual authentication scenarios in terms of computational logic, increases the relative weight of the fusion score, and highlights the high credibility of successful dual authentication.

[0110] With the above structure, the authentication enhancement module 11 relies on the authentication fusion function This achieves a quantitative fusion of near-field authentication and message platform authentication results, both through... and It balances the importance of the two authentication methods, and also uses small positive numbers This design ensures the robustness of computation and enhances the credibility of successful dual authentication. It enables the fusion results to comprehensively reflect the overall situation of multi-source authentication, improves the flexibility and reliability of the authentication process, and effectively adapts to the security authentication needs in complex IoT environments.

[0111] Please continue reading. Figure 2 The comprehensive authentication result includes a credibility authentication score and authentication strength. The authentication enhancement module 11 is also used for: The credibility authentication score is obtained by performing nonlinear normalization on the weighted and fused authentication score.

[0112] In some embodiments, the weighted fusion authentication score refers to the score obtained through the CADWFAA algorithm. The calculated weighted summation result; nonlinear normalization is performed using the sigmoid function in the CADWFAA algorithm. To achieve this, the weighted summation result is mapped to the (0,1) interval, and then combined with the authentication fusion function. The outputs are multiplied to obtain the final result, which is the credibility certification score. The score range is limited to 0 to 1 and is directly given by the CADWFAA algorithm. The higher the value, the higher the credibility of the certification. It can intuitively quantify the comprehensive credibility of multi-factor certification and dual-source certification results.

[0113] The credibility authentication score is transformed to obtain the authentication strength.

[0114] In some embodiments, the transformation processing performed by the authentication enhancement module 11 on the credibility authentication score employs a specific logarithmic transformation, as shown in Formula 12.

[0115]

[0116] Since the credibility authentication score is given by the CAWDFAA algorithm and ranges from 0 to 1, when the credibility authentication score is 0, the authentication strength is 0. As the credibility authentication score gradually approaches 1, 1-CADWFAA gradually approaches 0, and the negative value of its logarithm (i.e. authentication strength) tends to positive infinity. Through this transformation, the credibility score in the 0-1 interval is mapped to the range of 0 to positive infinity, so that a higher credibility score corresponds to a higher authentication strength, which more intuitively reflects the rigor and security level of the authentication.

[0117] Through the above structure, the authentication enhancement module 11 obtains a credibility authentication score in the 0-1 range through nonlinear normalization, which intuitively reflects the credibility of the authentication; then, it obtains the authentication strength through logarithmic transformation, amplifying the security level differences in high credibility scenarios; the two quantify the comprehensive authentication results from different dimensions, which not only ensures the interpretability of the score, but also enhances the distinguishability of security levels, providing accurate and multi-level authentication basis for the access control module 12 to formulate dynamic policies, and improving the system's adaptability to different security scenarios.

[0118] Please continue reading. Figure 2 The access control module 12 is further configured to: Network analysis is performed on the dynamic factors to obtain the network analysis results. Based on the received comprehensive authentication results and the network analysis results, an access permission score is generated. The dynamic factors include at least network topology and device relationships.

[0119] In some embodiments, when the access control module 12 performs network analysis on dynamic factors, it first constructs the IoT network topology and defines a network graph G=(V,E), where V is the set of device nodes and E is the set of connections between devices; and determines the set of neighboring devices of device d. The strength of the relationship between device d and its neighboring device j is calculated by methods such as the total amount of communication data traffic. and the strength of the relationship with all devices k in the network. Simultaneously, a graph neural network (GNN) is used to preprocess device i to obtain the resulting vector representation. The above together constitute the network analysis results; when generating the access permission score, the calculation formula is as shown in Formula 13.

[0120]

[0121] in, is a sigmoid function used to normalize the result to the [0,1] interval; α, β, γ, δ are adjustable weight parameters; AuthStrength and CADWFAA are the authentication strength and credibility scores in the comprehensive authentication result; The comprehensive features of neighboring devices of device d after processing by GNN; The strength of the relationship between device d and its neighboring devices is represented by the ratio of the strength of its relationship with all devices in the network. The access control module 12 substitutes the comprehensive authentication result and the network analysis result into formula 13 to calculate the access permission score P(u,d) of user u to device d.

[0122] The access permission score is optimized to obtain an optimized access permission score, and a dynamic access control policy is generated based on the optimized access permission score.

[0123] In some embodiments, the access control module 12 optimizes the access permission score through a policy optimization function, as shown in Formula 14.

[0124]

[0125] in, The optimized access permission score; λ is the time decay factor, t is the time since the last policy update, and τ is the time constant. This item is used to reduce the credibility of permissions that have not been used for a long time; μ is the historical similarity influence factor parameter. Let be the set of devices that user u has historically visited, and sim(d,k) be the cosine similarity between device d and the historically visited device k. For average historical interaction similarity, This item is used to adjust permissions based on the user's past interaction patterns; after obtaining... Then, the access control module 12 generates a dynamic policy by quantizing it into discrete access control levels, and the quantization rule is shown in Formula 15.

[0126]

[0127] in, For the predefined thresholds, 0 corresponds to no access permission, 1 corresponds to read-only permission, 2 corresponds to partial control permission, and 3 corresponds to full control permission.

[0128] Through the above structure, the access control module 12 integrates the comprehensive authentication results with dynamic factors such as network topology and device relationships. It achieves precise quantification and dynamic adjustment of access permissions through multi-dimensional scoring formulas and policy optimization functions, which solves the problem that traditional static access control is difficult to adapt to complex IoT environments and improves the security, flexibility and accuracy of access control.

[0129] Please continue reading. Figure 2 The access control module 12 is further configured to: The access permission score is optimized by introducing a time decay factor and historical interaction similarity to obtain the optimized access permission score.

[0130] In some embodiments, the time decay factor introduced by the access control module 12 is through This implementation uses λ as the time decay factor parameter, t as the time since the last policy update, and τ as a time constant. This time decay factor reduces the weight of long-unused permissions over time, avoiding security risks associated with long-term valid permissions. Historical interaction similarity is achieved through... The item is implemented, among which, Let be the set of devices that user u has historically visited. sim(d,k) is the cosine similarity between device d and historical device k. This term calculates the average similarity between the user's historically visited devices and the current device d, and then... (μ is the historical similarity influence factor parameter) The similarity is converted into a positive or negative adjustment to the permission score, making the permissions more consistent with the user's historical behavior patterns; the access control module 12 multiplies the time decay factor and historical interaction similarity with the initial access permission score P(u,d) to obtain the optimized access permission score. .

[0131] The optimized access permission scores are divided into different access control levels based on predefined thresholds, and a dynamic access control policy is determined based on the access control levels.

[0132] In some embodiments, the access control module 12 predefines a threshold. The optimized access permission score will be used. (Range [0,1]) is divided into four access control levels: when When, the corresponding level is 0 (no access); when When, it corresponds to level 1 (read-only permission); when When, it corresponds to level 2 (partial control permissions); when At that time, the corresponding level is 3 (full control permission); based on the divided access control level AccessLevel(u,d), the access control module 12 determines the specific dynamic access control policy, clarifies the scope of executable operations of user u on device d, and securely transmits the policy to the user's mobile terminal.

[0133] Through the above structure, the access control module 12 achieves dynamic optimization of permissions through time decay factor and historical interaction similarity, and achieves precise control of access level by combining threshold division. This enables the access control policy to adapt to changes in user behavior and the passage of time, while also clearly defining permission boundaries, effectively balancing system security and ease of use in the Internet of Things environment.

[0134] Please continue reading. Figure 2 The system further includes: an equipment risk prediction and anomaly detection module 13; used for: Monitor the status information of the target device; wherein the status information includes at least one of device performance indicators, environmental parameters, functional status, and network behavior.

[0135] In some embodiments, the device risk prediction and anomaly detection module 13 continuously monitors the status information of the target device, not limited to a single dimension; wherein, device performance indicators include, but are not limited to, parameters reflecting the device's operating load such as CPU utilization, memory usage, and network traffic; environmental parameters include, but are not limited to, physical characteristic parameters of the environment in which the device is located such as temperature and humidity; functional status includes, but is not limited to, the device's current operating status (such as normal operation, standby, fault pause), response rate, and other parameters reflecting the device's functional execution capability; network behavior includes, but is not limited to, whether the device is connected to the network, data transmission rate, and other parameters reflecting the device's network connection and data interaction; the above status information is acquired and temporarily stored through a preset monitoring period or real-time acquisition mechanism.

[0136] Analyze the time-series data of the status information to determine whether there are any anomalies in the status information.

[0137] In some embodiments, the equipment risk prediction and anomaly detection module 13 first organizes the continuously collected status information in chronological order to form time-series data of status information (i.e., a sequence of status parameters arranged in the time dimension); then, it uses a preset machine learning algorithm to analyze the time-series data (as shown in the convolutional network), and learns the regular features in the time-series data through the algorithm to construct a pattern model under normal operating conditions of the equipment; then, it compares the real-time collected time-series data with the normal pattern model to identify potential abnormal patterns that deviate from the normal pattern, thereby determining whether there is an anomaly in the current status information.

[0138] If it is determined that the status information is abnormal, an abnormal prompt message corresponding to the status information is generated, and the abnormal prompt message is sent to the terminal through the message platform.

[0139] In some embodiments, when the device risk prediction and anomaly detection module 13 determines that there is an anomaly in the status information through analysis (such as identifying anomaly types such as device failure, abnormal operation, or security threat), it generates an anomaly prompt message, which is presented in the form of a 5G message anomaly reminder card. The card content includes anomaly-related information (such as anomaly device identifier, anomaly type, anomaly occurrence time, anomaly details, etc.). Then, the 5G message anomaly reminder card is transmitted to the user's mobile terminal in real time through the 5G message platform to ensure that the user obtains device anomaly information in a timely manner.

[0140] Through the above structure, the equipment risk prediction and anomaly detection module 13 realizes continuous monitoring of the target equipment status, anomaly identification based on time-series data and machine learning algorithms, and real-time push of anomaly prompts. It can proactively discover risks and anomalies in equipment operation, prevent anomalies from escalating, and allow users to keep abreast of equipment status, effectively improving the security of the Internet of Things system and the reliability of equipment operation.

[0141] Please continue reading. Figure 2 The system further includes: a multi-device collaborative management module 14 and a message card generation module 15; wherein, The multi-device collaborative management module 14 is used to respond to a control command sent by the terminal and coordinate the collaborative work of at least two target devices based on the control command.

[0142] In some embodiments, when coordinating collaborative work, the multi-device collaborative management module 14 continuously analyzes the status (such as operating status, performance indicators, etc.) and task requirements (such as the operations and priorities that each device needs to perform) of all connected target devices; after receiving control commands sent by the terminal, it accurately distributes the commands to the corresponding IoT devices, drives the devices to perform corresponding operations, and optimizes the overall system performance (such as load balancing, resource allocation, etc.) during the execution process; at the same time, the module continuously monitors the execution effect of each device, and adjusts the status of the target devices in real time based on user feedback to ensure that the collaborative work meets user expectations.

[0143] The multi-device collaborative management module 14 is also used to send the collaborative status information to the message card generation module 15; wherein, the collaborative status information includes at least the connection status and task requirements.

[0144] In some embodiments, the collaborative status information sent by the multi-device collaborative management module 14 includes, in addition to connection status (such as whether the device is connected to the network, connection stability, etc.) and task requirements, device status (such as operating load, functional status, etc.) and network topology related information obtained through continuous analysis. This information together provides data support for the message card generation module 15 to build the context, ensuring that the generated message card can reflect the real-time situation of device collaboration.

[0145] The access control module 12 is also used to send access permission information to the message card generation module 15.

[0146] In some embodiments, the access permission information sent by the access control module 12 is based on the user's access control level (such as no access permission, read-only permission, etc.) and corresponding permission scope for each target device generated by the NAIAC module. This access permission information is used by the message card generation module 15 to constrain the operation options and device information that can be displayed in the personalized message card, ensuring that the card content matches the user's permissions.

[0147] The message card generation module 15 is used to receive the collaboration status information and the access permission information, generate a personalized message card based on the collaboration status information, the access permission information and historical interaction data, and send the personalized message card to the terminal.

[0148] In some embodiments, when generating personalized message cards, the message card generation module 15 collects three types of information: access permission information sent by the access control module 12, device status and network topology information (included in the collaborative status information) provided by the multi-device collaborative management module 14 and the device risk prediction and anomaly detection module 13, and the user's historical interaction data (such as historical click operation sequences). Subsequently, this information is processed by the fusion context personalized card generation method: first, the user and context fusion representation vector is calculated, as shown in Formula 16.

[0149]

[0150] Where u is the user's historical click operation sequence vector, and c is the context vector (integrating collaborative status, permissions, and other information). , Let b be a learnable weight matrix, b be a bias term, and σ( ) represents the sigmoid activation function, ⊙ represents element-wise multiplication, and ⊕ represents the concatenation operation, achieving a non-linear fusion of user preferences and context; then, a specific content generator is used to generate card elements, and the generation probability is calculated using formula 17.

[0151]

[0152] Where x is the content element to be generated for the card (such as title, operation buttons, etc.), and N is the number of elements. The generator function is shown in Equation 18.

[0153]

[0154] in, A collection of all content elements Let i be the template set of the i-th element. Let m be the scoring function for the fusion vector F (such as the BM25 algorithm), and ⊕ be the element combination operation; the final personalized 5G message card is pushed to the user terminal through the 5G message platform.

[0155] Through the above structure, the multi-device collaborative management module 14 realizes collaborative control and status monitoring of devices, and the message card generation module 15 generates a personalized interactive interface based on multi-dimensional information. The two work together to ensure the efficiency of device collaborative work and improve the user interaction experience through accurate information push.

[0156] Please continue reading. Figure 2 The message card generation module 15 is further configured to: The terminal interacts with the target device through the personalized message card to obtain historical interaction data.

[0157] In some embodiments, during data interaction between the terminal and the target device, the user initiates operations through personalized 5G message cards pushed by the message card generation module 15, such as clicking device control buttons on the card or viewing device status details. Information during the interaction is recorded in real time by the message card generation module 15, including but not limited to the time of the interaction, the type of operation performed by the user, the corresponding target device identifier, and the device's response to the operation. These records are then organized and stored in chronological order to form structured historical interaction data. It should be noted that the above examples are merely illustrative and do not limit the specific content.

[0158] The historical interaction data is sent to the authentication enhancement module 11, the access control module 12, the device risk prediction and anomaly detection module 13, and the message card generation module 15 so that each module can be optimized and adjusted.

[0159] In some embodiments, the message card generation module 15 transmits historical interaction data to the corresponding modules according to a preset period or in real-time triggering: For the authentication enhancement module 11 (EDMFA), historical interaction data can be used to analyze users' regular interaction scenarios and habits, thereby optimizing the dynamic multi-factor authentication strategy (such as adjusting the weight of authentication factors in different contexts); For the access control module 12 (NAIAC), historical interaction data can help identify users' frequently used devices and operating modes, and be used to adjust dynamic access control strategies (such as optimizing the calculation of device relationship strength or the weight of access permission scoring); For the device risk prediction and anomaly detection module 13 (DBPAD), historical interaction data can serve as a reference for normal behavior patterns, and be used to improve the accuracy of anomaly detection algorithms (such as updating the temporal feature model of normal interactions); For the message card generation module 15, historical interaction data can be used to learn users' preferences for card content and layout, thereby improving the personalized message card generation algorithm (such as optimizing the calculation parameters of the fusion representation vector or the scoring rules of the content template).

[0160] Through the above structure, the message card generation module 15 constructs a closed-loop feedback mechanism for the system by recording and distributing historical interaction data: every user interaction behavior can be transformed into the optimization basis for each module, so that the authentication strategy, access control strategy, anomaly detection capability and message card generation effect can be continuously iterated.

[0161] Please continue reading. Figure 2 The system further includes: a near-field automatic authentication and binding module 16; used for: A secure binding relationship is established between the terminal and the target device, and a near-field authentication token is generated; wherein, the near-field authentication token includes at least a communication device identifier, a timestamp, and a session key.

[0162] In some embodiments, the process by which the near-field automatic authentication and binding module 16 establishes a secure binding relationship and generates a near-field authentication token is as follows: When a user brings an NFC-enabled terminal close to a target device, NFC communication is triggered between the terminal and the target device; the terminal obtains the unique identifier of the target device through NFC communication and uploads the unique identifier to the near-field automatic authentication and binding module 16 of the platform system; after receiving the unique identifier, a secure authentication token containing a communication device identifier (identification information of the terminal and the target device), a timestamp (time information of token generation), and a session key (encryption key used for subsequent secure communication) is generated, i.e., a near-field authentication token; subsequently, the near-field authentication token is distributed to the terminal and the target device respectively, completing the distribution of the near-field authentication token.

[0163] The near-field authentication token is stored in the terminal and the target device so that the terminal and the target device can establish a trust relationship.

[0164] In some embodiments, after receiving the near-field authentication token issued by the near-field automatic authentication and binding module 16, the terminal and the target device will securely store it in their respective local secure storage areas (such as the terminal's security chip or the device's encrypted storage module). By storing the same near-field authentication token, an initial trust basis is formed between the terminal and the target device. In subsequent interactions, the identity of the other party can be confirmed by verifying the validity of the token (such as the validity of the timestamp and the matching of the session key), thereby establishing and maintaining a token-based trust relationship.

[0165] Through the above structure, the near-field automatic authentication and binding module 16 relies on NFC communication to realize close-range and rapid interaction between the terminal and the target device. By generating and storing a near-field authentication token containing security information, it provides a secure and convenient mechanism for establishing an initial trust relationship between the two, thereby improving the security and efficiency of the IoT device binding process.

[0166] Figure 3This is an interactive architecture diagram of a device control system provided in this embodiment. The interaction process is as follows: The user completes the initial binding between the terminal and the target device via the NFC system and the Near Field Automatic Authentication and Binding Module (NFAAB), and stores the near field authentication token to establish an initial trust relationship; the Authentication Enhancement Module (EDMFA) combines the user information from the messaging platform and the near field authentication result of NFAAB to perform dynamic multi-factor authentication, generates a comprehensive authentication result, and sends it to the Access Control Module (NAIAC); the NAIAC analyzes dynamic factors such as the network topology and device relationships of the IoT device network, generates a dynamic access control policy, sends it to the target device, and sends access permission information... The message card is sent to the Message Card Generation Module (CAMCG); the Device Risk Prediction and Anomaly Detection Module (DBPAD) monitors the device status, generates a prompt message when an anomaly occurs and sends it to the terminal, and simultaneously sends the device status information to the Multi-Device Collaborative Management Module (AMDCM) and CAMCG; AMDCM receives terminal control commands to coordinate the collaborative work of multiple devices and sends the collaborative status information to CAMCG; CAMCG combines access permission information, collaborative status information and user historical interaction data to generate personalized 5G message cards and pushes them to the terminal, and user interaction data is fed back to EDMFA, NAIAC, DBPAD and CAMCG to optimize the strategies or algorithms of each module.

[0167] Corresponding to the aforementioned equipment control system, this invention also proposes an equipment control method. Since the method embodiments of this invention correspond to the aforementioned system embodiments, details not disclosed in the method embodiments can be referred to the aforementioned system embodiments, and will not be repeated here.

[0168] Figure 4 This is a schematic flowchart of a device control method provided in an embodiment of the present disclosure.

[0169] like Figure 4 As shown, the method includes steps 101-102.

[0170] Step 101: In response to the received access request, multi-factor authentication is dynamically performed based on the access request using the context information to generate a comprehensive authentication result.

[0171] In some embodiments, the access request is initiated by the user through a terminal, and the context information includes, but is not limited to, geographic location, current time, device status, identity information, etc. When performing multi-factor authentication dynamically, the authentication weight and authentication score of the authentication factors (geographic location factor, time factor, device status factor, identity authentication factor) are adjusted according to the context information. The authentication results are combined with the near-field authentication results and the message platform authentication results to generate a comprehensive authentication result with credibility authentication score and authentication strength.

[0172] Step 102: Perform network analysis on dynamic factors to obtain network analysis results. Based on the comprehensive authentication results and the network analysis results, generate a dynamic access control policy and send the dynamic access control policy to the target device so that the target device can perform access control based on the dynamic access control policy.

[0173] In some embodiments, dynamic factors include at least network topology and device relationships; network analysis results include, but are not limited to, device network location, connection strength, etc.; when generating dynamic access control policies, the access permission score is calculated and optimized by combining the comprehensive authentication results and network analysis results, and the access control level is determined and sent to the target device, which then executes access control accordingly.

[0174] The above methods enable dynamic multi-factor authentication and dynamic access control policy generation, improving the security and dynamic adaptability of device control and meeting the device management needs in complex IoT environments.

[0175] In summary, this disclosure provides a device control method, which includes: responding to a received access request; dynamically performing multi-factor authentication based on the access request and context information to generate a comprehensive authentication result; performing network analysis on the dynamic factors to obtain network analysis results; generating a dynamic access control policy based on the comprehensive authentication result and the network analysis results; and sending the dynamic access control policy to the target device so that the target device can execute access control based on the dynamic access control policy. By dynamically executing multi-factor authentication and access control, the authentication process and the dynamic access control policy are dynamically adapted, improving system security while enhancing the adaptability of access control.

[0176] Figure 5 A flowchart illustrating a device control method provided in an embodiment of this disclosure is further shown. For example... Figure 5 As shown, the method includes: Step 201: Collect the context information.

[0177] Step 202: Dynamically adjust the authentication weights of the multi-factor authentication and the authentication scores corresponding to the authentication weights based on the context information to obtain the adjustment result.

[0178] Step 203: Obtain the near-field authentication result and the message platform authentication result, and generate the comprehensive authentication result based on the near-field authentication result, the message platform authentication result, and the adjustment result; wherein, the near-field authentication result is used to characterize the result of the terminal and the target device completing the initial authentication binding through near-field communication, and the message platform authentication result is used to characterize the result of the terminal initiating identity authentication through the message platform.

[0179] Figure 6A flowchart illustrating a device control method provided in an embodiment of this disclosure is further shown. For example... Figure 6 As shown, the method includes: Step 301: Calculate the geographic location factor based on the distance difference between the current location and the preset safe location and the duration of stay at the current location.

[0180] Step 302: Calculate the time factor based on daily cycle changes, weekly cycle changes, and time decay.

[0181] Step 303: Calculate the device status factor based on the current security score, version difference, and update time.

[0182] Step 304: Calculate the identity authentication factor based on the identity recognition information entropy, usage duration, and replacement frequency.

[0183] Figure 7 A flowchart illustrating a device control method provided in an embodiment of this disclosure is further shown. For example... Figure 7 As shown, the method includes: Step 401: Calculate the geographical location factor based on the first scoring function corresponding to the geographical location factor to obtain the geographical location score.

[0184] Step 402: Calculate the time factor based on the second scoring function corresponding to the time factor to obtain the time score.

[0185] Step 403: Calculate the equipment status factor based on the third scoring function corresponding to the equipment status factor to obtain the equipment status score.

[0186] Step 404: Calculate the identity authentication score based on the fourth scoring function corresponding to the identity authentication factor.

[0187] Figure 8 A flowchart illustrating a device control method provided in an embodiment of this disclosure is further shown. For example... Figure 8 As shown, the method includes: Step 501: Determine the reliability scores of the near-field authentication result and the message platform authentication result respectively, and fuse the near-field authentication result, the message platform authentication result, the reliability score corresponding to the near-field authentication result, and the reliability score corresponding to the message platform authentication result through an authentication fusion function to obtain a fusion result.

[0188] Step 502: If both the near-field authentication result and the message platform authentication result are successfully authenticated, a small positive factor is introduced into the fusion result to improve the fusion score.

[0189] Figure 9 A flowchart illustrating a device control method provided in an embodiment of this disclosure is further shown. For example... Figure 9 As shown, the method includes: Step 601: Perform nonlinear normalization on the weighted and fused authentication score to obtain the credibility authentication score.

[0190] Step 602: Transform the credibility authentication score to obtain the authentication strength.

[0191] Figure 10 A flowchart illustrating a device control method provided in an embodiment of this disclosure is further shown. For example... Figure 10 As shown, the method includes: Step 701: Perform network analysis on the dynamic factors to obtain the network analysis results. Based on the received comprehensive authentication results and the network analysis results, generate an access permission score. The dynamic factors include at least network topology and device relationships.

[0192] Step 702: Optimize the access permission score to obtain an optimized access permission score, and generate a dynamic access control policy based on the optimized access permission score.

[0193] Figure 11 A flowchart illustrating a device control method provided in an embodiment of this disclosure is further shown. For example... Figure 11 As shown, the method includes: Step 801: Introduce a time decay factor and historical interaction similarity to optimize the access permission score, and obtain the optimized access permission score.

[0194] Step 802: Divide the optimized access permission score into different access control levels according to a predefined threshold, and determine a dynamic access control policy based on the access control levels.

[0195] Figure 12 A flowchart illustrating a device control method provided in an embodiment of this disclosure is further shown. For example... Figure 12 As shown, the method includes: Step 901: Monitor the status information of the target device; wherein the status information includes at least one of device performance indicators, environmental parameters, functional status, and network behavior.

[0196] Step 902: Analyze the time-series data of the status information to determine whether there is any abnormality in the status information.

[0197] Step 903: If it is determined that the status information is abnormal, generate an abnormal prompt message corresponding to the status information and send the abnormal prompt message to the terminal through the message platform.

[0198] Figure 13 This is a schematic diagram of an anomaly prompt in a device control method provided in this embodiment. When the device risk prediction and anomaly detection module determines that there is an anomaly in the status information of the target device, it generates an anomaly prompt message containing the device ID, anomaly type, details and time. The message is sent to the terminal in the form of a 5G message card through the messaging platform. The terminal displays the anomaly prompt message and provides interactive options such as "view details" and "remotely shut down the device" to facilitate users to handle device anomalies in a timely manner.

[0199] Figure 14 A flowchart illustrating a device control method provided in an embodiment of this disclosure is further shown. For example... Figure 14 As shown, the method includes: Step 1001: In response to receiving a control command sent by the terminal, coordinate the collaborative work of the at least two target devices based on the control command.

[0200] Step 1002: Send the collaboration status information and access permission information to the message card generation module; wherein, the collaboration status information includes at least the connection status and task requirements.

[0201] Step 1003: Based on the collaborative status information, the access permission information, and historical interaction data, generate a personalized message card and send the personalized message card to the terminal.

[0202] Figure 15 This is a schematic diagram of a message card for a device control method provided in an embodiment of the present disclosure. The message card generation module generates a personalized message card based on access permission information, collaborative status information, and historical interaction data. The personalized message card includes the current status of the device, the last update time, operable options, and authentication level, and pushes it to the terminal for the user to view and interact with.

[0203] Figure 16 A flowchart illustrating a device control method provided in an embodiment of this disclosure is further shown. For example... Figure 16 As shown, the method includes: Step 1101: The terminal interacts with the target device through the personalized message card to obtain historical interaction data.

[0204] Step 1102: Send the historical interaction data to the authentication enhancement module, access control module, device risk prediction and anomaly detection module, and message card generation module so that each module can be optimized and adjusted.

[0205] Figure 17 A flowchart illustrating a device control method provided in an embodiment of this disclosure is further shown. For example... Figure 17 As shown, the method includes: Step 1201: Establish a secure binding relationship between the terminal and the target device, and generate a near-field authentication token; wherein the near-field authentication token includes at least a communication device identifier, a timestamp, and a session key.

[0206] Step 1202: Store the near-field authentication token in the terminal and the target device so that the terminal and the target device can establish a trust relationship.

[0207] Figure 18 An interactive diagram of a device control method provided in this embodiment of the disclosure is shown below, and the steps are as follows: Step 1: The terminal triggers near-field communication with the target device through the NFC system. The near-field automatic authentication and binding module obtains the unique identifier of the device and generates a near-field authentication token containing the communication identifier, timestamp and session key, which is stored in the terminal and the device to establish an initial trust relationship. Step 2: The authentication enhancement module receives the access request, dynamically adjusts the authentication weight and authentication score based on the context information, and merges the near-field authentication results with the message platform authentication results to generate a comprehensive authentication result containing a credibility score and authentication strength. Step 3: Receive the comprehensive authentication results, perform network analysis on dynamic factors such as network topology and device relationships, calculate and optimize access permission scores, generate dynamic access control policies and send them to the target device; Step 4: Continuously monitor the status information of the target device, analyze the time series data to identify anomalies, generate anomaly prompts and push them to the terminal via the message platform; Step 5: Receive terminal control commands, coordinate the collaborative work of multiple devices, and send collaborative information such as device connection status and task requirements to the message card generation module; Step 6: Combine access permission information, collaboration status information, and historical interaction data of the terminal to generate personalized message cards and push them to the terminal for terminal interaction; Step 7: Feedback the interaction data between the personalized message card and the device to the authentication enhancement module, access control module, device risk prediction and anomaly detection module, and message card generation module to optimize the strategies of each module.

[0208] The beneficial effects that can be achieved by the embodiments disclosed herein are as follows: 1. The system's CADWFAA algorithm provides higher security and adaptability, and can dynamically adjust the authentication factor weights according to the context.

[0209] 2. It can adapt to different usage scenarios and security requirements.

[0210] 3. The system's intelligent access control method takes into account network topology, device relationships, and user history behavior, providing more granular and dynamic access control.

[0211] 4. Dynamic rules enable it to cope with complex and ever-changing IoT environments.

[0212] 5. No additional applications need to be installed, lowering the barrier to entry for users.

[0213] 6. The lightweight interaction method based on 5G messaging improves response speed and user experience.

[0214] 7. The closed-loop feedback mechanism enables the system to continuously optimize itself and improve its intelligence level.

[0215] 8. A unified messaging interface simplifies multi-device management and improves system scalability.

[0216] 9. Combining the high bandwidth and low latency characteristics of 5G networks, more real-time and precise device control is achieved.

[0217] Corresponding to the aforementioned equipment control system, the present invention also proposes an equipment control device. Since the device embodiments of the present invention correspond to the aforementioned system embodiments, details not disclosed in the device embodiments can be referred to the aforementioned system embodiments, and will not be repeated here.

[0218] Figure 19 This is a schematic diagram of the structure of a device control apparatus provided in an embodiment of this disclosure, as shown below. Figure 19 As shown, it includes: an execution unit 51, a first generation unit 52, and a first sending unit 53.

[0219] Execution unit 51 is used to respond to the received access request, and dynamically perform multi-factor authentication based on the access request and context information to generate a comprehensive authentication result; The first generation unit 52 is used to perform network analysis on dynamic factors, obtain network analysis results, and generate dynamic access control policies based on the comprehensive authentication results and the network analysis results. The first sending unit 53 is used to send the dynamic access control policy to the target device so that the target device can perform access control based on the dynamic access control policy.

[0220] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 20 As shown, the execution unit 51 includes: Acquisition module 511 is used to acquire the context information; The adjustment module 512 is used to dynamically adjust the authentication weights of the multi-factor authentication and the authentication scores corresponding to the authentication weights based on the context information, so as to obtain the adjustment result; Module 513 is used to obtain near-field authentication results and message platform authentication results; The first generation module 514 is used to generate the comprehensive authentication result based on the near-field authentication result, the message platform authentication result, and the adjustment result.

[0221] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 20 As shown, the adjustment module 512 includes: The first calculation submodule 5121 is used to calculate the geographic location factor based on the distance difference between the current location and the preset safe location and the dwell time at the current location; The second calculation submodule 5122 is used to calculate the time factor based on daily cycle changes, weekly cycle changes and time decay. The third calculation submodule 5123 is used to calculate the device status factor based on the current security score, version difference and update time; The fourth calculation submodule 5124 is used to calculate the identity authentication factor based on the identity recognition information entropy, usage duration, and replacement frequency.

[0222] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 20 As shown, the execution unit 51 further includes a first determining module 515, which includes: The fifth calculation submodule 5151 is used to calculate the geographic location factor based on the first scoring function corresponding to the geographic location factor after the adjustment module 512 dynamically adjusts the authentication weight of the multi-factor authentication and the authentication score corresponding to the authentication weight according to the context information and obtains the adjustment result; The sixth calculation submodule 5152 is used to calculate the time factor based on the second scoring function corresponding to the time factor to obtain the time score; The seventh calculation submodule 5153 is used to calculate the equipment status factor based on the third scoring function corresponding to the equipment status factor to obtain the equipment status score; The eighth calculation submodule 5154 is used to calculate the identity authentication score based on the fourth scoring function corresponding to the identity authentication factor.

[0223] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 20 As shown, the execution unit 51 further includes: The second determining module 516 is used to determine the reliability scores of the near-field authentication results and the message platform authentication results after the obtaining module 513 obtains the near-field authentication results and the message platform authentication results, and to fuse the near-field authentication results, the message platform authentication results, the reliability scores corresponding to the near-field authentication results and the message platform authentication results corresponding to the message platform authentication results through an authentication fusion function to obtain a fusion result; The module 517 is introduced to improve the fusion score by introducing a small positive factor into the fusion result when it is determined that both the near-field authentication result and the message platform authentication result are successfully authenticated.

[0224] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 20 As shown, the comprehensive authentication result includes a credibility authentication score and authentication strength. The device also includes a determining unit 54, which includes: The first processing module 541 is used to perform nonlinear normalization processing on the weighted and fused authentication score to obtain the credibility authentication score. The second processing module 542 is used to transform the credibility authentication score to obtain the authentication strength.

[0225] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 20 As shown, the first generation unit 52 includes: The second generation module 521 is used to perform network analysis on the dynamic factors, obtain the network analysis results, and generate an access permission score based on the received comprehensive authentication result and the network analysis results; wherein, the dynamic factors include at least network topology and device relationships; The third generation module 522 is used to optimize the access permission score to obtain an optimized access permission score, and generate a dynamic access control policy based on the optimized access permission score.

[0226] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 20 As shown, the third generation module 522 includes: Submodule 5221 is introduced to optimize the access permission score by introducing a time decay factor and historical interaction similarity, so as to obtain the optimized access permission score. The determination submodule 5222 is used to divide the optimized access permission score into different access control levels according to a predefined threshold, and to determine a dynamic access control policy based on the access control level.

[0227] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 20 As shown, the device further includes: The monitoring unit 55 is used to monitor the status information of the target device after the first sending unit 53 sends the dynamic access control policy to the target device; wherein the status information includes at least one of device performance indicators, environmental parameters, functional status and network behavior. Analysis unit 56 is used to analyze the time-series data of the status information and determine whether there is any abnormality in the status information; The second generation unit 57 is used to generate an abnormality prompt message corresponding to the status information when it is determined that there is an abnormality in the status information, and send the abnormality prompt message to the terminal through a message platform.

[0228] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 20 As shown, the device further includes: Coordination unit 58 is configured to, after the first sending unit 53 sends the dynamic access control policy to the target device, respond to the control command sent by the terminal and coordinate the collaborative work of at least two target devices based on the control command. The second sending unit 59 is used to send the collaboration status information and access permission information to the message card generation module; wherein, the collaboration status information includes at least the connection status and task requirements; The third generation unit 510 is used to generate a personalized message card based on the collaborative status information, the access permission information and historical interaction data, and send the personalized message card to the terminal.

[0229] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 20 As shown, the device further includes: The interaction unit 511 is used to generate a personalized message card based on the collaborative status information, the access permission information and historical interaction data by the third generation unit 510, and send the personalized message card to the terminal. After that, the terminal interacts with the target device through the personalized message card to obtain historical interaction data. The third sending unit 512 is used to send the historical interaction data to the authentication enhancement module, access control module, device risk prediction and anomaly detection module, and message card generation module so that each module can be optimized and adjusted.

[0230] Furthermore, in one possible implementation of the embodiments of this disclosure, such as Figure 20 As shown, the device further includes: Establishment unit 513 is used to establish a secure binding relationship between the terminal and the target device and generate a near-field authentication token before the execution unit 51, in response to the received access request, dynamically performs multi-factor authentication based on the access request and generates a comprehensive authentication result; wherein, the near-field authentication token includes at least a communication device identifier, a timestamp and a session key; Storage unit 514 is used to store the near-field authentication token to the terminal and the target device so that the terminal and the target device can establish a trust relationship.

[0231] It should be noted that the foregoing explanation of the method embodiments also applies to the apparatus of the embodiments of this disclosure, and the principle is the same. Therefore, the embodiments of this disclosure are not limited thereto.

[0232] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0233] Figure 21 A schematic block diagram of an example electronic device 600 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0234] like Figure 21 As shown, the electronic device 600 includes a computing unit 601, which can perform various appropriate actions and processes based on a computer program stored in ROM (Read-Only Memory) 602 or loaded from storage unit 608 into RAM (Random Access Memory) 603. The RAM 603 may also store various programs and data required for the operation of the electronic device 600. The computing unit 601, ROM 602, and RAM 603 are interconnected via a bus 604. An I / O (Input / Output) interface 605 is also connected to the bus 604.

[0235] Multiple components in electronic device 600 are connected to I / O interface 605, including: input unit 606, such as keyboard, mouse, etc.; output unit 607, such as various types of displays, speakers, etc.; storage unit 608, such as disk, optical disk, etc.; and communication unit 609, such as network card, modem, wireless transceiver, etc. Communication unit 609 allows electronic device 600 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0236] The computing unit 601 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, CPUs (Central Processing Units), GPUs (Graphics Processing Units), various special-purpose AI (Artificial Intelligence) computing chips, various computing units running machine learning model algorithms, DSPs (Digital Signal Processors), and any suitable processor, controller, microcontroller, etc. The computing unit 601 performs the various methods and processes described above, such as device control methods. For example, in some embodiments, the device control method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by the computing unit 601, one or more steps of the methods described above may be performed. Alternatively, in other embodiments, the computing unit 601 may be configured to perform the aforementioned device control method by any other suitable means (e.g., by means of firmware).

[0237] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application-Specific Standard Products), SOCs (System-on-Chips), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0238] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0239] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, RAM, ROM, EPROM (Electrically Programmable Read-Only Memory) or flash memory, optical fiber, CD-ROM (Compact Disc Read-Only Memory), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0240] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0241] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include LANs (Local Area Networks), WANs (Wide Area Networks), the Internet, and blockchain networks.

[0242] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service system that addresses the shortcomings of traditional physical hosts and VPS (Virtual Private Server) services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.

[0243] It's important to note that artificial intelligence (AI) is the study of enabling computers to simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It encompasses both hardware and software technologies. AI hardware technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, and big data processing. AI software technologies primarily include computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graph technologies.

[0244] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0245] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A device control system, characterized in that, The system includes: an authentication enhancement module and an access control module; wherein... The authentication enhancement module is used to respond to a received access request, dynamically perform multi-factor authentication based on the access request and context information, generate a comprehensive authentication result, and send the comprehensive authentication result to the access control module. The access control module is used to perform network analysis on dynamic factors, obtain network analysis results, generate a dynamic access control policy based on the received comprehensive authentication result and the network analysis results, and send the dynamic access control policy to the target device so that the target device can perform access control based on the dynamic access control policy.

2. The system according to claim 1, characterized in that, The authentication enhancement module is also used for: Collect the context information; The authentication weights of the multi-factor authentication and the authentication scores corresponding to the authentication weights are dynamically adjusted based on the context information to obtain the adjustment result; The comprehensive authentication result is generated based on the near-field authentication result obtained by the near-field automatic authentication and binding module, the message platform authentication result, and the adjustment result. The near-field authentication result is used to characterize the result of the terminal and the target device completing the initial authentication binding through near-field communication, and the message platform authentication result is used to characterize the result of the terminal initiating identity authentication through the message platform.

3. The system according to claim 2, characterized in that, The context information includes geographical location, current time, device status, and identity verification information; The authentication weights of the multi-factor authentication include the geographical location factor corresponding to the geographical location, the time factor corresponding to the current time, the device status factor corresponding to the device status, and the identity authentication factor corresponding to the identity recognition information. The authentication enhancement module is also used for: The geographic location factor is calculated based on the distance difference between the current location and the preset safe location and the duration of stay at the current location; The time factor is obtained by calculation based on daily cycle changes, weekly cycle changes, and time decay. The device status factor is calculated based on the current security score, version difference, and update time. The identity authentication factor is calculated based on the identity recognition information entropy, usage duration, and replacement frequency.

4. The system according to claim 3, characterized in that, The authentication score corresponding to the authentication weight includes the geographical location score corresponding to the geographical location factor, the time score corresponding to the time factor, the device status score corresponding to the device status factor, and the identity authentication score corresponding to the identity authentication factor. The authentication enhancement module is also used for: The geographical location score is obtained by calculating the geographical location factor based on the first scoring function corresponding to the geographical location factor; The time factor is calculated based on the second scoring function corresponding to the time factor to obtain the time score; The equipment status factor is calculated based on the third scoring function corresponding to the equipment status factor to obtain the equipment status score; The identity authentication score is obtained by calculating based on the fourth scoring function corresponding to the identity authentication factor.

5. The system according to claim 2, characterized in that, The authentication enhancement module is also used for: Determine the reliability scores of the near-field authentication result and the message platform authentication result, and fuse the near-field authentication result, the message platform authentication result, the reliability score corresponding to the near-field authentication result, and the reliability score corresponding to the message platform authentication result through an authentication fusion function to obtain a fusion result; If both the near-field authentication result and the message platform authentication result are confirmed to be successful, a small positive factor is introduced into the fusion result to improve the fusion score.

6. The system according to claim 2, characterized in that, The comprehensive authentication result includes a credibility authentication score and authentication strength. The authentication enhancement module is also used for: The weighted and fused authentication score is subjected to nonlinear normalization to obtain the credibility authentication score; The credibility authentication score is transformed to obtain the authentication strength.

7. The system according to claim 1, characterized in that, The access control module is also used for: Network analysis is performed on the dynamic factors to obtain the network analysis results. Based on the received comprehensive authentication results and the network analysis results, an access permission score is generated. The dynamic factors include at least network topology and device relationships. The access permission score is optimized to obtain an optimized access permission score, and a dynamic access control policy is generated based on the optimized access permission score.

8. The system according to claim 7, characterized in that, The access control module is also used for: The access permission score is optimized by introducing a time decay factor and historical interaction similarity to obtain the optimized access permission score; The optimized access permission scores are divided into different access control levels based on predefined thresholds, and a dynamic access control policy is determined based on the access control levels.

9. The system according to claim 1, characterized in that, The system also includes: an equipment risk prediction and anomaly detection module; used for: Monitor the status information of the target device; wherein the status information includes at least one of device performance indicators, environmental parameters, functional status, and network behavior; Analyze the time-series data of the status information to determine whether there are any anomalies in the status information; If it is determined that the status information is abnormal, an abnormal prompt message corresponding to the status information is generated, and the abnormal prompt message is sent to the terminal through the message platform.

10. The system according to claim 1, characterized in that, The system also includes: a multi-device collaborative management module and a message card generation module; wherein... The multi-device collaborative management module is used to respond to the control command sent by the terminal and coordinate the collaborative work of at least two target devices based on the control command; The multi-device collaborative management module is also used to send collaborative status information to the message card generation module; wherein, the collaborative status information includes at least connection status and task requirements; The access control module is also used to send access permission information to the message card generation module; The message card generation module is used to receive the collaboration status information and the access permission information, generate a personalized message card based on the collaboration status information, the access permission information and historical interaction data, and send the personalized message card to the terminal.

11. The system according to claim 10, characterized in that, The message card generation module is also used for: The terminal interacts with the target device via the personalized message card to obtain historical interaction data; The historical interaction data is sent to the authentication enhancement module, the access control module, the device risk prediction and anomaly detection module, and the message card generation module so that each module can be optimized and adjusted.

12. The system according to claim 1, characterized in that, The system also includes: a near-field automatic authentication and binding module; used for: A secure binding relationship is established between the terminal and the target device, and a near-field authentication token is generated; wherein, the near-field authentication token includes at least a communication device identifier, a timestamp, and a session key; The near-field authentication token is stored in the terminal and the target device so that the terminal and the target device can establish a trust relationship.

13. A device control method, characterized in that, The method includes: In response to a received access request, multi-factor authentication is dynamically performed based on the access request and context information to generate a comprehensive authentication result; A network analysis is performed on dynamic factors to obtain network analysis results. Based on the comprehensive authentication results and the network analysis results, a dynamic access control policy is generated and sent to the target device so that the target device can perform access control based on the dynamic access control policy.

14. The method according to claim 13, characterized in that, In response to the received access request, based on the access request, multi-factor authentication is dynamically performed using context information to generate a comprehensive authentication result, including: Collect the context information; The authentication weights of the multi-factor authentication and the authentication scores corresponding to the authentication weights are dynamically adjusted based on the context information to obtain the adjustment result; The system obtains the near-field authentication result and the message platform authentication result, and generates the comprehensive authentication result based on the near-field authentication result, the message platform authentication result, and the adjustment result; wherein, the near-field authentication result is used to characterize the result of the terminal and the target device completing the initial authentication binding through near-field communication, and the message platform authentication result is used to characterize the result of the terminal initiating identity authentication through the message platform.

15. The method according to claim 14, characterized in that, The context information includes geographic location, current time, device status, and identity recognition information; the authentication weight of the multi-factor authentication includes the geographic location factor corresponding to the geographic location, the time factor corresponding to the current time, the device status factor corresponding to the device status, and the identity authentication factor corresponding to the identity recognition information. The multi-factor authentication weights and corresponding authentication scores are dynamically adjusted based on the context information to obtain the adjustment results, including: The geographic location factor is calculated based on the distance difference between the current location and the preset safe location and the duration of stay at the current location; The time factor is obtained by calculation based on daily cycle changes, weekly cycle changes, and time decay. The device status factor is calculated based on the current security score, version difference, and update time. The identity authentication factor is calculated based on the identity recognition information entropy, usage duration, and replacement frequency.

16. The method according to claim 15, characterized in that, The authentication score corresponding to the authentication weight includes the geographical location score corresponding to the geographical location factor, the time score corresponding to the time factor, the device status score corresponding to the device status factor, and the identity authentication score corresponding to the identity authentication factor. The certification score is determined based on the certification weights, including: The geographical location score is obtained by calculating the geographical location factor based on the first scoring function corresponding to the geographical location factor; The time factor is calculated based on the second scoring function corresponding to the time factor to obtain the time score; The equipment status factor is calculated based on the third scoring function corresponding to the equipment status factor to obtain the equipment status score; The identity authentication score is obtained by calculating based on the fourth scoring function corresponding to the identity authentication factor.

17. The method according to claim 14, characterized in that, After obtaining the near-field authentication result and the messaging platform authentication result, the following is included: Determine the reliability scores of the near-field authentication result and the message platform authentication result, and fuse the near-field authentication result, the message platform authentication result, the reliability score corresponding to the near-field authentication result, and the reliability score corresponding to the message platform authentication result through an authentication fusion function to obtain a fusion result; If both the near-field authentication result and the message platform authentication result are confirmed to be successful, a small positive factor is introduced into the fusion result to improve the fusion score.

18. The method according to claim 14, characterized in that, The comprehensive authentication result includes a credibility authentication score and authentication strength. Determining the credibility authentication score and authentication strength based on the authentication score includes: The weighted and fused authentication score is subjected to nonlinear normalization to obtain the credibility authentication score; The credibility authentication score is transformed to obtain the authentication strength.

19. The method according to claim 13, characterized in that, The process of performing network analysis on dynamic factors to obtain network analysis results, and generating dynamic access control policies based on the comprehensive authentication results and the network analysis results, includes: Network analysis is performed on the dynamic factors to obtain the network analysis results. Based on the received comprehensive authentication results and the network analysis results, an access permission score is generated. The dynamic factors include at least network topology and device relationships. The access permission score is optimized to obtain an optimized access permission score, and a dynamic access control policy is generated based on the optimized access permission score.

20. The method according to claim 19, characterized in that, The process of optimizing the access permission score to obtain an optimized access permission score, and generating a dynamic access control policy based on the optimized access permission score, includes: The access permission score is optimized by introducing a time decay factor and historical interaction similarity to obtain the optimized access permission score; The optimized access permission scores are divided into different access control levels based on predefined thresholds, and a dynamic access control policy is determined based on the access control levels.

21. The method according to claim 13, characterized in that, After sending the dynamic access control policy to the target device, the method further includes: Monitor the status information of the target device; wherein the status information includes at least one of device performance indicators, environmental parameters, functional status, and network behavior; Analyze the time-series data of the status information to determine whether there are any anomalies in the status information; If it is determined that the status information is abnormal, an abnormal prompt message corresponding to the status information is generated, and the abnormal prompt message is sent to the terminal through the message platform.

22. The method according to claim 13, characterized in that, After sending the dynamic access control policy to the target device, the method further includes: In response to receiving a control command from a terminal, coordinate the collaborative work of at least two target devices based on the control command; The collaboration status information and access permission information are sent to the message card generation module; wherein, the collaboration status information includes at least the connection status and task requirements; Based on the collaborative status information, the access permission information, and historical interaction data, a personalized message card is generated and sent to the terminal.

23. The method according to claim 22, characterized in that, After generating a personalized message card based on the collaborative status information, the access permission information, and historical interaction data, and sending the personalized message card to the terminal, the method further includes: The terminal interacts with the target device via the personalized message card to obtain historical interaction data; The historical interaction data is sent to the authentication enhancement module, access control module, device risk prediction and anomaly detection module, and message card generation module so that each module can be optimized and adjusted.

24. The method according to claim 13, characterized in that, Before responding to a received access request and dynamically performing multi-factor authentication based on the access request and context information to generate a comprehensive authentication result, the method further includes: A secure binding relationship is established between the terminal and the target device, and a near-field authentication token is generated; wherein, the near-field authentication token includes at least a communication device identifier, a timestamp, and a session key; The near-field authentication token is stored in the terminal and the target device so that the terminal and the target device can establish a trust relationship.

25. A device control apparatus, characterized in that, include: An execution unit is used to respond to a received access request, dynamically perform multi-factor authentication based on the access request and context information, and generate a comprehensive authentication result. The first generation unit is used to perform network analysis on dynamic factors, obtain network analysis results, and generate dynamic access control policies based on the comprehensive authentication results and the network analysis results. The first sending unit is used to send the dynamic access control policy to the target device so that the target device can perform access control based on the dynamic access control policy.

26. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 13-24.

27. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 13-24.

28. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method according to any one of claims 13-24.

Citation Information

Patent Citations

  • Zero-trust network architecture for industrial internet platform

    CN115361186A

  • Gateway intelligent arrangement method and system based on zero-trust network

    CN117118660A

  • Enterprise-level network access control system based on dynamic authentication

    CN120415765A

  • Multi-factor dynamic authentication internet of things network security access platform

    CN120546900A

  • Electric power artificial intelligence model security protection method and system based on zero-trust architecture

    CN120915521A