Security authentication and link management and control method for access of electric Hong Internet of Things
By maintaining the network communication link physically disconnected during the IoT access process and switching it to the conductive state after successful authentication, combined with cable management control, the security risks during the terminal device access process are solved, achieving highly secure and reliable access control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-22
- Publication Date
- 2026-03-17
AI Technical Summary
In existing technologies, when terminal devices connect to IoT platforms, there is a risk of unauthorized data eavesdropping and abnormal communication. Furthermore, the connection cables remain exposed even when authentication fails or malfunctions, which can easily lead to security vulnerabilities.
After the connection cable and the terminal device are electrically connected, the network communication link is kept physically disconnected. After successful authentication through local authentication, remote authentication or two-factor authentication, the connection is switched to physical conduction. In case of authentication failure or abnormality, the cable is automatically retracted and operation logs are generated and encrypted.
It reduces the risk of unauthorized communication, improves the security and reliability of access links, reduces security risks caused by exposed cables and human intervention, and provides traceability.
Smart Images

Figure CN121690793A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of IoT access security technology, and in particular to a method for IoT access security authentication and link control. Background Technology
[0002] In the current era of accelerated digital transformation, it has become commonplace for terminal devices to access power dispatching systems, operation and maintenance management platforms, and various industry-specific networks via the Internet of Things (IoT). Especially under the unified IoT platform architecture represented by E-Hong IoT, the frequency of network access between field terminal devices, mobile operation and maintenance terminals, and the back-end platform is constantly increasing, and the access scenarios are becoming increasingly complex, placing higher demands on the security and controllability of the access process.
[0003] In existing technologies, terminal devices typically authenticate themselves by using account passwords, software certificates, or platform-side identity verification when accessing IoT platforms. Their security control primarily relies on software authentication mechanisms at the logic or application layers. In such solutions, once the connection cable is electrically connected to the terminal device and power-on initialization is complete, the network communication link is physically active. Even if subsequent authentication fails, the device may still be at risk of being illegally eavesdropped on, maliciously scanned, or subjected to abnormal communication during the authentication window.
[0004] In practical engineering applications, the following problems are common: when authentication fails, communication is abnormal, or the terminal interface is accidentally disconnected, the connection cable remains exposed and connected. This not only makes it difficult to prevent repeated access attempts but also easily leads to safety hazards such as cable tangling, mis-plugging, or forced connection. Existing technologies mostly rely on software prompts or platform alarms for handling these issues, lacking effective control methods that link the physical connection status to the problem.
[0005] Therefore, it is necessary to provide a method and device for secure authentication and link management of the Internet of Things (IoT) that can physically control the network communication link at the initial stage of terminal access, and combine local authentication, remote authentication and physical cable control to achieve secure access, controllable link and traceable behavior, so as to solve the problems existing in the prior art. Summary of the Invention
[0006] The purpose of this invention is to address the shortcomings of existing technologies by providing a method for secure authentication and link management for IoT access, thereby resolving the problems mentioned in the background.
[0007] To achieve the above objectives, the present invention adopts the following technical solution: A method for secure authentication and link control of IoT access, comprising the following steps: S1. When the terminal interface of the connecting cable forms an electrical connection with the terminal device and completes power-on initialization, the control network communication link is kept physically disconnected, and the security authentication process is initiated. S2. Perform local authentication, remote authentication, or a combination of both on the user according to the preset authentication policy. S3. When the authentication result is passed, the control link connection control unit switches the network communication link from the physically disconnected state to the physically connected state to establish data communication. After the data communication is established, the main control unit performs data transmission status detection on the network communication link. S4. When the main control unit detects authentication failure or abnormal data transmission status, the control link connection control unit maintains or restores the physical disconnection state of the network communication link and sends a cable storage control signal to the cable storage control unit. S5. After receiving the storage control signal, the cable storage control unit drives the connecting cable to perform the storage action. S6. During the authentication, link connection / disconnection, and cable storage processes, generate and encrypt the corresponding operation log information.
[0008] Preferably, in step S2, authentication timing is started simultaneously with the execution of the security authentication process. If no authentication result is obtained within a preset time threshold, it is determined that the authentication has timed out, and steps S4 and S5 are executed.
[0009] Preferably, the physical disconnection and conduction states of the network communication link are controlled by physically switching on and off each signal line in the connecting cable.
[0010] Preferably, the security authentication in S2 includes local authentication based on biometrics and remote authentication based on the Dianhong IoT platform, and one or a combination thereof is selected and executed according to the application scenario.
[0011] Preferably, the abnormal data transmission status includes: terminal interface disconnection, communication timeout, and remote command disconnection.
[0012] Another objective of this invention is to provide a security authentication and link management device for Internet of Things (IoT) access, comprising: an interface module, wherein the interface module includes a terminal-side interface and a network-side interface; The connecting cable connects the terminal-side interface to the network-side interface. The main control unit is used to initiate the security authentication process and generate link control commands and storage control commands after the device is powered on. The link connection control unit is used to keep the network communication link physically disconnected before authentication is successful, and to switch the network communication link to a physically connected state after authentication is successful. The cable storage control unit is used to drive the connecting cable to perform a controlled automatic storage action after receiving the storage control command; The log management unit is used to encrypt and record the authentication process, link status changes, and abnormal events.
[0013] Preferably, the main control unit is located between the terminal-side interface and the network-side interface, and the main control unit includes a main control MCU, an authentication module, an IoT communication module, and a backup power supply.
[0014] Preferably, the authentication module includes a capacitive fingerprint recognition module, and the IoT communication module is a wireless module that supports communication with the Dianhong IoT platform; the identity authentication supports local fingerprint authentication, remote IoT authentication, and a combination of both, and the authentication mode is dynamically switched by the Dianhong IoT platform.
[0015] Preferably, the link on / off control unit is a high-speed analog switch, which is connected in series with the signal line of the connecting cable body to control the signal line independently. By default, all signal lines are physically disconnected.
[0016] Preferably, the cable storage control unit includes a geared drive motor, a cable reel, and a transmission mechanism, wherein the geared drive motor drives the cable reel to rotate through the transmission mechanism.
[0017] The present invention discloses a method and device for secure authentication and link management of Internet of Things (IoT) access, which has the following beneficial effects.
[0018] After the connection cable and terminal device are electrically connected and power-on initialization is completed, the present invention keeps the network communication link physically disconnected and only switches to the physically connected state after the security authentication is passed. This avoids the network link being connected in advance during the authentication process and reduces the risk of unauthorized data eavesdropping, scanning or abnormal communication during the authentication window. This invention implements independent physical on / off control of each signal line in the connection cable, so that the conduction and disconnection of the network communication link are directly controlled by the hardware state, reducing the possibility of misjudgment or bypass caused by relying solely on software logic for link management, and improving the security and reliability of access link control. According to the authentication strategy preset or dynamically issued by the Dianhong IoT platform, the present invention supports local authentication based on biometrics, remote authentication based on the Dianhong IoT platform, or a two-factor authentication method combining both. It can flexibly configure the authentication process according to different terminal types, usage scenarios and security level requirements, and improve the adaptability of the access authentication mechanism. When authentication failure, authentication timeout, or abnormal data transmission status is detected, the present invention can automatically maintain or restore the physical disconnection state of the network communication link, and synchronously trigger the controlled automatic storage of the connecting cable through the cable storage control unit, reducing the situation where the connecting cable is continuously exposed or repeatedly attempts to connect under abnormal conditions, and reducing the safety hazards caused by mis-insertion, forced insertion, and human intervention. This invention generates operation logs throughout the entire process of authentication, link connection / disconnection, and cable management, and encrypts and stores the log information, making terminal access behavior, abnormal events, and link status changes traceable, which is beneficial for subsequent operation analysis. Attached Figure Description
[0019] Figure 1 This is a flowchart of the Dianhong IoT access security authentication and link control method of the present invention.
[0020] Figure 2 This is a cross-sectional view of the connecting cable of the present invention.
[0021] Figure 3 This is a block diagram of the security authentication logic of the present invention.
[0022] Figure 4 This is an architecture diagram of the main control unit, link connection / disconnection control unit, and log management unit of the present invention.
[0023] In the diagram: 1. Central metal wire; 2. Multi-strand finely twisted copper core; 3. Outer soft rubber filling layer; 4. Shielding layer; 5. PVC sheath. Detailed Implementation
[0024] To illustrate the possible application scenarios, technical principles, implementable specific solutions, and achievable objectives and effects of this application in detail, the following description, in conjunction with the listed specific embodiments and accompanying drawings, provides a detailed explanation. The embodiments described herein are merely illustrative of the technical solutions of this application and are therefore intended to limit the scope of protection of this application.
[0025] In this document, the term "embodiment" means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The term "embodiment" appearing in various places throughout the specification does not necessarily refer to the same embodiment, nor does it specifically limit its independence or connection with other embodiments. In principle, in this application, as long as there are no technical contradictions or conflicts, the technical features mentioned in each embodiment can be combined in any way to form corresponding implementable technical solutions.
[0026] Unless otherwise defined, the technical terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the use of related terms herein is merely for the purpose of describing particular embodiments and is not intended to limit this application.
[0027] In the description of this application, the term "and / or" is used to describe the logical relationship between objects, indicating that three relationships can exist. For example, A and / or B means: A exists, B exists, and A and B exist simultaneously. Additionally, the character " / " in this document generally indicates that the preceding and following objects have an "or" logical relationship.
[0028] Unless otherwise specified, the use of terms such as “comprising,” “including,” “having,” or other similar expressions in this application is intended to cover non-exclusive inclusion, which does not exclude the presence of additional elements in a process, method, or product that includes the stated elements, such that a process, method, or product that includes a list of elements may include not only those defined elements but also other elements not expressly listed, or elements inherent to such a process, method, or product.
[0029] Unless otherwise expressly specified or limited, the terms "installation," "connection," "linking," "fixing," and "setting," as used in the description of the embodiments of this application, should be interpreted broadly. For example, "connection" can be a fixed connection, a detachable connection, or an integral setting; it can be a mechanical connection, an electrical connection, or a communication connection; it can be a direct connection or an indirect connection through an intermediate medium; it can be the internal connection of two components or the interaction between two components. For those skilled in the art to which this application pertains, the specific meaning of the above terms in the embodiments of this application can be understood according to the specific circumstances.
[0030] Example 1 As disclosed in the background section, when authentication fails, communication is abnormal, or the terminal interface is accidentally disconnected, the connection cable remains exposed and connected. This not only makes it difficult to prevent repeated access attempts but also easily leads to security risks such as cable tangling, mis-plugging, or forced connection. Existing technologies mostly rely on software prompts or platform alarms for handling these issues, lacking effective control measures that are linked to the physical connection status.
[0031] To address the aforementioned issues, a method for secure authentication and link management of IoT access is proposed, comprising the following steps: S1. When the terminal interface of the connecting cable forms an electrical connection with the terminal device and completes power-on initialization, the control network communication link is kept physically disconnected, and the security authentication process is initiated. S2. Perform local authentication, remote authentication, or a combination of both on the user according to the preset authentication policy. S3. When the authentication result is passed, the control link connection control unit switches the network communication link from the physically disconnected state to the physically connected state to establish data communication. After the data communication is established, the main control unit performs data transmission status detection on the network communication link. S4. When the main control unit detects authentication failure or abnormal data transmission status, the control link connection control unit maintains or restores the physical disconnection state of the network communication link and sends a cable storage control signal to the cable storage control unit. S5. After receiving the storage control signal, the cable storage control unit drives the connecting cable to perform the storage action. S6. During the authentication, link connection / disconnection, and cable management processes, generate and encrypt the corresponding operation log information.
[0032] The technical solution provided by this invention keeps the network communication link physically disconnected after the connection cable and terminal device form an electrical connection and complete power-on initialization. It only switches to a physically connected state after security authentication is passed, thereby avoiding premature link connection during the authentication process and reducing the risk of unauthorized communication. By implementing independent physical on / off control for each signal line in the connection cable, the link connection and disconnection are directly determined by the hardware state, improving the security and reliability of access link control. Meanwhile, based on the preset authentication policy or the authentication policy dynamically issued by the Dianhong IoT platform, it supports a flexible combination of local authentication, remote authentication, or two-factor authentication to adapt to the security needs of different terminals and application scenarios. When authentication failure, authentication timeout, or abnormal data transmission status is detected, it can automatically maintain or restore the physical disconnection of the network communication link and simultaneously trigger the controlled automatic retraction of the connection cable to reduce the security risks caused by repeated access and human intervention under abnormal conditions. In addition, operation logs are generated and encrypted and stored throughout the authentication, link connection and disconnection and cable storage process, making access behavior and abnormal events traceable, which is beneficial for subsequent operation analysis.
[0033] The above plan will be explained in detail below.
[0034] Please refer to Figure 1 A method for secure authentication and link management of IoT access, comprising the following steps: S1. When the terminal interface of the connecting cable forms an electrical connection with the terminal device and completes power-on initialization, the control network communication link is kept physically disconnected, and the security authentication process is initiated. Preferably, in this embodiment, the physical disconnection and conduction states of the network communication link are achieved by physically controlling the on / off states of each signal line in the connecting cable.
[0035] It should be noted that in this embodiment, when the device is powered on and initialized and authentication fails, all signal lines are physically disconnected by default to prevent unauthorized data communication.
[0036] In this embodiment, after the terminal interface of the connecting cable forms an electrical connection with the terminal device and completes power-on initialization, the main control unit initiates the security authentication process.
[0037] S2. Perform local authentication, remote authentication, or a combination of both on the user according to the preset authentication policy. Preferably, in this embodiment, authentication timing is started simultaneously with the security authentication process in S2. If no authentication result is obtained within the preset time threshold, it is determined that the authentication has timed out, and steps S4 and S5 are executed.
[0038] Preferably, in this embodiment, the security authentication in S2 includes local authentication based on biometrics and remote authentication based on the Dianhong IoT platform, and one or a combination thereof is selected and executed according to the application scenario.
[0039] In one embodiment, the main control unit pre-stores an authentication policy configuration table to limit the security authentication methods used in different application scenarios; the authentication policy configuration table can pre-set the corresponding authentication mode according to factors such as terminal device type, usage environment level, access permission level or historical security records.
[0040] In another embodiment, the authentication policy can be dynamically issued by the Elec-Tech IoT platform based on the real-time security situation. When a terminal device accesses the network, the environmental risk level changes, or the platform detects abnormal access behavior, the Elec-Tech IoT platform generates a corresponding authentication policy instruction and sends it to the main control unit through the IoT communication module.
[0041] After receiving the authentication policy instruction, the main control unit updates the configuration of the current authentication process to determine the authentication method to be used in subsequent authentication processes.
[0042] Updating the configuration includes, but is not limited to: enabling or disabling local biometric authentication, enabling or disabling remote platform authentication, or enabling both of the above authentication methods simultaneously to form a two-factor authentication process.
[0043] S3. When the authentication result is passed, the control link connection control unit switches the network communication link from the physically disconnected state to the physically connected state to establish data communication. After the data communication is established, the main control unit performs data transmission status detection on the network communication link. In this embodiment, the data transmission status detection can be based on the communication connection status, data interaction timing, or remote platform response status.
[0044] S4. When the main control unit detects authentication failure or abnormal data transmission status, the control link connection control unit maintains or restores the physical disconnection state of the network communication link and sends a cable storage control signal to the cable storage control unit. Preferably, in this embodiment, abnormal data transmission status includes: terminal interface disconnection, communication timeout, and remote command disconnection.
[0045] S5. After receiving the storage control signal, the cable storage control unit drives the connecting cable to perform the storage action. S6. During the authentication, link connection / disconnection, and cable management processes, generate and encrypt the corresponding operation log information.
[0046] In this embodiment, the key operation events during the operation of the log information recording device include at least: the start and end of the security authentication process, the authentication result, the time node when the network communication link switches from a physically disconnected state to a physically connected state, the triggering reason for the network communication link to return to a physically disconnected state, and the triggering and completion status of the connection cable retraction action; the encryption processing can be performed by the security module inside the main control unit or the log management unit, and the specific encryption method is not limited.
[0047] Example 2 Based on Embodiment 1, this embodiment provides a Dianhong IoT access security authentication and link control device, including: an interface module, which includes a terminal-side interface and a network-side interface; In this embodiment, the terminal-side interface can be selected from RJ45 male, USB-A male, or Type-C male, and the network-side interface can be selected from RJ45 female or Type-C female. A connecting cable is used to connect the terminal-side interface and the network-side interface; in one embodiment, such as... Figure 2 As shown, the connecting cable includes: a central metal wire 1, a multi-strand finely twisted copper core 2, an outer soft rubber filling layer 3, a shielding layer 4, and a PVC sheath 5.
[0048] The main control unit is used to initiate the security authentication process and generate link control commands and storage control commands after the device is powered on. In this embodiment, the main control unit enters the initialization state after the device is powered on. As the logic control core of the system, the main control unit comprehensively judges the authentication status, link status, and data transmission status to avoid unauthorized network access and continuous connection under abnormal communication conditions.
[0049] The link connection control unit is used to keep the network communication link physically disconnected before authentication is successful, and to switch the network communication link to a physically connected state after authentication is successful. The cable management control unit is used to drive the connecting cable to perform a controlled automatic cable management action after receiving a cable management control command; The log management unit is used to encrypt and record the authentication process, link status changes, and abnormal events.
[0050] In this embodiment, the log management unit is used to record key operation events during the operation of the device. The operation events include at least: the start and end of the security authentication process, the authentication result, the time node when the network communication link switches from a physically disconnected state to a physically connected state, the triggering reason for the network communication link to return to a physically disconnected state, and the triggering and completion status of the connection cable storage action.
[0051] The log management unit records logs under the control of the main control unit. When the main control unit detects a change in authentication status, a change in link connectivity, or the generation of a cable retraction control signal, it triggers the corresponding log recording operation.
[0052] Before storing operation log information, the log management unit encrypts the log content to prevent unauthorized reading or tampering of the log information.
[0053] Encryption processing can be performed by the security module inside the main control unit or log management unit, and the specific encryption method is not limited.
[0054] Preferably, in this embodiment, the main control unit is located between the terminal-side interface and the network-side interface, such as... Figure 4 As shown, the main control unit includes a main control MCU, an authentication module, an IoT communication module, and a backup power supply. In this embodiment, the main control MCU adopts the STM32 / GD32 series, and the Elec-Tech IoT module adopts the nRF52832; in this embodiment, the main control unit is also equipped with an LCD display module, a tri-color LED, a backup lithium battery pack, and a power supply voltage regulator circuit; LCD display module.
[0055] In this embodiment, when an abnormal interruption of the main power supply or a voltage lower than a preset threshold is detected, the main control unit controls the power switching module to connect the backup power supply, providing short-term power to the main control unit and the log management unit.
[0056] In standby power supply mode, the main control unit completes the recording and control of current key status information, and drives the log management unit to encrypt and store the operation logs that have not yet been written before entering low power or shutdown mode.
[0057] Preferably, in this embodiment, the authentication module includes a capacitive fingerprint recognition module, and the IoT communication module is a wireless module that supports communication with the Elec-Tech IoT platform; for example Figure 3 As shown, the identity authentication supports local fingerprint authentication, remote IoT authentication, and a combination of both, namely two-factor authentication. The authentication mode is dynamically switched by the Dianhong IoT platform. In this embodiment, the fingerprint recognition module uses TA0802. In this embodiment, the user inserts the terminal interface of the connecting cable into the terminal device, the LCD displays "Please authenticate with fingerprint" and the blue LED flashes; the fingerprint module collects the image and compares it with the locally stored template through the Minutiae Matching algorithm; if the comparison is successful, it sends the "0x01+UserID" signal to the MCU main controller; if it fails, it records the number of failures, and locks the device for 30 seconds after accumulating 5 failures. Remote IoT Authentication Process (based on Elec-Tech IoT): After the device is powered on, the IoT module connects to the Dehong IoT platform and broadcasts its UUID. The App scans and binds the UUID (the first binding requires administrator password verification). Users enter a password or biometric information through the app to generate a token containing the user ID, timestamp, and AES-based encrypted authentication information; the device verifies the legitimacy of the authentication information through the SM2 security chip. Two-factor authentication strategy: In high-security scenarios, fingerprint collection and App authorization must be completed simultaneously, and the link is closed only after both are successful.
[0058] After successful authentication, the MCU sends a closing command to the high-speed analog switch, the link is connected, the LCD displays "Connected + User ID + Connection Time", and the green LED is constantly lit; if authentication fails, the LCD displays "Authentication Failed" and the red LED flashes.
[0059] The LCD screen displays the authentication status, user ID, connection duration, and battery level in real time; the LED lights are solid green (connected), flashing red (authentication failed), and flashing blue (awaiting authentication). Preferably, in this embodiment, the link on / off control unit is a high-speed analog switch. The high-speed analog switch is connected in series with the signal line of the connecting cable body and is used to control the signal line to be independently on and off one by one. By default, all signal lines are physically disconnected.
[0060] In this embodiment, the high-speed analog switch adopts the ADG series, realizing independent control of 16 channels and covering all RJ45 / Type-C signal lines; the MCU master controller sends control commands through the SPI bus. In the default state, all channels output low level and the switch is open; after authentication, the MCU master controller outputs high level and closes the corresponding channels in sequence according to the signal line type to ensure synchronous signal conduction.
[0061] Preferably, in this embodiment, the cable storage control unit includes a geared drive motor, a winding wheel, and a transmission mechanism, wherein the geared drive motor drives the winding wheel to rotate through the transmission mechanism.
[0062] In this embodiment, the cable winding control unit is used to automatically wind up the connecting cable after receiving the winding control signal sent by the main control unit. It includes a geared drive motor, a winding wheel and a transmission mechanism. The geared drive motor drives the winding wheel to rotate through the transmission mechanism, thereby realizing the winding and winding up of the connecting cable.
[0063] In terms of specific structure, the winding reel can be configured as a hollow cylindrical structure, with its axial ends rotatably mounted inside the device housing via bearings. The outer circumferential surface of the winding reel is provided with an annular winding groove for winding the connecting cable, thereby limiting the cable rewinding path and preventing the cable from overlapping or misaligning during storage. A portion of the connecting cable is fixedly connected to the annular winding groove of the winding reel, and both the terminal-side interface and the network-side interface extend out of the device housing.
[0064] The geared drive motor is preferably a DC geared motor or a stepper geared motor, and its output shaft is connected to the shaft of the winding reel through a transmission mechanism. The transmission mechanism can be one of a gear drive, a synchronous belt drive, or a worm gear drive structure, used to transmit the output torque of the geared drive motor to the winding reel and further match the speed to ensure the speed stability and output torque of the winding reel during the winding process.
[0065] In terms of control method, the start, stop, and rotation direction of the geared drive motor are controlled by the main control unit. When the main control unit detects authentication failure, authentication timeout, or abnormal data transmission status and generates a cable winding control signal, it outputs the corresponding motor drive command to the cable winding control unit, causing the geared drive motor to drive the winding wheel to rotate in a preset direction, thereby gradually winding the connecting cable back into the device.
[0066] To avoid excessive pulling during cable winding, in this embodiment, the cable winding control unit can modulate the drive voltage or pulse signal of the geared drive motor to achieve uniform or low-speed rotation of the winding wheel. When the winding wheel reaches a preset number of rotations, the main control unit controls the geared drive motor to stop rotating, completing one cable winding process.
[0067] Through the above structure and control method, the cable storage control unit can realize the automatic and controlled recycling of connecting cables in abnormal or unauthorized access scenarios, thereby reducing the time when connecting cables are exposed and reducing the safety hazards caused by misinsertion, forced insertion and human intervention.
[0068] The above are merely preferred embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Substitutions may include replacements of some structures, devices, or method steps, or may be complete technical solutions. Equivalent substitutions or modifications made to the technical solutions and inventive concepts of the present invention should all be covered within the scope of protection of the present invention.
Claims
1. An Internet of Things access security authentication and link management method, characterized in that, The method comprises the following steps: S1, when the terminal interface of the connection cable forms an electrical connection with the terminal device and completes the power-on initialization, the control network communication link remains in a physically disconnected state, and a security authentication process is started; S2, according to a preset authentication strategy, a local authentication, a remote authentication or a combination of the two is performed on the user for security authentication; S3, when the authentication result is passed, the link on-off control unit switches the network communication link from the physically disconnected state to the physically connected state to establish data communication, and after the data communication is established, the main control unit detects the data transmission state of the network communication link; S4, when the main control unit detects that the authentication fails or the data transmission state is abnormal, the link on-off control unit maintains or restores the physically disconnected state of the network communication link, and sends a storage control signal to the cable storage control unit; S5, after receiving the storage control signal, the cable storage control unit drives the connection cable to perform the storage action; S6, during the authentication, link on-off and connection cable storage processes, corresponding operation log information is generated and encrypted.
2. The method of claim 1, wherein the method further comprises: In the S2, the authentication timing is started when the security authentication process is performed, and when the authentication pass result is not obtained within a preset time threshold, it is determined that the authentication is timed out, and steps S4 and S5 are performed. 3.The IoT access security authentication and link management method of claim 1, wherein, The physically disconnected state and the connected state of the network communication link are realized by physically controlling the on-off of the signal lines in the connection cable.
4. The IoT access security authentication and link management method of claim 1, wherein, The security authentication in the S2 includes local authentication based on biological characteristics and remote authentication based on the electric Hong Internet of Things platform, and one or a combination thereof is selected according to the application scenario.
5. The IoT access security authentication and link management method of claim 1, wherein, The data transmission state abnormality includes terminal interface disengagement, communication time timeout and remote link disconnection.
6. An Internet of Things access security authentication and link management device, characterized in that, It comprises: an interface module comprising a terminal side interface and a network side interface; a connection cable connecting the terminal side interface and the network side interface; a main control unit for starting a security authentication process and generating a link control instruction and a storage control instruction after the device is powered on; a link on-off control unit for keeping the network communication link in a physically disconnected state before authentication passes, and switching the network communication link to a physically connected state after authentication passes; a cable storage control unit for driving the connection cable to perform a controlled automatic storage action after receiving the storage control instruction; a log management unit for encrypting records of the authentication process, link state changes and abnormal events. 7.The IoT access security authentication and link management device of claim 6, wherein, The main control unit is arranged between the terminal side interface and the network side interface, and comprises a main control MCU, an authentication module, an Internet of Things communication module and a backup power supply. 8.The IoT access security authentication and link management device of claim 7, wherein, The authentication module comprises a capacitive fingerprint identification module, and the Internet of Things communication module is a wireless module supporting communication with the electric Hong Internet of Things platform; the identity authentication supports local fingerprint authentication, remote Internet of Things authentication and two-factor authentication combining the two, and the authentication mode is dynamically switched by the electric Hong Internet of Things platform. 9.The IoT access security authentication and link management device of claim 6, wherein, The link on-off control unit is a high-speed analog switch, which is connected in series on the signal line of the connecting cable body and is used for controlling the on-off of the signal line independently line by line, and all the signal lines are physically disconnected in the default state.
10. The IoT access security authentication and link management device of claim 6, wherein, The cable storage control unit comprises a speed reduction drive motor, a winding wheel and a transmission mechanism, and the speed reduction drive motor drives the winding wheel to rotate through the transmission mechanism.