Building intelligent integrated management method and system based on Internet of Things
By dividing the building area into sub-regions and establishing a monitoring line between the virtual aggregation gateway and the access control terminal, the problem of low database security in existing technologies is solved, enabling accurate monitoring and dynamic defense of the access control terminal and improving database security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-08
- Publication Date
- 2026-03-27
AI Technical Summary
Existing access control systems generally employ one-time authentication and fixed permission allocation mechanisms when accessing databases, making it difficult to identify abnormal operations after credential theft, thus reducing database security.
The building area is divided into multiple sub-areas, and a data chain is established for each sub-area. The data is monitored through a monitoring line between the virtual aggregation gateway and the access control terminal to determine whether the access control terminal meets the preset conditions. If it does, access is allowed; otherwise, it is marked and uploaded to the cloud. Dynamic defense is achieved through update mechanisms and mapping relationships.
It enables precise monitoring of access control terminals, reduces abnormal access, improves the security of data within the database, dynamically defends against attackers, and reduces the risk of data leakage.
Smart Images

Figure CN121750701A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of building intelligent safety management, more particularly, the present application relates to a building intelligent integrated management method and system based on the Internet of Things. BACKGROUND
[0002] With the deep integration of the Internet of Things and big data technology in building intelligent systems, modern buildings have developed from single-system independent operation to multi-subsystem cross-domain integration such as security and protection, energy efficiency, and environmental control. Such systems continuously gather multi-dimensional sensitive data such as device status, environmental parameters, and control parameters to the database through the deployment of a large number of sensors and control terminals, forming high-value data assets. However, the existing access control terminal generally uses one-time identity authentication and fixed permission allocation mechanism when accessing the database, which is difficult to identify abnormal operation behavior after credential theft, is not convenient to reduce access to the database by abnormal access control terminals, and is easy to reduce the security of data in the database.
[0003] In view of this, the present application provides a building intelligent integrated management method and system based on the Internet of Things to solve the above problems. SUMMARY
[0004] In order to overcome the above-mentioned defects of the prior art, in order to achieve the above-mentioned purpose, the present application provides the following technical scheme: a building intelligent integrated management method based on the Internet of Things, comprising the following steps: Divide the building area into multiple sub-areas, establish a data chain for each sub-area, and the data chain corresponds to multiple nodes; A virtual aggregation gateway is established for all data chains, an access control terminal is determined, and a monitoring line between the access control terminal and the virtual aggregation gateway is established; Determine whether the access control terminal meets the preset conditions based on the monitoring line, if yes, allow the access control terminal to access the nodes on the data chain through the virtual aggregation gateway, if not, mark the access control terminal and upload it to the corresponding cloud.
[0005] Further, the step of dividing the building area into multiple sub-areas, establishing a data chain for each sub-area, and the data chain corresponding to multiple nodes comprises: Determine the building space, divide the building area based on the building space, and obtain multiple sub-areas corresponding to the building area; Determine multiple collection devices and control devices in the sub-area, and each collection device and control device is regarded as a node; Encode and connect multiple nodes in each sub-area to obtain a data chain corresponding to the sub-area, wherein each node corresponds to a node code; Determine the kind of node, set a database for each kind of node respectively, the database is provided with a plurality of data points, the data points correspond to unique data point codes, and a mapping relationship between the node code and the data point code is established, wherein the data points are used to store the data corresponding to the node.
[0006] Further, the step of establishing the mapping relationship between the node code and the data point code comprises: establishing a first mapping relationship between the node and the database, and establishing a second mapping relationship between the database and the data point code; The first mapping relationship and the second mapping relationship are combined as the mapping relationship between the node code and the data point code, wherein an update mechanism is established according to the mapping relationship, and the mapping relationship is updated based on the update mechanism.
[0007] Further, a virtual aggregation gateway is established for all data chains, an access control end is determined, and a monitoring line between the access control end and the virtual aggregation gateway is established. All data chains are summarized, and a virtual aggregation gateway is established for all summarized data chains; Determine the access control end corresponding to the virtual aggregation gateway, set a plurality of monitoring points for each access control end, and set a plurality of verification points corresponding to the plurality of monitoring points of the access control end corresponding to the virtual aggregation gateway; Virtual connection is performed between the one-to-one verification points and the monitoring points, a plurality of virtual lines are obtained, and the plurality of virtual lines form a monitoring line between each access control end and the virtual aggregation gateway.
[0008] Further, the step of determining the access control end corresponding to the virtual aggregation gateway, setting a plurality of monitoring points for each access control end, and setting a plurality of verification points corresponding to the plurality of monitoring points of the access control end corresponding to the virtual aggregation gateway comprises: Determine the access control end corresponding to the virtual aggregation gateway, and set a unique identity for each access control end; Determine the inherent characteristics, associated characteristics and security characteristics of each access control end, wherein the identity information and location information of each access control end are obtained as the inherent characteristics of the access control end, the access control time, access control sequence and access control association of each access control end are obtained as the associated characteristics of the access control end, and the flow data, energy consumption data and security token of each access control end are obtained as the security characteristics of the access control end; The inherent characteristics, associated characteristics and security characteristics corresponding to each access control end are respectively used as a monitoring point, and a plurality of monitoring points corresponding to each access control end are obtained; Copy the plurality of monitoring points corresponding to each access control end to the corresponding virtual aggregation gateway to obtain a plurality of verification points.
[0009] Further, the step of virtually connecting between the one-to-one corresponding verification points and the monitoring points to obtain a plurality of virtual lines, the plurality of virtual lines forming the monitoring line between each access control end and the virtual aggregation gateway, comprises: virtually connecting between the one-to-one corresponding verification points and the monitoring points to obtain a plurality of virtual lines between each access control end and the virtual aggregation gateway; binding the plurality of virtual lines with the corresponding access control end to obtain the monitoring line between each access control end and the virtual aggregation gateway; deploying a plurality of monitoring probes corresponding to each virtual line, associating the plurality of monitoring probes with the corresponding virtual line, monitoring the corresponding virtual line based on the plurality of monitoring probes to obtain a monitoring result.
[0010] Further, the step of deploying a plurality of monitoring probes corresponding to each virtual line, associating the plurality of monitoring probes with the corresponding virtual line, monitoring the corresponding virtual line based on the plurality of monitoring probes to obtain a monitoring result, comprises: determining the monitoring node of each virtual line, and deploying a monitoring probe on the monitoring node of each virtual line; grouping all monitoring probes on each virtual line, and associating the grouped monitoring probes with the virtual line on which they are deployed; monitoring the virtual line using all the monitoring probes deployed thereon to obtain a monitoring result, and binding the monitoring result with the corresponding virtual line.
[0011] Further, the step of judging whether the access control end meets the preset condition based on the monitoring line, if yes, allowing the access control end to access the nodes on the data chain through the virtual aggregation gateway, and if not, marking the access control end and uploading it to the corresponding cloud, comprises: when the access control end accesses the virtual aggregation gateway, obtaining the monitoring result corresponding to the virtual line between the access control end and the virtual aggregation gateway, and comparing the monitoring result with the preset condition; if the comparison result meets the preset condition, allowing the access control end to access the nodes on the data chain through the virtual aggregation gateway; if the comparison result does not meet the preset condition, marking the access control end and uploading it to the corresponding cloud, and simultaneously updating the mapping relationship based on the update mechanism.
[0012] The application also provides the following technical scheme: a building intelligent integrated management system based on the Internet of Things, comprising: a division storage module for dividing a building area into a plurality of sub-areas, establishing a data chain corresponding to each sub-area, and the data chain corresponding to a plurality of nodes; The module is established to create a virtual aggregation gateway for all data chains, determine the access control terminal, and establish a monitoring line between the access control terminal and the virtual aggregation gateway. The monitoring and judgment module is used to determine whether the access control terminal meets the preset conditions based on the monitoring line. If it does, the access control terminal is allowed to access the nodes on the data chain through the virtual aggregation gateway. If it does not meet the conditions, the access control terminal is marked and uploaded to the corresponding cloud.
[0013] The technical effects and advantages of the IoT-based intelligent building integrated management method and system of this invention are as follows: 1. By identifying the inherent characteristics, associated characteristics, and security characteristics of each access control terminal and treating each characteristic as a monitoring point, precise monitoring of each access control terminal can be achieved. By replicating these characteristics to the corresponding virtual aggregation gateway and using them as verification points, and by establishing virtual lines between the corresponding monitoring points and verification points, the access control terminal can be monitored through the monitoring lines formed by multiple virtual lines. This facilitates timely detection of whether the access control terminal meets the preset conditions, reduces access to the database by abnormal access control terminals, and improves the security of data within the database. 2. By updating the mechanism and setting the mapping relationship, the intelligence detected by the attacker (abnormal access control terminal) can be rendered invalid, enabling dynamic defense and increasing the uncertainty for the attacker. This can reduce the possibility of data leakage in other databases caused by data leakage in a single database. Attached Figure Description
[0014] Figure 1 This is a flowchart illustrating an IoT-based integrated management method for intelligent building systems according to the present invention. Figure 2 This is a schematic diagram of the structure of an IoT-based integrated building intelligent management system according to the present invention. Detailed Implementation
[0015] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0016] Please see Figure 1 As shown in the figure, the IoT-based intelligent building integrated management method described in this embodiment includes the following steps: The building area is divided into multiple sub-areas, and a data chain is established for each sub-area, with multiple nodes corresponding to each data chain. Establish a virtual aggregation gateway for all data links, determine the access control terminal, and establish a monitoring line between the access control terminal and the virtual aggregation gateway; Based on the monitoring line, it is determined whether the access control terminal meets the preset conditions. If it does, the access control terminal is allowed to access the nodes on the data chain through the virtual aggregation gateway. If it does not meet the conditions, the access control terminal is marked and uploaded to the corresponding cloud.
[0017] In this embodiment, by determining the inherent characteristics, associated characteristics, and security characteristics of each access control terminal and treating each characteristic as a monitoring point, precise monitoring of each access control terminal can be achieved. By replicating these characteristics to the corresponding virtual aggregation gateway and using them as verification points, and by establishing virtual lines between the corresponding monitoring points and verification points, the access control terminal can be monitored through a monitoring line formed by multiple virtual lines. This facilitates timely detection of whether the access control terminal meets preset conditions, reduces access to the database by abnormal access control terminals, and improves the security of data within the database. Through the update mechanism and mapping relationship settings, intelligence already detected by attackers can be rendered invalid, enabling dynamic defense and increasing the uncertainty of attackers (abnormal access control terminals). This reduces the possibility of data leakage in other databases due to data leakage in one database. Furthermore, this invention solves the problem that existing access control terminals, when accessing the database, struggle to identify abnormal operations after credential theft, making it difficult to reduce access to the database by abnormal access control terminals and easily reducing the security of data within the database.
[0018] As an optional embodiment: the step of dividing the building area into multiple sub-areas, establishing a data chain for each sub-area, and the data chain corresponding to multiple nodes includes: Define the architectural space, and then divide the architectural area into multiple sub-areas based on the architectural space; Identify multiple acquisition and control devices within a sub-region, and treat each acquisition and control device as a node; Encode and connect multiple nodes within each sub-region to obtain the data chain corresponding to the sub-region, where each node corresponds to a node code; The types of nodes are determined, and a database is set up for each type of node. The database contains multiple data points, each data point corresponding to a unique data point code. A mapping relationship is established between node codes and data point codes. The data points are used to store the data corresponding to the nodes.
[0019] It should also be noted that the process involves collecting architectural design drawings, functional zoning, and IoT deployment plans (deployment information of various sensors within the building). The architectural design drawings determine the building space, and functional zoning divides the building area (larger functional zones can be further subdivided according to preset areas, such as 20㎡), resulting in multiple sub-regions. The IoT deployment plan identifies multiple data acquisition and control devices within each sub-region. Data acquisition devices include sensors for temperature, humidity, illuminance, smoke, energy consumption, and water quality; control devices include lighting switches, air conditioning units, fire valves, elevator dispatching systems, and access control systems. Each data acquisition and control device is treated as a node (i.e., an independent functional node), and each node is assigned a unique device code. Multiple nodes within each sub-region are connected (virtual connections, logical connections only, not actual connections), resulting in a data chain corresponding to the sub-region. This data chain represents the logical connection between all data acquisition and control devices within the corresponding sub-region, indicating that they belong to the same sub-region. By identifying the types of acquisition and control devices, a database is set up for each type of node. The database stores only the data acquired by that node. Each database contains multiple data points, each a storage space with a corresponding data point code. This code corresponds to the node code. The data points store the data acquired / collected by the corresponding node. Within each data point, the stored data is timestamped and arranged chronologically. By dividing the area into sub-regions and identifying the acquisition and control devices within each sub-region, and by setting up data chains, logical connections between all nodes within the sub-region can be established. This prevents the omission of any acquisition or control devices within a sub-region. Setting up a database for each type of node facilitates separate storage for each type of node (acquisition and control devices). The data points and their codes facilitate the subsequent establishment of a mapping relationship between node codes and data point codes, enabling access to or retrieval of data within the data points.
[0020] As an optional embodiment: the step of establishing the mapping relationship between node codes and data point codes includes: Establish the first mapping relationship between nodes and the database, and establish the second mapping relationship between the database and data point codes; The first mapping relationship and the second mapping relationship are combined to form a mapping relationship between node code and data point code. An update mechanism is established for the corresponding mapping relationship, and the mapping relationship is updated based on the update mechanism.
[0021] It should also be noted that a unique identifier is set for each database. The node code, data point code, and identifier are all unique in each new version after the mapping relationship is updated. A first mapping relationship is established between the identifiers of all databases and the codes of all nodes. A second mapping relationship is established between the identifiers of all databases and the data point codes. The first and second mapping relationships are combined to obtain the mapping relationship between the node code and the data point code. This mapping relationship is node code - database identifier - data point code. An update mechanism is set for the corresponding mapping relationship. The update mechanism is associated with whether the monitoring line corresponding to the access control terminal meets preset conditions. Therefore, when the access control terminal fails to meet the preset conditions, the mapping relationship can be updated in a timely manner according to the update mechanism. This update can update the data point, database identifier, and node code, making it difficult for the abnormal access control terminal to locate the data in the database through a fixed path. This reduces the leakage of data in the database and achieves a dynamic defense effect for the data in the database. Specifically, the update mechanism includes triggering conditions, update content, and update logs. The triggering condition is that the monitoring line corresponding to the access control terminal does not meet preset conditions. The update content involves remapping all database identifiers, node codes, and data point codes. This remapping is based on preset rules, which involve adding / deleting / replacing n characters according to a preset list for all existing database identifiers, node codes, and data point codes. The preset list is a sorted list of the n added characters, or it can be a pre-replacement of the next version, where the next version consists of all pre-mapped database identifiers, node codes, and data point codes. The preset rules, the next version, and the update log are all stored. Stored in the cloud; update logs are used to record the triggering reason and time, the executed operation, and the next version of the update; for example, the mapping relationship between database identifier, node code, and data point code is: S001-B001-D002. After the update mechanism is triggered, n characters are added to the existing node code, such as adding the TR character from the preset list. The new mapping relationship is: TRS001-TRB001-TRD002; therefore, after updating the mapping relationship of the current version, the intelligence detected by the attacker (abnormal access control terminal) can be rendered invalid, enabling dynamic defense and increasing the uncertainty for the attacker. It can also reduce the situation where data leakage in a single database leads to data leakage in other databases.
[0022] As an optional embodiment: the steps of establishing a virtual aggregation gateway for all data links, determining the access control terminal, and establishing a monitoring line between the access control terminal and the virtual aggregation gateway include: The data chains are aggregated, and a virtual aggregation gateway is established for all aggregated data chains. Determine the access control terminal corresponding to the virtual aggregation gateway, set multiple monitoring points for each access control terminal, and set multiple verification points for the multiple monitoring points of the virtual aggregation gateway corresponding to the access control terminal. Virtual connections are made between the one-to-one corresponding verification points and monitoring points to obtain multiple virtual lines. These multiple virtual lines form the monitoring line between each access control terminal and the virtual aggregation gateway.
[0023] It should also be noted that a virtual aggregation gateway is established for all data chains, and all data chains are stored within the virtual aggregation gateway. This virtual aggregation gateway serves as the sole logical entry point for all data flows and access requests, essentially functioning as a firewall integrating a zero-trust proxy, a dynamic data mapping controller, and a unified API gateway. Therefore, all data access from the access control end must pass through the virtual aggregation gateway. This virtual aggregation gateway facilitates the establishment of access links from the access control end to data points through monitoring lines and mapping relationships, thereby facilitating access to data within those data points. By combining this with the control requirements of intelligent building management, this ensures… The virtual aggregation gateway corresponds to an access control terminal, which includes one of the following: the central control room / local management terminal of the corresponding building, a mobile terminal, or a cloud terminal. By setting up multiple monitoring points and corresponding verification points for the access control terminal, and establishing virtual connections between the monitoring points and their corresponding verification points, multiple virtual lines are obtained. The virtual line is equivalent to establishing a one-way dedicated digital verification channel for real-time comparison between a certain monitoring point on the access control terminal and the corresponding verification point on the virtual aggregation gateway at the logical level. This enables one-to-one monitoring of each monitoring point, thereby enabling targeted monitoring of the characteristics (fixed characteristics, associated characteristics, and security characteristics) of the access control terminal.
[0024] As an optional embodiment: the step of determining the access control terminal corresponding to the virtual aggregation gateway, setting multiple monitoring points for each access control terminal, and setting multiple verification points corresponding to the multiple monitoring points of the virtual aggregation gateway for the access control terminal includes: Determine the access control terminal corresponding to the virtual aggregation gateway, and set a unique identity for each access control terminal. Determine the inherent characteristics, associated characteristics, and security characteristics of each access control terminal. Specifically, obtain the identity information and location information of each access control terminal as its inherent characteristics, obtain the access control time, access control sequence, and access control association of each access control terminal as its associated characteristics, and obtain the traffic data, energy consumption data, and security token of each access control terminal as its security characteristics. Each access control terminal has its inherent characteristics, associated characteristics, and security characteristics as a monitoring point, resulting in multiple monitoring points for each access control terminal. Multiple monitoring points corresponding to each access control terminal are copied to the corresponding virtual aggregation gateway to obtain multiple verification points.
[0025] It should also be noted that, by combining the control requirements of building intelligent management, the access control terminal corresponding to the virtual aggregation gateway is determined. The access control terminal determined here is the pre-set access port, which can be one of the following: the central control room / local control terminal, mobile terminal, or cloud terminal. By setting a unique identity for each access control terminal, the access monitoring terminal can be bound to the corresponding identity. By determining the inherent characteristics, associated characteristics, and security characteristics of each access control terminal and using these characteristics as monitoring points, each access control terminal can be accurately monitored. By copying these characteristics to the corresponding virtual aggregation gateway and using them as verification points, and by establishing virtual lines between the corresponding monitoring points and verification points, the access control terminal can be monitored through the monitoring lines formed by multiple virtual lines. This facilitates timely detection of whether the access control terminal meets the preset conditions, reduces abnormal access control terminals accessing the database, and improves the security of the data in the database. Specifically, by acquiring the identity and location information of each access control terminal as its inherent characteristics—including identity identifiers (i.e., the access control terminal's identity and hardware parameters) and location information (i.e., the real-time physical location information of the accessing client)—the inherent characteristics of the access control terminal can be monitored to prevent abnormal access control terminals from accessing data in the database. Furthermore, by acquiring the access control time, access control sequence, and access control associations of each access control terminal as its association characteristics—including access control time (i.e., the time point and duration of access control), access control sequence (i.e., the logical order of access requests, such as the typical indoor light-turning process being card swiping to open the door - automatic light turning on after entry - light turning off after completion; the logical order can be preset based on historical data or operation sequence), and access control associations (i.e., the business logic associations between different operations or requests)—these are all relevant to the access control terminal. The system employs several security measures, including: First, it identifies access control requests (e.g., linking card swipes to door opening with light activation). Second, it verifies requests from access control terminals (identifying abnormal behaviors that violate normal operating patterns and business logic), preventing unauthorized access to the database. Third, it acquires traffic data, energy consumption data, and security tokens from each access control terminal as security characteristics. These characteristics include traffic data (the entropy / load change of the access control terminal during access), energy consumption data (the power consumption change of the access control terminal when executing access requests; for example, abnormally high power consumption access may indicate that the device is controlled by malware rather than human operation), and security tokens (dynamic credentials used for session authentication between the access control terminal and the virtual aggregation gateway, uniformly generated and distributed by the virtual aggregation gateway, such as OAuth tokens, JWT tokens, or one-time passwords). This allows for real-time verification of the security of communication between the access control terminal and the virtual aggregation gateway.
[0026] As an optional embodiment: the step of establishing virtual connections between corresponding verification points and monitoring points to obtain multiple virtual lines, with the multiple virtual lines forming a monitoring line between each access control terminal and the virtual aggregation gateway, includes: Virtual connections are made between the one-to-one corresponding verification points and monitoring points to obtain multiple virtual lines between each access control terminal and the virtual aggregation gateway; Multiple virtual lines are bound to their corresponding access control terminals to obtain the monitoring line between each access control terminal and the virtual aggregation gateway; Multiple monitoring probes are deployed for each virtual line, and these probes are associated with the corresponding virtual lines. The virtual lines are then monitored based on these probes to obtain the monitoring results. As an optional embodiment: the step of deploying multiple monitoring probes for each virtual line, associating the multiple monitoring probes with the corresponding virtual line, monitoring the corresponding virtual line based on the multiple monitoring probes, and obtaining monitoring results includes: Identify the monitoring nodes for each virtual line and deploy monitoring probes on each monitoring node of the virtual line; Group all monitoring probes on each virtual line and associate the grouped monitoring probes with the virtual lines they are deployed on; Monitor the virtual line using all the monitoring probes deployed on it, obtain the monitoring results, and bind the monitoring results to the corresponding virtual line.
[0027] It should also be noted that by establishing virtual connections between corresponding verification points and monitoring points, corresponding monitoring lines are obtained, and multiple monitoring probes are deployed for each monitoring line. These monitoring probes are equivalent to monitors, such as miniature intelligent analysis sensors or digital sentinels. The monitoring probes are used to monitor the monitoring points and verification points corresponding to the monitoring lines. The locations where the monitoring probes are deployed on the virtual lines (i.e., monitoring nodes) are generally the starting point (access control terminal), the middle point (transmission switch), and the ending point (virtual aggregation gateway) of the virtual lines. Thus, by deploying multiple monitoring probes on the virtual lines, the virtual lines can be monitored. By monitoring all virtual lines, the corresponding monitoring results (i.e., the comparison results between monitoring points and verification points) can be obtained. The monitoring results of multiple virtual lines facilitate subsequent judgment on whether the monitoring lines meet the preset conditions.
[0028] As an optional embodiment: the step of determining whether the access control terminal meets the preset conditions based on the monitoring line, and if so, allowing the access control terminal to access the nodes on the data chain through the virtual aggregation gateway; if not, marking the access control terminal and uploading the information to the corresponding cloud, includes: When the access control terminal accesses the virtual aggregation gateway, it obtains the monitoring results corresponding to the virtual line between the access control terminal and the virtual aggregation gateway, and compares the monitoring results with preset conditions. If the comparison result meets the preset conditions, the access control terminal is allowed to access the nodes on the data chain through the virtual aggregation gateway; If the comparison result does not meet the preset conditions, the access control terminal is marked and uploaded to the corresponding cloud. At the same time, the mapping relationship is updated based on the update mechanism.
[0029] It should also be noted that by judging the monitoring results of multiple virtual lines corresponding to the monitoring line, it is possible to determine whether the monitoring line meets the preset conditions. The preset conditions include whether the corresponding characteristics between the monitoring point and the verification point corresponding to the virtual line are the same or exceed the preset difference. For example, if the energy consumption data in the security characteristics exceeds the preset energy consumption data, it is determined that it does not meet the preset conditions. If all the monitoring results corresponding to the monitoring line meet the preset conditions, the virtual aggregation gateway establishes an access link between the access control terminal and the corresponding data in the data point. If the preset conditions are not met, no access link is established between the access control terminal and the corresponding data in the data point, and the access control terminal is marked and uploaded to the corresponding cloud. At the same time, the mapping relationship is updated based on the update mechanism. This update can adjust the mapping relationship between the node and the database and the data point encoding, so that the intelligence that the attacker has detected becomes invalid, which can realize dynamic defense and increase the uncertainty of the attacker (abnormal access control terminal). It can reduce the situation where data leakage in a single database leads to data leakage in other databases.
[0030] Please see Figure 2 As shown in this embodiment, a building intelligent integrated management system based on the Internet of Things includes: The storage module is used to divide the building area into multiple sub-areas, establish a data chain for each sub-area, and the data chain corresponds to multiple nodes. The module is established to create a virtual aggregation gateway for all data chains, determine the access control terminal, and establish a monitoring line between the access control terminal and the virtual aggregation gateway. The monitoring and judgment module is used to determine whether the access control terminal meets the preset conditions based on the monitoring line. If it does, the access control terminal is allowed to access the nodes on the data chain through the virtual aggregation gateway. If it does not meet the conditions, the access control terminal is marked and uploaded to the corresponding cloud.
[0031] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed in this invention can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.
[0032] In the several embodiments provided by this invention, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only one method, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0033] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention.
[0034] In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A building intelligent integrated management method based on the Internet of Things, characterized in that, Includes the following steps: The building area is divided into multiple sub-areas, and a data chain is established for each sub-area, with multiple nodes corresponding to each data chain. Establish a virtual aggregation gateway for all data links, determine the access control terminal, and establish a monitoring line between the access control terminal and the virtual aggregation gateway; Based on the monitoring line, it is determined whether the access control terminal meets the preset conditions. If it does, the access control terminal is allowed to access the nodes on the data chain through the virtual aggregation gateway. If it does not meet the conditions, the access control terminal is marked and uploaded to the corresponding cloud.
2. The IoT-based integrated management method for intelligent building management according to claim 1, characterized in that, The steps of dividing the building area into multiple sub-regions and establishing a data chain for each sub-region, with each data chain corresponding to multiple nodes, include: Define the architectural space, and then divide the architectural area into multiple sub-areas based on the architectural space; Identify multiple acquisition and control devices within a sub-region, and treat each acquisition and control device as a node; Encode and connect multiple nodes within each sub-region to obtain the data chain corresponding to the sub-region, where each node corresponds to a node code; The types of nodes are determined, and a database is set up for each type of node. The database contains multiple data points, each data point corresponding to a unique data point code. A mapping relationship is established between node codes and data point codes. The data points are used to store the data corresponding to the nodes.
3. The IoT-based integrated management method for intelligent building management according to claim 2, characterized in that, The steps for establishing the mapping relationship between node codes and data point codes include: Establish the first mapping relationship between nodes and the database, and establish the second mapping relationship between the database and data point codes; The first mapping relationship and the second mapping relationship are combined to form a mapping relationship between node code and data point code. An update mechanism is established for the corresponding mapping relationship, and the mapping relationship is updated based on the update mechanism.
4. The IoT-based integrated management method for intelligent building management according to claim 3, characterized in that, The steps of establishing a virtual aggregation gateway for all data chains, determining the access control terminal, and establishing a monitoring line between the access control terminal and the virtual aggregation gateway include: The data chains are aggregated, and a virtual aggregation gateway is established for all aggregated data chains. Determine the access control terminal corresponding to the virtual aggregation gateway, set multiple monitoring points for each access control terminal, and set multiple verification points for the multiple monitoring points of the virtual aggregation gateway corresponding to the access control terminal. Virtual connections are made between the one-to-one corresponding verification points and monitoring points to obtain multiple virtual lines. These multiple virtual lines form the monitoring line between each access control terminal and the virtual aggregation gateway.
5. The IoT-based integrated management method for intelligent building management according to claim 4, characterized in that, The steps of determining the access control terminal corresponding to the virtual aggregation gateway, setting multiple monitoring points for each access control terminal, and setting multiple verification points corresponding to the multiple monitoring points of the virtual aggregation gateway for the access control terminal include: Determine the access control terminal corresponding to the virtual aggregation gateway, and set a unique identity for each access control terminal. Determine the inherent characteristics, associated characteristics, and security characteristics of each access control terminal. Specifically, obtain the identity information and location information of each access control terminal as its inherent characteristics, obtain the access control time, access control sequence, and access control association of each access control terminal as its associated characteristics, and obtain the traffic data, energy consumption data, and security token of each access control terminal as its security characteristics. Each access control terminal has its inherent characteristics, associated characteristics, and security characteristics as a monitoring point, resulting in multiple monitoring points for each access control terminal. Multiple monitoring points corresponding to each access control terminal are copied to the corresponding virtual aggregation gateway to obtain multiple verification points.
6. The IoT-based integrated management method for intelligent building management according to claim 5, characterized in that, The step of establishing virtual connections between corresponding verification points and monitoring points to obtain multiple virtual lines, and forming a monitoring line between each access control terminal and the virtual aggregation gateway, includes: Virtual connections are made between the one-to-one corresponding verification points and monitoring points to obtain multiple virtual lines between each access control terminal and the virtual aggregation gateway; Multiple virtual lines are bound to their corresponding access control terminals to obtain the monitoring line between each access control terminal and the virtual aggregation gateway; Multiple monitoring probes are deployed for each virtual line, and these probes are associated with the corresponding virtual lines. The virtual lines are then monitored based on these probes to obtain the monitoring results.
7. The IoT-based integrated management method for intelligent building management according to claim 6, characterized in that, The steps of deploying multiple monitoring probes for each virtual line, associating the multiple monitoring probes with the corresponding virtual line, and monitoring the corresponding virtual line based on the multiple monitoring probes to obtain monitoring results include: Identify the monitoring node for each virtual line and deploy a monitoring probe on each monitoring node of the virtual line; Group all monitoring probes on each virtual line and associate the grouped monitoring probes with the virtual lines they are deployed on; Monitor the virtual line using all the monitoring probes deployed on it, obtain the monitoring results, and bind the monitoring results to the corresponding virtual line.
8. The IoT-based integrated management method for intelligent building management according to claim 7, characterized in that, The step of determining whether the access control terminal meets preset conditions based on the monitoring line, and if so, allowing the access control terminal to access nodes on the data chain through the virtual aggregation gateway; if not, marking the access control terminal and uploading the information to the corresponding cloud, includes: When the access control terminal accesses the virtual aggregation gateway, it obtains the monitoring results corresponding to the virtual line between the access control terminal and the virtual aggregation gateway, and compares the monitoring results with preset conditions. If the comparison result meets the preset conditions, the access control terminal is allowed to access the nodes on the data chain through the virtual aggregation gateway; If the comparison result does not meet the preset conditions, the access control terminal is marked and uploaded to the corresponding cloud. At the same time, the mapping relationship is updated based on the update mechanism.
9. An IoT-based integrated management system for intelligent buildings, used to implement the IoT-based integrated management method for intelligent buildings as described in claims 1-8, characterized in that, include: The storage module is used to divide the building area into multiple sub-areas, establish a data chain for each sub-area, and the data chain corresponds to multiple nodes. The module is established to create a virtual aggregation gateway for all data chains, determine the access control terminal, and establish a monitoring line between the access control terminal and the virtual aggregation gateway. The monitoring and judgment module is used to determine whether the access control terminal meets the preset conditions based on the monitoring line. If it does, the access control terminal is allowed to access the nodes on the data chain through the virtual aggregation gateway. If it does not meet the conditions, the access control terminal is marked and uploaded to the corresponding cloud.