Intelligent monitoring cloud system based on multi-terminal cooperation and data management method thereof

By verifying the identity of third-party mobile devices and generating access tokens in the enterprise cloud, the flexibility and scalability issues in mobile data cloud storage technology are resolved, achieving both flexibility and security in data management.

CN122069095APending Publication Date: 2026-05-19GUANGDONG CONSTR ENG QUALITY & SAFETY INSPECTION STATION CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGDONG CONSTR ENG QUALITY & SAFETY INSPECTION STATION CO LTD
Filing Date
2026-03-11
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

Existing mobile data cloud storage technologies are insufficient in terms of flexibility and scalability, making it difficult to meet ever-changing needs.

Method used

By receiving data collaboration instructions from enterprise mobile devices and third-party mobile devices in the enterprise cloud, verifying the identity of third-party devices and generating access tokens, and sending access tokens only to authorized enterprise mobile devices, the system achieves flexibility and scalability in data management while restricting the permissions of third-party mobile devices.

Benefits of technology

It enables flexibility and scalability in data management, ensures data security, and prevents attackers from forging identities to obtain data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122069095A_ABST
    Figure CN122069095A_ABST
Patent Text Reader

Abstract

The invention provides an intelligent monitoring cloud system based on multi-terminal collaboration and a data management method thereof, belongs to the technical field of data management, and is used for realizing flexibility and expandability of data management. The method comprises the following steps: an enterprise terminal cloud receives a data collaboration instruction from an enterprise mobile terminal, wherein the data collaboration instruction is used for instructing the enterprise mobile terminal to authorize a data authority to a third-party mobile terminal; under the condition that the enterprise terminal cloud receives the monitoring data set from the third-party equipment, the enterprise terminal cloud verifies whether the third-party equipment is a third-party mobile terminal with the data authority in response to the data collaboration instruction; if yes, the enterprise terminal cloud generates an access token of the monitoring data set, and the access token is used when the enterprise mobile terminal obtains the monitoring data set from the enterprise terminal cloud; and the enterprise cloud sends the access token to the enterprise mobile terminal, and the third-party mobile terminal has no authority to obtain the access token.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data management technology, and in particular to an intelligent monitoring cloud system based on multi-terminal collaboration and its data management method. Background Technology

[0002] With the rapid development of mobile internet and cloud computing technologies, mobile data cloud storage technology has gradually become a research hotspot. Mobile data cloud storage technology refers to the technology of transmitting data from users' mobile devices to remote servers via the network for storage and management. This technology not only provides users with larger storage space and higher data security, but also enables cross-platform data sharing and backup.

[0003] Mobile data cloud storage technology primarily relies on the following key technologies: Data transmission protocols: such as HTTP and WebDAV, used for data transmission between mobile devices and cloud servers. Data synchronization algorithms: used to synchronize data between mobile devices and cloud servers, ensuring data up-to-dateness and consistency. Security technologies: including data encryption and authentication technologies, used to protect data security and privacy. Storage management: storage management technologies on the cloud server, used for data storage, backup, and recovery.

[0004] However, with the development of technology, mobile data cloud storage may require flexibility and scalability, so how to meet the requirements of flexibility and scalability is a current research issue. Summary of the Invention

[0005] This application provides an intelligent monitoring cloud system and its data management method based on multi-terminal collaboration, which can achieve flexibility and scalability in data management.

[0006] To achieve the above objectives, this application adopts the following technical solution: In a first aspect, embodiments of this application provide a data management method based on multi-terminal collaboration. The method is applied to an enterprise cloud platform and includes: the enterprise cloud platform receiving a data collaboration instruction from an enterprise mobile terminal, the data collaboration instruction instructing the enterprise mobile terminal to authorize data permissions to a third-party mobile terminal; when the enterprise cloud platform receives a monitoring dataset from a third-party device, in response to the data collaboration instruction, the enterprise cloud platform verifies whether the third-party device is a third-party mobile terminal with data permissions; if so, the enterprise cloud platform generates an access token for the monitoring dataset, the access token being used by the enterprise mobile terminal when obtaining the monitoring dataset from the enterprise cloud platform; the enterprise cloud platform sends the access token to the enterprise mobile terminal, and the third-party mobile terminal does not have permission to obtain the access token.

[0007] Optionally, the data collaboration indication includes the authorization indication of the enterprise mobile terminal and the identity information of the third-party mobile terminal. The authorization indication of the enterprise mobile terminal is used to instruct the enterprise mobile terminal to authorize data permissions. The enterprise cloud receives the monitoring dataset from the third-party mobile terminal, including: the monitoring dataset and the identity information of the third-party device received by the enterprise cloud.

[0008] Optionally, the identity information of the third-party mobile terminal includes first identification information and a first verification code for indicating the third-party mobile terminal. The first verification code is obtained by performing a secure operation on the feature characters in the first identification information. The identity information of the third-party device includes second identification information for indicating the third-party device. The enterprise cloud verifies whether the third-party device is a third-party mobile terminal with data permissions, including: the enterprise cloud performs a secure operation on the feature characters in the second identification information to obtain a second verification code; the enterprise cloud verifies whether the first verification code and the second verification code are consistent. If they are consistent, it indicates that the third-party device is a third-party mobile terminal with data permissions; otherwise, the third-party device is not a third-party mobile terminal with data permissions.

[0009] Optionally, the first identification information includes an X1-digit string, where X1 is an integer greater than 1. The X1-digit string can be divided into X3 equal segments, each of which has a length of X2, where X3 is an integer greater than 1 and X2 is a positive integer. Each of the X3 segments is moduloed by a preset X2-digit string to obtain a new string, resulting in a total of X3 strings. These X3 strings are then concatenated to obtain the feature character in the first identification information.

[0010] Optionally, the enterprise cloud generates an access token for the monitoring dataset, including: the enterprise cloud compresses and encodes the monitoring dataset to obtain a feature dataset; the enterprise cloud extracts the access token from the feature dataset.

[0011] Optionally, the enterprise cloud compresses and encodes the monitoring dataset to obtain a feature dataset, including: the enterprise cloud compresses and encodes the monitoring dataset to obtain a bit sequence; the enterprise cloud constructs the bit sequence into a matrix; the enterprise cloud determines an access token based on multiple isolated bits in the matrix, where the access token is the coordinate position of the multiple isolated bits in the matrix.

[0012] Optionally, the enterprise cloud constructs the bit sequence into a matrix, including: the enterprise cloud constructs the first or last N*M bits of the bit sequence into an N*M matrix, where N and M are both integers greater than 3; the enterprise cloud determines the access token based on multiple isolated bits in the matrix, including: the enterprise cloud determines multiple bits in the N*M matrix whose values ​​are different from the surrounding bits, and determines the coordinate positions of the multiple bits in the N*M matrix, where the multiple bits are isolated bits, and the coordinate positions of the multiple bits in the N*M matrix are the access token.

[0013] Optionally, the enterprise-side cloud constructs the bit sequence into a matrix, including: the enterprise-side cloud constructs an N*M matrix for every N*M bits of the bit sequence, constructing a total of K N*M matrices. The bits contained in the K N*M matrices correspond one-to-one with the K*N*M bits before or after the bit sequence, where N and M are both integers greater than 3, and K is an integer greater than 2. The enterprise-side cloud determines the access token based on multiple isolated bits in the matrix, including: in the K N*M matrices, the enterprise-side cloud determines multiple bits in any N*M matrix that satisfy a preset condition, and determines the coordinate position of each of the multiple bits in the N*M matrix. The multiple bits are isolated bits, and the coordinate positions of the multiple bits in the N*M matrix are the access token. Satisfying the preset condition means that for any one of the multiple bits at a coordinate position in the N*M matrix, the K bits at that coordinate position in the K N*M matrices repeat periodically.

[0014] Optionally, the enterprise cloud sends the access token to the enterprise mobile device, including: the enterprise cloud sends the access token to the enterprise mobile device through a secure transmission channel.

[0015] Secondly, embodiments of this application provide an intelligent monitoring cloud system based on multi-terminal collaboration, including an enterprise-side cloud and an enterprise mobile terminal. The enterprise-side cloud is configured to: receive a data collaboration instruction from the enterprise mobile terminal, the data collaboration instruction being used to instruct the enterprise mobile terminal to authorize data permissions to a third-party mobile terminal; when the enterprise-side cloud receives a monitoring dataset from a third-party mobile terminal, in response to the data collaboration instruction, the enterprise-side cloud verifies whether the third-party mobile terminal has data permissions; if so, the enterprise-side cloud generates an access token for the monitoring dataset, the access token being used by the enterprise mobile terminal when obtaining the monitoring dataset from the enterprise-side cloud; the enterprise-side cloud sends the access token to the enterprise mobile terminal, and the third-party mobile terminal does not have permission to obtain the access token.

[0016] Optionally, the data collaboration indication includes the authorization indication of the enterprise mobile terminal and the identity information of the third-party mobile terminal. The authorization indication of the enterprise mobile terminal is used to instruct the enterprise mobile terminal to authorize data permissions. The enterprise cloud receives the monitoring dataset from the third-party mobile terminal, including: the monitoring dataset and the identity information of the third-party device received by the enterprise cloud.

[0017] Optionally, the identity information of the third-party mobile terminal includes first identification information and a first verification code for indicating the third-party mobile terminal. The first verification code is obtained by performing a secure operation on the feature characters in the first identification information. The identity information of the third-party device includes second identification information for indicating the third-party device. The enterprise cloud verifies whether the third-party device is a third-party mobile terminal with data permissions, including: the enterprise cloud performs a secure operation on the feature characters in the second identification information to obtain a second verification code; the enterprise cloud verifies whether the first verification code and the second verification code are consistent. If they are consistent, it indicates that the third-party device is a third-party mobile terminal with data permissions; otherwise, the third-party device is not a third-party mobile terminal with data permissions.

[0018] Optionally, the first identification information includes an X1-digit string, where X1 is an integer greater than 1. The X1-digit string can be divided into X3 equal segments, each of which has a length of X2, where X3 is an integer greater than 1 and X2 is a positive integer. Each of the X3 segments is moduloed by a preset X2-digit string to obtain a new string, resulting in a total of X3 strings. These X3 strings are then concatenated to obtain the feature character in the first identification information.

[0019] Optionally, the enterprise cloud generates an access token for the monitoring dataset, including: the enterprise cloud compresses and encodes the monitoring dataset to obtain a feature dataset; the enterprise cloud extracts the access token from the feature dataset.

[0020] Optionally, the enterprise cloud compresses and encodes the monitoring dataset to obtain a feature dataset, including: the enterprise cloud compresses and encodes the monitoring dataset to obtain a bit sequence; the enterprise cloud constructs the bit sequence into a matrix; the enterprise cloud determines an access token based on multiple isolated bits in the matrix, where the access token is the coordinate position of the multiple isolated bits in the matrix.

[0021] Optionally, the enterprise cloud constructs the bit sequence into a matrix, including: the enterprise cloud constructs the first or last N*M bits of the bit sequence into an N*M matrix, where N and M are both integers greater than 3; the enterprise cloud determines the access token based on multiple isolated bits in the matrix, including: the enterprise cloud determines multiple bits in the N*M matrix whose values ​​are different from the surrounding bits, and determines the coordinate positions of the multiple bits in the N*M matrix, where the multiple bits are isolated bits, and the coordinate positions of the multiple bits in the N*M matrix are the access token.

[0022] Optionally, the enterprise-side cloud constructs the bit sequence into a matrix, including: the enterprise-side cloud constructs an N*M matrix for every N*M bits of the bit sequence, constructing a total of K N*M matrices. The bits contained in the K N*M matrices correspond one-to-one with the K*N*M bits before or after the bit sequence, where N and M are both integers greater than 3, and K is an integer greater than 2. The enterprise-side cloud determines the access token based on multiple isolated bits in the matrix, including: in the K N*M matrices, the enterprise-side cloud determines multiple bits in any N*M matrix that satisfy a preset condition, and determines the coordinate position of each of the multiple bits in the N*M matrix. The multiple bits are isolated bits, and the coordinate positions of the multiple bits in the N*M matrix are the access token. Satisfying the preset condition means that for any one of the multiple bits at a coordinate position in the N*M matrix, the K bits at that coordinate position in the K N*M matrices repeat periodically.

[0023] Optionally, the enterprise cloud sends the access token to the enterprise mobile device, including: the enterprise cloud sends the access token to the enterprise mobile device through a secure transmission channel.

[0024] Thirdly, embodiments of this application provide a computer-readable storage medium storing program code, which, when executed by the computer, performs the method described in the first aspect.

[0025] In summary, the above methods and systems have the following technical effects: If a company's mobile app authorizes data permissions to a third-party mobile app, the mobile app can inform the company's cloud platform. When the company's cloud platform receives monitoring datasets from the third-party device, it can verify the identity of the third-party device. If the verification confirms that the third-party device is indeed the authorized mobile app, the company's cloud platform can not only store the monitoring dataset but also provide the corresponding access token to the mobile app, allowing the mobile app to access the monitoring dataset. This achieves flexibility and scalability in data management. Furthermore, since the third-party mobile app lacks access tokens, it is restricted to providing data but not acquiring it, ensuring data security. For example, even if an attacker forges the identity of the third-party mobile app, they will not be able to obtain the corresponding data. Attached Figure Description

[0026] Figure 1 A schematic diagram of the architecture of an intelligent monitoring cloud system based on multi-terminal collaboration provided for embodiments of this application; Figure 2 A flowchart illustrating an intelligent monitoring cloud system and its data management method based on multi-terminal collaboration, provided for embodiments of this application; Figure 3 Illustration of application scenarios for the methods provided in the embodiments of this application Figure 1 ; Figure 4 Illustration of application scenarios for the methods provided in the embodiments of this application Figure 2 ; Figure 5 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0027] In this embodiment of the invention, "instruction" can include direct and indirect instructions, as well as explicit and implicit instructions. The information indicated by a certain piece of information is called the information to be instructed. In specific implementation, there are many ways to instruct the information to be instructed, such as, but not limited to, directly instructing the information to be instructed, such as the information to be instructed itself or its index. It can also indirectly instruct the information to be instructed by instructing other information, where there is a correlation between the other information and the information to be instructed. It can also instruct only a part of the information to be instructed, while the other parts are known or pre-agreed upon. For example, the instruction of specific information can be achieved by using a pre-agreed (e.g., protocol-defined) arrangement of various pieces of information, thereby reducing instruction overhead to some extent. Simultaneously, common parts of various pieces of information can be identified and uniformly indicated to reduce the instruction overhead caused by individually indicating the same information.

[0028] Furthermore, the specific indication method can also be any existing indication method, such as, but not limited to, the above-mentioned indication methods and their various combinations. Specific details of various indication methods can be found in existing technologies, and will not be elaborated upon here. As described above, for example, when multiple pieces of information of the same type need to be indicated, the indication methods for different pieces of information may differ. In specific implementation, the required indication method can be selected according to specific needs. This embodiment of the invention does not limit the selected indication method; therefore, the indication methods involved in this embodiment of the invention should be understood to cover various methods that enable the party to be indicated to obtain the information to be indicated.

[0029] It should be understood that the information to be indicated can be sent as a whole or divided into multiple sub-information messages sent separately, and the sending period and / or timing of these sub-information messages can be the same or different. The specific sending method is not limited in this embodiment of the invention. The sending period and / or timing of these sub-information messages can be predefined, for example, according to a protocol, or configured by the sending device by sending configuration information to the receiving device.

[0030] "Predefined" or "pre-configured" can be achieved by pre-saving corresponding codes, tables, or other means that can be used to indicate relevant information in the device. This embodiment of the invention does not limit the specific implementation method. "Saving" can refer to saving in one or more memories. These memories can be separate installations or integrated into the encoder, decoder, processor, or electronic device. Alternatively, some memories can be separate installations, while others are integrated into the decoder, processor, or electronic device. The type of memory can be any form of storage medium, and this embodiment of the invention does not limit this.

[0031] In the embodiments of this invention, "protocol" may refer to a protocol family in the field of communication, a standard protocol with a similar protocol family frame structure, or a related protocol applied to a reliable access method system for future Internet of Things devices. The embodiments of this invention do not specifically limit this.

[0032] In this embodiment of the invention, descriptions such as "when," "under the circumstances," "if," and "if" all refer to the device making corresponding processing under certain objective circumstances, and are not limited to a specific time. They do not require the device to make a judgment action during implementation, nor do they imply any other limitations.

[0033] In the description of the embodiments of the present invention, unless otherwise stated, " / " indicates that the objects before and after are in an "or" relationship. For example, A / B can represent A or B. "And / or" in the embodiments of the present invention is merely a description of the relationship between the related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, and B alone, where A and B can be singular or plural. Furthermore, in the description of the embodiments of the present invention, unless otherwise stated, "multiple" refers to two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple. Additionally, to facilitate a clear description of the technical solutions of the embodiments of the present invention, the terms "first" and "second" are used in the embodiments of the present invention to distinguish identical or similar items with essentially the same function and effect. Those skilled in the art will understand that the terms "first," "second," etc., do not limit the quantity or order of execution, and that "first," "second," etc., are not necessarily different. Furthermore, in the embodiments of this invention, words such as "exemplary" or "for example" are used to indicate that something is being described as an example, illustration, or description. Any embodiment or design scheme described as "exemplary" or "for example" in the embodiments of this invention should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner for ease of understanding.

[0034] The network architecture and business scenarios described in the embodiments of this invention are for the purpose of more clearly illustrating the technical solutions of the embodiments of this invention, and do not constitute a limitation on the technical solutions provided by the embodiments of this invention. As those skilled in the art will know, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided by the embodiments of this invention are also applicable to similar technical problems.

[0035] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0036] Please see Figure 1 This application provides an intelligent monitoring cloud system based on multi-terminal collaboration, which may include an enterprise cloud terminal, an enterprise mobile terminal, and a third-party mobile terminal.

[0037] Enterprise-side cloud computing can refer to cloud-based devices belonging to an enterprise, such as servers or server clusters deployed in the cloud, also known as cloud servers or cloud server clusters. Enterprise-side cloud computing is primarily responsible for data storage and management, such as authentication and secure data storage. For details, please refer to the relevant descriptions in the following method embodiments.

[0038] A company's mobile terminal can be a terminal device belonging to the company. A third-party mobile terminal can be a terminal device not belonging to the company. The aforementioned terminal device can also be referred to as user equipment (UE), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent, or user device. In the embodiments of this application, the terminal device can be a mobile phone, tablet computer, computer with wireless transceiver capabilities, virtual reality (VR) terminal device, augmented reality (AR) terminal device, wireless terminal in industrial control, wireless terminal in self-driving, wireless terminal in remote medical care, wireless terminal in smart grid, wireless terminal in transportation safety, wireless terminal in smart city, wireless terminal in smart home, etc.

[0039] The following section will provide a detailed explanation of the interactions between the enterprise cloud, enterprise mobile terminal, and third-party mobile terminal in the above system, using the methodology provided.

[0040] Please see Figure 2 This application provides a data management method based on multi-terminal collaboration, the process of which is as follows: S201, the enterprise cloud receives data collaboration instructions from the enterprise mobile terminal.

[0041] Data collaboration instructions are used to instruct enterprise mobile devices to grant data permissions to third-party mobile devices.

[0042] For example, data collaboration instructions include authorization instructions from the enterprise mobile device and the identity information of the third-party mobile device. The authorization instructions from the enterprise mobile device are used to instruct the enterprise mobile device to authorize data permissions, such as including the identifier of the enterprise mobile device and instruction information for authorizing data permissions. This is used to jointly instruct the enterprise mobile device to authorize data permissions to the third-party mobile device through the authorization instructions from the enterprise mobile device and the identity information of the third-party mobile device.

[0043] Enterprise mobile devices can establish connections with third-party mobile devices, such as via Wi-Fi or PC5. The enterprise mobile device can then verify the identity of the third-party mobile device. For example, it can determine if the third-party mobile device is a device authorized to grant data permissions, or if its device type is one of those authorized. If so, the enterprise mobile device confirms that the third-party mobile device is authorized to grant data permissions. Alternatively, it can verify if the third-party mobile device's manufacturer is one of those authorized to grant data permissions. If so, the enterprise mobile device confirms that the third-party mobile device is authorized to grant data permissions.

[0044] Once the enterprise mobile terminal determines that the third-party mobile terminal is a device that can be authorized to access data, the enterprise mobile terminal can also obtain the first identification information of the third-party mobile terminal through the connection with the third-party mobile terminal, and determine the identity information of the third-party mobile terminal based on the first identification information.

[0045] For example, the identity information of a third-party mobile device includes first identification information and a first verification code. The first verification code is obtained by performing secure operations on the characteristic characters in the first identification information. Specifically, the first identification information includes an X1-digit numeric string, where X1 is an integer greater than 1. For example, an example format of the first identification information is as follows: user123456@example.com, where user123456 is the username (identifying the user using the third-party mobile device), example.com is the domain name (identifying the manufacturer / device type of the third-party mobile device), and the X1-digit numeric string is 123456. The X1-digit numeric string can be divided into X3 equal numeric segments, meaning the enterprise mobile device divides the X1-digit numeric string into X3 equal numeric segments. The length of each segment of the X3 number string is X2, where X3 is an integer greater than 1 and X2 is a positive integer. The enterprise mobile terminal performs a modulo operation on each segment of the X3 number string with a preset X2-bit number string to obtain a number string, resulting in a total of X3 number strings. The X3 number strings are then concatenated to obtain the feature character in the first identification information.

[0046] To make it easier to understand, let's look at an example. Suppose the X1 digit string includes 123456, X3=3, meaning it's divided into three equal segments: the first segment is 12, the second is 34, and the third is 56, each containing two characters, so X2=2. If the preset X2 digit string is 15, then we first calculate 12 mod 15, which is 0; then we calculate 34 mod 15, which is 4; and finally, we calculate 56 mod 15, which is 11. These are concatenated to obtain 0411, which is the characteristic character. The enterprise mobile terminal then performs integrity protection on 0411, resulting in the first MAC (Checksum).

[0047] The advantage of this is that the first identification information is not directly used for integrity protection. Even if an attacker steals the first identification information, they cannot forge the corresponding checksum.

[0048] S202, when the enterprise cloud receives monitoring datasets from third-party devices, in response to the data collaboration instruction, the enterprise cloud verifies whether the third-party device is a third-party mobile terminal with data permissions.

[0049] For example, the enterprise cloud can receive monitoring datasets and the identity information of third-party devices. The identity information includes second identification information indicating the third-party device. Based on this, the enterprise cloud performs secure calculations on the characteristic characters in the second identification information to obtain a second verification code. The method for determining the characteristic characters in the second identification information is similar to that for the first identification information, and can be understood by referring to this method. If the third-party device is indeed a third-party mobile terminal, and the second identification information has not been tampered with during transmission, then the enterprise cloud can determine the same characteristic characters from the second identification information as those in the first identification information, thereby calculating the same message verification code. At this point, the enterprise cloud verifies whether the first verification code and the second verification code are consistent. If they are consistent, it indicates that the third-party device is a third-party mobile terminal with data permissions; otherwise, the third-party device is not a third-party mobile terminal with data permissions.

[0050] Of course, the second verification code can also be generated by a third-party device and provided to the enterprise cloud along with the monitoring dataset.

[0051] S203, if so, the enterprise-side cloud generates an access token for the monitoring dataset.

[0052] Access tokens are used by enterprise mobile devices to retrieve monitoring datasets from the enterprise cloud.

[0053] The enterprise-side cloud compresses and encodes the monitoring dataset to obtain a feature dataset. For example, the enterprise-side cloud can compress and encode the monitoring dataset to obtain a bit sequence, and then the enterprise-side cloud can construct a matrix from the bit sequence. At this time, the matrix can be a two-dimensional matrix or multiple two-dimensional matrices, that is, it can be regarded as a three-dimensional matrix in space. The following describes method 1 and method 2 respectively.

[0054] Method 1: The enterprise-side cloud can construct an N*M matrix from the first or last N*M bits of a bit sequence, where N and M are both integers greater than 3. For example, if N=M=10, the enterprise-side cloud can construct a 10*10 matrix from the first or last 100 bits of the bit sequence. The first 10 bits of the bit sequence would form the first row of the 10*10 matrix, the 11th to 20th bits would form the second row of the 10*10 matrix, and so on.

[0055] Method 2: The enterprise-side cloud constructs an N*M matrix for every N*M bits of the bit sequence, for a total of K N*M matrices. The bits in each of these K N*M matrices correspond one-to-one with the first or last K*N*M bits of the bit sequence, where N and M are integers greater than 3, and K is an integer greater than 2. For example, if K=3, N=M=10, the enterprise-side cloud can construct three 10*10 matrices from the first or last 300 bits of the bit sequence. The first 10 bits of the bit sequence form the first row of the first 10*10 matrix, bits 11 to 20 form the second row, and so on. Bits 91 to 100 form the tenth row, bits 101 to 110 form the first row, and so on.

[0056] The purpose of methods 1 and 2 above is to construct a structured matrix using unstructured sequences, and then use the structured features of the matrix to generate an access token. The access token is then bound to the structured features of the matrix. Since the enterprise cloud is a black box to attackers, they cannot obtain the information inside it, and therefore cannot obtain the structured features of the matrix. Consequently, they cannot forge the access token, thus ensuring the security of data reading. This will be explained in detail below.

[0057] Based on the above operations, the enterprise cloud can extract access tokens from the feature dataset. For example, the enterprise cloud can determine the access token based on multiple isolated bits in the matrix. The access token is the coordinate position of multiple isolated bits in the matrix. The following sections will continue to introduce methods 1 and 2.

[0058] Continue with method 1: On the enterprise side, the cloud identifies multiple bits in an N*M matrix whose values ​​are all different from their surrounding bits, and determines the coordinate positions of these multiple bits within the N*M matrix. These multiple bits are considered isolated bits, and their coordinate positions within the N*M matrix serve as the access token. For example, if a bit has a value of 1, and the bits above, below, to its left, and to its right all have values ​​of 0, then that bit is an isolated bit.

[0059] For ease of understanding, such as Figure 3As shown, taking a 6*6 matrix as an example, the bit at the coordinate position of the 3rd row and 2nd column is an isolated bit, and the bit at the coordinate position of the 2nd row and 5th column is also an isolated bit. Of course, there are other isolated bits, which will not be described in detail.

[0060] Continue with method 2: In K N*M matrices, the enterprise cloud determines multiple bits in any N*M matrix that satisfy preset conditions, and determines the coordinate positions of each bit in the N*M matrix. These multiple bits are isolated bits, and their coordinate positions in the N*M matrix represent access tokens. Satisfying the preset conditions means that for any bit in the N*M matrix at a given coordinate position, the K bits at that coordinate position in the K N*M matrices periodically repeat. For example, if the K bits are 01010, then for any given bit, the values ​​of its adjacent bits are all different from its own. For instance, if the first bit is 0, the next bit is 1 (different from 0); if the second bit is 1, the bits before and after it are both 01 (different from 1). Therefore, any bit can be considered an isolated bit, or an isolated bit in spatial dimension. For ease of understanding, such as Figure 4 As shown, taking three 6x6 matrices as an example, for the bit at the 2nd row and 6th column, the bit at that coordinate position is 0 in the first matrix, 1 in the second matrix, and 0 in the third matrix, i.e., 010. Each of these bits is an isolated bit. Similarly, for the bit at the 6th row and 3rd column, the bit at that coordinate position is 1 in the first matrix, 0 in the second matrix, and 1 in the third matrix, i.e., 101. Again, each of these bits is an isolated bit.

[0061] S204, the enterprise cloud sends the access token to the enterprise mobile device.

[0062] The third-party mobile device does not have permission to obtain the access token, meaning the enterprise cloud does not send the access token to the third-party mobile device.

[0063] The enterprise cloud sends the access token to the enterprise mobile device via a secure transmission channel; that is, the access token is encrypted and protected for integrity before being sent to the enterprise mobile device. At this time, the enterprise cloud also sends the identifier assigned to the monitoring dataset by the enterprise cloud to the enterprise mobile device.

[0064] Subsequently, to access the monitoring dataset, the enterprise mobile device can send an access token and the identifier assigned to the monitoring dataset to the enterprise cloud via a secure transmission channel. At this point, the access token is encrypted and protected for integrity before being sent to the enterprise cloud. After decryption and integrity verification, the enterprise cloud obtains the plaintext access token. Based on the identifier assigned to the monitoring dataset, the enterprise cloud can retrieve the aforementioned matrix and determine whether the bit at the coordinates indicated by the access token in the matrix is ​​an isolated bit. If so, the verification passes, and the enterprise cloud provides the monitoring dataset to the enterprise mobile device.

[0065] The enterprise cloud sends the access token to the enterprise mobile terminal via a secure transmission channel. In summary, if the enterprise mobile terminal authorizes data permissions to a third-party mobile terminal, the enterprise mobile terminal can inform the enterprise cloud. When the enterprise cloud receives monitoring datasets from a third-party device, it can verify the identity of the third-party device. If the verification confirms that the third-party device is indeed the authorized third-party mobile terminal, the enterprise cloud can not only store the monitoring dataset but also provide the corresponding access token to the enterprise mobile terminal, enabling the enterprise mobile terminal to access the monitoring dataset. This achieves flexibility and scalability in data management. Furthermore, since the third-party mobile terminal lacks the authority to obtain the access token, it is restricted to providing data but not acquiring it, ensuring data security. For example, even if an attacker forges the identity of the third-party mobile terminal, they cannot obtain the corresponding data.

[0066] The above combination Figure 2 The method provided in the embodiments of this application is described in detail. The following describes a multi-terminal collaborative intelligent monitoring cloud system for implementing the method provided in the embodiments of this application, wherein the enterprise-side cloud is configured as follows: the enterprise-side cloud receives a data collaboration instruction from an enterprise mobile terminal, the data collaboration instruction instructing the enterprise mobile terminal to authorize data permissions to a third-party mobile terminal; when the enterprise-side cloud receives a monitoring dataset from a third-party mobile terminal, in response to the data collaboration instruction, the enterprise-side cloud verifies whether the third-party mobile terminal has data permissions; if so, the enterprise-side cloud generates an access token for the monitoring dataset, the access token being used by the enterprise mobile terminal when obtaining the monitoring dataset from the enterprise-side cloud; the enterprise-side cloud sends the access token to the enterprise mobile terminal, and the third-party mobile terminal does not have permission to obtain the access token.

[0067] Optionally, the data collaboration indication includes the authorization indication of the enterprise mobile terminal and the identity information of the third-party mobile terminal. The authorization indication of the enterprise mobile terminal is used to instruct the enterprise mobile terminal to authorize data permissions. The enterprise cloud receives the monitoring dataset from the third-party mobile terminal, including: the monitoring dataset and the identity information of the third-party device received by the enterprise cloud.

[0068] Optionally, the identity information of the third-party mobile terminal includes first identification information and a first verification code for indicating the third-party mobile terminal. The first verification code is obtained by performing a secure operation on the feature characters in the first identification information. The identity information of the third-party device includes second identification information for indicating the third-party device. The enterprise cloud verifies whether the third-party device is a third-party mobile terminal with data permissions, including: the enterprise cloud performs a secure operation on the feature characters in the second identification information to obtain a second verification code; the enterprise cloud verifies whether the first verification code and the second verification code are consistent. If they are consistent, it indicates that the third-party device is a third-party mobile terminal with data permissions; otherwise, the third-party device is not a third-party mobile terminal with data permissions.

[0069] Optionally, the first identification information includes an X1-digit string, where X1 is an integer greater than 1. The X1-digit string can be divided into X3 equal segments, each of which has a length of X2, where X3 is an integer greater than 1 and X2 is a positive integer. Each of the X3 segments is moduloed by a preset X2-digit string to obtain a new string, resulting in a total of X3 strings. These X3 strings are then concatenated to obtain the feature character in the first identification information.

[0070] Optionally, the enterprise cloud generates an access token for the monitoring dataset, including: the enterprise cloud compresses and encodes the monitoring dataset to obtain a feature dataset; the enterprise cloud extracts the access token from the feature dataset.

[0071] Optionally, the enterprise cloud compresses and encodes the monitoring dataset to obtain a feature dataset, including: the enterprise cloud compresses and encodes the monitoring dataset to obtain a bit sequence; the enterprise cloud constructs the bit sequence into a matrix; the enterprise cloud determines an access token based on multiple isolated bits in the matrix, where the access token is the coordinate position of the multiple isolated bits in the matrix.

[0072] Optionally, the enterprise cloud constructs the bit sequence into a matrix, including: the enterprise cloud constructs the first or last N*M bits of the bit sequence into an N*M matrix, where N and M are both integers greater than 3; the enterprise cloud determines the access token based on multiple isolated bits in the matrix, including: the enterprise cloud determines multiple bits in the N*M matrix whose values ​​are different from the surrounding bits, and determines the coordinate positions of the multiple bits in the N*M matrix, where the multiple bits are isolated bits, and the coordinate positions of the multiple bits in the N*M matrix are the access token.

[0073] Optionally, the enterprise-side cloud constructs the bit sequence into a matrix, including: the enterprise-side cloud constructs an N*M matrix for every N*M bits of the bit sequence, constructing a total of K N*M matrices. The bits contained in the K N*M matrices correspond one-to-one with the K*N*M bits before or after the bit sequence, where N and M are both integers greater than 3, and K is an integer greater than 2. The enterprise-side cloud determines the access token based on multiple isolated bits in the matrix, including: in the K N*M matrices, the enterprise-side cloud determines multiple bits in any N*M matrix that satisfy a preset condition, and determines the coordinate position of each of the multiple bits in the N*M matrix. The multiple bits are isolated bits, and the coordinate positions of the multiple bits in the N*M matrix are the access token. Satisfying the preset condition means that for any one of the multiple bits at a coordinate position in the N*M matrix, the K bits at that coordinate position in the K N*M matrices repeat periodically.

[0074] Optionally, the enterprise cloud sends the access token to the enterprise mobile device, including: the enterprise cloud sends the access token to the enterprise mobile device through a secure transmission channel.

[0075] The following is combined Figure 5 A detailed introduction to each component of the electronic device 500 is provided below: The processor 501 is the control center of the electronic device 500. It can be a single processor or a collective term for multiple processing elements. For example, the processor 501 can be one or more central processing units (CPUs), application-specific integrated circuits (ASICs), or one or more integrated circuits configured to implement the embodiments of this application, such as one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs).

[0076] Optionally, the processor 501 can perform various functions of the electronic device 500, as described above, by running or executing software programs stored in the memory 502 and by calling data stored in the memory 502. Figure 2 The functions in the method shown.

[0077] In a specific implementation, as one example, the processor 501 may include one or more CPUs, for example... Figure 5 CPU0 and CPU1 are shown in the diagram.

[0078] In a specific implementation, as one example, the electronic device 500 may also include multiple processors. Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, a processor may refer to one or more devices, circuits, and / or processing cores used to process data (e.g., computer program instructions).

[0079] The memory 502 is used to store the software program that executes the solution of this application, and is controlled by the processor 501 to execute it. The specific implementation method can be referred to the above method embodiment, and will not be repeated here.

[0080] Optionally, memory 502 may be read-only memory (ROM) or other types of static storage devices capable of storing static information and instructions, such as random access memory (RAM) or... Other types of dynamic storage devices capable of storing information and instructions may also be electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, universal optical discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. Memory 502 may be integrated with processor 501 or exist independently, and may also be used with electronic device 500. Interface circuit ( Figure 5 (Not shown in the image) is coupled to processor 501, and this embodiment does not specifically limit this.

[0081] Transceiver 503 is used for communication with other devices. For example, in a multi-beam positioning device as a terminal, transceiver 503 can be used to communicate with network devices or with another terminal.

[0082] Alternatively, transceiver 503 may include a receiver and a transmitter. Figure 5 (Not shown separately). The receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function.

[0083] Optionally, the transceiver 503 can be integrated with the processor 501, or it can exist independently and be connected via the interface circuit of the electronic device 500. Figure 5(Not shown in the image) is coupled to processor 501, and this embodiment does not specifically limit this.

[0084] It should be noted that, Figure 5 The structure of the electronic device 500 shown does not constitute a limitation on the device. The actual electronic device 500 may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0085] Furthermore, the technical effects of the electronic device 500 can be referred to the technical effects of the methods in the above method embodiments, and will not be repeated here.

[0086] It should be understood that the processor in the embodiments of this application can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.

[0087] It should also be understood that the memory in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous DRAM (DDR SDRAM), enhanced synchronous DRAM (ESDRAM), synchronous linked DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0088] The above embodiments can be implemented, in whole or in part, by software, hardware (such as circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. Computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. A computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. Available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. Semiconductor media can be solid-state drives.

[0089] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. A and B can be singular or plural. Additionally, the character " / " in this article generally indicates an "or" relationship between the preceding and following related objects, but it can also represent an "and / or" relationship. Please refer to the context for a more accurate understanding.

[0090] In this application, "at least one" means one or more, and "more than one" means two or more. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of a single item or a plurality of items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be a single item or multiple items.

[0091] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0092] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0093] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0094] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some feature fields may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0095] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0096] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0097] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0098] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A data management method based on multi-terminal collaboration, characterized in that, The method is applied to an enterprise-level cloud platform, and the method includes: The enterprise cloud receives a data collaboration instruction from the enterprise mobile terminal, which instructs the enterprise mobile terminal to authorize data permissions to a third-party mobile terminal. When the enterprise cloud receives a monitoring dataset from a third-party device, in response to the data collaboration instruction, the enterprise cloud verifies whether the third-party device is the third-party mobile terminal with data permissions. If so, the enterprise cloud generates an access token for the monitoring dataset, which is used by the enterprise mobile device to obtain the monitoring dataset from the enterprise cloud; The enterprise cloud sends the access token to the enterprise mobile device, and the third-party mobile device does not have permission to obtain the access token.

2. The method according to claim 1, characterized in that, The data collaboration instruction includes the authorization instruction of the enterprise mobile terminal and the identity information of the third-party mobile terminal. The authorization instruction of the enterprise mobile terminal is used to instruct the enterprise mobile terminal to authorize data permissions. The enterprise-side cloud receives monitoring datasets from third-party mobile devices, including: The enterprise-side cloud receives the monitoring dataset and the identity information of the third-party device.

3. The method according to claim 2, characterized in that, The identity information of the third-party mobile terminal includes first identification information and a first verification code for indicating the third-party mobile terminal. The first verification code is obtained by performing a secure operation on the feature characters in the first identification information. The identity information of the third-party device includes second identification information for indicating the third-party device. The enterprise-side cloud verification of whether a third-party device is a third-party mobile terminal with data permissions includes: The enterprise cloud performs security calculations on the feature characters in the second identification information to obtain the second verification code; The enterprise-side cloud verifies whether the first verification code and the second verification code are consistent. If they are consistent, it means that the third-party device is the third-party mobile terminal with data permissions; otherwise, the third-party device is not the third-party mobile terminal with data permissions.

4. The method according to claim 3, characterized in that, The first identification information includes an X1-digit string, where X1 is an integer greater than 1. The X1-digit string can be divided into X3 equal segments, each of which has a length of X2, where X3 is an integer greater than 1 and X2 is a positive integer. Each of the X3 segments is moduloed by a preset X2-digit string to obtain a new string, resulting in a total of X3 strings. These X3 strings are then concatenated to obtain the feature character in the first identification information.

5. The method according to claim 1, characterized in that, The enterprise-side cloud generates an access token for the monitoring dataset, including: The enterprise-side cloud platform compresses and encodes the monitoring dataset to obtain a feature dataset; The enterprise-side cloud extracts the access token from the feature dataset.

6. The method according to claim 5, characterized in that, The enterprise-side cloud platform compresses and encodes the monitoring dataset to obtain a feature dataset, including: The enterprise-side cloud platform compresses and encodes the monitoring dataset to obtain a bit sequence; The enterprise-side cloud constructs the bit sequence into a matrix; The enterprise-side cloud determines the access token based on multiple isolated bits in the matrix, where the access token represents the coordinate positions of the multiple isolated bits in the matrix.

7. The method according to claim 6, characterized in that, The enterprise-side cloud constructs the bit sequence into a matrix, including: The enterprise-side cloud constructs the first or last N*M bits of the bit sequence into an N*M matrix, where N and M are both integers greater than 3; The enterprise-side cloud determines the access token based on multiple isolated bits in the matrix, including: The enterprise-side cloud determines multiple bits in the N*M matrix whose values ​​are different from the surrounding bits, and determines the coordinate positions of the multiple bits in the N*M matrix. The multiple bits are the isolated bits, and the coordinate positions of the multiple bits in the N*M matrix are the access token.

8. The method according to claim 6, characterized in that, The enterprise-side cloud constructs the bit sequence into a matrix, including: The enterprise cloud constructs an N*M matrix from every N*M bits of the bit sequence, and constructs a total of K N*M matrices. The bits contained in the K N*M matrices correspond one-to-one with the K*N*M bits before or after the bit sequence. N and M are both integers greater than 3, and K is an integer greater than 2. The enterprise-side cloud determines the access token based on multiple isolated bits in the matrix, including: In the K N*M matrices, the enterprise cloud determines multiple bits in any N*M matrix that satisfy a preset condition, and determines the coordinate position of each of the multiple bits in the N*M matrix. The multiple bits are the isolated bits, and the coordinate position of the multiple bits in the N*M matrix is ​​the access token. Satisfying the preset condition means that for any one of the multiple bits at a coordinate position in the N*M matrix, the K bits located at that coordinate position in the K N*M matrices repeat periodically.

9. The method according to any one of claims 6-8, characterized in that, The enterprise cloud sends the access token to the enterprise mobile terminal, including: The enterprise cloud terminal sends the access token to the enterprise mobile terminal through a secure transmission channel.

10. A smart monitoring cloud system based on multi-terminal collaboration, characterized in that, This includes an enterprise cloud platform and an enterprise mobile platform; the enterprise cloud platform is configured as follows: The enterprise cloud receives a data collaboration instruction from the enterprise mobile terminal, which instructs the enterprise mobile terminal to authorize data permissions to a third-party mobile terminal. When the enterprise cloud receives a monitoring dataset from a third-party mobile device, in response to the data collaboration instruction, the enterprise cloud verifies whether the third-party mobile device has data permissions. If so, the enterprise cloud generates an access token for the monitoring dataset, which is used by the enterprise mobile device to obtain the monitoring dataset from the enterprise cloud; The enterprise cloud sends the access token to the enterprise mobile device, and the third-party mobile device does not have permission to obtain the access token.