Access Control Method, Apparatus, Device, and Storage Medium

The access control method addresses inefficiencies in IoT data transmission by establishing a correspondence between data types and application types, automating permission settings and enhancing the efficiency of data access control.

JP7693666B2Active Publication Date: 2025-06-17BOE TECHNOLOGY GROUP CO LTD +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2022530969
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-11-28
Filing Date
2020-11-25
Publication Date
2025-06-17
Estimated Expiration
2040-11-25

AI Technical Summary

Technical Problem

Current methods for directional data transmission in the Internet of Things (IoT) require complex permission settings, particularly in subscription and acquisition modes, which can be inefficient and prone to errors.

Method used

An access control method that determines an access control policy based on the data type from a device, establishing a correspondence relationship between data types and application types, thereby controlling which applications can access specific data types.

Benefits of technology

This approach simplifies the access control process by automating the permission settings based on data types and application types, enhancing efficiency and reducing errors in data transmission within IoT systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007693666000001
    Figure 0007693666000001
  • Figure 0007693666000002
    Figure 0007693666000002
  • Figure 0007693666000003
    Figure 0007693666000003
Patent Text Reader

Abstract

The present disclosure provides an access control method, an apparatus, a device, and a storage medium, the access control method including: obtaining data types of data from a device; and determining an access control policy for data of at least one of the data types, so as to control application types of applications accessing the data from the device, the access control policy including a correspondence between the data type and the application type, and for a target application type and a target data type that have a correspondence, an application of the target application type is configured to be allowed to access data of the target data type.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application claims the priority of a Chinese patent application with an application number of 201911191739.4 filed on November 28, 2019, and the entire content thereof is incorporated herein by reference.

[0002] The present disclosure relates to the field of communication technologies, and particularly to an access control method, apparatus, device, and storage medium.

Background Art

[0003] In the Internet of Things technology, usually, data needs to be transmitted directionally according to the type of application. For example, for instance, sensor data related to energy is only transmitted to applications related to energy. Currently, there are two methods for directional transmission of data: the subscription mode and the acquisition mode. However, in these two modes, both are related to the setting of application resource access permissions. For example, in the subscription mode, the application needs to have the permission to create a subscription resource under the target resource. In the query mode, the application needs to have the permission to query the target resource.

Summary of the Invention

Means for Solving the Problems

[0004] In view of this, the objective of the present disclosure is to provide an access control method, apparatus, device, and storage medium.

[0005] According to a first aspect of the present disclosure, an access control method is provided. The access control method includes obtaining a data type from a device and determining an access control policy for data of at least one data type among the data types so as to control an application type of an application that accesses the data from the device. The access control policy includes a correspondence relationship between the data type and the application type. For a target application type and a target data type for which the correspondence relationship exists, an application of the target application type is arranged to be permitted to access the data of the target data type.

[0006] Optionally, the method further includes receiving an application template creation request sent from the application, where the application template creation request includes a correspondence relationship between a data type and an application type, and creating an application template for the application according to the application template creation request.

[0007] Optionally, determining an access control policy for data of at least one data type among the data types includes determining a first application type corresponding to a first data type of data from the device according to the created application template, and arranging an application of the first application type to be permitted to access the data of the first data type.

[0008] Optionally, arranging an application of the first application type to be permitted to access the data of the first data type includes adding an identifier of the first application type to an access control policy for the data of the first data type.

[0009] Optionally, determining an access control policy for data of at least one of the data types includes sending a notification including the data type of data from the device to a client, causing the client to determine the access control policy according to a pre-stored application template, and receiving the access control policy sent from the client.

[0010] Optionally, the application template includes a plurality of application types and at least one data type respectively corresponding to the plurality of application types.

[0011] Optionally, the application template includes one application type and at least one data type corresponding to the one application type. Optionally, the method further includes receiving a registration request sent from the device, where the registration request includes the data type of data from the device, and registering the device according to the registration request. Optionally, obtaining the data type of data from the device includes obtaining the data type of data from the device from the registration request.

[0012] Optionally, the method further includes receiving a container resource creation request sent from the device, where the container resource creation request includes the data type of data from the device, and creating a container for the device according to the container resource creation request.

[0013] Optionally, obtaining the data type of data from the device includes obtaining the data type of data from the device from the container resource creation request.

[0014] Optionally, the method further includes receiving a client subscription request for a newly registered device or receiving a client subscription request for data of at least one data type before receiving a registration request sent from the device.

[0015] Optionally, the method further includes obtaining a data acquisition request sent from the application, the data acquisition request including a second data type of data to be acquired, determining, according to the access control policy, whether a second application type of the application corresponds to the second data type, and determining that an application of the second application type is permitted to access data of the second data type in response to the second application type corresponding to the second data type.

[0016] According to a second aspect of the present disclosure, an access control method is provided. The access control method includes receiving a notification sent from a server, the notification including a data type of data from a device registered with the server, determining an application type corresponding to the data type according to a pre-stored application template, the application template including a correspondence between an application type and a data type, and sending an access control policy for data of at least one data type of the device to the server. The access control policy includes a correspondence between a data type and an application type, and for a target application type and a target data type for which the correspondence exists, an application of the target application type is arranged to be permitted to access data of the target data type.

[0017] Optionally, the method further includes sending, to the server, a resource subscription request for subscribing to a newly registered device at the server.

[0018] Optionally, the method further includes sending, to the server, a resource subscription request for subscribing to data of at least one data type.

[0019] According to a third aspect of the present disclosure, an access control device is provided. The access control device includes an acquisition module for acquiring a data type of data from a device, and a first determination module for determining an access control policy for data of at least one data type among the data types so as to control an application type of an application accessing the data from the device. The access control policy includes a correspondence relationship between a data type and an application type, and for a target application type and a target data type for which the correspondence relationship exists, an application of the target application type is arranged to be permitted to access data of the target data type.

[0020] According to a fourth aspect of the present disclosure, an access control device is provided. The access control device includes a receiving module for receiving a notification transmitted from a server, the notification including a data type of data from a device registered in the server; a second determination module for determining an application type corresponding to the data type according to a pre-stored application template, the application template including a correspondence between the application type and the data type; and a transmitting module for transmitting an access control policy of data of at least one data type of the device to the server. The access control policy includes a correspondence between the data type and the application type, and for a target application type and a target data type having the correspondence, an application of the target application type is arranged to permit access to data of the target data type.

[0021] According to a fifth aspect of the present disclosure, an electronic device is provided, including a memory storing a computer program, and a processor for executing the computer program to implement the access control method according to any one of the first and second aspects of the present disclosure.

[0022] According to a sixth aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer-executable computer instructions is provided, the computer instructions being for causing the computer to execute the access control method according to any one of the first and second aspects of the present disclosure.

[0023] To more clearly explain the technical solutions in the embodiments of the present disclosure or the prior art, the drawings necessary for the description of the embodiments or the prior art will be briefly described below. Of course, the drawings described below are some embodiments of the present disclosure. On the premise that no creative work is required for those skilled in the art, other drawings can be further obtained based on these drawings.

Brief Description of the Drawings

[0024]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Modes for Carrying Out the Invention

[0025] To make the objectives, technical solutions, and advantages of the present disclosure more clear, the present disclosure will be described in more detail below in conjunction with specific embodiments and with reference to the accompanying drawings.

[0026] Unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present disclosure should have the ordinary meanings understood by those skilled in the art to which the present disclosure pertains. It should be noted that the "first", "second" and similar words used in the present disclosure do not indicate order, quantity or importance, but are only used to distinguish different components. "Including" or "having" and other similar words mean that the elements or items appearing before this word include the elements or items listed after this word and their equivalents, but do not exclude other elements or items. Similar words such as "connected" or "connected to each other" are not limited to physical or mechanical connections, and include electrical connections, whether direct or indirect. "Above", "below", "left", "right", etc. are only used to indicate relative positional relationships, and when the absolute positions of the described objects change, the relative positional relationships may change accordingly.

[0027] FIG. 1 is a flowchart showing an access control method 100 according to an exemplary embodiment of the present disclosure, and the access control method 100 can be executed by a server, for example, by a smart home management server. As shown in FIG. 1, the method 100 includes step 101 and step 102.

[0028] In step 101, the data type of the data from the device is obtained.

[0029] In step 101, the device may be a sensor or an electronic device on which at least one sensor is installed. The device may have a function of collecting data. According to an embodiment, the device can be registered with a server. Specifically, before step 101, method 100 further includes receiving a registration request of the device and registering the device according to the registration request. For example, a registration request for the device to register with the server is received, and the registration request may include information for indicating the identity of the device, such as an identifier of the device. When the received registration request of the device includes the data type of the data from the device, the data type of the data of the device can be obtained from the registration request. When the registration request does not include the data type of the data of the device, the server can obtain the data type of the data of the device from other messages sent from the device to the server, and this situation will be described in detail below in conjunction with the embodiments.

[0030] According to an embodiment, the data type includes one data type or a plurality of data types. The data type of the data of the device is the data type of the data that the device can provide, and hereinafter it is simply referred to as the data type of the device. Taking a smartwatch as an example, it can provide the user's health data, location data, exercise data, multimedia data, and the energy data of the device itself (for example, the current remaining power of the smartwatch), and these data types are the data types of the smartwatch.

[0031] In step 102, an access control policy for data of at least one of the data types is determined so as to control the application type of the application that accesses the data from the device. According to an embodiment, the access control policy includes a correspondence relationship between the data type and the application type, and for the target application type and the target data type for which this correspondence relationship exists, the application of the target application type is arranged to be permitted to access the data of the target data type.

[0032] In step 102, after the server knows that a new device has been registered and further knows the data type of the data that the device can provide, the server can determine the application type corresponding to the data type according to the pre-stored application template. Alternatively, the server can send the data type of the device to the client. After the client knows the data type of the device registered with the server, the client can determine the application type corresponding to the data type according to the pre-stored application template. Here, in the application template, the application type corresponding to the data type may be pre-defined. For example, one application type may correspond to multiple data types, or one data type may correspond to multiple application types. Here, the application type can be classified into an energy application, a health application, a security application, a social application, an image processing application, a transaction application, a multimedia application, etc. according to the function of the application.

[0033] According to the access control method of the embodiments of the present disclosure, after a device is registered with the server, the data type of the device is known, and the access control policy for the data of at least one data type of the device is determined according to the data type, so as to determine the application type of the application that can access the data of the target data type of the device. Thereby, after a new device is registered with the server, it is not necessary to turn on the access rights to the specified type of data of the device for various types of applications in sequence, and the efficiency of access control is improved.

[0034] According to an embodiment, the access control method 100 may further include receiving an application template creation request sent from an application, where the application template creation request includes an application type and a data type corresponding to the application type, and creating an application template for the application according to the application template creation request. According to an embodiment, the application template may include a plurality of application types and at least one data type corresponding to each of the plurality of application types. According to an embodiment, the application template may include one application type and at least one data type corresponding to the one application type.

[0035] According to an embodiment, the application may be various applications. For example, it may include an energy management application, a health application, and a smart home management application (one example of the above client). The server takes a smart home management server as an example, and the device takes a sensor as an example. According to an embodiment, the energy management application and the health application can each send an application template creation request to the smart home management server, and the smart home management server verifies the application template creation request and creates an application template for the energy management application and the health application. The application template includes an application type and a data type. The smart home management server sends an application template creation response to the energy management application and the health application respectively. Here, since the correspondence between the device type and the data type may be preset in the smart home server, the application template creation request can be verified according to the correspondence to determine the legitimacy of the request.

[0036] According to an embodiment, determining an access control policy for data of at least one data type of a device may include determining a first application type corresponding to a first data type of the device according to a created application template, and arranging an application of the first application type to permit access to data of the first data type of the device. According to an embodiment, the server may add an identifier of the first application type to the access control policy for data of the first data type. For example, the device is a smartwatch as an example, the data types that the smartwatch can provide include physiological data (an example of the first data type), and when a template of a certain health application defines that the data types corresponding to the health application include exercise data and physiological data, it can be determined that an application whose application type is a health application (an example of the first application type) is an application for physiological data that permits access to the smartwatch, and an identifier of the health application can be added to the access control policy for the data of the smartwatch.

[0037] According to an embodiment, the access control method 100 may further include receiving a data acquisition request sent from an application, where the data acquisition request includes a second data type of the data to be acquired, determining whether a second application type of the application corresponds to the second data type according to an access control policy, and determining that a second type of application is permitted to access data of the second data type of the device in response to the second application type corresponding to the second data type. According to an embodiment, an energy management application sends a request (an example of a data acquisition request) for acquiring resources of a sensor (an example of the device) to a smart home management server and verifies the application according to an access control policy for the sensor data. If it can be determined according to the access control policy for the sensor data that the second application type corresponds to the second data type to be acquired, a response for acquiring sensor resources is sent to the energy management application. In addition, so that the server can store the data of the device, the device may be configured to report the collected data to the server after collecting the data. Based on this, when the server determines that the data acquisition request is legal according to the access control policy for the device data, the server can send the data requested by the application to the application.

[0038] According to an embodiment, the access control method 100 may further include receiving a subscription request from a client (smart home management application) for a newly registered device at the server before receiving a registration request for the device. In other embodiments, a subscription request from the client for data of at least one data type is received. When a subscription request from the client for a newly registered device at the server is received, after the new device is registered at the server, the server can send the data type of the device to the client. In other embodiments, when a subscription request from the client for data of at least one data type is received, after a new device is registered at the server, the server can send the data type of the device to the client.

[0039] According to an embodiment, the access control method 100 may further include, after obtaining the data type from the device, sending a notification including the data type of the data from the device to the client, so that the client determines an access control policy according to a pre-stored application template. According to an embodiment, based on the pre-stored application template, the application type can be determined according to the data type. After obtaining the data type and the corresponding application type, the client sends an update request to the server. The update request includes the application type of the application permitted to access the data of at least one data type of the device.

[0040] According to an embodiment, the server may obtain the device data type according to the data type included in the device registration request. According to an embodiment, the server may receive a container resource creation request sent from a device. The container resource creation request may include the device data type. According to an embodiment, the server creates a container for the device according to the container resource creation request and obtains the device data type from the container resource creation request. For example, when a sensor sends a registration request to a smart home management server, the registration request may carry the data type of the sensor, or may further carry the ID of the sensor. Further, for example, after the sensor is successfully registered with the smart home management server and then sends a container resource creation request to the smart home management server, the request may carry the data type of the sensor.

[0041] Further, for example, after receiving the sensor registration request, the smart home management server obtains the sensor data type from the request, sends the sensor data type to the smart home management application, and thereby the smart home management application determines the application type of the application that can access at least one data type of the sensor according to the application template, and can determine the access control policy of the sensor according to the application type. Further, for example, after receiving the sensor container resource creation request, the smart home management server obtains the sensor data type from the request, sends the sensor data type to the smart home management application, and thereby the smart home management application determines the application type of the application that can access at least one data type of the sensor according to the application template, and can determine the access control policy of the sensor according to the application type.

[0042] FIG. 2 is a flowchart showing an access control method 200 according to another exemplary embodiment of the present disclosure. The access control method 200 is executable by a client, which may be, for example, a smart home management application. The method 200 includes steps 201 to 203.

[0043] Step 201 is to receive a notification sent from a server, where the notification includes the data type of data from a device registered with the server.

[0044] According to an embodiment, after a device sends a registration request to the server or the device sends a container resource creation request to the server, the server can send the data type information carried in the registration request or the container resource creation request to the client in the form of a notification. According to an embodiment, before a new device is registered with the server, the client can send a resource subscription request to the server, and the resource subscription request is used to request a subscription to a newly registered device on the server or to request a subscription to data of at least one data type.

[0045] Step 202 is to determine the application type corresponding to the data type according to a pre-stored application template, where the application template includes the correspondence between the application type and the data type.

[0046] Step 203 sends an access control policy for data of at least one data type of the device to the server. Here, the access control policy includes the correspondence between the data type and the application type. For the target application type and the target data type where this correspondence exists, the application of the target application type is arranged to be permitted to access the data of the target data type. Here, the client stores an application template locally in advance, and the correspondence between the application type and the data type is defined in the application template. This correspondence may be a one-to-many or many-to-one relationship, and the application template may be sent from the server to the client.

[0047] According to the embodiment, the application template includes a plurality of application types and at least one data type corresponding to each of the plurality of application types. In other embodiments, the application template includes one application type and at least one data type corresponding to the one application type. The client sending a subscription request to the server can send a subscription request for a newly registered device to the server or send a subscription request for data of at least one data type to the server.

[0048] According to the access control method of the embodiment of the present disclosure, after the device is registered with the server, the data type of the device is known, and according to the data type, the access control policy for at least one data type of the device is determined, and the application type of the application that can access the data of the target data type of the device is determined. Thereby, after a new device is registered with the server, it is not necessary to turn on the access rights to the specified type of data of the device for various types of applications in sequence, and the efficiency of access control is improved.

[0049] FIG. 3 and FIG. 4 are signaling flowcharts showing an access control method according to an exemplary embodiment of the present disclosure. Hereinafter, the access control methods 100 and 200 of the embodiments of the present disclosure will be exemplarily described with reference to FIG. 3 and FIG. 4 respectively.

[0050] The access control method shown in FIG. 3 The smart home management server receives an application template creation request sent from an application, and the application template may include the correspondence between the application type and the data type. The smart home management server verifies the application template creation request, and after passing the verification, creates an application template. According to the embodiment, the smart home management server may further send the application template request to the smart home management application for verification. The smart home management server sends an application template creation response to the application. The smart home management application sends a subscription request to the smart home management server to subscribe to a new sensor access system. The smart home management server sends a subscription response to the smart home management application. The sensor sends a registration request to the smart home management server, and the registration request includes the data type of the sensor. The smart home management server sends a registration response to the sensor. The smart home management server sends a notification request to the smart home management application, and the request includes the sensor ID and the data type of the sensor. The smart home management application sends a notification response to the smart home management server. The smart home management application determines the corresponding application type (the determined application type may be one or more) according to the data type of the sensor according to the application template, and sends an update request to the smart home management server to update the access control policy of the sensor. Thereby, it permits the application of the corresponding application type to access the data of the specified data type of the sensor, The smart home management server receives a resource acquisition request of the application, and the smart home management server verifies the application according to the access control policy of the sensor. If the verification is passed, it returns a successful resource acquisition response to the application.

[0051] The access control method shown in FIG. 4 The smart home management server receives a registration request sent from the application, The smart home management server sends a registration response to the application, The smart home management application sends a subscription request to the smart home management server to subscribe to a resource of a certain data type, The smart home management server sends a subscription response to the smart home management application, The sensor sends a registration request to the smart home management server and receives the registration response of the smart home management server, The sensor sends a container resource creation request to the smart home management server, and the request includes the data type, The smart home management server sends a resource creation response to the sensor, The smart home management server sends a notification request to the smart home management application, and the request includes the sensor ID and the data type of the sensor, The smart home management application determines the application type that is permitted to access the data type according to the data type, The smart home management application sends an update request to the smart home management server to update the access control policy of the sensor, so that the application of the application type that matches the data type of the sensor can access the data of the data type. The smart home management application receives the update response sent from the smart home management server. The energy management application sends a resource operation request to the smart home management server. The smart home management server determines whether the application type of the energy management application meets the requirements of the access control policy of the sensor. If the requirements are met, access is permitted; if the requirements are not met, access is denied.

[0052] FIG. 5 is a block diagram showing an access control device 500 according to an exemplary embodiment of the present disclosure. As shown in FIG. 5, the device 500 includes An acquisition module 510 for acquiring the data type of the data from the device, where the data type may include one or more data types. A first determination module 520 for determining an access control policy for at least one data type of the data types to control the application type of the application accessing the data from the device.

[0053] Here, the access control policy includes the correspondence between the data type and the application type. For the target application type and the target data type where this correspondence exists, the application of the target application type is arranged to be permitted to access the data of the target data type.

[0054] According to an embodiment, the access control device 500 receives an application template creation request transmitted from an application. The application template creation request includes a correspondence relationship between a data type and an application type. According to the application template creation request, the access control device 500 may further include a creation module for creating an application template for the application.

[0055] According to an embodiment, an application template includes a plurality of application types and at least one data type corresponding to each of the plurality of application types. Alternatively, an application template includes one application type and at least one data type corresponding to the one application type.

[0056] According to an embodiment, the first determination module 520 determines a first application type corresponding to a first data type of a device according to an application template, determines that an application conforming to the first application type is permitted to access the data of the first data type of the device, and adds an identifier of the first application type to an access control policy of the first data type.

[0057] According to an embodiment, the first determination module 520 can transmit the data type of the device to a client and receive an access control policy transmitted from the client.

[0058] According to an embodiment, the access control device 500 receives a data acquisition request sent from an application, where the data acquisition request includes a second data type of the data to be acquired, and according to an access control policy, determines whether a second application type of the application corresponds to the second data type, and in response to the second application type corresponding to the second data type, further includes an access module for determining that an application of the second application type is permitted to access data of the second data type of the device.

[0059] According to an embodiment, the access control device 500 may further include a subscription receiving module for receiving a client's subscription request for a newly registered device on the server, or a client's subscription request for at least one type of data, before receiving a registration request for the device.

[0060] According to an embodiment, the acquisition module 510 is for acquiring the data type of the device from a registration request.

[0061] According to an embodiment, the access control device 500 receives a container resource creation request sent from a device, where the container resource creation request includes the data type of the device, and may further include a container creation module for creating a container for the device according to the container resource creation request. The acquisition module 510 can acquire the data type of the device from the container resource creation request.

[0062] FIG. 6 is a block diagram showing an access control device 600 according to another exemplary embodiment of the present disclosure. As shown in FIG. 6, the device 600 includes a receiving module 610 for receiving a notification sent from a server, where the notification includes the data type of data from a device registered on the server A second determination module 620 for determining an application type corresponding to the data type according to a pre-stored application template, where the application template includes a correspondence between the application type and the data type, and the second determination module 620; And a transmission module 630 for transmitting an access control policy for data of at least one data type of the device to the server.

[0063] Here, the access control policy includes a correspondence between the data type and the application type. For the target application type and the target data type with a correspondence, the application of the target application type is arranged to permit access to the data of the target data type.

[0064] According to an embodiment, the application template includes a plurality of application types and at least one data type respectively corresponding to the plurality of application types. Alternatively, the application template includes one application type and at least one data type corresponding to the one application type. The subscription transmission module is for transmitting a subscription request to the server for a newly registered device to the server or transmitting a subscription request for data of at least one data type to the server.

[0065] The present disclosure further provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable by the processor. When the processor executes the program, any one of the above access control methods is realized.

[0066] The present disclosure further provides a non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute any one of the above access control methods.

[0067] Note that the method of the embodiments of the present disclosure may be executed by a single device such as one computer or server. The method of this embodiment can also be applied to a distributed scenario and completed by multiple devices cooperating with each other. In this distributed scenario, one of these multiple devices can execute only one or more steps in the method of the embodiments of the present disclosure, and these multiple devices interact with each other to complete the method.

[0068] The device of the above embodiment is for realizing the corresponding method in the above embodiment and has the beneficial effects of the embodiment of the corresponding method, but will not be repeated here.

[0069] Those skilled in the art should understand that any discussion of the above embodiments is merely illustrative and is not intended to mean that the scope of the present disclosure (including the scope of the claims) is limited to these examples. Under the idea of the present disclosure, the technical features in the above embodiments or different embodiments can also be combined, and the steps can be implemented in any order. There are many other changes in different aspects of the present disclosure as described above, and they are not described in detail for the sake of brevity.

[0070] Furthermore, for the purpose of simplifying the description and discussion and not obscuring the present disclosure, well-known power / ground connections of integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Furthermore, to avoid making the present disclosure difficult to understand, the device can be shown in the form of a block diagram, and this also takes into account the fact that the details of the embodiments regarding these block diagram devices highly depend on the platform for implementing the present disclosure (i.e., these details should be within the understanding of those skilled in the art). When specific details (such as circuits) are described to illustrate exemplary embodiments of the present disclosure, it is obvious to those skilled in the art that the present disclosure can be implemented without these specific details or when these specific details are changed. Therefore, these descriptions should be regarded as illustrative rather than restrictive.

[0071] Although the present disclosure has been described in conjunction with specific embodiments thereof, many substitutions, modifications, and variations of these embodiments will be apparent to those skilled in the art based on the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) can use the embodiments discussed.

[0072] The embodiments of the present disclosure are intended to cover all such substitutions, modifications, and variations that fall within the broad scope of the appended claims. Accordingly, omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present disclosure should be included within the protection scope of the present disclosure.

Description of Reference Numerals

[0073] 100 Access control method 200 Access control method 500 Access control device 510 Acquisition module 520 Determination module 600 Access control device 610 Reception module 620 Determination module 630 Transmission module

Claims

1. Receive a client subscription request for a newly registered sensor device, or receive a client subscription request for data of at least one data type of a newly registered sensor device, receive a registration request sent from the sensor device, the registration request includes the data type of data from the sensor device, the data type of data from the sensor device includes the data type of data that the sensor device can sense, register the sensor device according to the registration request, and obtain the data type of data from the sensor device from the registration request, or, Receive a container resource creation request sent from the sensor device, the container resource creation request includes the data type of data from the sensor device, and includes obtaining the data type of data from the sensor device from the container resource creation request, and, Determining an access control policy for data of at least one of the data types to control the application type of an application that accesses the data from the sensor device, The access control policy includes a correspondence between a data type and an application type, and for the target application type and target data type for which the correspondence exists, the application of the target application type is arranged to be permitted to access the data of the target data type, Receive an application template creation request sent from the application, the application template creation request includes a correspondence between a data type and an application type, and, Further including creating an application template for the application according to the application template creation request, Determining the access control policy for data of at least one of the data types is, Determining a first application type corresponding to a first data type of data from a sensor device according to a created application template, and arranging an application of the first application type to permit access to data of the first data type. An access control method comprising: **Claim 2** Arranging an application of the first application type to permit access to data of the first data type comprises adding an identifier of the first application type to an access control policy for data of the first data type. The method according to claim 1. **Claim 3** Determining an access control policy for data of at least one of the data types comprises sending a notification including the data type of data from the sensor device to a client to enable the client to determine the access control policy according to a pre-stored application template, and receiving the access control policy sent from the client. The method according to claim 1. **Claim 4** The application template includes a plurality of application types and at least one data type corresponding to each of the plurality of application types. The method according to any one of claims 1 to 3. **Claim 5** The application template includes one application type and at least one data type corresponding to the one application type. The method according to any one of claims 1 to 3. **Claim 6** The method according to claim 1, further comprising creating a container for the sensor device according to the container resource creation claim. **Claim 7** Obtain a data acquisition claim sent from the application, where the data acquisition claim includes a second data type of data to be acquired, Determine, according to the access control policy, whether a second application type of the application corresponds to the second data type, Further comprising determining that an application of the second application type is permitted to access data of the second data type in response to the second application type corresponding to the second data type. The method according to any one of claims 1 to 6.

8. Send a resource subscription claim for subscribing to a newly registered sensor device on the server to the server, or Send a resource subscription claim for subscribing to data of at least one data type to the server, Receive a notification sent from the server, where the notification includes a data type of data from a sensor device registered on the server, and the data type of data from the sensor device includes a data type of data that the sensor device can sense, Determine an application type corresponding to the data type according to a pre-stored application template, where the application template includes a correspondence relationship between the application type and the data type, Send an access control policy for data of at least one data type of the sensor device to the server, The access control policy includes a correspondence relationship between the data type and the application type. For a target application type and a target data type for which the correspondence relationship exists, an application of the target application type is arranged to be permitted to access data of the target data type, Determining an application type corresponding to the data type according to a pre-stored application template, determining a first application type corresponding to a first data type of data from a sensor device according to a pre-stored application template, and an access control method including arranging an application of the first application type to permit access to data of the first data type. **Claim 9** a subscription receiving module configured to receive a client subscription request for a newly registered sensor device at a server or to receive a client subscription request for at least one type of data of a newly registered sensor device; an acquisition module configured to receive a registration request transmitted by the sensor device, the registration request including a data type of data from the sensor device, the data type of data from the sensor device including a data type of data that the sensor device can sense, and after registering the sensor device according to the registration request, acquiring the data type of data from the sensor device from the registration request; or a container creation module configured to receive a request to create a container resource transmitted by the sensor device, the request to create the container resource including a data type of data from the sensor device, and the acquisition module acquiring the data type of data from the sensor device from the request to create the container resource; a first determination module configured to determine an access control policy for data of at least one of the data types so as to control an application type of an application accessing data from the sensor device. The access control policy includes a correspondence relationship between a data type and an application type. For a target application type and a target data type for which the correspondence relationship exists, the application of the target application type is arranged to permit access to the data of the target data type. Receive an application template creation request sent from an application. The application template creation request includes a correspondence relationship between a data type and an application type, and includes a creation module for creating an application template for the application according to the application template creation request. The first determination module determines a first application type corresponding to a first data type of data from a sensor device according to the created application template, and is an access control device that arranges an application of the first application type to permit access to the data of the first data type.

10. Send a subscription request for a sensor device newly registered on the server to the server, or A subscription sending module that sends a resource subscription request to the server to send a subscription request for data of at least one data type to the server. A receiving module for receiving a notification sent from the server. The notification includes a data type of data from a sensor device registered on the server, and the data type of data from the sensor device includes a data type of data that the sensor device can sense. A second determination module for determining an application type corresponding to the data type according to a pre-stored application template. The application template includes a correspondence relationship between an application type and a data type. A transmission module for transmitting an access control policy for data of at least one data type of the sensor device to the server, The access control policy includes a correspondence relationship between a data type and an application type. For a target application type and a target data type for which the correspondence relationship exists, an application of the target application type is arranged to permit access to data of the target data type. The second determination module determines a first application type corresponding to a first data type of data from a sensor device according to a pre-stored application template, and arranges an application of the first application type to permit access to data of the first data type. An access control device.

11. A memory storing a computer program, An electronic device including a processor for executing the computer program so as to implement the access control method according to any one of claims 1 to 7 or claim 8.

12. A non-transitory computer-readable storage medium storing computer-executable computer instructions, wherein the computer instructions cause the computer to execute the access control method according to any one of claims 1 to 7 or claim 8. A non-transitory computer-readable storage medium.

Citation Information

Patent Citations

  • A method and apparatus for accessing a local network

    CN109842535A

  • Managing application execution and data access on a device

    EP2725511A1

  • Device and method for distributing program component

    JP1999096014A

  • Remote monitoring control system of equipment, and server

    JP2009289274A

  • Methods and apparatus for secure software platform access

    JP2012506584A