Access control method, electronic device, and storage medium
By generating a prompt message when the first device receives a remote access request, and requiring the user to grant or deny the remote access permission of the second device to the functional module used to collect privacy information, the problem that the user's privacy information may be accessed unauthorized in the remote access scenario is solved, and effective protection of the privacy information is achieved.
Patent Information
- Application Number
- PCT/CN2024/128980
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-21
- Filing Date
- 2024-10-31
- Publication Date
- 2025-05-30
AI Technical Summary
In remote access scenarios, the user's privacy information may be accidentally or illegally accessed by an unauthorized device or account, resulting in privacy security being compromised.
By generating a prompt message when the first device receives a remote access request, the user is required to grant or deny remote access rights of the second device to the functional module for collecting privacy information.
It strengthens users' perception of remote access, provides control over whether to grant remote access permissions, and enhances the control of remote access, thereby ensuring user privacy and security.
Smart Images

Figure CN2024128980_30052025_PF_FP_ABST
Abstract
Description
Access control method, electronic device, and storage medium
[0001] This application claims priority to Chinese patent application No. 202311564732.9 filed on November 21, 2023, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The present disclosure relates to the field of communications, and in particular to an access control method, an electronic device, and a storage medium. Background Art
[0003] With the development of science and technology, remote access technology is becoming increasingly mature. It has been widely used in various fields, including enterprises, institutions, and individuals. Remote access technology can provide users with convenience, such as remote work, remote monitoring, and remote collaboration.
[0004] Summary of the Invention
[0005] In a first aspect, an access control method is provided, which is applied to a first device; the access control method includes: receiving a remote access request from a second device; when the remote access request is used to request access to a first type of functional module of the first device, generating a first prompt message, the first prompt message being used to prompt a user whether to grant the second device permission to remotely access the first type of functional module, the first type of functional module being a functional module for collecting privacy information.
[0006] In a second aspect, an electronic device is provided, comprising: a memory and a processor. The memory is coupled to the processor; the memory is used to store a computer program; and the processor implements the above-mentioned access control method when executing the computer program.
[0007] In a third aspect, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the above-mentioned access control method is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0008] To more clearly illustrate the technical solutions of the present disclosure, the following briefly introduces the drawings required for use in some embodiments of the present disclosure. Obviously, the drawings described below are only drawings of some embodiments of the present disclosure, and those skilled in the art can also derive other drawings based on these drawings.
[0009] FIG1 is a schematic diagram of a system architecture according to an embodiment of the present disclosure.
[0010] FIG2 is a schematic structural diagram of a first device according to an embodiment of the present disclosure.
[0011] FIG3 is a flowchart of an access control method according to an embodiment of the present disclosure.
[0012] FIG4 is a flowchart of another access control method according to an embodiment of the present disclosure.
[0013] FIG5 is a flowchart of another access control method according to an embodiment of the present disclosure.
[0014] FIG6 is a flowchart of another access control method according to an embodiment of the present disclosure.
[0015] FIG7 is a flowchart of another access control method according to an embodiment of the present disclosure.
[0016] FIG8 is a flowchart of another access control method according to an embodiment of the present disclosure.
[0017] FIG9 is a schematic structural diagram of an access control device according to an embodiment of the present disclosure.
[0018] FIG10 is a schematic structural diagram of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0019] The following will clearly and completely describe the technical solutions of this disclosure in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of this disclosure, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of this disclosure without inventive effort are within the scope of protection of this disclosure.
[0020] It should be noted that, in this disclosure, words such as "exemplary" or "for example" are used to describe examples, illustrations, or explanations. Any embodiment or design described in this disclosure using words such as "exemplary" or "for example" should not be interpreted as being more preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0021] In the following, the terms "first," "second," etc., are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the quantity of the technical features indicated. Thus, a feature defined by "first," "second," etc. may explicitly or implicitly include one or more of the features.
[0022] In the description of this disclosure, unless otherwise specified, " / " means "or". For example, A / B can mean A or B. "And / or" in this document is only used to describe the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can mean: only A, only B, and A and B. In addition, "at least one" means one or more, and "a plurality" means two or more.
[0023] With the development of science and technology, remote access technology is becoming more and more mature. Remote access technology has been widely used in different fields such as enterprises, institutions and individuals, which can provide convenience for users. For example, the home version of the smart speaker has a care mode function. Users can remotely access the home version of the smart speaker and use the camera configured on the home version of the smart speaker to take care of the elderly and children at home. However, if the home version of the smart speaker is placed in other scenarios (such as hotels, homestays, etc.), there may be some remote devices (or remote accounts) that accidentally or illegally access the home version of the smart speaker. If the user cannot perceive the access of the remote device in time, it will not be possible to restrict and control it in time, which may cause the user's privacy and security to be violated.
[0024] In response to the above technical problems, the embodiments of the present disclosure provide an access control method, the idea of which is that after receiving a remote access request from a second device, the first device generates a first prompt message to prompt the user whether to grant the second device remote access to the first type of functional module (the first type of functional module is a functional module for collecting privacy information) when the remote access request is used to request access to the first type of functional module of the first device, that is, when there is a risk of the second device collecting the privacy information of the user or the first device. It can be seen that the access control method provided by the embodiments of the present disclosure enhances the user's perception of remote access to the second device by generating the first prompt message, and provides the user with control over whether to grant remote access to the second device, thereby enhancing the user's control over remote access to the second device and thus protecting the user's privacy security.
[0025] 1 is a schematic diagram of the system architecture of the access control method according to an embodiment of the present disclosure. As shown in FIG1 , the system includes: a first device 100, a second device 200, and a server 300. The second device 200 and the server 300 are respectively connected to the first device 100 for communication.
[0026] The first device 100 is configured to receive a remote access request from the second device 200 and, based on the remote access request, determine whether to grant the second device 200 permission to remotely access the first device 100 .
[0027] In some embodiments, remote access refers to the act of sending a request message from one device to another device to obtain or operate a remote resource via a communication method such as a cellular network or a wireless fidelity (WIFI) network.
[0028] In some embodiments, as shown in FIG. 2 , the first device 100 includes: a receiving module 101 , a query module 102 , a parsing module 103 , a detection module 104 , a request module 105 , a prompt module 106 and a playback module 107 .
[0029] In some embodiments, the receiving module 101 is configured to receive a remote access request from the second device 200. Exemplarily, the receiving module 101 receives a data packet from the second device 200 via a cellular network or a WIFI network, where the data packet includes the remote access request from the second device 200.
[0030] In some embodiments, the query module 102 is used to query whether the remote access permission function of the first device 100 is turned on, and is also used to query whether the first device 100 has set a remote access whitelist and whether the first device 100 has turned on the privacy mode.
[0031] Parsing module 103 is configured to parse the remote access request to determine relevant information about the second device 200, and to determine whether the remote access request from the second device 200 is intended to access the first category of functional modules of the first device 100. In some embodiments, the remote access request includes at least one of the following: the login account of the second device 200, the device identifier, the geographic location, the time of the remote access request, and the local area network where the second device 200 is located. The first category of functional modules is a functional module for collecting private information. For example, the first category of functional modules may be a camera, a microphone, a sensor, etc.
[0032] It should be noted that the above remote access content is only an example given in the embodiment of the present disclosure. In actual application, the content of the remote access request may be more or less than that given in the embodiment of the present disclosure, and the embodiment of the present disclosure does not limit this.
[0033] The request module 105 is used to send a request to the first device 100 and / or the server 300, so that the first device 100 and / or the server 300 confirms whether the access behavior of the second device 200 is compliant.
[0034] The prompt module 106 is configured to prompt the user whether to grant the second device 200 remote access to the first type of functional modules of the first device 100. In some embodiments, the prompt module 106 is further configured to prompt the user that the second device 200 is performing remote access.
[0035] The playing module 107 is used to play the audio and video preset locally on the first device 100 after the user refuses to grant the second device 200 the permission to remotely access the first device 100, so as to prompt the user of the second device 200 that it does not allow remote access.
[0036] The detection module 104 is used to receive the request sent by the request module 105, and detect whether the access behavior of the second device 200 is compliant based on the request.
[0037] Exemplarily, the first device 100 may be a smart speaker, a smart watch, a smart bracelet, a smart TV, a mobile phone, a tablet computer, a camera, a smart air conditioner, a smart refrigerator, a smart curtain, or other device that can access the Internet and collect user information. The embodiment of the present disclosure does not impose any special restrictions on the specific form of the first device 100.
[0038] The second device 200 is configured to send a remote access request to the first device 100 , and remotely access the first type of functional modules when the first device 100 grants the second device 200 remote access permission to the first type of functional modules of the first device 100 .
[0039] Exemplarily, the second device 200 may be a mobile phone, a tablet computer, a desktop computer, a laptop computer, a handheld computer, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, a personal digital assistant (PDA), an augmented reality (AR) or virtual reality (VR) device, or other device with remote access capabilities. The embodiments of the present disclosure do not impose any special restrictions on the specific form of the second device 200.
[0040] The server 300 is configured to store user data and device information. In some embodiments, the server 300 is configured to receive a request sent by the request module 105 and detect whether the access behavior of the second device 200 is compliant based on the request.
[0041] In some embodiments, the receiving module 101 is further used to receive a detection result of whether the access behavior of the server 300 to the second device 200 is compliant.
[0042] For example, the server 300 may be a single server, or a server cluster composed of multiple servers. In some implementations, the server cluster may also be a distributed cluster.
[0043] It should be noted that the system architecture and application scenarios described in the embodiments of the present disclosure are intended to more clearly illustrate the technical solutions of the embodiments of the present disclosure and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Persons skilled in the art will appreciate that, as system architectures evolve and new business scenarios emerge, the technical solutions provided by the embodiments of the present disclosure will also be applicable to similar technical problems.
[0044] An access control method provided by an embodiment of the present disclosure is described below with reference to the accompanying drawings.
[0045] Referring to Figure 3, which is a flow chart of an access control method according to an embodiment of the present disclosure, as shown in Figure 3, the access control method provided by the embodiment of the present disclosure is applied to a terminal and can be implemented as follows: S101 and S102.
[0046] In S101 , a remote access request from a second device is received.
[0047] In some embodiments, a first device receives a data packet sent by a second device, where the data packet includes a remote access request from the second device. The remote access request is used to request access to the first device.
[0048] In some embodiments, the remote access request includes at least one of the following: a login account of the second device, a device identifier, a geographic location, a time of remote access request, and a local area network (LAN) on which the second device is located. For example, the remote access request from the second device includes: login account of the second device: 123; device identifier: 321; geographic location: Shanghai; time of remote access request: 16:25; and local area network (LAN) on which the second device is located: LAN A.
[0049] In some embodiments, the remote access request also includes: information about the functional module requested by the second device. As an example, the remote access request may include the module name of the functional module requested for access. For example, if the second device requests access to a camera, the remote access request includes: functional module requested for access: camera. As another example, the remote access request may include the module identifier of the functional module requested for access. For example, if the second device requests access to a microphone, and the module identifier of the microphone is 222, the remote access request includes: functional module requested for access: 222.
[0050] In S102 , when the remote access request is used to request access to a first type of functional module of a first device, first prompt information is generated.
[0051] The first prompt information is used to prompt the user whether to grant the second device permission to remotely access the first type of functional modules.
[0052] As an example, the first prompt information may be audio information, for example, audio for prompting the user whether to grant the second device permission to remotely access the first type of functional modules.
[0053] As another example, the first prompt information may be image information, for example, an image used to prompt the user whether to grant the second device permission to remotely access the first type of functional module.
[0054] It should be noted that the above-mentioned forms of the first prompt information are only some examples given in the embodiments of the present disclosure. In actual implementation, the form of the first prompt information may also be different according to actual needs and the device capabilities of the first device, and the embodiments of the present disclosure do not limit this.
[0055] In some embodiments, the first device includes a first type of functional module and a second type of functional module. The first type of functional module is a functional module for collecting private information, such as a camera, microphone, sensor, etc. The second type of functional module is a functional module not involved in collecting private information, such as a timer, switch, etc.
[0056] In some embodiments, after receiving a remote access request, the first device parses the remote access request to determine whether the functional module requested by the second device to access is a first-category functional module or a second-category functional module. For example, when the first device parses the remote access request and determines that the functional module requested by the second device to access is a camera, i.e., the second device requests access to the first-category functional module, a first prompt message is generated.
[0057] It is understandable that after receiving a remote access request from a second device, the first device generates a first prompt message to prompt the user whether to grant the second device remote access to the first type of functional module (the first type of functional module is a functional module for collecting privacy information) when the remote access request is used to request access to the first type of functional module of the first device (the first type of functional module is a functional module for collecting privacy information), that is, when there is a risk that the second device will collect privacy information of the user or the first device. It can be seen that in the method provided by the embodiment of the present disclosure, the first device generates the first prompt message, which not only enhances the user's perception of remote access to the second device, but also provides the user with control over whether to grant remote access to the second device, thereby enhancing the user's control over remote access to the second device and thus protecting the user's privacy security.
[0058] As an implementation manner, after the first prompt information is generated, as shown in FIG4 , the access control method further includes: S103a to S105a.
[0059] In S103a, a first operation of a user for instructing to grant the second device a permission to remotely access a first type of functional module is received.
[0060] As an example, the first operation can be a user's voice command operation through the voice assistant of the first device or the voice recognition function of the first device. For example, the user can issue a voice command directly to the first device through the voice recognition function of the first device to grant the second device remote access to the first category of functional modules. For example, the user can say, "Allow the second device to access the camera," and the first device will receive the user's first operation.
[0061] As another example, the first operation may be a click operation by the user on the display interface of the first device. For example, the user opens the system setting interface on the first device and grants the second device remote access to the first type of functional modules through a simple click operation.
[0062] It should be noted that the content of the above-mentioned first operation is only some examples given in the embodiments of the present disclosure. During implementation, the content of the first operation may also be different based on different user selections and different capabilities of the first device, and the embodiments of the present disclosure do not limit this.
[0063] In S104a, in response to the first operation, an operation corresponding to the remote access request is executed.
[0064] In some embodiments, after receiving the first operation, the first device executes the operation corresponding to the remote access request. At this time, the second device can access the first type of functional module of the first device.
[0065] In S105a, second prompt information is generated.
[0066] The second prompt information is used to prompt the user that the second device is remotely accessing the first type of functional module of the first device.
[0067] As an example, the second prompt information may be audio information, for example, audio for prompting the user that the second device is remotely accessing the first type of functional module.
[0068] As another example, the second prompt information may be text information, for example, text prompting the user that the second device is remotely accessing the first type of functional module.
[0069] It should be noted that the above-mentioned second prompt information is only some examples given in the embodiments of the present disclosure. In actual implementation, the form of the second prompt information may also be different according to actual needs and the device capabilities of the first device, and the embodiments of the present disclosure do not limit this.
[0070] It can be understood that in the access control method provided by the embodiment of the present disclosure, when the second device accesses the first type of functional module of the first device, the first device prompts the user by generating a second prompt message, so that the user can perceive the access behavior of the second device, which is convenient for the user to manage and control the second device according to the access behavior of the second device, reducing the risk of user privacy being leaked and improving the user's usage experience.
[0071] As an example, in response to the first operation, after executing the operation corresponding to the remote access request, in addition to generating the second prompt information, as shown in FIG5 , the above method further includes: S201a and S202a.
[0072] In S201a, the duration of the current visit of the second device is determined.
[0073] In some embodiments, after the first device performs the operation corresponding to the remote access request, that is, after the second device starts to remotely access the first type of functional module, the first device accumulates the duration of this access by the second device.
[0074] In S202a, when the duration of this visit is greater than the first threshold, third prompt information is generated.
[0075] The third prompt information is used to prompt the user whether to disconnect the remote access of the second device.
[0076] As an example, the third prompt information may be audio information, for example, audio used to prompt the user whether to disconnect the remote access of the second device.
[0077] As another example, the third prompt information can be text information, such as text for prompting the user whether to disconnect the remote access of the second device. In addition, the first device can also provide the user with a button to disconnect the remote access so that the user can operate it.
[0078] It should be noted that the form of the third prompt information is only some examples given in the embodiments of the present disclosure. In actual implementation, the form of the third prompt information may also be different according to actual needs and the device capabilities of the first device, and the embodiments of the present disclosure do not limit this.
[0079] In some embodiments, the first threshold may be 30 minutes. For example, if the access duration is 31 minutes, which is greater than the first threshold, the first device plays an audio message "Access has timed out" to prompt the user whether to disconnect the remote access of the second device.
[0080] It is understandable that the access control method provided in the embodiment of the present disclosure, after the first device grants the second device permission to access the first type of functional module, will also determine the duration of the second device's current access to ensure that the second device does not excessively access the first type of functional module. At the same time, the access control method provided in the embodiment of the present disclosure generates a third prompt message when the current access duration exceeds the first threshold, thereby enhancing the user's awareness of the second device's access duration, allowing the user to further determine whether to disconnect the second device's remote access, thereby improving the management and control of remote access to the second device.
[0081] In some embodiments, if the user disconnects remote access to the second device based on the third prompt information, then after S202a, the access control method further includes: receiving a second operation from the user indicating that remote access to the second device is being disconnected, and in response to the second operation, sending a prompt information to the second device indicating that the first device has disconnected remote access to the second device. Exemplarily, the prompt information indicating that the first device has disconnected remote access to the second device may be an audio message. For example, the first device generates an audio message that reads "Remote access disconnected" and sends it to the second device.
[0082] As an example, the second operation can be performed by a user through a voice command on the first device's voice assistant or voice recognition function. For example, the user can issue a voice command directly on the first device through the voice recognition function of the first device to disconnect remote access to the second device. For example, the user can say, "Disconnect remote access to the second device."
[0083] As another example, the second operation may be a click operation of the user on the display interface of the first device. For example, the user clicks a button for disconnecting remote access on the first device to indicate disconnecting remote access of the second device.
[0084] It should be noted that the content of the second operation is only some examples given in the embodiment of the present disclosure. In implementation, based on different user selections and different capabilities of the first device, the content of the second operation may also be different, and the embodiment of the present disclosure does not limit this.
[0085] It can be understood that in the access control method provided by the embodiment of the present disclosure, after receiving the user's second operation, the first device will disconnect the remote access of the second device to reduce potential security risks; at the same time, the first device will send a prompt message to the second device to prompt the second device that the remote access has been disconnected, so that the second device can determine the status of its remote access in time and enhance user perception.
[0086] As another example, in response to the first operation, after executing the operation corresponding to the remote access request, in addition to generating the second prompt information, as shown in FIG6 , the access control method further includes: S201b and S202b.
[0087] In S201b, the duration of the current visit of the second device is determined.
[0088] In some embodiments, after the first device performs the operation corresponding to the remote access request, that is, after the second device starts to remotely access the first type of functional module, the first device accumulates the duration of this access by the second device.
[0089] In S202b, when the duration of this visit is greater than the first threshold, fourth prompt information is generated.
[0090] The fourth prompt information is used to indicate that the first device disconnects the remote access of the second device.
[0091] As an example, the fourth prompt information may be audio information, for example, audio used to indicate that the first device disconnects the remote access of the second device.
[0092] As another example, the fourth prompt information may be text information, for example, text indicating that the first device disconnects the remote access to the second device.
[0093] It should be noted that the form of the fourth prompt information is only some examples given in the embodiments of the present disclosure. In actual implementation, the form of the fourth prompt information may also be different according to actual needs and the device capabilities of the first device, and the embodiments of the present disclosure do not limit this.
[0094] In some embodiments, the first threshold may be 20 minutes. For example, if the duration of the current access is 21 minutes, which is greater than the first threshold, the first device plays an audio message stating "This access has timed out, remote access has been disconnected" to prompt the first device to disconnect the remote access of the second device.
[0095] It is understood that the access control method provided in the embodiments of the present disclosure, after the first device grants the second device permission to access the first category of functional modules, also determines the duration of the second device's current access to ensure that the second device does not excessively access the first category of functional modules. Furthermore, if the current access duration exceeds the first threshold, the access control method provided in the embodiments of the present disclosure generates a fourth prompt message to enhance the user's awareness of the second device's access duration and promptly notify the second device that its remote access has been disconnected.
[0096] As another implementation, as shown in FIG7 , after the first prompt information is generated, the access control method further includes: S103b and S104b.
[0097] In S103b, a third operation of the user for indicating a refusal to grant the second device the permission to remotely access the first type of functional modules is received.
[0098] As an example, the third operation can be performed by a user through a voice command on the first device's voice assistant or the first device's voice recognition function. For example, the user can issue a voice command directly on the first device through the first device's voice recognition function to deny the second device remote access to the first category of functional modules. For example, the user can say, "Reject remote access."
[0099] As another example, the third operation may be a click operation by the user on the display interface of the first device. For example, the user clicks a button on the first device to deny remote access, indicating that the second device is denied permission to remotely access the first type of functional modules.
[0100] It should be noted that the content of the third operation is only some examples given in the embodiment of the present disclosure. In implementation, based on different user selections and different capabilities of the first device, the content of the third operation may also be different, and the embodiment of the present disclosure does not limit this.
[0101] In S104b, in response to the third operation, fifth prompt information is sent to the second device.
[0102] The fifth prompt information is used to indicate that the first device rejects the remote access request.
[0103] As an example, the fifth prompt information may be audio information. For example, the first device generates an audio message of "remote access denied" and sends it to the second device as the fifth prompt information.
[0104] As another example, the fifth prompt information may be a text message. For example, the first device generates a text message "Remote access denied" and sends it to the second device as the fifth prompt information.
[0105] It should be noted that the form of the fifth prompt information is only some examples given in the embodiments of the present disclosure. In actual implementation, the form of the fifth prompt information may also be different according to actual needs and the device capabilities of the first device, and the embodiments of the present disclosure do not limit this.
[0106] It is understandable that after receiving the third operation of the user refusing to grant the second device remote access to the first type of functional module, the first device will send a fifth prompt message to the second device, so that the operator of the second device can promptly know that its remote access request has been rejected, so that the second device can promptly adjust or improve its remote access request.
[0107] In some embodiments, after receiving a remote access request from a second device, the access control method further includes: determining whether the second device is allowed to remotely access the first device. That is, after receiving a remote access request from a second device, the first device does not directly grant the second device remote access permission, but instead first determines whether the first device allows the second device to remotely access the device. Therefore, the generation of the first prompt message when the remote access request is used to request access to a first type of functional module of the first device can be implemented as: generating the first prompt message when the second device is allowed to remotely access the first device and when the remote access request is used to request access to a first type of functional module of the first device.
[0108] It can be understood that after the first device receives the remote access request from the second device, it determines whether to allow the second device to perform remote access, which can prevent the second device from accessing the first device without authorization and reduce the risk of privacy leakage. At the same time, the embodiment of the present disclosure can strengthen access control of the second device and protect the privacy security of the user by determining whether to allow the second device to perform remote access.
[0109] In some embodiments, determining whether the second device is allowed to remotely access the first device includes at least one of the following: determining whether the remote access function of the first device is turned on; determining whether the access behavior of the second device is compliant; and determining whether the functional module accessed by the remote access request is within the functional module allowed to be accessed by the first device.
[0110] In some embodiments, the first device records the second device's past remote access requests, for example, the second device's login account, device identification, geographic location, time of remote access request, local area network where the second device is located, reasons for success / failure of the second device's remote access, reasons for rejecting the second device's remote access, etc., and performs statistics, analysis, and integration on them to facilitate subsequent judgment on whether the second device's access behavior is compliant.
[0111] As an implementation, determining whether to allow the second device to remotely access the first device is based on at least one of the following conditions: the remote access permission function of the first device is enabled; the second device's access behavior complies with regulations; and the functional module accessed by the remote access request is within the functional modules permitted to be accessed by the first device. For example, if the remote access permission function of the first device is enabled, determining whether to allow the second device to remotely access the first device is based on at least one of the following conditions:
[0112] As another example, if the access behavior of the second device complies with the regulations, it is determined that the second device is allowed to remotely access the first device. In some embodiments, the access behavior of the second device complies with the regulations and includes at least one of a to i.
[0113] a. The login account and / or device identifier is in the whitelist. In some embodiments, the user sets a whitelist for login accounts and / or device identifiers that are allowed to access (for example, configuring a whitelist for the login accounts of parents, friends, and classmates), and the user can update the whitelist at any time as needed to determine whether the access behavior of the second device is compliant based on the whitelist. For example, if the login accounts in the whitelist include: 123, 124, 125, and the login account of the second device is 123, then the login account is in the whitelist, that is, the access behavior of the second device meets the requirements of rule a.
[0114] b. The geographic location is within the preset login range. In some embodiments, the preset login range can be a province, city, region, etc. For example, if the preset login range is Fengtai District and Haidian District in Beijing, and the geographic location of the second device is Chaoyang District in Beijing, then the access behavior of the second device does not meet the requirements of rule b.
[0115] It should be noted that the above-mentioned preset login range is only an example given in the present disclosure. In actual implementation, the preset login range can be flexibly selected according to actual conditions, and the present disclosure embodiment does not limit this.
[0116] c. The time of requesting remote access is within the preset access period. For example, the preset access period may be: 9:00-12:00. If the time of requesting remote access is 9:32, the access behavior of the second device meets the requirements of rule c.
[0117] d. The second device is in the same local area network as the first device. For example, if the second device and the first device are both in local area network A (for example, a parent's phone remotely accesses a camera on a child's desk in the living room, and the parent's phone and the camera on the desk are connected to the same Wi-Fi network), then the second device's access behavior meets the requirements of Rule d.
[0118] e. The number of devices accessed by the login account of the second device is less than or equal to the second threshold. In some embodiments, the server can configure a device record table for each login account, recording information about the devices accessed by that account. Based on a remote access request, the first device can send the login account of the second device to the server, allowing the server to query the device record table for the number of devices accessed by the login account of the second device. For example, the second threshold can be 4. If the number of devices accessed by the login account of the second device is 3, then the access behavior of the second device meets the requirements of Rule e.
[0119] f. The historical access duration of the second device to the first device is less than or equal to a third threshold. For example, the third threshold may be 2 hours. If the historical access duration is 1 hour and 20 minutes, which is less than 2 hours, then the second device's access behavior is determined to meet the requirements of rule f.
[0120] g. The second device's access frequency to the first device is less than or equal to a fourth threshold. For example, the fourth threshold may be three times per day. If the second device accesses the first device twice on that day, i.e., the access frequency is two times per day, then the second device's access behavior is determined to meet the requirements of Rule g.
[0121] h. The number of times the first device has denied access to the second device is less than or equal to a fifth threshold. As an example, the number of times access has been denied may be the number of times access has been denied that day. As another example, the number of times access has been denied may be the number of times access has been denied in the past. For example, the fifth threshold may be 4. If the first device has denied access to the second device 3 times, then the second device's access behavior is determined to meet the requirements of Rule h.
[0122] i. The number of times the first device grants access rights to the second device is greater than or equal to a sixth threshold. For example, the sixth threshold may be 5 times. If the number of times the first device grants access rights to the second device is 8 times, then the second device's access behavior is determined to meet the requirements of rule i.
[0123] It can be understood that the access control method provided by the embodiment of the present disclosure judges whether the access behavior of the second device is compliant based on different dimensions, thereby improving the judgment of the security and credibility of the second device, avoiding the problem of user privacy leakage caused by accidental or malicious access of the second device to the first device, and improving the security of remote access.
[0124] As another example, if the functional module accessed by the remote access request is within the functional module that the first device allows access to, it is determined that the second device is allowed to remotely access the first device. In some embodiments, when the first device turns on the privacy protection mode, the functional modules that the first device allows access to include the second type of functional modules; or, when the first device turns off the privacy protection mode, the functional modules that the first device allows access to include the first type of functional modules and the second type of functional modules. Therefore, when determining whether the functional module accessed by the remote access request is within the functional module that the first device allows access to, it is possible to first determine whether the first device has turned on the privacy protection mode. For example, if the first device turns on the privacy protection mode, the functional modules that the first device allows access to include the second type of functional modules; if the functional module that the second device requests to access is the first type of functional module, the second device is not allowed to remotely access the first device.
[0125] It is understandable that when managing the remote access rights of the second device, the related technologies often simply determine whether the second device has access rights based on a single access by the second device. The judgment dimension is single and not precise enough, and the security of access is not guaranteed. In the access control method provided by the embodiment of the present disclosure, by determining whether the remote access permission function of the first device is turned on, determining whether the access behavior of the second device is compliant, and determining whether the functional module accessed by the remote access request is within the functional module allowed to be accessed by the first device, it is achieved that when the second device requests remote access, the remote access rights of the second device are judged in multiple dimensions through different management and control methods, thereby strengthening the management and control of the remote access rights of the second device and thus protecting the privacy and security of the user.
[0126] As another implementation method, since the first device is configured with a function that allows remote access, the user can flexibly turn this function on or off. Therefore, when the function of allowing remote access is turned off, even if the access behavior of the second device is compliant or the functional module accessed by the remote access request is within the functional module that the first device allows access to, the second device cannot remotely access the first device. When the function of allowing remote access is turned on, if the access behavior of the second device is compliant and / or the functional module accessed by the remote access request is within the functional module that the first device allows access to, it is determined that the second device is run to remotely access the first device. Exemplarily, if the function of allowing remote access of the first device is turned off, it is determined that the second device is denied remote access to the first device; if the function of allowing remote access of the first device is turned on, and the access behavior of the second device is compliant, it is determined that the second device is allowed remote access to the first device.
[0127] It is understandable that when the first device is configured with a function that allows remote access, once this function is turned off, the second device will not be able to remotely access the first device, eliminating the hidden danger of user privacy leakage caused by remote access of the second device and ensuring the user's privacy security.
[0128] For ease of understanding, the access control method provided by the embodiment of the present disclosure is described below using a scenario in which a second device requests to access a camera of a first device as an example.
[0129] Exemplarily, as shown in FIG8 , in this scenario, the access control method provided by the embodiment of the present disclosure may be implemented as the following a1 to a8.
[0130] In a1 , a remote access request from a second device is received.
[0131] In a2, determine whether the remote access permission function of the first device is enabled; if so, execute a3; if not, execute a8.
[0132] In a3, the remote access request is parsed to determine the device information of the second device.
[0133] In a4, it is determined whether the access behavior of the second device is in compliance with regulations; if so, a5 is executed; if not, a7 is executed.
[0134] In some embodiments, the first device may send a request to the server, requesting the server to confirm whether the access behavior of the second device is compliant. For example, the first device may send the login account of the second device to the server, requesting the server to confirm whether the number of devices accessed by the login account of the second device is greater than a second threshold; if the number of devices accessed by the login account of the second device is greater than the second threshold, the access behavior of the second device is determined to be non-compliant.
[0135] In a5, a first prompt message is issued.
[0136] The first prompt information is used to prompt the user whether to grant the second device permission to remotely access the camera.
[0137] In step a6 , in response to the user granting the second device permission to remotely access the camera, a second prompt message is issued, and step a8 is executed.
[0138] The second prompt information is used to prompt the user that the second device is remotely accessing the camera.
[0139] In a7, the first device sends third prompt information to the second device.
[0140] The third prompt information is used to prompt the second device user not to allow remote access. In some embodiments, the third prompt information can be locally preset audio and video information.
[0141] In a8, this session ends.
[0142] It can be understood that in the access control method provided by the embodiment of the present disclosure, after the first device receives a remote access request from the second device, if the remote access request is used to request access to the first type of functional module of the first device (the first type of functional module is a functional module for collecting privacy information), that is, if the second device has a risk of collecting privacy information of the user or the first device, a first prompt message is generated to prompt the user whether to grant the second device remote access to the first type of functional module. It can be seen that in the access control method provided by the embodiment of the present disclosure, the first device strengthens the user's perception of remote access to the second device by generating the first prompt message, and also provides the user with control over whether to grant remote access to the second device, thereby enhancing the user's control over remote access to the second device and thus protecting the user's privacy security.
[0143] The above mainly introduces the solution of the embodiment of the present disclosure from the perspective of method. It can be understood that in order to realize the above functions, the access control device includes at least one of the hardware structure and software modules corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiment disclosed herein, the embodiment of the present disclosure can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the embodiment of the present disclosure.
[0144] The embodiment of the present disclosure can divide the access control device into functional modules according to the above-mentioned method embodiment. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one functional module. The above-mentioned integrated module can be implemented in the form of hardware or software. It should be noted that the division of modules in the embodiment of the present disclosure is schematic and is only a logical functional division. There may be other division methods in actual implementation. The following is an example of dividing each functional module corresponding to each function.
[0145] Figure 9 is a schematic diagram of the structure of an access control device according to an embodiment of the present disclosure. The access control device, applied to a first device, can execute the access control method provided by the above method embodiment. As shown in Figure 9, the access control device 400 includes a receiving module 401, a generating module 402, an executing module 403, a determining module 404, a sending module 405, and a judging module 406.
[0146] The receiving module 401 is configured to receive a remote access request from a second device.
[0147] Generating module 402 is configured to generate a first prompt message when the remote access request is for accessing a first type of functional module of the first device. The first prompt message is configured to prompt a user whether to grant the second device remote access to the first type of functional module, where the first type of functional module is a functional module for collecting private information.
[0148] In some embodiments, the receiving module 401 is further configured to receive a first operation from a user indicating that the second device is granted remote access to the first type of functional module, and the executing module 403 is configured to execute an operation corresponding to the remote access request in response to the first operation.
[0149] In some embodiments, the generating module 402 is further configured to generate second prompt information. The second prompt information is configured to prompt the user that the second device is remotely accessing the first type of functional module of the first device.
[0150] In some embodiments, the determining module 404 is configured to determine a duration of the current access by the second device. The generating module 402 is configured to generate a third prompt message if the current access duration exceeds a first threshold. The third prompt message is configured to prompt the user whether to disconnect the remote access of the second device.
[0151] In some embodiments, the determining module 404 is configured to determine a duration of the current access by the second device. The generating module 402 is configured to generate a fourth prompt message if the current access duration exceeds a first threshold. The fourth prompt message is configured to indicate that the first device has disconnected remote access to the second device.
[0152] In some embodiments, receiving module 401 is further configured to receive a third operation from a user indicating a refusal to grant the second device remote access to the first category of functional modules. Sending module 405 is further configured to send a fifth prompt message to the second device in response to the third operation. The fifth prompt message indicates that the first device has rejected the remote access request.
[0153] In some embodiments, the determination module 406 is configured to determine whether the second device is allowed to remotely access the first device. The generation module 402 is configured to generate a first prompt message, for example, when the second device is allowed to remotely access the first device and the remote access request is for requesting access to a first type of functional module of the first device.
[0154] In some embodiments, determining whether the second device is allowed to remotely access the first device includes at least one of the following: determining whether the remote access function of the first device is turned on; determining whether the access behavior of the second device is compliant; and determining whether the functional module accessed by the remote access request is within the functional module allowed to be accessed by the first device.
[0155] In some embodiments, it is determined that the second device is allowed to remotely access the first device when at least one of the following is met: the remote access function of the first device is turned on; the access behavior of the second device is compliant; the functional module accessed by the remote access request is within the functional module allowed to be accessed by the first device.
[0156] In some embodiments, the remote access request includes at least one of the following: a login account of the second device, a device identifier, a geographic location, a time when the remote access is requested, and a local area network where the second device is located.
[0157] In some embodiments, compliance of the access behavior of the second device includes at least one of the following: the login account and / or device identification is in the whitelist; the geographical location is within the preset login range; the time of requesting remote access is within the preset access period; the second device and the first device are in the same local area network; the number of devices accessed by the login account of the second device is less than or equal to the second threshold; the historical access duration of the second device to the first device is less than or equal to the third threshold; the frequency of access of the second device to the first device is less than or equal to the fourth threshold; the number of times the second device is denied access rights by the first device is less than or equal to the fifth threshold; the number of times the second device is granted access rights by the first device is greater than or equal to the sixth threshold.
[0158] In some embodiments, when the first device is in privacy protection mode, the functional modules allowed to be accessed by the first device include the second category functional modules; or when the first device is in privacy protection mode, the functional modules allowed to be accessed by the first device include the first category functional modules and the second category functional modules. The second category functional modules are functional modules that do not involve the collection of private information.
[0159] In the case of implementing the functions of the above-mentioned integrated modules in the form of hardware, the embodiments of the present disclosure provide a structure of the electronic device involved in the above-mentioned embodiments. As shown in Figure 10, the electronic device 500 includes: a processor 502 and a bus 504. In some embodiments, the electronic device 500 may also include a memory 501. In some embodiments, the electronic device 500 may also include a communication interface 503.
[0160] The processor 502 may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the embodiments of the present disclosure. The processor 502 may be a central processing unit, a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array, or other programmable logic device, a transistor logic device, a hardware component, or any combination thereof, and may implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the embodiments of the present disclosure. The processor 502 may also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP (digital signal processor) and a microprocessor, and the like.
[0161] The communication interface 503 is used to connect to other devices via a communication network, such as Ethernet, wireless access network, or wireless local area network (WLAN).
[0162] The memory 501 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0163] As an implementation, the memory 501 may exist independently of the processor 502. The memory 501 may be connected to the processor 502 via a bus 504 and used to store instructions or program codes. When the processor 502 calls and executes the instructions or program codes stored in the memory 501, the access control method provided in the embodiments of the present disclosure can be implemented.
[0164] In another implementation, the memory 501 may also be integrated with the processor 502 .
[0165] Bus 504 can be an Extended Industry Standard Architecture (EISA) bus, etc. Bus 504 can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, FIG10 shows only one thick line, but this does not mean that there is only one bus or only one type of bus.
[0166] Some embodiments of the present disclosure provide a computer-readable storage medium (e.g., a non-transitory computer-readable storage medium) having computer program instructions stored therein. When the computer program instructions are executed on a computer, the computer executes the access control method described in any of the above embodiments.
[0167] For example, the computer-readable storage media may include, but are not limited to, magnetic storage devices (e.g., hard disks, floppy disks, or magnetic tapes), optical disks (e.g., compact disks (CDs), digital versatile disks (DVDs), etc.), smart cards, and flash memory devices (e.g., erasable programmable read-only memories (EPROMs), cards, sticks, or key drives, etc.). The various computer-readable storage media described in the present disclosure may represent one or more devices and / or other machine-readable storage media for storing information. The term "machine-readable storage medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.
[0168] An embodiment of the present disclosure provides a computer program product comprising instructions. When the instructions are executed on a computer, the computer is enabled to execute the access control method described in any one of the above embodiments.
[0169] Based on the access control scheme provided by the embodiment of the present disclosure, after receiving a remote access request from the second device, the first device generates a first prompt message to prompt the user whether to grant the second device remote access to the first type of functional module (the first type of functional module is a functional module for collecting privacy information) when the remote access request is used to request access to the first type of functional module of the first device (the first type of functional module is a functional module for collecting privacy information), that is, when there is a risk that the second device will collect privacy information of the user or the first device. It can be seen that in the scheme provided by the embodiment of the present disclosure, the first device generates the first prompt message, which not only enhances the user's perception of remote access to the second device by generating the first prompt message, but also provides the user with control over whether to grant remote access to the second device, thereby enhancing the user's control over remote access to the second device and thus protecting the user's privacy security.
[0170] The above is only a specific embodiment of the present disclosure, but the scope of protection of the present disclosure is not limited thereto. Any changes or replacements within the technical scope disclosed in the present disclosure should be included in the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure should be based on the scope of protection of the claims.
Claims
1. An access control method, applied to a first device, comprising: receiving a remote access request from a second device; In the case where the remote access request is used to request access to a first type of functional module of the first device, a first prompt message is generated, and the first prompt message is used to prompt the user whether to grant the second device remote access to the first type of functional module, and the first type of functional module is a functional module used to collect privacy information.
2. The method according to claim 1, further comprising: receiving a first operation by the user for instructing to grant the second device a permission to remotely access the first type of functional modules; In response to the first operation, an operation corresponding to the remote access request is performed.
3. The method according to claim 2, further comprising: Generate second prompt information, where the second prompt information is used to prompt the user that the second device is remotely accessing the first type of functional module of the first device.
4. The method according to claim 2, further comprising: Determine the duration of this access by the second device; When the duration of the current visit is greater than the first threshold, generating third prompt information; The third prompt information is used to prompt the user whether to disconnect the remote access of the second device.
5. The method according to claim 2, further comprising: Determine the duration of this access by the second device; When the duration of the current visit is greater than the first threshold, generating fourth prompt information; The fourth prompt information is used to indicate that the first device disconnects the remote access of the second device.
6. The method according to claim 1, further comprising: receiving a third operation by the user for indicating a refusal to grant the second device a permission to remotely access the first type of functional modules; In response to the third operation, fifth prompt information is sent to the second device, where the fifth prompt information is used to indicate that the first device rejects the remote access request.
7. The method according to claim 1, wherein: After receiving the remote access request of the second device, the method further includes: Determining whether to allow the second device to remotely access the first device; The generating first prompt information when the remote access request is used to request access to the first type of functional module of the first device includes: When the second device is allowed to remotely access the first device and the remote access request is used to request access to a first type of functional module of the first device, first prompt information is generated.
8. The method according to claim 7, wherein: The determining whether to allow the second device to remotely access the first device includes at least one of the following: Determining whether a remote access permission function of the first device is enabled; Determining whether the access behavior of the second device is compliant; It is determined whether the function module accessed by the remote access request is within the function modules allowed to be accessed by the first device.
9. The method according to claim 8, wherein: It is determined that the second device is allowed to remotely access the first device when at least one of the following is satisfied: The remote access permission function of the first device is turned on; The access behavior of the second device complies with the regulations; The function module accessed by the remote access request is within the function modules that the first device is allowed to access.
10. The method according to claim 9, wherein: The remote access request includes at least one of the following: a login account, a device identifier, a geographic location, a time of requesting remote access, and a local area network where the second device is located.
11. The method according to claim 10, wherein: The access behavior of the second device complies with at least one of the following: The login account and / or the device identification is in the whitelist; The geographical location is within a preset login range; The time of requesting remote access is within a preset access period; The second device and the first device are in the same local area network; The number of devices accessed by the login account of the second device is less than or equal to a second threshold; The historical access duration of the second device to the first device is less than or equal to a third threshold; The access frequency of the second device to the first device is less than or equal to a fourth threshold; The number of times that the first device refuses to grant access rights to the second device is less than or equal to a fifth threshold; The number of times that the first device grants access rights to the second device is greater than or equal to a sixth threshold.
12. The method according to claim 8, wherein: When the privacy protection mode is turned on for the first device, the functional modules that the first device allows access to include the second category functional modules; or, when the privacy protection mode is turned off for the first device, the functional modules that the first device allows access to include the first category functional modules and the second category functional modules; wherein, the second category functional modules are functional modules that do not involve the collection of privacy information.
13. An electronic device comprising: a processor and a memory for storing instructions executable by the processor; The processor is configured to execute the instructions so that the electronic device performs the method according to any one of claims 1 to 12.
14. A computer-readable storage medium, wherein: The computer-readable storage medium stores computer instructions, and when the computer instructions are executed on an electronic device, the electronic device executes the method according to any one of claims 1 to 12.
Citation Information
Patent Citations
Permission sharing method of smart home, server, system and readable storage medium
CN108737424A
Control authority setting method and device based on smart home control system
CN110391959A
Distributed access control method, related device and system
CN115081010A
Application program authority management method, system and related device
CN116933219A
Remote direct memory access authorization
US20190141041A1