IP Library Granted Patent US 12695760
Granted Patent B2
US 12695760 · App. 18/547,636 · Granted Jul 28, 2026

Access control method and related apparatus

Inventors: Bingfei Ren (Beijing, CN); Zhewen Mao (Beijing, CN)
Assignee: Huawei Technologies Co., Ltd.
H04L63/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12695760
App. No.
18/547,636
Granted
Jul 28, 2026
Kind
B2
Abstract

A method includes: an electronic device sends a sign-in request to enable a management party device to learn that the electronic device has entered a specific environment. The management party device selects one access policy from one or more stored access policies based on one or more of the following: restriction levels for the specific environment, restriction categories for functions of electronic devices in the specific environment, a device type or a login user of an electronic device, a time point at which the management party device receives the sign-in request, or an area in which the electronic device is located in the specific environment, and sends the access policy to the electronic device, to restrict a function of the electronic device.

Claims (81)

1 . A method, comprising:

receiving, by a second device, a first request sent by a first device, the first request carries information about a third device;

selecting, by the second device, a first access policy from a plurality of access policies based on: a device type of the first device and at least one of: restriction levels set by the second device for a first environment, restriction categories for functions of electronic devices in the first environment, a login user of the first device, a time point at which the second device receives the first request, or an area in which the first device is located in the first environment;

sending, by the second device, the first access policy to the first device in response to the first request; and

in response to the first request carrying the information about the third device, sending, by the second device, a second access policy to the third device through the first device, wherein whether the second access policy and the first access policy are a same access policy or the second access policy and the first access policy are different access policies is determined based on the device type of the first device and a device type of the third device.

2 . The method according to claim 1 , wherein after the sending, by the second device, the first access policy to the first device, the method further comprises:

receiving, by the second device, a second request sent by the first device; and

sending, by the second device, first feedback information to the first device in response to the second request or sending the first feedback information to the first device after a first duration after sending the first access policy to the first device, wherein the first device deletes or disables the first access policy in response to the first feedback information.

3 . The method according to claim 1 , further comprising storing, by the second device, the plurality of access policies, wherein the plurality of access policies comprises:

access policies respectively corresponding to a plurality of restriction levels of the first environment;

access policies respectively corresponding to a plurality of restriction categories for the functions of the electronic devices in the first environment;

access policies respectively corresponding to a plurality of device types of the electronic devices in the first environment;

access policies respectively corresponding to a plurality of login users of the electronic devices in the first environment;

access policies respectively corresponding to a plurality of time periods in the first environment; or

access policies respectively corresponding to a plurality of areas in the first environment.

4 . The method according to claim 1 , wherein after the sending, by the second device, the first access policy to the first device, the method further comprises:

receiving, by the second device, an execution status of the first access policy sent by the first device, wherein the execution status of the first access policy comprises: an executed state or an execution-refused state; and

when the execution status is the execution-refused state, outputting, by the second device, information about the first device or sending, by the second device, first prompt information to the first device.

5 . The method according to claim 2 , wherein after the sending, by the second device, the first access policy to the first device, the method further comprises:

receiving, by the second device, an execution status of the first access policy sent by the first device, wherein the execution status of the first access policy comprises: an executed state or an execution-refused state; and

when the execution status is the execution-refused state, outputting, by the second device, information about the first device or sending, by the second device, first prompt information to the first device.

6 . The method according to claim 3 , wherein after the sending, by the second device, the first access policy to the first device, the method further comprises:

receiving, by the second device, an execution status of the first access policy sent by the first device, wherein the execution status of the first access policy comprises: an executed state or an execution-refused state; and

when the execution status is the execution-refused state, outputting, by the second device, information about the first device or sending, by the second device, first prompt information to the first device.

7 . The method according to claim 1 , wherein after the sending, by the second device, the second access policy to the third device through the first device, the method further comprises:

receiving, by the second device, an execution status of executing the second access policy by the third device through the first device, wherein the execution status of the second access policy comprises: an executed state or an execution-refused state; and

when the execution status of the second access policy is the execution-refused state, outputting, by the second device, the information about the third device or sending, by the second device, second prompt information to the third device.

8 . An electronic device, comprising:

a non-transitory memory; and

one or more processors, wherein the non-transitory memory is coupled to the one or more processors, the non-transitory memory is configured to store computer program code, the computer program code comprises computer instructions, and the one or more processors invoke the computer instructions to enable a computer to perform operations including:

receiving a first request sent by a first device, the first request carries information about a second device;

selecting a first access policy from a plurality of access policies based on a device type of the first device and at least one of: restriction levels set by the second device for a first environment, restriction categories for functions of electronic devices in the first environment, a login user of the first device, a time point at which the second device receives the first request, or an area in which the first device is located in the first environment;

sending the first access policy to the first device in response to the first request; and

in response to the first request carrying the information about the second device, sending a second access policy to the second device through the first device, wherein whether the second access policy and the first access policy are a same access policy or the second access policy and the first access policy are different access policies is determined based on the device type of the first device and a device type of the second device.

9 . The electronic device according to claim 8 , wherein after the sending the first access policy to the first device, the operations further comprise:

receiving a second request sent by the first device; and

sending first feedback information to the first device in response to the second request or sending the first feedback information to the first device after a first duration after sending the first access policy to the first device, wherein the first device deletes or disables the first access policy based on the first feedback information.

10 . The electronic device according to claim 8 , wherein the non-transitory memory stores the plurality of access policies, and the plurality of access policies comprises one or more of:

access policies respectively corresponding to a plurality of restriction levels of the first environment;

access policies respectively corresponding to a plurality of restriction categories for the functions of the electronic devices in the first environment;

access policies respectively corresponding to a plurality of device types of the electronic devices in the first environment;

access policies respectively corresponding to a plurality of login users of the electronic devices in the first environment;

access policies respectively corresponding to a plurality of time periods in the first environment; or

access policies respectively corresponding to a plurality of areas in the first environment.

11 . The electronic device according to claim 8 , wherein after the sending the first access policy to the first device, the operations further comprise:

receiving an execution status of the first access policy sent by the first device, wherein the execution status of the first access policy comprises: an executed state or an execution-refused state; and

when the execution status is the execution-refused state, outputting information about the first device or sending first prompt information to the first device.

12 . The electronic device according to claim 9 , wherein after the sending the first access policy to the first device, the operations further comprise:

receiving an execution status of the first access policy sent by the first device, wherein the execution status of the first access policy comprises: an executed state or an execution-refused state; and

when the execution status is the execution-refused state, outputting information about the first device or sending first prompt information to the first device.

13 . The electronic device according to claim 10 , wherein after the sending the first access policy to the first device, the operations further comprise:

receiving an execution status of the first access policy sent by the first device, wherein the execution status of the first access policy comprises: an executed state or an execution-refused state; and

when the execution status is the execution-refused state, outputting information about the first device or sending first prompt information to the first device.

14 . The electronic device according to claim 8 , wherein after sending the second access policy to the second device through the first device, the operations further comprise:

receiving an execution status of executing the second access policy by the second device through the first device, wherein the execution status of the second access policy comprises: an executed state or an execution-refused state; and

when the execution status of the second access policy is the execution-refused state, outputting the information about the second device or sending second prompt information to the second device.

15 . A non-transitory computer-readable storage medium, storing instructions, wherein when the instructions are run on one or more processors of an electronic device, the electronic device is enabled to perform operations including:

receiving a first request sent by a first device, the first request carries information about a second device;

selecting a first access policy from a plurality of access policies based on a device type of the first device and at least one of: restriction levels set by the second device for a first environment, restriction categories for functions of electronic devices in the first environment, a login user of the first device, a time point at which the second device receives the first request, or an area in which the first device is located in the first environment;

sending the first access policy to the first device in response to the first request; and

in response to the first request carrying the information about the second device, sending a second access policy to the second device through the first device, wherein whether the second access policy and the first access policy are a same access policy or the second access policy and the first access policy are different access policies is determined based on the device type of the first device and a device type of the second device.

16 . The non-transitory computer-readable storage medium according to claim 15 , wherein after the sending the first access policy to the first device, the operations further comprise:

receiving a second request sent by the first device; and

sending first feedback information to the first device in response to the second request or sending the first feedback information to the first device after a first duration after sending the first access policy to the first device, wherein the first device deletes or disables the first access policy based on the first feedback information.

17 . The non-transitory computer-readable storage medium according to claim 15 , wherein the non-transitory computer-readable storage medium stores the plurality of access policies, and the plurality of access policies comprises one or more of:

access policies respectively corresponding to a plurality of restriction levels of the first environment;

access policies respectively corresponding to a plurality of restriction categories for the functions of the electronic devices in the first environment;

access policies respectively corresponding to a plurality of device types of the electronic devices in the first environment;

access policies respectively corresponding to a plurality of login users of the electronic devices in the first environment;

access policies respectively corresponding to a plurality of time periods in the first environment; or

access policies respectively corresponding to a plurality of areas in the first environment.

18 . The non-transitory computer-readable storage medium according to claim 15 , wherein after the sending the first access policy to the first device, the operations further comprise:

receiving an execution status of the first access policy sent by the first device, wherein the execution status of the first access policy comprises: an executed state or an execution-refused state; and

when the execution status is the execution-refused state, outputting information about the first device, or sending first prompt information to the first device.

19 . The non-transitory computer-readable storage medium according to claim 16 , wherein after the sending the first access policy to the first device, the operations further comprise:

receiving an execution status of the first access policy sent by the first device, wherein the execution status of the first access policy comprises: an executed state or an execution-refused state; and

when the execution status is the execution-refused state, outputting information about the first device or sending first prompt information to the first device.

20 . The method according to claim 1 ,

the selecting comprising selecting the first access policy based on the device type of the first device, the restriction levels, the restriction categories, the login user of the first device, the time point at which the second device receives the first request, and the area in which the first device is located in the first environment,

the second device sending the second access policy to the third device through the first device in response to both the first request requesting to perform sign-in and the first request carrying the information about the third device, and

the third device logging in to a same account as the first device.