Intelligent lock system of cash internet of things management terminal

By using a portable terminal and digital lock system, combined with national cryptographic algorithms and a multimodal acquisition module, a dynamic key is generated and dual verification is performed, which solves the problems of high maintenance costs and poor coordination of existing smart lock devices, and realizes safe, efficient and integrated transportation of cash logistics management.

CN120783416BActive Publication Date: 2025-12-30BANK OF COMM CO LTD ANHUI BRANCH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511110367.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-08
Publication Date
2025-12-30
Estimated Expiration
2045-08-08

AI Technical Summary

Technical Problem

In existing cash logistics management systems, smart lock devices are diverse, have high maintenance costs, fragmented operation processes, and poor multi-terminal coordination, making it difficult to meet the needs of security, efficiency, and integration.

Method used

It employs a portable terminal, digital lock, and backend system, combined with a communication module, security processing chip, multimodal acquisition module, positioning module, and dynamic key generation unit. It generates dynamic keys using national cryptographic algorithms to achieve dual verification and path verification. It supports BeiDou/GPS dual-mode positioning and electronic fence functions to prevent non-compliant transfer of cash boxes and data leakage.

Benefits of technology

It significantly reduces the risk of key cracking or misuse, ensures the compliance of operator identities, improves system interaction security, prevents cash box swapping, enhances emergency protection capabilities, and improves the efficiency of dynamic monitoring of transportation routes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120783416B_ABST
    Figure CN120783416B_ABST
Patent Text Reader

Abstract

The application discloses a kind of intelligent lock systems of cash internet of things management terminal, comprising: portable terminal, at least one digital lock and background system;The portable terminal includes: communication module, configured to interact logistics task data and verification instruction with background system in real time;Security processing chip, built-in national secret SM2 / SM4 algorithm encryption and decryption unit;Digital key interface, the passive lock cylinder of digital lock is connected by physical plug;Multi-modal acquisition module, integrated double-sided camera, fingerprint instrument, RFID reader and non-contact certificate reader;Positioning module, support Beidou / GPS dual-mode positioning and electronic fence function;Dynamic key generation unit, based on logistics task identifier, terminal real-time position coordinates and time stamp generates disposable dynamic key.The application can more comprehensively carry out cash internet of things management terminal security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of smart lock systems, and more specifically to a smart lock system for a cash Internet of Things (IoT) management terminal. Background Technology

[0002] In the daily operations of commercial banks, cash logistics management is the lifeline for maintaining the normal operation of branches. Its security and efficiency are directly related to business continuity and customer trust. Cash flow involves long links, many nodes, and complex forms, requiring the collaboration of multiple roles such as vault personnel, security guards, and branch tellers. There is an urgent need for efficient and secure centralized and unified control over information flow, logistics, and capital flow.

[0003] In the wave of digital transformation, IoT technology has become crucial for improving the efficiency of cash logistics management. State-owned and large joint-stock commercial banks are actively exploring ways to build a fully traceable control system by deploying smart devices on cash carriers and personnel identification. Among these, digital locks with electronic access control are the core security node for physical transfers, and their management efficiency and security are paramount. However, existing technologies suffer from a wide variety of devices, resulting in high maintenance costs, fragmented operational processes that affect efficiency, and poor multi-terminal coordination that increases security risks. These issues make it difficult to meet the core requirements of cash logistics for security, efficiency, and integration. Therefore, this paper proposes a smart lock system for cash IoT management terminals. Summary of the Invention

[0004] This invention solves the problems of the prior art through the following technical solutions, which include:

[0005] Portable terminal, at least one digital lock, and a back-end system;

[0006] The portable terminal includes:

[0007] The communication module is configured to interact with the backend system in real time with logistics task data and verification instructions;

[0008] The security processing chip has a built-in national standard SM2 / SM4 algorithm encryption and decryption unit;

[0009] The digital key interface connects to the passive lock cylinder of the digital lock via a physical plug;

[0010] The multimodal acquisition module integrates a dual-sided camera for capturing facial images, a fingerprint scanner for capturing fingerprint information, an RFID reader for reading RFID data from the cash box, and a contactless document reader for reading document chip data.

[0011] The positioning module supports BeiDou / GPS dual-mode positioning and electronic fence function, and triggers a security mechanism when the terminal exceeds the preset geographical range;

[0012] The dynamic key generation unit generates a one-time dynamic key based on the logistics task identifier, the real-time location coordinates of the terminal, and the timestamp.

[0013] The logistics status sensing unit synchronously integrates RFID data, QR code information, and positioning coordinates to construct a logistics path verification model (used to verify the compliance of the cash box transportation path).

[0014] The digital lock has a built-in hardware identification device, a fingerprint sensor. d The hardware identifier is pre-registered to the backend system and synchronized to the security processing chip of the portable terminal. After receiving the dynamic key for decryption and verification, the terminal performs the opening and closing operation.

[0015] Furthermore, the dynamic key generation unit is used to perform:

[0016] Obtain the logistics task identifier T id The real-time location coordinates (x, y) and timestamp t of the terminal are used to generate the dynamic key K using the following formula:

[0017] K = SM4(H(T) id )⊕H(x‖y)⊕Δt);

[0018] H(·) is the SM3 hash function; x||y means concatenating the coordinates x and y in order into a string;

[0019] Δt is the encrypted offset dynamically issued by the backend system based on the current time.

[0020] Furthermore, the lifecycle of the dynamic key K is controlled by the following rules:

[0021] The validity period T of the dynamic key K k Related logistics task phases:

[0022]

[0023] t verify t is the point in time when authentication is successful. open t represents the time point at which the unlock command is executed. scan The time point at which the scanning of the cash box information is completed, t close This refers to the point in time when the latch instruction is executed;

[0024] Dynamic keys K that have not been used within the time limit will automatically expire (the background system and the digital lock will synchronously clear the verification permissions of this key).

[0025] Furthermore, the opening and closing operation of the digital lock includes a dual authentication mechanism:

[0026] First verification layer: The backend system compares the dynamic key K with the pre-generated task key (the pre-generated task key is generated by the backend system based on the logistics task identifier T). id The pre-calculated base key has the same generation logic as the dynamic key K in the dynamic key generation unit.

[0027] The second verification layer: The multimodal acquisition module acquires the operator's biometric data (fingerprints, faces) and the decrypted data of the ID card chip (identity information stored in the ID card chip) to verify the validity of the multimodal feature fusion relationship.

[0028] Furthermore, the object feature data includes the extraction of fingerprint feature vectors. With facial feature vectors Extracting fingerprint feature vectors With facial feature vectors By comparing the decrypted data D′ from the ID card chip, we can verify that the following formula holds true:

[0029]

[0030] The decrypted data D′ of the ID card chip is the biometric baseline data extracted after decryption from the ID card chip, including fingerprint and facial feature templates associated with the ID card holder;

[0031] SM2_Sig(·) is the national cryptographic SM2 digital signature verification function.

[0032] Furthermore, the second verification layer also includes a joint confidence score calculation based on biometric features, the specific calculation process of which is as follows:

[0033]

[0034] Wherein, α and β are the weighting coefficients of fingerprint features and facial features, respectively (dynamically configured by the backend system according to the task security level); These are the normalized similarity values ​​(ranging from 0 to 1) of the fingerprint feature vector and the face feature vector, respectively.

[0035] When Cb is greater than the preset threshold γ (γ∈[0.6,0.9], configured by the backend system) and the biometric similarity of D′ meets the standard (i.e., the baseline features in D′ are similar to the collected features), When the matching degree exceeds 85%, the digital key interface is activated.

[0036] Furthermore, the digital lock also implements a two-way authentication mechanism:

[0037] After receiving the dynamic key K, the device fingerprint F is returned to the portable terminal. d (the F) d (This is a unique hardware identifier for the chip built into the digital lock, pre-registered to the backend system);

[0038] Security processing chip verification F d After matching with the pre-stored device registration information (digital lock identifier library synchronized to the portable terminal by the backend system), an open / close command is sent to the digital lock.

[0039] Furthermore, the system collects the RFID serial number R of the cash box, the cash box identifier Q obtained from the QR code parsing, and the location coordinates (x, y) in real time, and verifies the compliance of the path through the following process:

[0040]

[0041] Where (x0, y0) are the coordinates of the logistics path nodes preset by the backend system;

[0042] ‖(x,y)-(x0,y0)‖ represents the Euclidean distance between the real-time coordinates of the terminal and the preset node coordinates;

[0043] δ is the allowable coordinate deviation radius, which is configured by the backend system based on the node position characteristics;

[0044] R≡Q indicates that the RFID serial number and the QR code identifier correspond to the same identity of the box.

[0045] Furthermore, when validation fails, i.e., ValidPath = 0, a path tracing mechanism is triggered:

[0046] Historical location coordinates are retrieved to generate an abnormal path map (marking the time and location of deviations from preset nodes); the risk value of tampering is calculated based on the matching degree between the RFID serial number R and the cash box identifier Q.

[0047]

[0048] Where, N match N represents the number of nodes in the logistics path where R and Q are matched; total This represents the total number of nodes in the logistics path.

[0049] When Risk > η, the operation permissions of the digital lock are frozen, and the backend system sends a locking command to the digital lock. η is a preset risk threshold, which is configured by the backend system.

[0050] Furthermore, the electronic fence function triggers a remote kill mechanism for the terminal:

[0051] The positioning module monitors the terminal's location in real time. When it detects that the terminal has exceeded the preset electronic fence range (the geographical boundary predefined by the backend system), it sends a self-destruct command to the security processing chip.

[0052] The security processing chip responds to commands, erases the stored dynamic key and task data, and physically locks the digital key interface to prevent any physical connection operations.

[0053] Compared with existing technologies, this invention has the following advantages: The smart lock system of this cash IoT management terminal, through the construction of an encryption system, generates a dynamic key by combining logistics task identifiers, real-time location, timestamps, and dynamic offsets, and has a lifecycle associated with the task stage, significantly reducing the risk of key cracking or abuse and ensuring the security of the encryption logic. Through a first verification layer comparing the dynamic key with a pre-generated task key, and a second verification layer fusing multimodal biometrics and document chip data, combined with biometric joint confidence calculation, the uniqueness and compliance of the operator's identity are ensured. Simultaneously, the bidirectional device fingerprint authentication between the digital lock and the portable terminal prevents unauthorized personnel from using the system. By integrating compliant devices, the system enhances interactive security. It integrates RFID, QR codes, and positioning coordinates to construct a path verification model. Through real-time coordinates and Euclidean distance judgment with preset nodes, as well as consistency verification of cash box identification, it achieves dynamic monitoring of the transportation path. When verification fails, it triggers anomaly tracing and swapping risk calculation. If the risk exceeds the standard, it freezes the digital lock, effectively preventing the cash box from being transferred or swapped in violation of regulations. It supports Beidou / GPS dual-mode positioning and electronic fence function. When the terminal exceeds the preset range, it automatically triggers a remote kill mechanism (erasing keys and task data, and physically locking the interface) to avoid data leakage and non-compliant operations after the terminal is lost or taken away from the compliant area, thus strengthening the system's emergency protection capabilities. Attached Figure Description

[0054] Figure 1 This is an overall structural diagram of the present invention. Detailed Implementation

[0055] The embodiments of the present invention are described in detail below. These embodiments are implemented based on the technical solution of the present invention, and provide detailed implementation methods and specific operation processes. However, the scope of protection of the present invention is not limited to the following embodiments.

[0056] like Figure 1 As shown, this embodiment provides a technical solution: a smart lock system for a cash IoT management terminal, comprising:

[0057] Portable terminal, at least one digital lock, and a back-end system;

[0058] The portable terminal includes:

[0059] The communication module is configured to interact with the backend system in real time with logistics task data and verification instructions;

[0060] The security processing chip has a built-in national standard SM2 / SM4 algorithm encryption and decryption unit;

[0061] The digital key interface connects to the passive lock cylinder of the digital lock via a physical plug;

[0062] The multimodal acquisition module integrates a dual-sided camera for capturing facial images, a fingerprint scanner for capturing fingerprint information, an RFID reader for reading RFID data from the cash box, and a contactless document reader for reading document chip data.

[0063] The positioning module supports BeiDou / GPS dual-mode positioning and electronic fence function, and triggers a security mechanism when the terminal exceeds the preset geographical range;

[0064] The dynamic key generation unit generates a one-time dynamic key based on the logistics task identifier, the real-time location coordinates of the terminal, and the timestamp.

[0065] The logistics status sensing unit integrates RFID data, QR code information, and positioning coordinates to build a logistics path verification model, which is used to verify the compliance of the cash box transportation path.

[0066] The digital lock has a built-in hardware identification device, a fingerprint sensor. d The hardware identifier is pre-registered to the backend system and synchronized to the security processing chip of the portable terminal. After receiving the dynamic key for decryption and verification, the terminal performs the opening and closing operation.

[0067] The dynamic key generation unit is used to perform:

[0068] Obtain the logistics task identifier T id The real-time location coordinates (x, y) and timestamp t of the terminal are used to generate the dynamic key K using the following formula:

[0069] K = SM4(H(T) id )⊕H(x‖y)⊕Δt);

[0070] H(·) is the SM3 hash function; x||y means concatenating the coordinates x and y in order into a string;

[0071] Δt is the encrypted offset dynamically issued by the backend system based on the current time;

[0072] Key K is based on the logistics task identifier (T) id The system generates real-time location coordinates (x, y) and dynamically distributed encrypted offsets (Δt) based on the current time. Different tasks, locations, and times (Δt dynamically changes) will generate completely different keys, avoiding the risk of fixed keys being reused over a long period. This significantly improves the key's resistance to cracking and enhances the key's anti-cracking capabilities. (T) idSpatial information (location coordinates) and time dynamic factor (Δt) are fused through hash and XOR operations to strongly bind the key to the specific logistics scenario. It is only valid within a specific task, specific location, and specific time window, preventing the key from being transferred in violation of regulations or abused across scenarios.

[0073] It adopts the national cryptographic standard SM3 hash function (H(·)) and SM4 encryption algorithm, which has high encryption strength and can effectively resist common encryption threats such as collision attacks and brute-force attacks.

[0074] Suppose a bank is handling a cash transportation task:

[0075] Logistics Task Identifier T id The code 20250710_YZ001 represents mission number 001, which was transported from City A to City B on July 10, 2025.

[0076] When the transport vehicle arrives at the preset node 1 (position coordinates x=116.3°, y=39.9°), the portable terminal acquires the coordinates in real time and stitches them together to form 116.339.9;

[0077] At this time, the encryption offset Δt dynamically issued by the backend system is +30s, adjusted based on the current time.

[0078] First calculate H(T) id The result of hashing SM320250710_YZ001 is assumed to be hash value A.

[0079] Calculate the result of H(x||y) = SM3 hash 116.339.9, and assume it to be the hash value B;

[0080] Perform an XOR operation: A⊕B⊕Δt, to obtain the intermediate value C;

[0081] Finally, the intermediate value C is encrypted using SM4 to generate the dynamic key K1.

[0082] When the vehicle reaches the next node 2 (coordinates x = 116.4°, y = 40.0°), and the backend sends a change Δt to +45s:

[0083] The new H(x||y) becomes hash 116.440.0 (hash value D), and the XOR result is A⊕D⊕45s (intermediate value E). The generated dynamic key K2 is completely different from K1.

[0084] The lifecycle of the dynamic key K is controlled by the following rules:

[0085] The validity period Tk of the dynamic key K is associated with the logistics task stage:

[0086]

[0087] tverify t is the point in time when authentication is successful. open t represents the time point at which the unlock command is executed. scan The time point at which the scanning of the cash box information is completed, t close This refers to the point in time when the latch instruction is executed;

[0088] Dynamic keys K that are not used within the specified time will automatically expire. The backend system and the digital lock will simultaneously clear the verification permissions of the key, preventing dynamic keys from being valid for a long time. They are only usable within a specific time window of the corresponding task stage and will automatically expire upon expiration. This significantly reduces the risk of keys being intercepted and misused across time periods. The validity period of the key is directly related to specific operation stages such as unlocking and locking, ensuring that the key is only effective in the current task stage. This prevents the key from being used for non-compliant operations in non-corresponding stages (such as using a key from the unlocking stage to attempt to lock, or vice versa), strengthens the compliance of the operation process, and requires no manual intervention. The backend system and the digital lock will automatically clear the verification permissions of expired keys, reducing human management loopholes and improving system security and efficiency.

[0089] Assume a bank's cash transportation task T id Dynamic key generation scenario for =20250710_YZ001:

[0090] Example of unlocking phase:

[0091] When the transport vehicle arrives at the preset node 1 (coordinates x = 116.3°, y = 39.9°), the operator completes identity verification. Multimodal biometrics and identification verification are successful. At this point, the identity verification time t... verify =9:00:00.

[0092] The system's basic dynamic key generation unit generates a dynamic key K1 according to its rules, and associates it with T. id Node 1 coordinates, Δt = +30s.

[0093] The key validity period T during the unlocking phase k =t open -t verify , t open This is the execution time for the unlock command. Assume the allowed operation window for the unlocking phase of this task is 5 minutes (i.e., T). k =300 seconds), then K1 is only valid from 9:00:00 to 9:05:00.

[0094] If the operator is delayed due to temporary matters and attempts to unlock the door with K1 at 9:05:30, K1 will automatically expire due to its validity period. The background system and the digital lock will simultaneously clear its verification permissions, and the operator will need to complete the identity verification again and generate a new dynamic key before the unlocking operation can be performed.

[0095] Example of the locking phase:

[0096] After the cash transfer is completed, the operator scans the RFID and QR code on the cash box to collect information. The scanning completion time is t. scan =10:00:00.

[0097] The system generates a dynamic key K2 for the locking phase (based on the current task Tid, node 2 coordinates x = 116.4°, y = 40.0°, Δt = +45s).

[0098] Key validity period T during the locking phase k =t close -t scan (t close (This refers to the execution time of the latching instruction). Assume the allowed operation window during the latching phase of this task is 3 minutes (i.e., T). k =180 seconds), then K2 is only valid from 10:00:00 to 10:03:00.

[0099] If the operator does not lock the box in time and attempts to lock it with K2 at 10:03:10, K2 will be invalid by then. The cash box information will need to be scanned again and a new key generated to complete the locking process. This is to avoid the security risks caused by the key remaining valid for a long time after the handover.

[0100] The opening and closing operation of the digital lock includes a dual authentication mechanism:

[0101] First verification layer: The backend system compares the dynamic key K with the pre-generated task key (the pre-generated task key is generated by the backend system based on the logistics task identifier T). id The pre-calculated base key has the same generation logic as the dynamic key K in the dynamic key generation unit.

[0102] The second verification layer: acquires the operator's biometric data (such as fingerprints and faces) and ID chip decryption data (such as identity information stored in the ID chip) through the multimodal acquisition module to verify the validity of the multimodal feature fusion relationship;

[0103] The first verification layer, which compares the dynamic key with the pre-generated task key, and the second verification layer, which combines multimodal biometrics with the decryption data from the document chip, offer the following benefits:

[0104] Dual authentication forms a security loop from two dimensions: key compliance and operator identity compliance. This prevents a single authentication link from being breached. For example, verifying only the key may be abused due to key leakage, and verifying only the identity may become invalid due to identity information theft. This greatly improves the system's resistance to attacks.

[0105] The first verification layer ensures that the key is strictly matched with the current logistics task to prevent the abuse of keys across tasks. The second verification layer ensures that the operator has compliant permissions to prevent unauthorized personnel from using valid keys. The two work together to ensure that the operation is only effective in compliant tasks and compliant personnel scenarios, thereby strengthening the compliance of the operation.

[0106] Continue using bank cash transportation task T id =20250710_YZ001, the transport vehicle has arrived at the preset node 1 (coordinates x=116.3°, y=39.9°), and the digital lock needs to be opened to complete the cash transfer:

[0107] First verification layer (comparison of dynamic key and pre-generated task key):

[0108] The backend system has already used T when generating tasks. id =20250710_YZ001, Node 1 preset coordinates, task planning time and other parameters, the dynamic key generation unit pre-generates the benchmark key K benchmark (consistent with the dynamic key generation logic).

[0109] When the operator initiates an unlocking request at node 1, the portable terminal generates a dynamic key K1 (based on T). id (Real-time coordinates of node 1, Δt = +30s).

[0110] The backend system compares K1 with the pre-stored K benchmark and confirms that they are consistent (because the generation logic is the same and the parameters match), and the first verification layer passes.

[0111] The second verification layer verifies multimodal biometric features and ID chip decryption data:

[0112] Operators need to provide fingerprints (feature vector F collected by a fingerprint scanner) and facial images (feature vector If collected by a dual-sided camera), and place their work ID card close to the contactless document reader (to read the document chip decryption data D', which includes the holder's preset fingerprint and facial reference templates).

[0113] System Calculation Verification passed (i.e., signature compliance); and the combined confidence level of biometrics was also achieved. (α = 0.6, β = 0.4, configured in the background according to the task security level), assuming ||F|| = 0.9 (fingerprint similarity) and ||If|| = 0.85 (face similarity), then C b =0.6×0.9+0.4×0.85=0.86, exceeding the preset threshold γ=0.7; and the matching degree between the baseline fingerprint and F in D' is 92%, and the matching degree between the baseline face and If is 88% (both exceeding 85%), so the second verification layer passes.

[0114] The actual protective effect of dual verification:

[0115] If an unauthorized person intercepts the dynamic key K1 (potentially bypassing the first verification layer), but cannot provide the fingerprints, face, and corresponding identification documents of a compliant operator (D' mismatch), the second verification layer will fail directly, and the digital lock will refuse to open or close, thus avoiding the risk of operation based solely on the key.

[0116] If an unauthorized person steals the biometrics and credentials of a compliant operator (potentially bypassing the second layer of verification), but the key K used is not based on the current task T... id If the node coordinates are not generated (and do not match the pre-generated K-baseline), the first verification layer will fail and the operation will also be impossible. This is to prevent non-compliant operations caused by identity information leakage but key mismatch.

[0117] Biometric data includes the extraction of fingerprint feature vectors. With facial feature vectors Extracting fingerprint feature vectors With facial feature vectors By comparing the decrypted data D′ from the ID card chip, we can verify that the following formula holds true:

[0118]

[0119] The decrypted data D′ of the ID card chip is the biometric baseline data extracted after decryption from the ID card chip, including fingerprint and facial feature templates associated with the ID card holder;

[0120] Where SM2_Sig(·) is the national cryptographic SM2 digital signature verification function;

[0121] Strengthening the binding between biometrics and certificate holders: Real-time biometric data is collected and verified against pre-stored baseline biometrics in the certificate chip through hash fusion and digital signature. This ensures that the biometrics provided by the operator strictly match the compliant certificate holder registered on the certificate, preventing the risk of biometrics being stolen but unrelated to the certificate (such as using someone else's fingerprint / face to forge a certificate). Enhancing the tamper resistance of verification data: Biometric data is digested using the SM3 hash function and then verified with an SM2 digital signature, ensuring that the biometric data has not been tampered with during collection, transmission, and comparison. It also complies with national cryptographic standards, has high encryption strength, and resists data forgery attacks.

[0122] If the bank cash transportation task T is continued id =20250710_YZ001, the operator is Zhang San, an authorized employee of the bank, and the decryption number D' pre-stored in his work ID chip includes: Zhang San's fingerprint baseline template Fbase and face baseline template Ifbase (that is, D' is associated with Zhang San's compliant biometric features).

[0123] When Zhang San performs the unlocking operation at node 1 (x = 116.3°, y = 39.9°), the second verification layer needs to verify:

[0124] The multimodal acquisition module acquires Zhang San's real-time fingerprint feature vector F (which is of the same origin as Fbase) and real-time face feature vector If (which is of the same origin as Ifbase);

[0125] The contactless document reader reads the chip on Zhang San's work permit and decrypts it to obtain D' (containing Fbase and Ifbase);

[0126] The system performs the following calculations: First, it hashes the concatenated string (F‖If) of F and If using the SM3 hash function to obtain H = SM3(F‖If);

[0127] Calculate the XOR result of H and D': H⊕D';

[0128] The above result is then verified using the SM2 digital signature verification function SM2_Sig(·), resulting in Verify = 1 (verification passed).

[0129] At this point, successful verification means that Zhang San's real-time biometric features (F, If) completely match the baseline features (D') registered in the ID chip, confirming that it was Zhang San himself who performed the operation.

[0130] If non-compliant scenarios exist:

[0131] Li Si, an unqualified person, stole Zhang San's fingerprint film (which can collect F' consistent with F) and facial photo (which can collect If' similar to If), but used a forged blank document (D" is empty or does not contain Zhang San's basic features);

[0132] During verification, the result of SM3(F'‖If')⊕D” cannot be verified by SM2_Sig (because D” is irrelevant to Zhang San's baseline features), Verify = 0 (verification failed), and the digital lock rejects the operation.

[0133] The second verification layer also includes the calculation of joint confidence scores based on biometric features. The specific calculation process is as follows:

[0134]

[0135] Wherein, α and β are the weighting coefficients of fingerprint features and facial features, respectively (dynamically configured by the backend system according to the task security level); These are the normalized similarity values ​​(ranging from 0 to 1) of the fingerprint feature vector and the face feature vector, respectively.

[0136] When C bThe similarity of the biometric features resolved by D′ is greater than the preset threshold γ (γ∈[0.6,0.9], configured by the backend system) and meets the standard (i.e., the baseline features in D′ are similar to the collected features). When the matching degree exceeds 85%, the digital key interface is activated;

[0137] The weighting coefficients (α, β) of fingerprint and facial features are dynamically configured by the backend according to the task security level. Fingerprint weight can be increased for high-risk tasks, and facial weight can be increased for low-risk tasks, achieving a dynamic balance between security and efficiency.

[0138] Verification of accuracy and rigor: through joint confidence (C b The comparison between the fingerprint chip and the preset threshold (γ) and the matching degree requirement (>85%) of the base features of the document chip and the collected features form a double threshold. This avoids misjudgment caused by single feature error, such as when the fingerprint is blurry but the face is clear, the joint calculation may still meet the standard, while ensuring the overall matching accuracy and preventing low similarity features from passing the verification.

[0139] Continue using task T id =20250710_YZ001, in two scenarios:

[0140] Scenario 1: High-security tasks, such as large cash transactions:

[0141] Backend configuration: Due to the high risk of the task, α=0.6 is set, fingerprint weight is higher, accuracy is prioritized, β=0.4, threshold γ=0.8, and strict standards are applied.

[0142] Verification data for operator Zhang San: fingerprint feature normalized similarity ||F|| = 0.92, clearly acquired;

[0143] The normalized similarity of facial features |If| = 0.78 (slightly blurry due to dim lighting);

[0144] The matching degree between the baseline features of the ID chip D' and F and If is 93% and 89% respectively (both > 85%).

[0145] Calculate the joint confidence level: C b =0.6×0.92+0.4×0.78=0.552+0.312=0.864>γ(0.8).

[0146] Result: C b If the requirements are met and the D' matching degree is satisfactory, activate the digital key interface and allow operation.

[0147] Advantages: Although facial features are slightly blurry, fingerprints are clear and have a higher weight, and joint calculations still pass, avoiding normal operation obstacles caused by errors in a single feature.

[0148] Scenario 2: Irregular attempts to impersonate others, low-security tasks;

[0149] Background configuration: Regular task, set α=0.3 (face has higher weight, convenience is prioritized), β=0.7, threshold γ=0.7.

[0150] Li Si, an unqualified individual, stole Zhang San's blurred fingerprint film (‖F‖=0.65) and synthesized face image (‖If‖=0.72). The matching degree between the baseline features analyzed by the ID chip D' and F and If is only 70% and 65% respectively (both <85%).

[0151] Calculate the joint confidence level: C b =0.3×0.65+0.7×0.72=0.195+0.504=0.699≈0.7 (close to the threshold).

[0152] Although C b The threshold is approaching, but the D' matching degree is not up to standard, the digital key interface is not activated, and the operation is rejected.

[0153] Even if the joint confidence level is close to the threshold, the low matching degree of the document's baseline features can still block non-compliant operations and avoid the risk of impersonation by someone with similar features but not the person in question.

[0154] The digital lock also implements a two-way authentication mechanism:

[0155] After receiving the dynamic key K, the device fingerprint F is returned to the portable terminal. d (the F) d (This is a unique hardware identifier for the chip built into the digital lock, pre-registered to the backend system);

[0156] Security processing chip verification F d After matching with the pre-stored device registration information (digital lock identifier library synchronized to portable terminals by the backend system), an open / close execution command is sent to the digital lock;

[0157] The hardware identifier F of the digital lock d It is unique and pre-registered. Two-way authentication ensures that only compliant digital locks that have been registered in the backend system can interact with the portable terminal, preventing non-compliant and counterfeit digital locks (such as counterfeit cash drawer locks) from accessing the system and avoiding device-level fraud risks.

[0158] Mutual recognition of compliance between the two parties: Not only does the digital lock need to verify the validity of the dynamic key, but the portable terminal also needs to verify the device identity of the digital lock, forming a two-way trust chain between the terminal recognizing the lock and the lock recognizing the terminal, eliminating abnormal interactions such as compliant terminals connecting to non-compliant locks or non-compliant terminals connecting to compliant locks, and strengthening the closed-loop security of the system from the device layer;

[0159] Continue using bank cash transportation task T id=20250710_YZ001, the hardware identifier F of the compliant digital lock (cash box lock) corresponding to this task. d =CashLock_2025_001, this F d It has been pre-registered to the backend system and synchronized to the digital lock identifier library stored in the security processing chip of the portable terminal.

[0160] When an operator performs an unlocking operation at node 1 (x = 116.3°, y = 39.9°), the two-way authentication process is as follows:

[0161] The portable terminal generates a dynamic key K1 that conforms to the rules of the dynamic key generation unit and sends it to the digital lock.

[0162] After receiving K1 and completing the decryption verification, the digital lock returns its own hardware identifier F to the portable terminal. d =CashLock_2025_001;

[0163] The portable terminal's security processing chip calls the pre-stored digital lock identifier library to verify whether CashLock_2025_001 is in the library, i.e. whether it is a compliant digital lock authorized for this task. After confirming a match, it sends an unlocking execution command to the digital lock, and the digital lock executes the unlocking.

[0164] If non-compliant scenarios exist:

[0165] Someone counterfeited a digital lock with a similar appearance; its hardware identifier was F. d =FakeLock_2025_999, not registered in the background, nor synchronized to the portable terminal's identifier library;

[0166] When the forged lock receives the dynamic key K1 and returns F d When the value is FakeLock_2025_999, the security processing chip verification of the portable terminal detects this F... d If the device is not in the pre-stored identifier database, it is determined to be a non-compliant device, and no opening or closing commands will be sent. The counterfeit lock cannot be opened.

[0167] The system collects the RFID serial number R of the cash box, the cash box identifier Q obtained from the QR code parsing, and the location coordinates (x, y) in real time, and verifies the compliance of the path through the following process:

[0168]

[0169] Where (x0, y0) are the coordinates of the logistics path nodes preset by the backend system;

[0170] ‖(x,y)-(x0,y0)‖ represents the Euclidean distance between the real-time coordinates of the terminal and the preset node coordinates;

[0171] δ is the allowable coordinate deviation radius, which is configured by the backend system based on the node position characteristics;

[0172] R≡Q indicates that the RFID serial number and the QR code identifier correspond to the same identity of the cash box;

[0173] It determines whether the transportation is within the compliant geographical range by comparing real-time coordinates with the Euclidean distance of preset nodes, and prevents the cash box from being switched by verifying the consistency of RFID and QR code labels. This achieves dual control over both location compliance and item compliance, avoiding loopholes in single-dimensional verification. For example, checking only the location without checking the item may allow switching, and checking only the item without checking the location may allow non-compliant transfers.

[0174] Verification based on real-time data collected by the positioning module and tags can immediately detect path deviations or abnormalities in cash boxes, which is more timely than post-event tracing and provides a basis for timely intervention.

[0175] Strong adaptability to different scenarios: The preset node coordinates and deviation radius δ can be configured by the backend according to the scenario. For example, the accuracy of urban nodes is high and the accuracy of suburban nodes can be relaxed, which can flexibly adapt to the needs of different transportation environments.

[0176] Continue using bank cash transportation task T id =20250710_YZ001, the task's preset node 1 is the entrance of Bank A's vault, with coordinates (x0, y0) = (116.3°, 39.9°), and the backend configuration deviation radius δ = 50 meters, allowing operation within 50 meters of the vault entrance; the cash box's RFID serial number R and QR code identifier Q are both preset to CashBox_001 (uniquely corresponding to the cash box for this task).

[0177] Compliance scenarios:

[0178] The transport vehicle arrives at node 1 as planned, with real-time positioning coordinates (x, y) = (116.3005°, 39.8998°). Calculate the Euclidean distance between the real-time coordinates and the preset node:

[0179] ||(x,y)-(x0,y0)||≈30 meters, which is less than δ=50 meters;

[0180] At the same time, the RFID reader reads R = CashBox_001, and the Q code is parsed as Q = CashBox_001, that is, R≡Q.

[0181] ValidPath=1 indicates the path is compliant, the system determines the transportation is normal, and allows subsequent operations, such as unlocking and handover.

[0182] Non-compliant scenario 1, deviating from the route:

[0183] The transport vehicle did not arrive at node 1 as planned, but instead deviated to a position 160 meters away from node 1 (coordinates (x,y)=(116.301°,39.901°)). At this time:

[0184] ||(x,y)-(x0,y0)||≈60 meters (greater than δ=50 meters);

[0185] Even if R = Q = CashBox_001, it still satisfies ValidPath = 0 (path is not compliant), and the system immediately triggers an alarm, indicating that it has deviated from the preset path node.

[0186] Non-compliant scenario 2: Cash box swapping:

[0187] Although the transport vehicle has reached node 1 (20 meters away, less than δ), the cash box was improperly switched en route. At this point:

[0188] The RFID reader reads R = FakeBox_002 (the cash box identifier after being switched), and the Q code is parsed as Q = CashBox_001 (the original cash box identifier), meaning R≡Q is not true;

[0189] According to the rules, ValidPath=0 (path is not compliant), the system triggers an alarm, indicating that the box identification is inconsistent and suspected of being switched.

[0190] When validation fails, i.e., ValidPath = 0, the path tracing mechanism is triggered:

[0191] Historical location coordinates are retrieved to generate an abnormal path map (marking the time and location of deviations from preset nodes); the risk value of tampering is calculated based on the matching degree between the RFID serial number R and the cash box identifier Q.

[0192]

[0193] Where, N match N represents the number of nodes in the logistics path where R and Q are matched; total This represents the total number of nodes in the logistics path.

[0194] When Risk > η, the operation permissions of the digital lock are frozen (the backend system sends a locking command to the digital lock), where η is a preset risk threshold configured by the backend system.

[0195] When verification fails, historical location coordinates are automatically retrieved to generate an abnormal path map, accurately marking the time and location of deviation from preset nodes, providing clear trajectory evidence for subsequent investigations, facilitating rapid location of the problem. Through the calculation formula of the risk value of the swapped box, the risk of swapping the cash box is transformed into a quantifiable value, avoiding subjective judgment bias. Combined with preset risk thresholds, a tiered response of automatic freezing when the risk exceeds the standard is realized, ensuring that non-compliant operations can be blocked in a timely manner in high-risk scenarios.

[0196] When the risk of tampering reaches the threshold, the back-end system directly freezes the digital lock operation permissions to prevent the cash box from being further processed in a non-compliant manner under high-risk conditions. This mechanism achieves risk interception in advance and reduces the possibility of escalating losses.

[0197] Continue using bank cash transportation task T id =20250710_YZ001, the preset transportation route for this task contains 5 nodes (N total =5), the compliance identifier for the cash box is R=Q=CashBox_001, and the risk threshold η=0.3 is configured in the backend.

[0198] Scenario 1: Slight deviation, risk not exceeded;

[0199] During transportation, due to temporary traffic control, the vehicle deviated from the allowable range (δ = 50 meters) at node 2 (preset coordinates (x0, y0) = (116.35°, 39.92°)), resulting in ValidPath = 0 for this node (R = Q still matches), while the other 4 nodes are compliant (ValidPath = 1, R = Q matches).

[0200] Abnormal path map generation: mark the deviation time (10:15) and actual coordinates (60 meters away from the preset node) of node 2.

[0201] Risk of product swapping: N match =4 (4 nodes R and Q are matched), N total =5, Risk = 1 - 4 / 5 = 0.2.

[0202] Since Risk = 0.2 < η = 0.3, no freeze is triggered. The system only records the abnormal trajectory and prompts the operator to follow the correct path.

[0203] Scenario 2: Multiple substitutions lead to excessive risk.

[0204] During transportation, the cash boxes were improperly switched at nodes 1, 3, and 5 (R≠Q), but not at nodes 2 and 4 (R=Q), and all nodes showed varying degrees of deviation (ValidPath=0).

[0205] Anomaly path map generation: Mark the deviation time (e.g., node 1: 9:00, node 3: 11:00, etc.) and corresponding deviation position of 5 nodes.

[0206] Risk of product swapping: N match =2 (only 2 nodes R and Q match), N total =5, Risk = 1 - 2 / 5 = 0.6.

[0207] Since Risk = 0.6 > η = 0.3, the back-end system immediately sends a locking command to the digital lock, freezing its operation permissions (preventing it from being opened or closed), to prevent the cash box from being transferred or opened improperly after being switched, and at the same time triggers an alarm to notify the management personnel to intervene in the investigation.

[0208] The electronic fence function triggers a remote kill mechanism on the terminal:

[0209] The positioning module monitors the terminal's location in real time. When it detects that the terminal has exceeded the preset electronic fence range (the geographical boundary predefined by the backend system), it sends a self-destruct command to the security processing chip.

[0210] The security processing chip responds to commands, erases the stored dynamic key and task data, and physically locks the digital key interface to prevent any physical connection operations.

[0211] When a terminal exceeds the preset electronic fence range, such as being abnormally taken away from the transportation route or work area, the security processing chip automatically erases the stored dynamic keys and task data. This ensures that even if the terminal is stolen or out of control, sensitive key information and logistics task data will not be abnormally obtained, thus blocking the risk of data leakage at the source. The digital key interface is physically locked, prohibiting any subsequent physical connection operations. This means that even if the terminal is taken away from the compliant area, abnormal personnel cannot connect to the digital lock through the interface to perform opening and closing operations, completely eliminating the possibility of using the terminal within an abnormal geographical range. The remote killing mechanism is triggered by the positioning module in real time and can be executed automatically without manual operation. It can respond immediately when the terminal just goes out of range, avoiding the expansion of security risks due to untimely detection or processing delays, and improving the timeliness and reliability of emergency protection. By binding the preset electronic fence with the remote killing mechanism, the reasonable geographical range of terminal use is strictly limited, ensuring that cash logistics-related operations are only carried out within the authorized area. This strengthens the compliance of system use from a spatial perspective and effectively prevents various non-standard behaviors after the terminal is taken away from the compliant area.

[0212] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. In the description of this invention, "a plurality of" means at least two, such as two, three, etc., unless otherwise explicitly specified.

[0213] In the description of this specification, the references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples. Moreover, without contradiction, those skilled in the art can combine and integrate the different embodiments or examples described in this specification, as well as the features of different embodiments or examples.

[0214] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.

Claims

1. An intelligent lock system of a cash Internet of Things management terminal, characterized in that, Comprise: A portable terminal, at least one digital lock and a background system; The portable terminal comprises: A communication module configured to interact with the background system in real time logistics task data and verification instructions; A security processing chip with built-in SM2 / SM4 algorithm encryption and decryption unit; A digital key interface connected to the passive lock cylinder of the digital lock through a physical plug; A multi-modal acquisition module integrating a double-sided camera, a fingerprint instrument, an RFID reader and a non-contact certificate reader; A positioning module supporting Beidou / GPS dual-mode positioning and electronic fence function; A dynamic key generation unit generates a one-time dynamic key based on the logistics task identifier, the terminal real-time position coordinates and the timestamp; A logistics state perception unit synchronously integrates RFID data, two-dimensional code information and positioning coordinates to construct a logistics path verification model for verifying the compliance of the case transportation path; The digital lock built-in hardware identification device fingerprint F d The hardware identification is pre-registered to the background system and synchronized to the security processing chip of the portable terminal, and the start and stop operation is performed after receiving the dynamic key decryption verification. The opening and closing operation of the digital lock includes a double verification mechanism: The first verification layer: the background system compares the dynamic key K with the pre-generated task key; The second verification layer: the multi-modal acquisition module obtains the biological feature data of the operator and the certificate chip decryption data, and verifies that the multi-modal feature fusion relationship is established; Real-time acquisition of case RFID serial number R, two-dimensional code analysis of case identifier Q and positioning coordinates (x, y), and verification of path compliance through the following process: ; wherein, preset by the background system; represents the Euclidean distance between the terminal real-time coordinate and the preset node coordinate; Delta is the allowed coordinate deviation radius, which is configured by the background system according to the node position characteristics; R≡Q represents that the RFID serial number and the two-dimensional code identifier correspond to the same case identity.

2. The intelligent lock system of a cash Internet of Things management terminal according to claim 1, characterized in that: The dynamic key generation unit is used to execute: Acquiring a logistics task identifier T id , terminal real-time position coordinates (x, y) and a timestamp t, to generate a dynamic key K.

3. The intelligent lock system of claim 2, wherein: The life cycle of the dynamic key K is controlled by the following rules: Validity period T of dynamic key K k Associated logistics task phase: ; t verify is a point in time for identity verification to pass open is a point in time for the execution of the unlocking instruction scan is a point in time for the completion of the trunk information scanning close is a point in time for the execution of the locking instruction The dynamic key K that is not used within a certain time is automatically invalidated.

4. The intelligent lock system of a cash Internet of Things management terminal according to claim 1, characterized in that: The biometric data includes extracting a fingerprint feature vector with the face feature vector , extracting a fingerprint feature vector , the face feature vector and the certificate chip decryption data D', verifying that the following formula is true: ; The certificate chip decryption data D' is the biological feature reference data extracted after decryption in the certificate chip, including the fingerprint and face feature template associated with the certificate holder; Where SM2_Sig(⋅) is the SM2 digital signature verification function, and SM3(⋅) is the SM3 hash function.

5. The intelligent lock system of claim 4, wherein: The second verification layer also includes biological feature joint confidence calculation, and the specific calculation process is: ; Wherein, alpha, beta are weight coefficients of the fingerprint feature and the face feature respectively; , are normalized similarity values of the fingerprint feature vector and the face feature vector respectively. When C b When the biometric similarity D' is greater than the preset threshold γ, the digital key interface is activated.

6. The intelligent lock system of a cash Internet of Things management terminal according to claim 1, characterized in that: The digital lock also performs a two-way authentication mechanism: Upon receiving the dynamic key K, the device fingerprint F is returned to the portable terminal d ; Security processing chip verification F d After matching with the pre-stored device registration information, the on-off execution instruction is sent to the digital lock.

7. The intelligent lock system of a cash Internet of Things management terminal according to claim 1, characterized in that: When the verification fails, i.e. ValidPath=0, the path tracing mechanism is triggered: Call the historical positioning coordinates to generate an abnormal path map (label the deviation time and position from the preset node); Based on the matching degree of RFID serial number R and case identifier Q, the risk value of the package is calculated: ; wherein N match is the number of nodes in the logistic path that R matches with Q; N total is the total number of nodes of the logistic path; When Risk>η, the operation permission of the digital lock is frozen, the background system sends a locking instruction to the digital lock, and η is a preset risk threshold configured by the background system. 8.The intelligent lock system of a cash Internet of Things management terminal according to claim 1, wherein: The electronic fence function triggers the terminal remote kill mechanism: The positioning module monitors the terminal position in real time, and sends a self-destruction instruction to the security processing chip when it detects that the terminal exceeds the preset electronic fence range; The security processing chip responds to the instruction, erases the stored dynamic key and task data, and physically locks the digital key interface.

Citation Information

Patent Citations

  • Remote control method and system for escort vehicle

    CN105812485A

  • Guard and escort electronic handover management system for bank

    CN202230515U