Data processing device and communication method based on open-source honk and star flash communication protocol

By using a data processing device based on the open-source HarmonyOS and the StarFlash communication protocol, the problems of insufficient connection reliability, latency, networking capability and security in the distributed terminal collaboration system are solved. It achieves wireless communication with microsecond-level transmission latency and high anti-interference capability, supports hot-swapping and plug-and-play of multiple authentication modules, and reduces the complexity of system deployment.

CN122372996APending Publication Date: 2026-07-10BEIJING ANSHIHUAYE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING ANSHIHUAYE TECH CO LTD
Filing Date
2026-05-18
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

Existing wireless communication technologies in distributed terminal collaboration systems suffer from problems such as insufficient connection reliability, uncontrollable response latency, weak multi-device networking capabilities, insufficient security, and high power consumption, making it difficult to meet the requirements of high reliability, low latency, and multi-node collaboration.

Method used

It adopts a data processing device based on the open-source HarmonyOS and StarScan communication protocol, and combines physical layer hybrid modulation adaptive switching, improved time division multiplexing and carrier sense multiple access hybrid access mechanism to realize device discovery, security authentication, resource allocation and data fusion, and supports hot-swapping and plug-and-play of multiple authentication modules.

Benefits of technology

It achieves microsecond-level end-to-end transmission latency, high anti-interference capability, and builds an end-to-end encrypted communication system, improving the system's scalability and deployment flexibility, ensuring automatic device discovery and dynamic networking, and reducing the complexity of system deployment and maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122372996A_ABST
    Figure CN122372996A_ABST
Patent Text Reader

Abstract

This invention discloses a data processing device and communication method based on the open-source HarmonyOS and the StarScan communication protocol. The device employs the StarScan protocol, combining physical layer hybrid modulation adaptive switching, improved time-division multiplexing and carrier sense hybrid access, and a simplified protocol stack to achieve microsecond-level end-to-end latency and high anti-interference capability. An end-to-end security system is constructed through device pre-registration, elliptic curve key negotiation, AES-256-GCM encryption, and two-way certificate authentication. Standardized interfaces for multiple types of terminals are implemented with dynamic resource allocation, supporting hot-swapping and improving scalability. The D-S evidence theory is used to fuse verification results from multiple terminals, improving identification accuracy and anti-spoofing capabilities, while reserving emergency bandwidth and implementing priority scheduling to ensure anomaly handling. Automatic device discovery is achieved based on enhanced beacon broadcasting and sliding window detection, combined with improved on-demand distance vector routing for topology optimization, supporting dynamic networking and self-maintenance, reducing deployment and maintenance complexity.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of wireless communication and Internet of Things (IoT) technology, specifically to data processing devices and communication methods based on the open-source HarmonyOS and the StarScan communication protocol. Background Technology

[0002] Distributed terminal collaboration systems are a core component of smart buildings, smart parks, and industrial IoT systems. Their main function is to enable authentication, data exchange, and collaborative decision-making among multiple terminal nodes within a physical space. With the rapid development of IoT technology, such systems are evolving from traditional stand-alone, wired architectures towards networked, wireless, and intelligent architectures.

[0003] Currently, the connection methods between core data processing equipment and various functional terminals are mainly divided into the following two categories: Traditional wired connection solutions: Traditional systems commonly use wired communication methods such as RS-485, Wiegand, or Ethernet. While this solution offers advantages such as stable transmission and strong anti-interference capabilities, it suffers from several insurmountable problems in practical applications: High cabling costs and complex engineering: Functional terminals are typically deployed in multiple locations such as building entrances, elevator lobbies, and office doors, requiring dedicated communication and power cables to be laid between them and core data processing equipment. When renovating existing buildings or historical buildings, cabling projects require damage to walls, floors, or ceilings, resulting in long construction periods, high costs, and even making implementation impossible.

[0004] Poor scalability: When it is necessary to add new terminal nodes or change the location of equipment, cables must be re-laid, involving a series of engineering operations such as trenching, conduit installation, and restoration, which has extremely low flexibility.

[0005] Maintenance difficulties: After long-term use, wired lines may experience aging, poor contact, rodent bites, and other faults. Troubleshooting requires specialized tools to check each section, which is time-consuming and labor-intensive. During this period, terminal nodes may be in a malfunctioning state, posing safety hazards. Existing wireless technology solutions: To overcome the limitations of wired solutions, solutions based on existing wireless communication technologies such as Wi-Fi, Bluetooth, and Zigbee have emerged in recent years. However, these wireless technologies are not designed for distributed data processing scenarios requiring high reliability, low latency, and multi-node collaboration, and have revealed the following technical shortcomings in practical applications: Insufficient connection reliability: In high-concurrency scenarios (such as multiple users simultaneously verifying during peak hours), Wi-Fi technology is prone to signal conflicts, increased retransmissions, and connection instability, leading to service request timeouts or failures. Bluetooth technology uses a frequency-hopping spread spectrum mechanism, but the probability of connection interruption increases significantly when the 2.4GHz public frequency band is affected by various interference sources such as microwave ovens, cordless phones, and nearby Wi-Fi networks. For systems requiring immediate decision-making, a single service failure can mean system unavailability, severely impacting user experience and security.

[0006] Uncontrollable response latency: The system has strict requirements on the response time from data acquisition to action execution, typically requiring a latency of no more than 200 milliseconds; otherwise, it will affect overall operating efficiency. Wi-Fi's media access control layer uses a carrier sense multiple access / collision avoidance (CSMA / CA) mechanism. When network load increases, the backoff time grows exponentially, leading to severe latency jitter, which can reach several seconds in the worst case. Bluetooth Classic mode connection establishment time is approximately 100-200 milliseconds. While Bluetooth Low Energy has low power consumption, its data transmission rate is limited and latency is uncertain. These characteristics cannot meet the real-time and deterministic requirements of distributed collaborative scenarios.

[0007] Weak multi-device networking capabilities: Such systems typically require simultaneous connection of multiple terminal devices. In Wi-Fi's star topology, the concurrent processing capacity of access points is limited; when the number of terminals exceeds a certain threshold, the effective bandwidth of each terminal drops sharply. Bluetooth's piconet architecture supports a maximum of seven slave devices, which cannot meet the needs of large-scale deployments. While Zigbee supports mesh networks, its data transmission rate is low (typically below 250kbps), making it unsuitable for transmitting high-definition images or feature data.

[0008] Insufficient security: Existing wireless technologies often employ security mechanisms designed for consumer applications, resulting in limited security levels. While Wi-Fi's WPA2 / WPA3 encryption offers some protection, its device authentication mechanisms are vulnerable (e.g., KRACK attacks, PMKID attacks). Bluetooth's pairing mechanism is susceptible to man-in-the-middle attacks. Furthermore, these technologies generally lack enhanced security mechanisms for distributed data processing scenarios, such as device access control, two-way certificate authentication, and regular session key updates, making them vulnerable to attacks common in security scenarios, including device spoofing, replay attacks, and signal hijacking.

[0009] Power consumption and deployment limitations: Some wireless terminals require continuous power, but existing Wi-Fi and Bluetooth chips have high power consumption, limiting the battery life of battery-powered devices. Furthermore, these technologies vary in their wall-penetrating capabilities and coverage in complex indoor environments, requiring the deployment of additional relay equipment, which increases system complexity and cost. Summary of the Invention

[0010] To address the shortcomings of the existing technologies mentioned above, this application provides a data processing device and communication method based on the open-source HarmonyOS and the StarScan communication protocol.

[0011] Firstly, this application proposes a data processing device based on the open-source HarmonyOS and the StarScan communication protocol, including: The core controller module runs the OpenHarmony operating system, which includes a distributed soft bus, comprising a device discovery service component, a data transmission service component, and a distributed scheduling service component. The StarScan communication module is electrically connected to the core controller module, and the StarScan communication module includes a physical layer processing unit and a media access control layer processing unit. The device discovery service component is configured to: broadcast a first beacon frame at a fixed period through the StarFlash communication module, the first beacon frame containing a device type field, a MAC address field, and an encryption certificate fingerprint field; simultaneously listen for a second beacon frame through the StarFlash communication module, and process the received signal strength values ​​using a sliding window detection algorithm. The sliding window detection algorithm maintains a window of a preset length, calculates the arithmetic mean of all signal strength values ​​within the window, and determines that a valid device has been discovered when the arithmetic mean exceeds a preset signal strength threshold. The distributed scheduling service component is configured to allocate processing resources according to a preset fixed priority order when multiple terminal devices simultaneously initiate verification requests. The fixed priority order from high to low is: VIP mode, face recognition mode, fingerprint recognition mode, and card recognition mode.

[0012] In some embodiments, the media access control layer processing unit is configured to: divide the time axis sequentially into a beacon period, a contention access period, and multiple guaranteed time slots, wherein the beacon period is used to broadcast network synchronization information; the contention access period employs a carrier sense collision avoidance mechanism for transmitting control commands; each guaranteed time slot is pre-allocated to an already connected terminal device for exclusive data transmission by that terminal device, and the guaranteed time slot duration varies for different types of terminal devices, with terminal devices of the large data transmission type being allocated a longer guaranteed time slot.

[0013] In some embodiments, the physical layer processing unit is configured to: Measure the real-time signal-to-noise ratio and compare the real-time signal-to-noise ratio with a dynamic threshold; When the real-time signal-to-noise ratio is greater than the dynamic threshold, first-order quadrature amplitude modulation is used, and each symbol carries a first number of bits of data. When the real-time signal-to-noise ratio is less than the dynamic threshold, the system switches to second-order quadrature amplitude modulation, with each symbol carrying a second number of bits of data, wherein the first number is greater than the second number. The dynamic threshold is calculated based on the preset target bit error rate and the current number of bits per symbol.

[0014] In some embodiments, the star-flash communication module further includes an anti-interference unit, which is configured to: Scan multiple sub-channels within a preset frequency band; For each sub-channel, three factors are comprehensively evaluated: packet error rate, signal-to-noise ratio, and channel occupancy. Packet error rate is given the highest evaluation weight, followed by signal-to-noise ratio, and channel occupancy is the lowest. The quality score of each sub-channel is determined based on the comprehensive result of the three factors and their weights. Select a predetermined number of sub-channels with the highest quality scores, and arrange the selected sub-channels in descending order of scores as a frequency hopping sequence; The operating channel is switched at a fixed period according to the frequency hopping sequence.

[0015] In some embodiments, a modular terminal access module is also included, which is connected to the StarFlash communication module, and the modular terminal access module includes a dynamic resource allocation unit. The dynamic resource allocation unit is configured to calculate a priority metric for each connected terminal device. The priority metric comprehensively considers the ratio of the current channel quality of the terminal device to the historical average rate, the data waiting time of the terminal device, and a preset delay sensitivity coefficient. The longer the data waiting time, the higher the priority metric. Then, according to the proportion of each terminal device's priority metric in the total priority metric of all terminal devices, a corresponding bandwidth share is allocated to each terminal device. Furthermore, a predetermined percentage of bandwidth is reserved from the total bandwidth as an emergency bandwidth pool, which is used only for transmitting emergency events.

[0016] In some embodiments, the modular terminal access module further includes a heterogeneous data fusion unit, which is configured as follows: Obtain the first confidence score output by the first terminal device and the second confidence score output by the second terminal device, wherein the first terminal device and the second terminal device belong to different device types; According to the DS evidence theory, the first confidence score and the second confidence score are respectively used as the basic confidence level of each evidence body in verifying the valid proposition, and 1 minus each confidence score is used as the basic confidence level in verifying the invalid proposition. By combining the trust levels of all evidence and eliminating conflicting trust levels among them, the joint trust level for verifying the valid proposition is calculated; where conflicting trust level refers to contradictory combinations where different evidence supports both valid and invalid propositions. When the joint trust level is greater than the preset fusion threshold, a verification pass signal is output.

[0017] In some embodiments, the StarScan communication module further includes a security authentication unit configured to perform the following three-stage process: The first stage is device pre-registration: read the device's MAC address and serial number, concatenate the two and input them into a secure hash function to output the device's unique fingerprint, and bind the device's unique fingerprint to the digital certificate; The second stage is session key negotiation: On the preset elliptic curve, each party uses its own private key to multiply the other party's public key to obtain shared coordinate values, and then concatenates the horizontal and vertical coordinates to form the shared key. The third stage involves data transmission encryption: an authentication encryption algorithm is used, and each data frame contains a random number and a message authentication code.

[0018] In some embodiments, the core controller module further includes a rules engine that supports script extensions and is configured to execute the following linkage logic: Read the current date and time, and determine if it is a preset workday type; Determine whether the current time is within a preset time window; When both the weekday type match and the time fall within the time window, at least one recognition mode is disabled, and only the verification result of the other recognition mode is allowed to trigger the door opening action.

[0019] Secondly, this application proposes a communication method based on the open-source HarmonyOS and the StarScan communication protocol, including the following steps: Receiving steps: Receive encrypted data packets through the StarFlash communication module. The encrypted data packets include a device ID field, a verification result field, a timestamp field, and a message authentication code field. The verification result field is encoded using a bitmask and includes a verification success flag and a verification failure flag. Parsing steps: Decrypt the encrypted data packet using the pre-stored session key and verify the message authentication code; after successful verification, read the verification success flag in the verification result field; Query steps: When the verification success flag is set, query the local database to obtain the user role based on the device ID field, and obtain the time tag based on the current system time; Judgment steps: Output the door opening command if and only if the following three conditions are met simultaneously: the verification success flag is set, the user role belongs to the set of roles allowed by the pre-stored door area permission bitmap, and the time tag falls within the pre-stored valid time period rule set. Execution steps: In response to the door opening command, a pulse width modulation signal is output through the GPIO pin, and the pulse duration of the pulse width modulation signal is a preset standard duration.

[0020] Thirdly, this application proposes an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method described above.

[0021] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the method described above.

[0022] The beneficial effects of this invention are: By adopting the StarFlash communication protocol and combining it with physical layer hybrid modulation adaptive switching, improved time division multiplexing and carrier sense multiple access hybrid access mechanism, and simplified protocol stack, microsecond-level end-to-end transmission delay and high anti-interference capability are achieved, meeting the stringent requirements of access control systems for real-time response and stable connection. By employing multiple security mechanisms, including device pre-registration, session key negotiation based on the elliptic curve Diffie-Hellman protocol, AES-256-GCM data encryption, and two-way authentication of device certificates, an end-to-end encrypted communication system is constructed, effectively preventing device forgery, data eavesdropping, and replay attacks. By standardizing interfaces and dynamically allocating resources for biometric, credential verification, and status monitoring terminal devices, the system supports hot-swapping and plug-and-play functionality for various identity verification modules, significantly improving system scalability and deployment flexibility. By employing the DS evidence theory to fuse verification results from different terminals, we can comprehensively utilize multiple pieces of evidence to improve identification accuracy and anti-spoofing capabilities. At the same time, by reserving emergency bandwidth and prioritizing scheduling, we ensure efficient handling of abnormal events. Automatic device discovery is achieved through enhanced beacon broadcasting and sliding window detection algorithms. Topology optimization is performed in conjunction with an improved on-demand distance vector routing protocol, supporting dynamic networking of devices, link quality self-checking, and automatic session key updates, which greatly reduces the complexity of system deployment and maintenance. Attached Figure Description

[0023] Figure 1 This is a structural block diagram of the data processing device of the present invention.

[0024] Figure 2 This is a schematic diagram of the protocol time slot allocation.

[0025] Figure 3 This is a schematic diagram of state transition conditions. Detailed Implementation

[0026] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein; rather, these embodiments are provided so that a more thorough understanding of the invention can be achieved and that the full scope of the invention can be conveyed to those skilled in the art.

[0027] The first aspect of this application proposes a data processing device based on the open-source HarmonyOS and the StarScan communication protocol, such as... Figure 1 As shown, it includes: The core controller module runs the OpenHarmony operating system, which includes a distributed soft bus, comprising a device discovery service component, a data transmission service component, and a distributed scheduling service component. In some embodiments, the core controller module further includes a rules engine that supports script extensions and is configured to execute the following linkage logic: Read the current date and time, and determine if it is a preset workday type; Determine whether the current time is within a preset time window; When both the weekday type match and the time fall within the time window, at least one recognition mode is disabled, and only the verification result of the other recognition mode is allowed to trigger the door opening action.

[0028] The core controller module employs a master device based on the OpenHarmony operating system. This device is equipped with a high-performance processor (such as an ARM Cortex-A series chip) and a dedicated security chip (such as a TPM module), running OpenHarmony version 3.2 or later. The system constructs the inter-device communication infrastructure through distributed soft bus technology, which includes three key components: Device Discovery Service (DDS), Data Transmission Service (DTS), and Distributed Scheduling Service (DSS). After the device powers on, the DDS component continuously scans the surrounding environment, broadcasting device identifiers (including device type, MAC address, and encrypted certificate fingerprint) via the StarScan protocol, while simultaneously listening for broadcast signals from other devices. When a new terminal device is detected, the system triggers a two-way authentication process: first, exchanging digital certificates in X.509 format; then, performing signature verification using the ECDSA algorithm; and finally, establishing an encrypted communication channel using the negotiated AES-256 key.

[0029] During network deployment, the DTS component maintains the multi-hop routing table of the StarScan protocol and uses an improved OLSR protocol to achieve dynamic path selection. Each data packet includes a sequence number and CRC checksum to ensure transmission reliability. The DSS component optimizes task scheduling. For example, when multiple terminals initiate verification requests simultaneously, it dynamically allocates processing resources based on device priority (configurable as VIP mode > face recognition > fingerprint recognition > card recognition) and network load. The controller's built-in rule engine supports Lua script extensions, allowing the definition of complex linkage logic, such as scenario policies like "only face recognition is allowed to open doors from 7:00 to 9:00 on weekdays." VIP mode refers to the highest priority verification mode preset for specific high-privilege users (such as company executives or security personnel). In this mode, the system reserves dedicated resources and skips some regular verification steps.

[0030] The device discovery and networking mechanism is based on OpenHarmony distributed capabilities and the StarSpark protocol, enabling the core controller to automatically discover, securely pair, and network StarSpark terminal devices.

[0031] 1. Device Discovery Mechanism: Device discovery is achieved using an enhanced beacon broadcast mechanism based on the StarFlash protocol. Terminal devices periodically send beacon frames, the content of which includes the MAC address, device type, capability bitmap, and calibrated signal strength indication. The controller employs a sliding window detection algorithm to filter transient interference: signal strength values ​​are continuously collected within multiple time windows, and their arithmetic mean is calculated. Only when this average exceeds a preset signal strength threshold (e.g., -70 dB / mW) is the device considered valid; otherwise, it is considered interference and ignored.

[0032] 2. Secure Pairing Protocol: Based on an improved elliptic curve Diffie-Hellman key negotiation protocol. The terminal generates a temporary key pair, including a random private key and a corresponding public key (obtained by multiplying the private key by the elliptic curve base point). After the controller verifies the terminal's digital certificate, both parties use their own private key and the other party's public key to calculate the same shared key. Subsequently, the system uses a hash-based key derivation function to combine the shared key with a fixed string (such as "NearLink_DoorAccess") to derive a 32-byte session key for subsequent communication encryption.

[0033] Topology optimization algorithm: A hybrid star-mesh topology is adopted, using an improved on-demand distance vector routing protocol. During the path discovery phase, a signal quality metric is introduced to evaluate each candidate path: the path score is equal to the product of the signal quality factors of each hop on the path, where the signal quality factor of each hop is defined as 1 minus the ratio of the received signal strength of that hop to the lowest available signal strength threshold (a higher ratio indicates a weaker signal). The system selects the route with the highest path score. Simultaneously, a link stability factor is added when maintaining the neighbor table. This factor comprehensively considers the proportion of online time (the ratio of online time to total time) and the degree of signal strength fluctuation; links with smaller fluctuations and more stable online performance receive higher stability scores.

[0034] The StarScan communication module is electrically connected to the core controller module, and the StarScan communication module includes a physical layer processing unit and a media access control layer processing unit. In some embodiments, the media access control layer processing unit is configured to: divide the time axis sequentially into a beacon period, a contention access period, and multiple guaranteed time slots, wherein the beacon period is used to broadcast network synchronization information; the contention access period employs a carrier sense collision avoidance mechanism for transmitting control commands; each guaranteed time slot is pre-allocated to an already connected terminal device for exclusive data transmission by that terminal device, and the guaranteed time slot duration varies for different types of terminal devices, with terminal devices of the large data transmission type being allocated a longer guaranteed time slot.

[0035] In some embodiments, the physical layer processing unit is configured to: Measure the real-time signal-to-noise ratio and compare the real-time signal-to-noise ratio with a dynamic threshold; When the real-time signal-to-noise ratio is greater than the dynamic threshold, first-order quadrature amplitude modulation is used, and each symbol carries a first number of bits of data. When the real-time signal-to-noise ratio is less than the dynamic threshold, the system switches to second-order quadrature amplitude modulation, with each symbol carrying a second number of bits of data, wherein the first number is greater than the second number. The dynamic threshold is calculated based on the preset target bit error rate and the current number of bits per symbol.

[0036] The device discovery service component is configured to: broadcast a first beacon frame at a fixed period through the StarFlash communication module, the first beacon frame containing a device type field, a MAC address field, and an encryption certificate fingerprint field; simultaneously listen for a second beacon frame through the StarFlash communication module, and process the received signal strength values ​​using a sliding window detection algorithm. The sliding window detection algorithm maintains a window of a preset length, calculates the arithmetic mean of all signal strength values ​​within the window, and determines that a valid device has been discovered when the arithmetic mean exceeds a preset signal strength threshold. The distributed scheduling service component is configured to allocate processing resources according to a preset fixed priority order when multiple terminal devices simultaneously initiate verification requests. The fixed priority order from high to low is: VIP mode, face recognition mode, fingerprint recognition mode, and card recognition mode.

[0037] In some embodiments, the star-flash communication module further includes an anti-interference unit, which is configured to: Scan multiple sub-channels within a preset frequency band; For each sub-channel, three factors are comprehensively evaluated: packet error rate, signal-to-noise ratio, and channel occupancy. Packet error rate is given the highest evaluation weight, followed by signal-to-noise ratio, and channel occupancy is the lowest. The quality score of each sub-channel is determined based on the comprehensive result of the three factors and their weights. Select a predetermined number of sub-channels with the highest quality scores, and arrange the selected sub-channels in descending order of scores as a frequency hopping sequence; The operating channel is switched at a fixed period according to the frequency hopping sequence.

[0038] The StarScan communication module establishes a wireless connection through the StarScan communication protocol, featuring microsecond-level low latency, high throughput, high concurrency, high reliability, and strong encryption authentication.

[0039] Starflash protocol physical layer optimization: such as Figure 3 As shown, a hybrid modulation technique is employed to achieve a maximum transmission rate of 12 megabits per second within a 1 MHz bandwidth. Specifically, when channel conditions are favorable, high-order quadrature amplitude modulation (16QAM, carrying 4 bits of data per symbol) is used; when channel quality deteriorates, the system automatically switches to low-order modulation (QPSK, carrying 2 bits of data per symbol). The modulation mode switching is based on a comparison between the real-time signal-to-noise ratio (SNR) and a dynamic threshold. This threshold is calculated based on the target bit error rate (set to 10^-6) and the current transmission rate. When the measured SNR falls below this threshold, modulation degradation is triggered to ensure transmission reliability.

[0040] Multi-device access scheduling: An improved time-division multiplexing and carrier sense multiple access hybrid access mechanism is adopted, dividing the time axis into three time periods: the beacon time period (fixed 20 microseconds) is used to broadcast network synchronization information; the contention access time period adopts the carrier sense collision avoidance mechanism to transmit control commands; and the time slot is guaranteed to allocate a dedicated time period for each terminal for large data transmission.

[0041] Anti-interference mechanism: An adaptive frequency hopping scheme is implemented, dividing the 2.4 GHz band into 79 1 MHz sub-channels. The system scans the spectrum in real time and comprehensively evaluates the quality of each channel. The evaluation mainly considers three factors: packet error rate (lower is better), signal-to-noise ratio (higher is better), and channel occupancy rate (lower is better), and calculates a comprehensive quality score according to preset weights (packet error rate accounts for 60%, signal-to-noise ratio accounts for 30%, and channel occupancy rate accounts for 10%). The system selects the three optimal channels to form a frequency hopping sequence based on the score, thereby effectively avoiding interference.

[0042] Low latency optimization: The end-to-end latency is ensured to be less than 100 microseconds through the following measures: simplifying the protocol stack, compressing the traditional seven-layer network model into three layers: physical layer, network layer, and application layer; reserving retransmission buffers and priority scheduling queues for critical messages to achieve pre-allocation of resources; and integrating cyclic redundancy check and encryption / decryption coprocessors into the RF chip to achieve hardware acceleration.

[0043] In some embodiments, a modular terminal access module is also included, which is connected to the StarFlash communication module, and the modular terminal access module includes a dynamic resource allocation unit. The dynamic resource allocation unit is configured to calculate a priority metric for each connected terminal device. The priority metric comprehensively considers the ratio of the current channel quality of the terminal device to the historical average rate, the data waiting time of the terminal device, and a preset delay sensitivity coefficient. The longer the data waiting time, the higher the priority metric. Then, according to the proportion of each terminal device's priority metric in the total priority metric of all terminal devices, a corresponding bandwidth share is allocated to each terminal device. Furthermore, a predetermined percentage of bandwidth is reserved from the total bandwidth as an emergency bandwidth pool, which is used only for transmitting emergency events.

[0044] In some embodiments, the modular terminal access module further includes a heterogeneous data fusion unit, which is configured as follows: Obtain the first confidence score output by the first terminal device and the second confidence score output by the second terminal device, wherein the first terminal device and the second terminal device belong to different device types; According to the DS evidence theory, the first confidence score and the second confidence score are respectively used as the basic confidence level of each evidence body in verifying the valid proposition, and 1 minus each confidence score is used as the basic confidence level in verifying the invalid proposition. By combining the trust levels of all evidence and eliminating conflicting trust levels among them, the joint trust level for verifying the valid proposition is calculated; where conflicting trust level refers to contradictory combinations where different evidence supports both valid and invalid propositions. When the joint trust level is greater than the preset fusion threshold, a verification pass signal is output.

[0045] Modular terminal access supports wireless access to various authentication terminal modules, including face recognition, fingerprint recognition, iris recognition, keypad, card reader, and door magnetic status monitoring sensor.

[0046] 1. Terminal equipment classification and interface standardization: The access terminals are divided into three categories and a unified interface specification is defined.

[0047] Biometric identification (face / fingerprint / iris): A unified biometric interface is used. The transmitted feature vector must meet the normalization condition with a modulus of 1, and a confidence score is also transmitted. The confidence score maps the original matching score to between 0 and 1 using a sigmoid function. The function includes two calibration parameters to adjust the sensitivity and offset of the mapping.

[0048] Credential verification (card reader / keyboard): Uses a unified credential interface. The data packet format includes device identifier, credential type, credential data length, credential data body, and verification code.

[0049] Status monitoring class (door magnet / tamper switch): Employs a unified monitoring interface, transmitting status bytes in an event-driven mode. Each bit of this byte represents a Boolean state: the least significant bit indicates the door state (0 closed, 1 open), the second least significant bit indicates tamper triggering, and the remaining bits are reserved. Dynamic resource allocation algorithm: Uses an improved Proportional Fair scheduling algorithm to allocate bandwidth to different terminals. Dynamic resource allocation algorithm: An improved proportional-fair scheduling algorithm is used to allocate bandwidth to different terminals. The system calculates a priority metric for each terminal, which comprehensively considers three factors: the ratio of the current channel quality to the historical average rate (reflecting the instantaneous channel advantage), data latency (the longer the delay, the higher the priority), and a latency sensitivity coefficient (used to adjust the weight of the latency). Then, the system allocates the total bandwidth to all terminals according to the proportion of each terminal's priority metric. In addition, the system reserves a fixed proportion of bandwidth for emergency events (such as tamper alarms) to ensure that high-priority events can be transmitted in a timely manner.

[0050] Heterogeneous Data Fusion: The Dempster evidence theory (DS) is used to process multimodal verification results. First, a basic probability allocation is performed on the verification results of each terminal: when a terminal outputs a confidence score, that score is used as the confidence level for the proposition "verification is valid," while the confidence level for "verification is invalid" is 1 minus that score. Then, the Dempster combination rule is used to fuse the evidence from multiple terminals and calculate the joint confidence level. The core logic of this rule is: for a given proposition, its joint confidence level equals the sum of the combined probabilities of all evidence supporting that proposition, divided by a normalization factor (used to exclude conflicting parts between evidence). Finally, when the joint confidence level exceeds a set decision threshold (e.g., 0.85), the system triggers an opening action.

[0051] Device hot-swap management: Implements state machine-based device lifecycle management, including states such as uninitialized, discovered, authenticated, online, faulty, and offline. Figure 3 As shown, the transition conditions between states are defined.

[0052] In some embodiments, the StarScan communication module further includes a security authentication unit configured to perform the following three-stage process: The first stage is device pre-registration: read the device's MAC address and serial number, concatenate the two and input them into a secure hash function to output the device's unique fingerprint, and bind the device's unique fingerprint to the digital certificate; The second stage is session key negotiation: On the preset elliptic curve, each party uses its own private key to multiply the other party's public key to obtain shared coordinate values, and then concatenates the horizontal and vertical coordinates to form the shared key. The third stage involves data transmission encryption: an authentication encryption algorithm is used, and each data frame contains a random number and a message authentication code.

[0053] Enhanced Security Authentication: A three-stage authentication process is employed. First, device pre-registration is performed, generating a unique fingerprint for each device using a secure hash algorithm (SHA-3), calculated based on the device's MAC address and serial number. Next, session key negotiation occurs using an improved elliptic curve Diffie-Hellman protocol. On the secp256r1 elliptic curve, both communicating parties use their private keys and the other party's public keys to calculate shared coordinate values, which are then combined to form the shared key. Finally, data transmission is encrypted using AES-256-GCM mode. Each data frame includes a 12-byte random number and a 16-byte message authentication code, ensuring data confidentiality and integrity.

[0054] Secondly, this application proposes a communication method based on the open-source HarmonyOS and the StarScan communication protocol, including the following steps: Receiving steps: Receive encrypted data packets through the StarFlash communication module. The encrypted data packets include a device ID field, a verification result field, a timestamp field, and a message authentication code field. The verification result field is encoded using a bitmask and includes a verification success flag and a verification failure flag. Parsing steps: Decrypt the encrypted data packet using the pre-stored session key and verify the message authentication code; after successful verification, read the verification success flag in the verification result field; Query steps: When the verification success flag is set, query the local database to obtain the user role based on the device ID field, and obtain the time tag based on the current system time; Judgment steps: Output the door opening command if and only if the following three conditions are met simultaneously: the verification success flag is set, the user role belongs to the set of roles allowed by the pre-stored door area permission bitmap, and the time tag falls within the pre-stored valid time period rule set. Execution steps: In response to the door opening command, a pulse width modulation signal is output through the GPIO pin, and the pulse duration of the pulse width modulation signal is a preset standard duration.

[0055] The business processing workflow adopts a layered processing architecture to achieve efficient decision-making and execution: Verification Result Receiving Layer: The StarScan communication module receives encrypted data packets sent by the terminal device. The data packet format includes the device ID, verification result field, timestamp, and message authentication code used for integrity verification. The verification result field uses bitmask encoding: the least significant bit indicates successful verification, the second least significant bit indicates verification failure, and the third bit indicates timeout.

[0056] The access control engine implements multi-level permission verification based on a role-based access control model. The final decision on whether to allow door access requires three conditions to be met simultaneously: First, the success flag in the verification result field is set (i.e., verification passed); second, the current user's role belongs to the set of allowed roles for that door area (roles retrieved from the user database are matched against the door area permission bitmap); third, the current time is within the user's valid time period rule set. All three conditions are indispensable; failure to meet any one condition results in door access being denied.

[0057] Execution control layer: The door opening signal is generated using pulse width modulation (PWM), with two pulse duration modes: 500 milliseconds in standard mode and 1000 milliseconds in unobstructed mode. The signal level is output through a designated GPIO pin, with a drive capability of 500 mA.

[0058] Event processing subsystem: Logs are recorded in a structured format, including serial number, device ID, user ID, event type, result code, and optional GPS coordinates. Alarm triggering conditions include: more than 3 consecutive verification failures for the same device, detection of a forced door opening event, or door opening time exceeding 30 seconds (door sensor status indicates door is not properly closed). An alarm is triggered when any of these conditions are met.

[0059] The technical solution of this invention will be described in detail and completely below, taking into account a specific deployment scenario of an office building access control system: I. System Initialization and Automatic Network Setup; Step 1.1 Power on the equipment and broadcast to the beacon; After physical installation is complete, all devices are powered on. The core controller module of the main controller starts the OpenHarmony operating system, and the device discovery service component in its distributed soft bus begins continuously scanning the StarScan channel. Simultaneously, each terminal device begins sending enhanced beacon frames at fixed intervals. The beacon frame contains: the terminal's MAC address, device type (e.g., face recognition, fingerprint recognition), capability bitmap, and a calibrated transmit power indication. The beacon frames are broadcast on a preset communication frequency band via the StarScan protocol.

[0060] Step 1.2 Sliding window detection and device discovery; Upon receiving a beacon frame, the main controller does not immediately determine the device's validity. Instead, it employs a sliding window detection algorithm to filter out transient interference. Specifically, the controller maintains a fixed-length sliding window for each signal source, recording the most recently received signal strength values. The controller calculates the arithmetic mean of all signal strength values ​​within the window, and only determines the device as valid if this average consistently and stably exceeds a preset received strength threshold. Conversely, if a signal is abnormally weakened due to sudden interference (such as a microwave oven starting up), the deviation is effectively smoothed out during the averaging calculation within the sliding window, preventing the system from mistakenly classifying it as invalid and thus avoiding accidental device discarding due to transient interference.

[0061] Step 1.3 Secure pairing and session key derivation; After determining that the device is valid, the system triggers a secure pairing process. Taking a facial recognition terminal as an example: The terminal generates a temporary key pair, including a randomly generated private key and a corresponding public key, and sends the public key and its digital certificate to the main controller. The digital certificate uses the X.509 format and contains the device serial number and manufacturer's signature.

[0062] The main controller uses a pre-configured CA root certificate to verify the terminal's certificate signature. After confirming the terminal's legitimate identity, it generates its own temporary public-private key pair and sends its public key to the terminal.

[0063] Both communicating parties use their own private keys and the other party's public keys to perform a dot product operation on a predefined elliptic curve. Due to the mathematical properties of elliptic curves, both parties will calculate identical shared coordinate values. Concatenating the x-coordinate and y-coordinate values ​​of this shared coordinate yields the original shared key.

[0064] Subsequently, both parties execute a hash-based key derivation function: taking the shared key and a fixed string constant (such as "NearLink_DoorAccess") as input, and after multiple hash iterations, a fixed-length session key is derived. This session key is used for the encryption protection of all subsequent communication data.

[0065] Subsequent communications all use an authentication and encryption mode, with each data frame accompanied by a random number and a message authentication code for integrity verification.

[0066] Step 1.4 Topology optimization and route selection; The main controller employs a hybrid star-mesh topology. For terminal devices with high signal strength and short distances, the system directly establishes a star connection. For devices located further away and whose signals require relays, the system uses an improved on-demand distance vector routing protocol for multi-hop path discovery.

[0067] During the path discovery phase, the system evaluates the quality of each candidate path. The evaluation logic is as follows: the quality score of a path is determined by the cumulative signal quality factors of each hop along that path. The signal quality factor of each hop depends on the relative relationship between the received signal strength at that hop and the minimum usable signal strength allowed by the system—the closer the signal strength is to or below the minimum threshold, the lower the quality factor of that hop. The total score of the entire path is the product of the quality factors of each hop. The system selects the route with the highest path score as the communication path.

[0068] In addition, the system incorporates a link stability factor when maintaining the neighbor table. This factor comprehensively evaluates the proportion of online time of a link (i.e., the ratio of the actual online time of the link to the total observed time) and the fluctuation range of signal strength. Links with longer online times and smaller signal strength fluctuations will receive higher stability scores and will therefore be given priority in routing selection.

[0069] Step 1.5 Time slot allocation and frequency hopping configuration; After the network is established, the multi-device access scheduling unit of the main controller allocates a guaranteed time slot to each terminal. During allocation, the system determines the time slot length based on the amount of data transmitted by the terminal: terminals that need to transmit a large amount of data (such as facial feature data) are allocated a longer guaranteed time slot; terminals that only transmit a small amount of status information are allocated a shorter guaranteed time slot.

[0070] Simultaneously, the anti-interference unit scans the entire preset communication frequency band and comprehensively evaluates each sub-channel based on three factors: packet error rate, signal-to-noise ratio, and channel occupancy rate. Packet error rate is given the highest evaluation weight, followed by signal-to-noise ratio, with channel occupancy rate receiving the lowest. Based on the comprehensive evaluation results, the system selects several sub-channels with the highest quality scores, arranges these channels in descending order of score as a frequency hopping sequence, and switches the operating channel according to this sequence at fixed intervals, thereby effectively avoiding interference. At this point, the system completes initialization and enters the ready state.

[0071] II. Routine Operation – Single Biometric Verification; Scenario: On a weekday morning, an employee (user role: department manager, permissions: all areas of the specified floor, effective time period: 07:00-22:00) arrives at the side door and uses fingerprint verification.

[0072] Step 2.1 Fingerprint collection and verification; The employee places their finger on the fingerprint terminal. The terminal's built-in fingerprint sensor captures an image, extracts detailed feature points, and compares them with a locally stored registration template to obtain a raw matching score. The terminal then maps this raw score to a confidence score between 0 and 1 using preset calibration parameters (including scaling factors and offsets). Because this side door is configured for two-factor authentication, the terminal does not directly output an opening command but instead sends the verification result to the main controller.

[0073] Step 2.2 Data transmission and encryption; The fingerprint terminal constructs an encrypted data packet containing a device ID, a verification result field (encoded using a bitmask, where the least significant bit indicates successful verification), a timestamp, and a message authentication code calculated based on the session key. Then, within its allocated guaranteed time slot, the terminal sends the data packet to the main controller using a modulation scheme appropriate to the current channel quality (the physical layer optimization unit automatically selects high-order or low-order modulation based on the real-time signal-to-noise ratio). Before transmission, the anti-interference unit checks the current frequency-hopping channel to confirm that the channel's packet error rate, signal-to-noise ratio, and other quality indicators meet the requirements.

[0074] Step 2.3 Receiving and decrypting; The main controller's StarScan communication module receives the data packet in the corresponding time slot, decrypts it using the negotiated session key, and verifies the consistency of the message authentication code. After successful verification, it transmits the verification result field, device ID, and other information to the business processing layer.

[0075] Step 2.4 Access Control Decision; The permission decision engine performs the following three layers of verification: First layer: Verify whether the success flag in the result field is set. If it is not set, refuse to open the door.

[0076] The second layer: Query the local database based on the device ID field to obtain the current user's role, and determine whether the role belongs to the set of roles allowed by the pre-stored permission bitmap for this door area. If not, refuse to open the door.

[0077] The third layer: retrieves the current system time and determines whether it falls within the user's pre-stored valid time period rule set. If not, the door is refused entry.

[0078] The decision engine will only output the instruction to allow the door to open when all three conditions are met simultaneously.

[0079] Step 2.5 Execution control and linkage; Upon receiving the door opening command, the execution control layer outputs a pulse width modulation (PWM) signal via a designated GPIO pin. The pulse duration of this signal is a preset standard length, used to trigger the electromagnetic lock relay, thereby opening the door. Simultaneously, the event processing subsystem records a structured log, including serial number, device ID, user ID, event type, result code, and optional GPS coordinates. The system also synchronizes this log to the cloud management platform via a security protocol and can, based on configuration, link with the attendance system to update employee check-in status. The entire end-to-end latency meets the real-time design requirements of the access control system.

[0080] III. Multimodal fusion verification; Scenario: A visitor is accompanied by an employee to the main entrance. The main entrance is configured with a two-factor authentication mode of "face recognition and card swipe", and the two authentication methods must come from two different physical terminals.

[0081] Step 3.1 Face capture and confidence score output; A visitor stands in front of a facial recognition terminal. The terminal captures a facial image and transmits it to the main controller via a satellite link. The main controller uses a facial recognition algorithm to extract feature vectors and compares them with the visitor's pre-registered template to obtain a matching score. Due to poor lighting conditions, the matching score is low, and the confidence score after parameter calibration is close to 0. This means that facial verification alone will fail.

[0082] Step 3.2 Card swipe data collection and confidence level output; Simultaneously, the accompanying employee swipes their authorization card on the RFID reader. The reader reads the card's unique identifier and compares it with the local whitelist. Since the card is a legitimate employee card, the match is successful, resulting in a high initial score. However, the system has set a high threshold for opening the door on its own for two-factor authentication scenarios, so this card swipe result alone is insufficient to trigger door opening.

[0083] Step 3.3 Integration of DS Evidence Theories; The heterogeneous data fusion unit of the main controller acquires the two verification results mentioned above. The fusion unit uses the confidence score from the face recognition terminal as the basic confidence level supporting the proposition "verification is valid", and the complement of the score (i.e., 1 minus the score) as the basic confidence level supporting "verification is invalid". The same process is performed on the card swiping terminal.

[0084] Then, the fusion unit makes a fusion decision based on the combination rules of the DS evidence theory: it first calculates the probability that all pieces of evidence simultaneously support "valid verification"; it also calculates the probability of conflict between the pieces of evidence (i.e., some evidence supports validity while others supports invalidity). The final joint confidence level is obtained by dividing the probability of valid combinations by a normalization factor after excluding conflicting parts. In other words, the fusion unit synthesizes a more reliable joint confidence level by eliminating contradictory information between pieces of evidence.

[0085] In this scenario, due to the extremely low confidence level of the facial recognition and the high confidence level of the card swipe, there is a serious conflict between the two pieces of evidence. The combined trust level after fusion remains very low, not exceeding the preset fusion threshold (e.g., 0.85), therefore the system does not trigger door opening. Conversely, if both verification methods provide moderate to high confidence levels, the combined trust level after fusion will be significantly higher than any single piece of evidence, thus reliably triggering door opening. This is precisely the advantage of the DS evidence theory: by combining multiple weak pieces of evidence to obtain strong evidence, it improves the accuracy of identification and the ability to resist deception.

[0086] Step 3.4 Decision-making and execution; When the joint trust level exceeds the preset fusion threshold, the fusion unit generates a verification pass result. The permission decision engine further verifies the visitor's appointment time slot and the role permissions of the accompanying person. Once all are satisfied, the door is opened, and special event types are logged.

[0087] IV. Dynamic Resource Allocation During Peak Periods Scenario: During the morning rush hour, a large number of people are queuing for verification at the main entrance, side gates, and VIP channels simultaneously, and the system detects a surge in concurrent requests.

[0088] Step 4.1 Priority metric calculation; The dynamic resource allocation unit re-evaluates the priority of each connected terminal at fixed intervals (e.g., every 100 milliseconds). The priority metric calculation logic takes into account the following factors: The ratio of a terminal's current instantaneous channel quality to its historical average transmission rate—terminals with current channel quality better than the historical average level receive higher priority. The waiting time of terminal data in the buffer — terminals with longer waiting times receive higher priority; The preset latency sensitivity coefficient is used to adjust the weight of waiting time in priority calculation.

[0089] The system combines the above factors to calculate a priority metric for each terminal. Then, based on the proportion of each terminal's priority metric to the total priority metrics of all terminals, a corresponding bandwidth share is allocated to each terminal. In addition, the system reserves a fixed percentage of the total bandwidth as an emergency bandwidth pool, which is used only for transmitting emergency events such as tamper alarms, ensuring that high-priority events can be processed in a timely manner.

[0090] For example, during peak hours, face recognition terminals located at the main entrance receive higher priority due to their good channel quality and short data waiting time, and are therefore allocated most of the bandwidth. In contrast, door magnetic sensors, despite having good channel quality, receive extremely low priority and consume almost no bandwidth because they do not report new data for extended periods. The system's reserved emergency bandwidth pool remains available at all times for potential emergencies.

[0091] Step 4.2 Dynamic adjustment of time slots; The multi-device access scheduling unit dynamically adjusts the guaranteed time slot length for each terminal based on the new bandwidth allocation ratio: the total duration of each communication cycle is allocated to each terminal according to the bandwidth ratio, with terminals carrying larger amounts of data receiving longer time slots. Simultaneously, contention for access is appropriately compressed to increase effective data transmission efficiency.

[0092] Step 4.3 Adaptive modulation scheme; The physical layer optimization unit measures the signal-to-noise ratio (SNR) of the current communication channel in real time and compares this real-time SNR with a dynamic threshold. This dynamic threshold is calculated based on the system's preset target bit error rate (BER) and the currently used modulation order. When the real-time SNR is higher than the dynamic threshold, the system uses high-order quadrature amplitude modulation (QAM), carrying more bits of data per symbol to achieve a higher transmission rate. When the real-time SNR is lower than the dynamic threshold, the system automatically switches to low-order QAM, carrying fewer bits of data per symbol, thereby reducing the BER and ensuring transmission reliability.

[0093] During peak hours, the large flow of people causes signal attenuation. When the system detects that the signal-to-noise ratio has dropped below a threshold, it automatically downgrades from high-order modulation to low-order modulation. Although the transmission rate is reduced, the bit error rate is significantly improved, still meeting the transmission requirements for single-pass verification data.

[0094] Through the detailed description of the above four parts, the embodiments of the present invention fully demonstrate the entire process from device initialization, automatic networking, daily single verification, multimodal fusion decision-making to dynamic resource scheduling during peak periods.

[0095] Thirdly, this application proposes an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method described above.

[0096] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the method described above.

[0097] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is merely an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiments can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit. Furthermore, the specific names of the functional units and modules are only for easy differentiation and are not intended to limit the scope of protection of this application. The specific working process of the units and modules in the above system can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0098] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0099] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this disclosure.

[0100] In the embodiments provided in this disclosure, it should be understood that the disclosed apparatus / computer devices and methods can be implemented in other ways. For example, the apparatus / computer device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. Multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces, and the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0101] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0102] Furthermore, the functional units in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0103] If an integrated module / unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program may include computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. A computer-readable medium may include: any entity or device capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in a computer-readable medium may be appropriately added to or subtracted according to the requirements of legislation and patent practice in a jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media may not include electrical carrier signals and telecommunication signals.

[0104] The above are merely preferred embodiments of the present invention. It should be noted that any modifications and improvements made by those skilled in the art without departing from the present technical solution should also be considered to fall within the scope of protection claimed by the present solution.

Claims

1. A data processing device based on the open-source HarmonyOS and the StarScan communication protocol, characterized in that, include: The core controller module runs the OpenHarmony operating system, which includes a distributed soft bus, comprising a device discovery service component, a data transmission service component, and a distributed scheduling service component. The StarScan communication module is electrically connected to the core controller module, and the StarScan communication module includes a physical layer processing unit and a media access control layer processing unit. The device discovery service component is configured to: broadcast a first beacon frame at a fixed period through the StarFlash communication module, the first beacon frame containing a device type field, a MAC address field, and an encryption certificate fingerprint field; simultaneously listen for a second beacon frame through the StarFlash communication module, and process the received signal strength values ​​using a sliding window detection algorithm. The sliding window detection algorithm maintains a window of a preset length, calculates the arithmetic mean of all signal strength values ​​within the window, and determines that a valid device has been discovered when the arithmetic mean exceeds a preset signal strength threshold. The distributed scheduling service component is configured to allocate processing resources according to a preset fixed priority order when multiple terminal devices simultaneously initiate verification requests. The fixed priority order from high to low is: VIP mode, face recognition mode, fingerprint recognition mode, and card recognition mode.

2. The device according to claim 1, characterized in that: The media access control layer processing unit is configured to: divide the time axis into beacon periods, contention access periods, and multiple guaranteed time slots in sequence, wherein the beacon periods are used to broadcast network synchronization information; the contention access periods employ a carrier sense collision avoidance mechanism for transmitting control commands; each guaranteed time slot is pre-allocated to the connected terminal device for exclusive data transmission by that terminal device, and the guaranteed time slot durations are different for different types of terminal devices, with terminal devices of large data transmission types being allocated longer guaranteed time slots.

3. The device according to claim 2, characterized in that: The physical layer processing unit is configured to: Measure the real-time signal-to-noise ratio and compare the real-time signal-to-noise ratio with a dynamic threshold; When the real-time signal-to-noise ratio is greater than the dynamic threshold, first-order quadrature amplitude modulation is used, and each symbol carries a first number of bits of data. When the real-time signal-to-noise ratio is less than the dynamic threshold, the system switches to second-order quadrature amplitude modulation, with each symbol carrying a second number of bits of data, wherein the first number is greater than the second number. The dynamic threshold is calculated based on the preset target bit error rate and the current number of bits per symbol.

4. The device according to claim 3, characterized in that: The star-flash communication module further includes an anti-interference unit, which is configured as follows: Scan multiple sub-channels within a preset frequency band; For each sub-channel, three factors are comprehensively evaluated: packet error rate, signal-to-noise ratio, and channel occupancy. Packet error rate is given the highest evaluation weight, followed by signal-to-noise ratio, and channel occupancy is the lowest. The quality score of each sub-channel is determined based on the comprehensive result of the three factors and their weights. Select a predetermined number of sub-channels with the highest quality scores, and arrange the selected sub-channels in descending order of scores as a frequency hopping sequence; The operating channel is switched at a fixed period according to the frequency hopping sequence.

5. The device according to claim 4, characterized in that: It also includes a modular terminal access module, which is connected to the StarFlash communication module, and the modular terminal access module includes a dynamic resource allocation unit. The dynamic resource allocation unit is configured to calculate a priority metric for each connected terminal device. The priority metric comprehensively considers the ratio of the current channel quality of the terminal device to the historical average rate, the data waiting time of the terminal device, and a preset delay sensitivity coefficient. The longer the data waiting time, the higher the priority metric. Then, according to the proportion of each terminal device's priority metric in the total priority metric of all terminal devices, a corresponding bandwidth share is allocated to each terminal device. Furthermore, a predetermined percentage of bandwidth is reserved from the total bandwidth as an emergency bandwidth pool, which is used only for transmitting emergency events.

6. The device according to claim 5, characterized in that: The modular terminal access module further includes a heterogeneous data fusion unit, which is configured as follows: Obtain the first confidence score output by the first terminal device and the second confidence score output by the second terminal device, wherein the first terminal device and the second terminal device belong to different device types; According to the DS evidence theory, the first confidence score and the second confidence score are respectively used as the basic confidence level of each evidence body in verifying the valid proposition, and 1 minus each confidence score is used as the basic confidence level in verifying the invalid proposition. By combining the trust levels of all evidence and eliminating conflicting trust levels among them, the joint trust level for verifying the valid proposition is calculated; where conflicting trust level refers to contradictory combinations where different evidence supports both valid and invalid propositions. When the joint trust level is greater than the preset fusion threshold, a verification pass signal is output.

7. The device according to claim 6, characterized in that: The StarScan communication module also includes a security authentication unit, which is configured to perform the following three-stage process: The first stage is device pre-registration: read the device's MAC address and serial number, concatenate the two and input them into a secure hash function to output the device's unique fingerprint, and bind the device's unique fingerprint to the digital certificate; The second stage is session key negotiation: On the preset elliptic curve, each party uses its own private key to multiply the other party's public key to obtain shared coordinate values, and then concatenates the horizontal and vertical coordinates to form the shared key. The third stage involves data transmission encryption: an authentication encryption algorithm is used, and each data frame contains a random number and a message authentication code.

8. The device according to claim 7, characterized in that: The core controller module also includes a rules engine, which supports script extensions and is configured to execute the following linkage logic: Read the current date and time, and determine if it is a preset workday type; Determine whether the current time is within a preset time window; When both the weekday type match and the time fall within the time window, at least one recognition mode is disabled, and only the verification result of the other recognition mode is allowed to trigger the door opening action.

9. A communication method based on the open-source HarmonyOS and the StarScan communication protocol, characterized in that: Includes the following steps: Receiving steps: Receive encrypted data packets through the StarFlash communication module. The encrypted data packets include a device ID field, a verification result field, a timestamp field, and a message authentication code field. The verification result field is encoded using a bitmask and includes a verification success flag and a verification failure flag. Parsing steps: Decrypt the encrypted data packet using the pre-stored session key and verify the message authentication code; After successful verification, read the verification success flag from the verification result field. Query steps: When the verification success flag is set, query the local database to obtain the user role based on the device ID field, and obtain the time tag based on the current system time; Judgment steps: Output the door opening command if and only if the following three conditions are met simultaneously: the verification success flag is set, the user role belongs to the set of roles allowed by the pre-stored door area permission bitmap, and the time tag falls within the pre-stored valid time period rule set. Execution steps: In response to the door opening command, a pulse width modulation signal is output through the GPIO pin, and the pulse duration of the pulse width modulation signal is a preset standard duration.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program that, when executed by a processor, implements the steps of the method as described in claim 9.