Intelligent Lock Control Methods and Systems
Patent Information
- Application Number
- CN202310267321.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-20
- Publication Date
- 2026-09-01
- Estimated Expiration
- 2043-03-20
AI Technical Summary
[0005]本发明针对现有技术中并没有对通信接口进行物理管控,且同时无法确保物理管控下后台遭受入侵盗用授权信息时能阻碍物理管控的非正常授权开启,提供一种智能化锁控方法及系统,通过通信接口闭锁装置物理闭锁通信接口以确保未授权时,通信接口无法进行通信,确保通信在授权下进行;同时采用工作站接收信息与电脑钥匙生成信息一次验证、电脑钥匙与通信接口闭锁装置生成信息二次验证,确保在任一环节出现入侵时,都无法开启通信接口闭锁装置,确保通信接口不会在非正常授权的情况下开启
[0016] The beneficial effects of this invention are as follows: By receiving the correct authorization information from the workstation through the computer key and matching it with the verification information output by the received communication interface locking device, the correct information verification from the computer key, workstation, and communication interface locking device is required before the next matching step can be carried out. This effectively avoids security issues such as information exposure when any one of the parties has a problem, and improves the security of information transmission.
Smart Images

Figure CN116467694B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication security technology, and in particular to intelligent lock control methods and systems. Background Technology
[0002] With the increasing number of IT communication devices such as computers, switches, and routers in substations, their various communication interfaces (such as USB and network interfaces), while providing convenience, also pose potential information security risks. If unauthorized devices use the USB or network ports of these IT communication devices to launch viruses, perform hacking attacks, or engage in other illegal activities against various information systems within the substation, it will pose a significant security risk to the stable operation of the power system. Therefore, it is necessary to implement physical security controls on the communication interfaces of IT devices to ensure that their use and activation are authorized, thereby guaranteeing the safe and stable operation of various information systems within the substation. However, physical security controls require reliable authorization information as support, and it is essential to ensure that this authorization information is accurate and secure.
[0003] Chinese patent "A Method and System for Preventing Misoperation Locking", publication number: CN 113077568 A, publication date: July 6, 2021, discloses a method that combines public and private keys with operation tickets to ensure that the instructions received by the lock are authorized. However, this solution uses a computer key to receive the private key and a wireless lock to obtain the public key, and compares the public and private keys to determine if the result is correct, thereby opening multiple locks. Although it has multiple locks, it actually only has one layer of comparison between public and private keys. That is, once the public and private keys match correctly, all multiple locks will be opened. At this time, if the backend is compromised and the correct private key is obtained, the lock can be opened, resulting in low security and a complex structural judgment.
[0004] Chinese patent "A Low-Power Smart Lock System and Unlocking Method with NBIOT Internet of Things Functionality", publication number: CN 111696233 A, publication date: September 22, 2020, discloses a method that records personnel identity information and access control layout information of various locations within a substation into a computer backend management terminal, stores it in an NBIOT data storage device, and sets personnel unlocking permission ranges. When unlocking, the computer backend management terminal or the user's mobile phone terminal retrieves door lock device data from the NBIOT, remotely issues an unlocking command through the computer backend management terminal or the user's mobile phone terminal, establishes a connection with the communication module in the smart lock via the mobile network, exchanges data, drives the chip to control the magnetically encoded lock cylinder, and the magnetically encoded lock cylinder controls the motor clutch actuator to unlock. Although this solution restricts personnel unlocking permissions, it also has the problem that when personnel permissions are stolen, it cannot prevent abnormal authorization of the communication interface, affecting the normal operation of the power grid system. Summary of the Invention
[0005] This invention addresses the shortcomings of existing technologies that lack physical control over communication interfaces and fail to prevent unauthorized access when the backend is compromised and authorization information is stolen. It provides an intelligent locking method and system that physically locks the communication interface to ensure unauthorized communication is impossible, guaranteeing that communication is only authorized. Furthermore, it employs a primary verification process involving the workstation receiving information and the computer key generating information, followed by a secondary verification process involving the computer key and the communication interface locking device generating information. This ensures that the communication interface locking device cannot be opened in the event of an intrusion at any stage, preventing unauthorized access to the communication interface.
[0006] To achieve the above-mentioned technical objectives, as a first aspect of the present invention, an intelligent lock control method is provided, characterized by the following steps: S1: The workstation sends a lock control signal to the computer key according to the lock control requirements, and the computer key generates first verification information; S2: The operator ID, operation password, and ID of the selected communication interface locking device are obtained, a first interception position and a first interception length are set, the interception is synthesized into a first verification password and output to the computer key; S3: The first verification password is matched with the first verification information. If the match is successful, a second interception position and a second interception length are set, the interception is synthesized into a second verification password, and the matching information is sent to the communication interface locking device. If the match is unsuccessful, an alarm message is output to the workstation; S4: After receiving the matching information, the communication interface locking device outputs the second verification information to the computer key, matches the second verification password with the second verification information, and if the match is successful, a third interception position and a third interception length are set, the interception is synthesized into a lock control credential, the lock control credential is sent to the communication interface locking device for unlocking control, and unlocking information is output to the workstation; if the match is unsuccessful, an alarm message is output to the workstation.
[0007] Preferably, the first verification information includes at least the permission feature data that matches the selected communication interface locking device.
[0008] Preferably, the first truncation position includes several position information and the first truncation length includes several length information.
[0009] Preferably, the first verification information also includes at least the location information of the permission feature data.
[0010] Preferably, the computer key selects the set values for the second interception position and the second interception length according to the selected communication interface locking device.
[0011] Preferably, the second verification information includes at least the ID of the communication interface locking device and the characteristic data of the operation password.
[0012] Preferably, random numbers are added for recombination when generating the first verification password and the second verification password.
[0013] Preferably, it also includes: S5: Store each matching result. When a matching fails, retrieve the previous matching result. If it is a mismatch, output an alarm message to the workstation and lock all communication interface interlocking devices.
[0014] As another aspect of this application, an intelligent lock control system is provided, comprising: a workstation for receiving lock control instructions from an operator and sending a first verification password to a computer key; a computer key for receiving verification information from the workstation and the communication interface locking device respectively, performing verification, obtaining lock control credentials to open the communication interface locking device; and a communication interface locking device for mechanically locking the communication interface.
[0015] Preferably, the communication interface locking device is a network port lock or a USB lock.
[0016] The beneficial effects of this invention are as follows: By receiving the correct authorization information from the workstation through the computer key and matching it with the verification information output by the received communication interface locking device, the correct information verification from the computer key, workstation, and communication interface locking device is required before the next matching step can be carried out. This effectively avoids security issues such as information exposure when any one of the parties has a problem, and improves the security of information transmission. Attached Figure Description
[0017] Figure 1 This is a flowchart illustrating an intelligent lock control method according to one embodiment of the present invention.
[0018] Figure 2 This is a schematic diagram of the structure of an intelligent lock control system according to another embodiment of the present invention. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only one preferred embodiment of this invention and are only used to explain this invention. They do not limit the scope of protection of this invention. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.
[0020] like Figure 1 As shown, the intelligent lock control method provided in this application includes the following steps:
[0021] S1: The workstation sends a locking signal to the computer key according to the locking requirements, and the computer key generates the first verification information;
[0022] S2: Obtain the operator ID, operation password, and ID of the selected communication interface locking device; set the first interception position and the first interception length; intercept and synthesize the first verification password and output it to the computer key.
[0023] S3: Match the first verification password with the first verification information. If the match is successful, set the second interception position and the second interception length, intercept and synthesize the second verification password, and send the matching information to the communication interface locking device. If the match is unsuccessful, output alarm information to the workstation.
[0024] S4: After receiving the matching information, the communication interface locking device outputs the second verification information to the computer key. The second verification password is matched with the second verification information. If the match is successful, the third interception position and the third interception length are set, the interception is synthesized to obtain the lock control certificate, and the lock control certificate is sent to the communication interface locking device to perform unlocking control and output the unlocking information to the workstation. If the match is unsuccessful, an alarm message is output to the workstation and all communication interface locking devices are locked.
[0025] Specifically, in step S1, the operator needs to first select the communication interface locking device that needs to be controlled for unlocking on the workstation. The workstation outputs the corresponding lock control signal to the computer key according to the selected communication interface locking device. Based on the corresponding lock control signal, the computer key generates the first verification information.
[0026] Preferably, the first verification information includes at least the permission feature data that matches the corresponding communication interface locking device.
[0027] Furthermore, in step S2, the operator inputs their ID and operation password. The workstation outputs the ID of the communication interface locking device according to the selected communication interface locking device information, and sets the first interception position and the first interception length to intercept part of the feature data in the operator ID, the communication interface locking device ID and the operation password, and synthesizes the feature data to obtain the first verification password.
[0028] Preferably, the first truncation position includes at least a number of position information, and the first truncation length includes at least a number of length information. Each position information is a truncation position, and each length information is a truncation length. That is, feature information is obtained by truncation at different positions and at different lengths in a piece of data information, which increases the difficulty of password cracking and improves information security.
[0029] In a further preferred embodiment, the workstation selects the set values of the first interception position and the first interception length according to the selected communication interface interlocking device. That is, the first interception position and the first interception length are different depending on the selected communication interface interlocking device, which further improves the security of information matching.
[0030] Optionally, the data segments containing ID information and operation password can be synthesized first, and then feature data can be extracted from the data segments.
[0031] Preferably, the workstation encrypts the first verification password and sends it to the computer key.
[0032] Furthermore, in step S3, the computer key receives the first verification password sent by the workstation and matches it with the first verification information it generates. If the match is successful, the computer key extracts the feature data from the first and second verification passwords according to the set second extraction position and second extraction length, and synthesizes the feature data to obtain the second verification password and sends it to the communication interface locking device. If the match is unsuccessful, an alarm message is sent to the workstation, and the operator can confirm whether the communication interface locking device has been selected incorrectly based on the alarm message from the workstation.
[0033] Specifically, the first verification password includes at least the operator's permission feature data, which is matched with the permission feature information in the first verification information. If the match is successful, it proves that the operator has the authority to unlock the door.
[0034] Preferably, the first verification information also includes at least the location information of the permission feature information in the data segment. That is, the permission feature information in the first verification password and its corresponding location information must both match the first verification information to determine a successful match. In other words, by adding interference numbers to the first verification password, even if the first verification password is stolen during transmission, the actual data information in the first verification password cannot be obtained, thus ensuring information security.
[0035] More preferably, the second cutting position includes at least a number of cutting positions, and the second cutting length includes at least a number of cutting lengths.
[0036] More preferably, the computer key selects the set values of the second interception position and the second interception length according to the selected communication interface locking device. That is, the second interception position and the second interception length are different depending on the selected communication interface locking device, which further improves the security of information matching.
[0037] Specifically, in step S4, after receiving the matching information from the computer key, the communication interface locking device generates second verification information and transmits it to the computer key for matching with the second verification password. If the match is successful, the computer key, according to the set third interception position and third interception length, intercepts and synthesizes the lock control credential, sends it to the communication interface locking device to unlock, and outputs the unlocking information to the workstation for recording. If the match fails, it is determined to be malicious unlocking, and an alarm message is output to the workstation for recording. Then, all communication interface locking devices are locked to prevent deception and intrusion. It can be understood that locking all communication interface locking devices here means that the state of all communication interface locking devices no longer changes, not that all communication interfaces are completely closed. This ensures the normal operation of the system while preventing illegal external intrusion.
[0038] Preferably, the second verification password includes at least the ID information of the corresponding communication interface locking device and the characteristic data of the operation password information. It is matched with the characteristic data of the ID information and password information in the second verification information. If the match is successful, it is confirmed that the operator does indeed need to open the corresponding communication interface locking device.
[0039] Specifically, the second verification information also includes at least the location information of the feature data in the data segment. That is, the ID information and password information in the second verification password and their corresponding location information must match the first verification information for a successful match to be determined. In other words, by adding interference numbers to the second verification password, even if the second verification password is stolen during transmission, the actual data information in the second verification password cannot be obtained, thus ensuring information security.
[0040] More specifically, the operator selects the communication interface interlocking device to be opened at the workstation. At this time, the computer key receives a locking signal from the workstation. The computer key retrieves the authorization information that can control the communication interface interlocking device based on the communication interface interlocking device information. It generates first verification information based on the authorization information and matches it with the authorization information in the first verification password. If the match is successful, it proves that the operator has the actual operating authority. If the match is unsuccessful, an alarm message is sent to the workstation and the operator is notified. After a successful match, the computer key sends a matching signal to the communication interface interlocking device, causing it to generate second verification information. The second verification information is then matched with the second verification password to confirm that the communication interface interlocking device selected by the operator is correct, thus generating the interlocking credentials. The system first verifies the operator's identity. When an operator has multiple access permissions or when multiple operators need shared permissions, a second verification is performed. If the operator is deemed legitimate, the computer key receives a second verification message from the communication interface locking device. This second verification checks if the communication interface locking device selected by the operator matches the actual device. If they don't match, it's considered malicious intrusion, and all communication interface locking devices will no longer accept unlocking commands until the lock is released. Essentially, the matching command issued by the computer key corresponds to the nearest communication interface locking device. When the operator approaches the device with the computer key, it sends a matching signal to the nearest locking device, obtaining its ID. If the ID doesn't match the selected device, it's considered malicious intrusion, and the locking program cannot be initiated.
[0041] Optionally, the operator controls the computer key to send a matching signal.
[0042] Optionally, S5 also includes: storing matching information during each authorization process; if the verification result does not match, retrieving the previous matching result; if the previous matching result was also a mismatch, it is determined to be a malicious intrusion, and the communication interface locking device is locked; if the previous matching result matched, only an alarm is triggered, and the device is not locked. This avoids operator error causing the communication interface locking device to lock directly; if there is a mismatch during the first verification, only an alarm is triggered. It is understood that the matching information for each authorization process is stored separately and does not interfere with each other.
[0043] Since the operator's permissions are checked during the first verification, if an error occurs, it can be assumed that the operator has made a mistake, so only an alarm message is generated and the operator is notified. However, during the second verification, the selected communication interface locking device is checked. If an error occurs during the second verification, it is determined to be a malicious intrusion, triggering an alarm and locking the device to prevent subsequent intrusions. This improves the accuracy of the operator's operation while ensuring the security of the final communication interface locking device.
[0044] Preferably, the correctness of the operation password is verified again during the second verification.
[0045] More preferably, random numbers are added for recombination when generating the first verification password. In this case, the position of the feature data information of the first verification password is arranged according to the selected communication interface locking device, that is, different selections of communication interface locking devices correspond to different permutations and combinations of data information. Similarly, random numbers are also added for recombination when generating the second verification password. In this case, the position of the feature data information of the second verification password is arranged according to the selected communication interface locking device, so that the feature data in the final generated second verification password is significantly different from the initially input operator ID, communication interface locking device ID, and operation password. Therefore, when comparing with the second verification information, the operator cannot deduce the corresponding communication interface locking device from the ID and password, thereby improving operational security. At the same time, matching data at multiple positions in the two data segments avoids the possibility of accidental matching during the interception process, further ensuring communication security.
[0046] Optionally, secondary verification can be performed within the workstation. This involves inputting both the first and second verification information output by the computer key and the communication interface locking device into the workstation for verification. However, unlocking with the computer key requires the computer key to be near the communication interface locking device, making remote control difficult. Considering the inconvenience of operators having to travel back and forth, the preferred solution is for the computer key to receive and verify the verification information, reducing the need for staff to travel back and forth. This also avoids the problem of all information being exposed if the workstation is compromised. Using the computer key as an intermediary, when the workstation is compromised, the information within the workstation cannot be verified as correct by the computer key. When the computer key is compromised, the workstation no longer transmits information to the computer key. Since both parties need to verify the other's correct information before proceeding to the next matching step, this effectively avoids security issues such as information exposure when either party malfunctions, thus improving the security of information transmission.
[0047] This application provides a specific embodiment for illustration. When opening the communication interface locking device C, both operator A and operator B need joint authorization. Operators A and B select the communication interface locking device C at the workstation. The workstation sends a locking signal to the computer key. The computer key generates first verification information based on the communication interface locking device C, namely, retrieving the relevant authorization code 0000000100000010 for the communication interface locking device C. Operators A and B then enter their respective IDs and passwords. Since the IDs of operators A and B are character data, the ID data is first digitized as follows:
[0048] Operator A's ID: CZA, converted to binary, is 01000011 01011010 01000001;
[0049] Operator B's ID: CZB, converted to binary, is 01000011 01011010 01000010;
[0050] Operator A's password is 4431, which in binary is 00110100 00110100 0011001100110001;
[0051] Operator B's password is 5231, which in binary is 00110101 00110010 0011001100110001;
[0052] The ID of the communication interface locking device C is ZZC, which is 01011010 01011010 01000011 in binary.
[0053] The above data is synthesized to obtain the data segment: 01000011 01011010 01000001 0010101000011010011 00110001 01000011 01011010 01000010 00110101 0011001000110011 0011000101011010 01011010 01000011; At this time, a length of 17 bytes is obtained. According to the selected communication interface locking device C, the first truncation position and truncation length information in the recording workstation are selected. In this embodiment, byte[2], byte[3], byte[4], byte[9], byte
[10] , byte
[11] , and byte
[16] are used as the feature dataset. Taking byte[2] as an example, the first truncation position and truncation length recorded by the workstation are byte[2], 1, and 2, that is, two bits are truncated starting from the first position of byte[2]. The data is converted with 00000011 using the "AND operator" as follows:
[0054] Original data: 01000001;
[0055] Calculate data 00000011;
[0056] Data obtained: 00000001.
[0057] Converting to decimal gives the final result 1. Similarly, we can get byte[3], 5, 2, byte[4], 1, 1, byte[9], 1, 2, byte
[10] , 5, 2, byte
[11] , 1, 1, byte
[16] , 1, 4, which are 48, 0, 2, 48, 0, 3 respectively. The first verification password is 148024803, which is converted to binary as 1000110100101010110111100011. We can insert a random number at a specified position according to the selected communication interface locking device C, such as 15240180264680643. We can see that we will get 17 bytes. The position of the permission feature data is used as the matching position, that is, byte[0] and byte[8] are used for matching. Similarly, we can add a random number to the relevant permission code of the communication interface locking device C and record the position of the feature data. When matching, we can retrieve the position of the feature data. Similarly, the second verification password is also retrieved in the same way as described above. Since some bits in the binary are discarded and then supplemented by random numbers during the interception process, the second verification password obtained is not the same as the first verification password. It is then matched with the second verification information. At this time, the password feature data position and the communication interface locking device C feature data position are used as the matching position, that is, the feature data in byte[3], byte[4], byte
[10] , byte
[11] , and byte
[16] are used as the matching position in the second verification password, and the matching calculation is performed.
[0058] Alternatively, the number of digits can be truncated through conversions to quaternary, octal, hexadecimal, etc.
[0059] Preferably, encryption algorithms such as MD5, RSA, and SHA can be used to encrypt the result a second time.
[0060] Optionally, a Java program can be used to process the data.
[0061] like Figure 2 As shown, this application also provides an intelligent lock control system, including a workstation, a computer key, and a communication interface locking device. The workstation is used to receive lock control commands from the operator and send them to the computer key. The computer key receives verification information from the workstation and the communication interface locking device, verifies it, and obtains lock control credentials to open the communication interface locking device. The communication interface locking device is used to mechanically lock the communication interface, preventing it from communicating.
[0062] Specifically, a communication interface locking device is installed between the communication interfaces of the system and the equipment. The device uses a baffle to lock and prevent communication between the two, thus ensuring communication security. At the same time, a two-factor authentication method is adopted, so that the computer key has the right to open the communication interface locking device only when the operator's permissions, password, and selected communication interface locking device are all accurate. This ensures that all communication between system devices is authorized and guarantees communication security.
[0063] Optionally, the communication interface locking device can be any type such as a network port lock or a USB lock.
[0064] The above-described specific embodiments are preferred embodiments of the intelligent lock control method and system of the present invention, and are not intended to limit the specific scope of the present invention. The scope of the present invention includes, but is not limited to, these specific embodiments. All equivalent changes made in accordance with the shape and structure of the present invention are within the protection scope of the present invention.
Claims
1. An intelligent lock control method, characterized in that: Includes the following steps: S1: The workstation sends a locking signal to the computer key according to the locking requirements, and the computer key generates the first verification information; S2: Obtain the operator ID, operation password, and ID of the selected communication interface locking device; set the first interception position and the first interception length; intercept and synthesize the first verification password and output it to the computer key. S3: Match the first verification password with the first verification information. If the match is successful, set the second interception position and the second interception length, intercept and synthesize the second verification password, and send the matching information to the communication interface locking device. If the match is unsuccessful, output alarm information to the workstation. S4: After receiving the matching information, the communication interface locking device outputs the second verification information to the computer key, matches the second verification password with the second verification information, and if the match is successful, sets the third interception position and the third interception length, intercepts and synthesizes to obtain the lock control certificate, sends the lock control certificate to the communication interface locking device to perform unlocking control, and outputs unlocking information to the workstation; if the match is unsuccessful, it outputs alarm information to the workstation. In step S2, partial feature data from the operator ID, communication interface locking device ID, and operation password are extracted and synthesized to obtain the first verification password. In step S3, the feature data of the first verification password and the first verification information are extracted and synthesized to obtain the second verification password; In step S4, the feature data of the second verification password and the second verification information are intercepted and synthesized to obtain the lock control credentials.
2. The intelligent lock control method as described in claim 1, characterized in that: The first verification information includes at least the permission feature data that matches the selected communication interface locking device.
3. The intelligent lock control method as described in claim 1, characterized in that: The first cut-off position includes several position information, and the first cut-off length includes several length information.
4. The intelligent lock control method as described in claim 2, characterized in that: The first verification information also includes at least the location information of the permission feature data.
5. The intelligent lock control method as described in claim 1, characterized in that: The computer key selects the second interception position and the second interception length setting value according to the selected communication interface locking device.
6. The intelligent lock control method as described in claim 1, characterized in that: The second verification information includes at least the ID of the communication interface locking device and the characteristic data of the operation password.
7. The intelligent lock control method as described in claim 1, characterized in that: Random numbers are added and recombined when generating the first verification password and the second verification password.
8. The intelligent lock control method as described in claim 1, characterized in that: Also includes: S5: Store each matching result. When a match fails, retrieve the previous matching result. If it is a mismatch, output an alarm message to the workstation and lock all communication interface interlocking devices.
9. An intelligent lock control system for implementing any one of the intelligent lock control methods as described in claims 1 to 8, characterized in that: include: The workstation is used to receive lock control commands from operators and send the first verification password to the computer key; The computer key is used to receive verification information from the workstation and the communication interface locking device, verify them, obtain the lock control credentials, and open the communication interface locking device. A communication interface locking device is used to mechanically lock the communication interface.
10. The intelligent lock control system as described in claim 9, characterized in that: The communication interface locking device is a network port lock or a USB lock.
Citation Information
Patent Citations
Low-power-consumption intelligent lock system with NBIOT Internet of Things function and unlocking method
CN111696233A
Anti-misoperation locking method and system
CN113077568A
Cipher lock system and authentication method
CN107979472A
Method for generating dynamic password of intelligent lock and intelligent lock system
CN111612945A