Electronic lock device and encryption and authentication method thereof

By using random numbers and atomic clock timing systems to generate dynamic keys in electronic lock devices, and combining the key management system and encryption authentication process of the security chip, the security issues of mechanical and smart lock cores are resolved, and high-security electronic lock control is achieved.

CN119232358BActive Publication Date: 2025-09-09JIANGSU DAZHOU JIYE INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411306677.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-19
Publication Date
2025-09-09
Estimated Expiration
2044-09-19

AI Technical Summary

Technical Problem

Existing mechanical lock cylinders and smart lock cylinders have deficiencies in security and convenience, are easily illegally opened or forged, and existing cryptographic technology lacks comprehensive security control throughout the data life cycle.

Method used

An electronic lock device is used, and a random number generator is used to generate a random number as the first key. Combined with the dynamic time parameters obtained by the atomic clock timing system, a public and private key pair for the lock cylinder and smart password key is generated through the key management system. Mathematical operations and hash value encryption are performed, and a secure chip storage and authentication process is constructed to ensure data security at every link.

Benefits of technology

It realizes high-security control without mechanical lock core, avoids illegal unlocking, ensures the uniqueness and dynamism of the key, improves the security level of the electronic lock, and ensures convenience and safety.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119232358B_ABST
    Figure CN119232358B_ABST
Patent Text Reader

Abstract

The present invention relates to an electronic lock device and its encryption and authentication method. When a user purchases a lock cylinder, the electronic lock device generates a random number as a first key. The current time obtained by an atomic clock timing system is used as a dynamic parameter to generate the lock cylinder's public and private keys and the super administrator's public and private keys. The super administrator then authorizes the generation of the authorized user's public and private keys. The public key of any super administrator is used to perform mathematical operations with the authorized user's public key and the corresponding authorized user's physical feature data to obtain cryptographic feature data and physical feature data, and calculate hash values ​​for each. The cryptographic feature data and its hash value, as well as the physical feature data and its hash value, are encrypted and stored using a first key. A hash value is simultaneously calculated for the encrypted array, and the hash value is encrypted with the first key and stored. The present invention ensures the security of each link in the lock cylinder control process based on each node in the integrated electronic lock application scenario, thus achieving a high-security level for electronic lock cylinder control and unlocking applications.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information security technology, and in particular relates to an electronic lock device and an encryption and authentication method thereof. Background Art

[0002] Traditional door lock cylinders or smart lock cylinders have one thing in common: they use mechanical keys and increase the strength of the lock cylinder by increasing the number of pins inside the lock cylinder. The designs of A, B, and C type lock cylinders currently on the market still cannot avoid the possibility of successful unlocking by experts.

[0003] With the development of electronic information technology, smart locks that unlock through IC card recognition have emerged. These smart locks do not have traditional mechanical lock cylinders. Although they also increase the use of keys, IC cards can be easily illegally read and copied by card readers, allowing forgers to illegally authorize unlocking, resulting in poor security. There are also smart locks that use facial and fingerprint image features to determine whether the lock can be unlocked. Although these smart locks greatly increase convenience during use, they also increase significant security risks. For example, faces can be synthesized through AI, fingerprints can be extracted, key passwords can be guessed by combination, and feature recognition errors can occur.

[0004] Various public documents contain numerous methods for implementing cryptographic technologies in various application scenarios. However, these methods only describe data encryption and signature-based tamper-proofing functions, lacking specific approaches for implementing secure, reliable, and leak-proof cryptographic technologies throughout the critical data lifecycle of product applications. The application of cryptographic technology is a comprehensive approach, requiring both its use and scientific application. A flawed cryptographic solution can lead to the leakage of core data or keys due to vulnerabilities within the solution. Summary of the Invention

[0005] A first object of the present invention is to provide an encryption method for an electronic lock device.

[0006] To achieve the above object, the present invention adopts the following technical solutions:

[0007] An encryption method for an electronic lock device, the electronic lock device comprising an electronic lock cylinder and a paired smart password key, the smart password key having a security chip therein, and the electronic lock cylinder having a security chip and a processing chip therein, the encryption method comprising:

[0008] When a user purchases a lock cylinder, a random number generator is used to generate a random number as the first key;

[0009] Using the buyer's identity information as a fixed first parameter, the current time obtained from the atomic clock timing system as a dynamic second parameter, and the seller's information as a fixed third parameter, a key management system device is used to generate a lock cylinder public and private key and m pairs of super administrator public and private keys, which are written into the lock cylinder and the m super administrators' smart password keys respectively. The super administrator authorizes the generation of n pairs of authorized user public and private keys, which are written into the n authorized users' smart password keys respectively. The lock cylinder public key and the public keys of the m+n smart password keys are encrypted with the first key and stored in the lock cylinder's security chip.

[0010] Use the public key of any super administrator to perform mathematical operations with the public key of the authorized user and the physical feature data of the corresponding authorized user to obtain the password feature data and the physical feature data, and calculate the hash value respectively; encrypt the password feature data and its hash value, the physical feature data and its hash value respectively using the first key to obtain the array { }、{ } and stored in the lock cylinder's security chip; }、{ }Calculate the hash value and obtain the hash array { },Will{ }The public key of the lock core is encrypted with the first key and then stored in the security chip of the lock core; when the product is put into use, the public key of the lock core is encrypted with the public key of the authorized user and transmitted to the security chip of the smart password key corresponding to the authorized user.

[0011] As a preferred embodiment, the security chip has a readable and writable general storage area, and an unreadable private storage area and a secure storage area. The general storage area stores public key data, the private storage area stores the first key, and other data is stored in the secure storage area.

[0012] As a preferred embodiment, the electronic lock device pre-installs the manufacturer's public and private key pair in the lock cylinder and the security chip of the smart password key before leaving the factory. After the user purchases the electronic lock device, the public and private key pair of the super administrator and the authorized user are used to replace the pre-installed manufacturer's public and private key pair;

[0013] Preferably, the manufacturer's public-private key pair is generated based on manufacturer information, and the manufacturer's information-related parameters are used to generate the manufacturer's public-private key pair using a key management system device. Further, the manufacturer information includes name, address, telephone number and / or time when the parameters were entered into the device.

[0014] As a preferred embodiment, the super administrator authorizes the generation of n pairs of public and private keys for authorized users in the following manner: using the super administrator's public key as the first fixed parameter, the current time obtained from the atomic clock timing system as the dynamic second parameter, and the vendor information as the fixed third parameter, and utilizing the key management system device to generate n pairs of public and private keys for authorized users.

[0015] As a preferred embodiment, the method further comprises: Sign with the lock core public key respectively, The signature array and the hash value corresponding to the signature array are exported and stored in other storage areas in the lock core or stored in a removable storage medium as a disaster recovery backup or for restoring the highest authority.

[0016] As a preferred embodiment, the method further comprises: Sign each key with the lock core public key, and store the obtained signature array in the lock core password chip;

[0017] When the product is put into use, first save the { }、{ }Using hash array { } to perform hash value verification, and at the same time }, { } to perform signature verification. If the verification and signature verification are correct, the encrypted data { After decrypting the key with the first key and extracting the authorized user's public key, the lock cylinder's public key is encrypted with the authorized user's public key and transmitted to the security chip of the smart password key corresponding to the authorized user via a digital envelope. Preferably, after extracting the authorized user's public key, a hash value check is performed on the authorized user's public key, and it is used after verification.

[0018] As a preferred implementation, if the public keys of different super administrators are used to perform mathematical operations with the public keys of authorized users and the physical feature data of the corresponding authorized users, a record table is constructed in the lock core to record the authorized users and the corresponding super administrator public keys for signature verification during authentication.

[0019] A second object of the present invention is to provide an authentication method for the electronic lock device, comprising:

[0020] The authorized user sends an unlock request, unlocks the encrypted lock core public key with the authorized user's private key, obtains the lock core public key, and uses the lock core public key to unlock the authorized user's public key d usri The encrypted data is sent to the security chip of the lock core;

[0021] After the lock core security chip receives the unlock request, it decrypts the data sent by the authorized user with the lock core private key, and then uses the saved authorized user encryption public key and hash value to verify the decrypted data. After the signature verification is passed, the feature data corresponding to the authorized user is extracted from the lock core security chip. }、{ } and hash value data { }, and decrypt with the first key;

[0022] After decryption, { }、{ } is hashed and compared with the hash value { }Compare, if correct, then d usri Add the corresponding authorized administrator's public key and calculate the hash value, and save the d usri 'Compare, if the comparison is correct, the lock core's security chip generates a random number α, and α and its hash value are used with the authorized user's public key d usri The smart password key is encrypted and sent to the authorized user;

[0023] The authorized user uses his private key to decrypt the random number α and its hash value, and performs a hash value verification on α. ​​After the verification passes, the random number α is used to encrypt the hash value, and the hash value is signed with the lock core public key and sent to the lock core security chip;

[0024] The lock core security chip uses the private key and α decryption to perform hash value verification on the data sent by the authorized user. If the comparison is correct, it means that the user is a legitimate authorized user. The user's password feature data and physical feature data are collected and compared. If the comparison is consistent, the verification is passed.

[0025] As a preferred implementation, if any link fails to pass the authentication, the lock core security chip triggers the alarm module to issue a warning, and triggers the video acquisition device to extract data of the continuous physical characteristics of the surrounding environment, and sends an illegal unlocking prompt and the extracted physical characteristic data information to the authorized user's terminal.

[0026] A third object of the present invention is to provide an electronic lock device constructed based on the above encryption method.

[0027] The present invention has the following beneficial effects:

[0028] (1) The electronic lock device of the present invention uses a cryptographic algorithm to realize lock core control, without the need for a mechanical lock core, thus reducing the possibility of illegal mechanical unlocking to zero.

[0029] (2) The present invention uses an atomic clock timing system to obtain precise time as a dynamic parameter for generating the lock cylinder and smart password key. Because the time obtained from the timing system is constantly changing, using it as a dynamic parameter for generating the key makes it unique at that point in time, and also makes the result of the key different, thereby avoiding the situation where the parameters are consistent due to artificially set time.

[0030] (3) The present invention uses cryptographic algorithms and discrete mathematics knowledge to control and use data generation, change, data flow, data security control, etc. at each node according to the comprehensive application scenario. Without losing convenience, it ensures the security of each link of the lock core control and realizes the application of high-security electronic lock core control and unlocking. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 This is a flowchart of the administrator's public and private key generation process.

[0032] Figure 2 This is a schematic diagram of the electronic lock verification process. DETAILED DESCRIPTION

[0033] The technical solution of the present invention will be further described below in conjunction with the accompanying drawings and specific implementation methods.

[0034] Some of the terms involved in the embodiments are explained as follows:

[0035] A key management system refers to a mature key management system equipment product that has passed the national cryptographic product testing and certification. It is used to create and manage keys. It has functions such as disassembly and self-destruction. After purchase, the user runs it independently and closed (not allowed to connect to the Internet), and existing mature products can be used.

[0036] The atomic clock timing system refers to the group of atomic clocks established by the National Time Service Center to provide standard timing points.

[0037] A security chip refers to a cryptographic security chip that has passed national testing and certification. It has an independent processor and storage unit inside. The storage unit is divided into a private storage area, a secure storage area, and a common storage area. The private storage area and the secure storage area cannot be read out but can only be written in. The common storage area can be read and written. In this embodiment, the public key is written into the common storage area of ​​the cryptographic security chip for storage, and the random number Write to the private storage area for storage, and other data (including private keys) are written to the secure storage area for storage.

[0038] Example 1

[0039] This embodiment provides a specific process for constructing an electronic lock device.

[0040] The electronic lock device shown in this embodiment includes an electronic lock cylinder and a paired smart key. The electronic lock cylinder houses a security chip and a processing chip (a microprocessor, i.e., the lock cylinder's CPU / main control chip). There are m+n smart keys, m of which are super administrator keys, and the remaining n keys are owned by n authorized users. The m super administrator keys consist of one key for the purchaser (the super administrator with the highest authority) and m-1 backup keys. Each backup super administrator can use their public key to encrypt and store the authorized user's signature data.

[0041] The encryption method of the electronic lock device includes the following steps:

[0042] 1) Initialization of the device before leaving the factory.

[0043] Before shipment, the manufacturer pre-sets a public-private key pair on the lock cylinder's security chip and the m+n smart key security chips. This pre-set public-private key pair is generated based on manufacturer information, which may include name, address, phone number, and current time (the time when production parameters were entered into the password management system). This manufacturer information is used as the production parameters for the factory key. These production parameters are fed into the key management system for calculation, generating the manufacturer's public-private key pair. This key pair is then written into the lock cylinder's security chip and the smart key's security chip. The smart key's public key is also written into the lock cylinder's security chip.

[0044] 2) The virtual legal identity of the electronic lock user (including m super administrators and n authorized users) is confirmed, and the key pair preset by the manufacturer is replaced with the key pair generated by the buyer when the purchase is actually made.

[0045] The purchaser of the lock cylinder is the legal owner of the item and can be called the "super administrator" of the lock cylinder. When the lock cylinder purchaser purchases the lock cylinder, his personal identity authentication information (such as ID number or mobile phone number) is used as one of the basic fixed parameters for generating the key. The current date and time T of the parameter entered (into the key management system device) is obtained from the timing system and used as the dynamic second parameter. Combined with the seller information (such as the seller's name) as the third parameter, the key management system device then calculates the lock cylinder's public and private key pair and m pairs of public and private key pairs (d usrj ,W usrj ),like Figure 1 The buyer's time for the m smart password keys is S' Usrj , j is the serial number of the smart password key, j∈[1,m−1], calculate U usrj =[S' usrj ]G, where G is a finite field of elliptic curve. ID number or mobile phone number is ID usr , the manufacturer (or distributor) name is P usr,, these parameters are sent to the key management system device for calculation, and 1+m pairs of random data are generated as the corresponding public-private key pairs. The public-private key pairs of the lock core are written into the password security chip of the lock core (the public key is symmetrically encrypted with β and saved), and the public-private key pairs of m super administrators are written into the super administrator's smart password key, replacing the preset manufacturer's public-private key pairs, and the public key of the super administrator's smart password key is symmetrically encrypted with β (i.e. , Enc() is a symmetric encryption algorithm), and calculates the hash value of the encrypted data (i.e. ), encrypt the public key and hash value Any super administrator can authorize n users, so the administrator public key is uniformly referred to as d in the following text. usr If multiple super administrators have authorized different users, a record table can be built in the lock core to record the authorized users and the public keys of the super administrators who authorized them for subsequent signature verification.

[0046] In addition, a random number is generated by a random number generator when purchasing As the top-level key, it serves as the symmetric encryption key for data protection of the lock cylinder.

[0047] The "super administrator"'s public-private key pair authorizes the generation of n public-private key pairs, which are then written into the n smart keys, replacing the factory-installed public-private key pair. The super administrator's public-private key pair is the one with the highest control authority over the lock cylinder and the n smart keys in future use.

[0048] Secondly, since the time for generating each pair of public and private keys cannot be completely consistent, even if the personal identity authentication information and seller information are consistent, the time released by the atomic clock's timing system cannot be modified. Therefore, each pair of public and private keys generated is different.

[0049] By performing mathematical operations on the digital features of the purchaser (personal identity authentication information, seller and T), the virtual identity of the legal owner of the association between the "lock" and the "key" is established. Moreover, due to the characteristics of discrete mathematics, the above digital features can be calculated under certain specific circumstances, and these parameters can be deduced in reverse, thereby ensuring that the purchaser is the owner of the highest management authority of the lock core.

[0050] After the super administrator (purchaser) is confirmed and authorized and generates the super administrator's public-private key pair, any super administrator (or different super administrators can be authorized) can generate the remaining n authorized users' public-private key pairs in the same way as above ( Figure 1The only difference is that the digital features (personal identity authentication information) of the purchaser are replaced with the public key of the super administrator as its digital features, which are input into the key management system as an important parameter to participate in the calculation and generate the public-private key pairs of n authorized users (d usri ,W usri ), write the public-private key pair into the smart password key of the corresponding authorized user, replace the preset public-private key pair of the manufacturer, and use β to symmetric encrypt the public key (i.e. , and calculate the hash value of the encrypted data (i.e. ), encrypt the public key and hash value Place it in the security chip of the lock cylinder.

[0051] Through the above operations, after the user purchases, these n smart password keys have obtained the basic permissions for controlling and managing the lock cylinder after being authorized by the "super administrator" smart password key. This is equivalent to completing the initialization work before using the smart password key and the lock cylinder. After this initialization is completed, the public and private key pairs originally set at the factory are replaced, thereby completing the change of the core parameters of the key generation from the factory settings to the core permission data of the actual purchaser through the above operations.

[0052] 3) Initialization of characteristic data of authorized user i (user):

[0053] 3.1) Use the public key d of any smart password key with the highest management authority (super administrator) usr and the public key d of the other n smart password keys that can grant the lock cylinder unlocking authority usri After adding (i∈[1,n], n is a natural number), the added data is hashed to prevent tampering, and the hashed data d is obtained. usri '(i∈[1,n], n is a natural number), public key d usri That is, password characteristic data.

[0054] 3.2) For the n authorized smart password keys, determine the unique representative physical feature data of the user corresponding to the smart password key Array, use the public key of the super administrator (d usr ) + physical characteristic data Then, the sum data is hashed to obtain the hash value. , where M represents the specific physical feature data of a person or object, s represents the classification attribute of the feature, m represents the attribute number of the attribute, and n represents the specific value of the attribute.

[0055] The uniquely representative physical feature data may be uniquely representative physical data of the human body such as fingerprints and faces.

[0056] 3.3) Encrypt and hash the physical and password feature data to ensure that even if the sensitive security parameters (top-level keys) are leaked, the lock's security will not be compromised. The specific operations are as follows:

[0057] 3.3.1 Data representing the physical characteristics of the authorized user (such as fingerprint recognition data of people or objects, face recognition data, etc.), hash value of physical feature data With top-level key As the symmetric encryption key to encrypt the array { }, the public key data d usri (i∈[1,n], n is a natural number) and data d representing the unique cryptographic digital feature usri '(i∈[1,n], n is a natural number) with top-level key As the symmetric encryption key to encrypt the array { }, save these two arrays to the secure storage area of ​​the security chip in the electronic lock core, or store them in the lock core security chip and the key chip in a double backup manner.

[0058] The calculation process is shown as follows: } as an example:

[0059] ( , ) = { }.

[0060] 3.3.2 Using hash algorithm to }and{ }Calculate and obtain the hash array of encrypted data { }.

[0061] That is: Hash ({ }, { })={ }

[0062] 3.3.3 The hash array { }Reuse The encrypted data is stored in the security chip of the electronic lock core to protect the hash array. As of this step, the feature data { }、{ } and hash array { }Security purposes of separate calculations.

[0063] 3.3.4 The signature array is obtained by signing with the lock core public key, and the signature array is stored in the secure storage area of ​​the lock core password chip.

[0064] 4) Feature Encryption Data Backup: The signature array and the hash value corresponding to the signature array are exported and saved elsewhere in the lock core or stored in a removable storage medium (such as a USB flash drive) for use as disaster recovery backup and recovery of the highest authority.

[0065] 5) When the lock is put into use, the data stored in the lock core will be hashed and decrypted for backup

[0066] When the product is put into use, the { }, { } Perform hash calculation and compare the result with the saved hash value { }, and compare { }, { } to verify the signature. If the result is consistent, it means that the data has not been changed or forged. } is decrypted with β. After decryption, it is restored to (d usri , d usri '), take out the authorized public key d usri Calculate the hash value after adding it to the corresponding authorized administrator's public key, and d usri 'Compare and verify that there is no error, then encrypt the public key of the lock cylinder with the public key of the authorized user through the digital envelope transmission method and send it to the ordinary storage area of ​​the password security chip of the authorized user's smart password key for standby use.

[0067] Example 2

[0068] This embodiment specifically describes the verification process of the electronic lock cylinder of the present invention. Figure 2 As shown, including:

[0069] 1. The authorized user sends an unlock request and uses the encrypted lock cylinder public key to unlock the lock cylinder with the authorized user's private key W. usri Unlock, obtain the lock core public key, and use the lock core public key to usri Encrypted and sent to the password security chip in the lock cylinder.

[0070] 2. After receiving the unlocking request, the security chip of the lock core decrypts the data sent by the authorized user with its private key.

[0071] 3. The lock core uses the saved authorized user to encrypt the public key and hash value The authorized user public key d obtained by decrypting the private key usriAfter the signature is verified, the password security chip of the lock core extracts the feature data corresponding to the authorized user from the secure storage area. }、{ } and hash value data { }, and use Decrypt.

[0072] 4. Will pass After decryption { }、{ }Data is hashed to calculate a hash value, and the hash value is compared with the decrypted hash value { } is compared, if it is correct, it proves that the data stored in the security chip has not been tampered with or forged. usri Calculate the hash value after adding it to the corresponding authorized administrator's public key, and save the hash value d usri 'Make a comparison.

[0073] If the comparison is correct, the password security chip of the lock core generates a 128-bit random number α, which is used as the key for symmetric encryption. This random number α and its hash value are used with the public key d usri The encrypted data is sent to authorized users.

[0074] 5. After receiving the data, the authorized user uses his private key W usri Decryption is performed to obtain the random number α and the hash value, and the hash value of α is calculated and compared with the hash value obtained by decryption.

[0075] 6. After the authorized user calculates and compares correctly, the random number α is used to encrypt the hash value and signed with the public key of the lock core's security chip.

[0076] 7. The password security chip of the lock core uses the private key to decrypt the data sent by the authorized user, and uses the random number α generated by it as the decryption key to decrypt it. The obtained value is compared with the original hash value. If the comparison is correct, it means that the user is a legitimate authorized user.

[0077] 8. If the comparison is correct, the various data collection modules are triggered to start data collection. The collected physical and password data are extracted and encrypted using the public key of the lock cylinder's password security chip and sent to the lock cylinder. The lock cylinder's password security key decrypts the obtained data with the private key and compares it with the physical and password data previously stored in the secure area of ​​the lock cylinder. If the physical and password characteristics are also correctly compared, the embedded control system (COS) of the password security chip in the lock cylinder issues a command to the servo motor to unlock the door and sends an unlock prompt to the authorized user's mobile terminal / PC.

[0078] If the comparison is incorrect, the embedded control system (COS) of the password security chip in the lock core will send instructions to various alarm modules to generate alarm sounds, while triggering the collection function module to extract continuous physical feature data of the surrounding environment and send illegal unlocking prompt data information to the authorized user's mobile terminal / PC.

Claims

1. An encryption method for an electronic lock device, wherein the electronic lock device includes an electronic lock cylinder and a paired smart password key, characterized in that: The smart password key is provided with a security chip, the electronic lock core is provided with a security chip and a processing chip, and the encryption method includes: When a user purchases a lock cylinder, a random number generator is used to generate a random number as the first key; Using the buyer's identity information as a fixed first parameter, the current time obtained from the atomic clock timing system as a dynamic second parameter, and the seller's information as a fixed third parameter, a key management system device is used to generate a lock cylinder public and private key and m pairs of super administrator public and private keys, which are written into the lock cylinder and the m super administrators' smart password keys respectively. The super administrator authorizes the generation of n pairs of authorized user public and private keys, which are written into the n authorized users' smart password keys respectively. The lock cylinder public key and the public keys of the m+n smart password keys are encrypted with the first key and stored in the lock cylinder's security chip. Use the public key of any super administrator to perform mathematical operations with the public key of the authorized user and the physical feature data of the corresponding authorized user to obtain the password feature data and the physical feature data, and calculate the hash value respectively; encrypt the password feature data and its hash value, the physical feature data and its hash value respectively using the first key to obtain the array { }、{ } and stored in the lock cylinder's security chip; }、{ }Calculate the hash value and get the hash array { },Will{ }The public key of the lock core is encrypted with the first key and then stored in the security chip of the lock core; when the product is put into use, the public key of the lock core is encrypted with the public key of the authorized user and transmitted to the security chip of the smart password key corresponding to the authorized user.

2. The encryption method according to claim 1, wherein: The security chip includes a readable and writable common storage area, a non-readable private storage area, and a secure storage area. The common storage area stores public key data, the private storage area stores a first key, and other data is stored in the secure storage area.

3. The encryption method according to claim 1, wherein: Before the electronic lock device leaves the factory, the manufacturer's public and private key pair is preset in the lock cylinder and the security chip of the smart password key. After the user purchases the electronic lock device, the public and private key pair of the super administrator and the authorized user are used to replace the preset manufacturer's public and private key pair.

4. The encryption method according to claim 1, wherein: The method for the super administrator to authorize the generation of n pairs of public and private keys for authorized users is: using the super administrator's public key as the first fixed parameter, the current time obtained from the atomic clock timing system as the dynamic second parameter, and the vendor information as the fixed third parameter, and using the key management system device to generate n pairs of public and private keys for authorized users.

5. The encryption method according to claim 1, wherein: Also includes, Sign with the lock core public key respectively, The signature array and the hash value corresponding to the signature array are exported and stored in other storage areas in the lock core or stored in a removable storage medium as a disaster recovery backup or for restoring the highest authority.

6. The encryption method according to claim 1, wherein: Also includes, and Sign each key with the lock core public key, and store the obtained signature array in the lock core password chip; When the product is put into use, first save the { }、{ }Using hash array { } to perform hash value verification, and at the same time }, { } to perform signature verification. If the verification and signature verification are correct, the encrypted data { }After decrypting with the first key and taking out the public key of the authorized user, the public key of the lock core is encrypted with the public key of the authorized user and transmitted to the security chip of the smart password key corresponding to the authorized user through the digital envelope transmission method.

7. The encryption method according to claim 1, wherein: If mathematical operations are performed using the public keys of different super administrators and the public keys of authorized users and the physical feature data of the corresponding authorized users, a record table is constructed in the lock core to record the authorized users and the corresponding super administrator public keys for signature verification during authentication.

8. The authentication method for an electronic lock device according to any one of claims 1 to 7, characterized in that: include: The authorized user sends an unlock request, unlocks the encrypted lock core public key with the authorized user's private key, obtains the lock core public key, and uses the lock core public key to unlock the authorized user's public key d usri The encrypted data is sent to the security chip of the lock core; After the lock core security chip receives the unlock request, it decrypts the data sent by the authorized user with the lock core private key, and then uses the saved authorized user encryption public key and hash value to verify the decrypted data. After the signature verification is passed, the feature data corresponding to the authorized user is extracted from the lock core security chip. }、{ } and hash value data { }, and decrypt with the first key; After decryption, { }、{ } is hashed and compared with the hash value { }Compare, if correct, then d usri Add the corresponding authorized administrator's public key and calculate the hash value, and save the d usri 'Compare, if the comparison is correct, the lock core's security chip generates a random number α, and α and its hash value are used with the authorized user's public key d usri The smart password key is encrypted and sent to the authorized user; The authorized user uses his private key to decrypt the random number α and its hash value, and performs a hash value verification on α. ​​After the verification passes, the random number α is used to encrypt the hash value, and the hash value is signed with the lock core public key and sent to the lock core security chip; The lock core security chip uses the private key and α decryption to perform hash value verification on the data sent by the authorized user. If the comparison is correct, it means that the user is a legitimate authorized user. The user's password feature data and physical feature data are collected and compared. If the comparison is consistent, the verification is passed.

9. The authentication method according to claim 8, wherein: If any link fails to pass the authentication, the lock core security chip triggers the alarm module to issue a warning, and triggers the video acquisition device to extract data of the continuous physical characteristics of the surrounding environment, and sends an illegal unlocking prompt and the extracted physical characteristic data information to the authorized user's terminal.

10. An electronic lock device constructed using the encryption method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Electronic lock safety system and key distribution method thereof

    CN111815816A

  • Special vehicle electronic key security authentication device and method

    CN116528224A