Information updating method and device, storage medium and electronic device
By using a decryption mechanism that combines a key generated by a cloud server with a reference key from the target device, the biometric information of smart locks can be remotely and securely managed. This overcomes the limitations of traditional smart lock information entry processes and enhances the system's convenience and security.
Patent Information
- Application Number
- CN202411637844.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-15
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2044-11-15
AI Technical Summary
Traditional smart locks limit information entry to physical locations, restricting users' remote management capabilities, increasing inconvenience and time costs, and potentially posing data security risks.
The biological information is encrypted using a first key generated by the cloud server and decrypted using a reference key generated by the target device, enabling remote and secure addition or deletion of biological information, thus avoiding direct input on the target device.
It enables the secure addition or deletion of biometric information across different devices, improving the system's convenience and security, and overcoming the limitations of traditional smart door lock information entry processes.
Smart Images

Figure CN119479116B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of smart home, in particular to an information updating method and device, a storage medium and an electronic device. BACKGROUND
[0002] The progress in the field of smart home has significantly improved the comfort and safety of modern life. As a key component of the home security system, the intelligent door lock realizes efficient and safe access control through biometric identification technology.
[0003] However, the information entry mode of the traditional intelligent door lock has certain limitations, that is, the user must enter the biological information at the physical location of the door lock. This mode limits the user's ability to remotely manage the door lock information. Especially in the case of multiple users or frequent changes in permissions, it is necessary to operate the door lock in person, which undoubtedly increases the inconvenience and time cost of use. At the same time, it may also bring data security risks due to the entry process outdoors.
[0004] At present, there is no effective solution to the problem of strong process limitation of traditional intelligent door lock information entry in the related art.
[0005] Therefore, it is necessary to improve the related art to overcome the defects in the related art. SUMMARY
[0006] The embodiments of the present application provide an information updating method and device, a storage medium and an electronic device to at least solve the problem of strong process limitation of traditional intelligent door lock information entry.
[0007] According to an aspect of an embodiment of the present application, an information updating method is provided. The method includes: sending a first request instruction to a cloud server, and obtaining a first key and a target random number sent by the cloud server in response to the first request instruction, wherein the first request instruction is used to request adding or deleting biological information in a target device, and the first key is a key generated by the cloud server using a first preset algorithm based on the target random number and device information of the target device; processing the obtained target biological information based on the first key to obtain encrypted data, wherein the biological information includes the target biological information; sending a second request instruction to the target device, wherein the second request instruction carries the encrypted data, the target random number, and the first request instruction; the second request instruction is used to instruct the target device to generate a reference key using the first preset algorithm based on the target random number and the device information of the target device, and to obtain the target biological information based on the reference key and the encrypted data, and to add or delete the target biological information in a biological information list of the target device based on the first request instruction.
[0008] In an example embodiment, processing the obtained target biological information based on the first key to obtain encrypted data includes: encrypting the target biological information using the first key to obtain the encrypted data; wherein the target device decrypts the encrypted data based on the reference key to obtain the target biological information.
[0009] In an example embodiment, processing the obtained target biological information based on the first key to obtain encrypted data includes: generating a second key based on the first key and account information of a target account using a second preset algorithm, wherein the target account is an account that sends the first request instruction to the cloud server; encrypting the target biological information using the second key to obtain the encrypted data; wherein the second request instruction also carries the account information of the target account; and the second request instruction is used to instruct the target device to generate the second key based on the reference key and the account information of the target account using the second preset algorithm after generating the reference key, and to decrypt the encrypted data using the second key to obtain the target biological information.
[0010] In an example embodiment, after the target biological information obtained is processed based on the first key to obtain encrypted data, the method further comprises: in the case that the terminal device and the target device do not establish a communication connection, storing the second request instruction to a target storage area of the terminal device, wherein the terminal device has a target application thereon, the target application has a target account logged in thereon, the target application is an application corresponding to the target device, and the target account is an account that sends the first request instruction to the cloud server; and sending a second request instruction to the target device, including: in the case that the terminal device and the target device establish a communication connection, sending the second request instruction to the target device.
[0011] In an example embodiment, after the second request instruction is sent to the target device, the method further comprises: obtaining response information sent by the target device in response to the second request instruction; and in the case that the response information is used to indicate that the target device successfully adds the target biological information or successfully deletes the target biological information in the biological information list, sending a record instruction to the cloud server, wherein the record instruction is used to instruct the cloud server to record target operation information, and the target operation information includes that the target account adds the target biological information or deletes the target biological information in the target device, and the target account is an account that sends the first request instruction to the cloud server.
[0012] In an example embodiment, obtaining the first key and the target random number sent by the cloud server in response to the request instruction comprises: obtaining the first key and the target random number sent by the cloud server in response to the request instruction in the case that the target account is verified to be passed, wherein the target account is an account that sends the first request instruction to the cloud server.
[0013] In an example embodiment, before the target biological information obtained is processed based on the first key to obtain encrypted data, the method further comprises: collecting the target biological information through a terminal device, wherein the terminal device has a target application thereon, the target application has a target account logged in thereon, the target application is an application corresponding to the target device, and the target account is an account that sends the first request instruction to the cloud server; or obtaining the target biological information sent by a specific account, wherein the specific account is an account corresponding to the target application.
[0014] According to another aspect of the embodiments of the present application, an information updating apparatus is further provided, which comprises: a first sending module, configured to send a first request instruction to a cloud server, and acquire a first key and a target random number sent by the cloud server in response to the first request instruction, wherein the first request instruction is used to request adding or deleting biological information in a target device, and the first key is a key generated by the cloud server using a first preset algorithm according to the target random number and device information of the target device; a processing module, configured to process the acquired target biological information based on the first key to obtain encrypted data, wherein the biological information comprises the target biological information; and a second sending module, configured to send a second request instruction to the target device, wherein the second request instruction carries the encrypted data, the target random number and the first request instruction, and the second request instruction is used to instruct the target device to generate a reference key using the first preset algorithm according to the target random number and the device information of the target device, and obtain the target biological information based on the reference key and the encrypted data, and add or delete the target biological information in a biological information list of the target device based on the first request instruction.
[0015] According to still another aspect of the embodiments of the present application, a computer readable storage medium is further provided, which stores a computer program, wherein the computer program is configured to execute the information updating method when running.
[0016] According to still another aspect of the embodiments of the present application, an electronic apparatus is further provided, which comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor executes the information updating method through the computer program.
[0017] According to still another aspect of the embodiments of the present application, a computer program product is further provided, which comprises a computer program, and the computer program executes the information updating method when executed by a processor.
[0018] According to the embodiments of the present application, the target biological information is processed by acquiring the first key generated by the cloud server to obtain encrypted data, the encrypted data is sent to the target device, the target device is instructed to obtain the target biological information based on the reference key generated by the target device and the encrypted data, and the obtained target biological information is added or deleted in the biological list of the target device, so that the biological information is safely added or deleted between different devices by combining the operation instruction with the biological information encryption processing, the biological information can only be input on the target device is avoided, and the problem that the process of inputting information of the traditional intelligent door lock is limited is solved. BRIEF DESCRIPTION OF DRAWINGS
[0019] The accompanying drawings, which are incorporated herein and constitute part of this specification, illustrate embodiments consistent with the application and serve to explain the principles of the application, in which, by way of illustration, a number of embodiments are shown.
[0020] In order to more clearly illustrate the technical solutions of the embodiments of the present application or the prior art, the accompanying drawings required by the embodiments or prior art description will be briefly introduced as follows. Obviously, those skilled in the art can obtain other drawings according to these drawings without any creative effort.
[0021] Figure 1 Fig. 1 is a schematic diagram of a hardware environment of an information updating method according to an embodiment of the present application;
[0022] Figure 2 Fig. 2 is a flowchart of an information updating method according to an embodiment of the present application;
[0023] Figure 3 Fig. 3 is a timing diagram of an optional information updating method according to an embodiment of the present application;
[0024] Figure 4 Fig. 4 is a structural block diagram of an information updating device according to an embodiment of the present application;
[0025] Figure 5 Fig. 5 is a structural schematic diagram of an optional electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0026] In order to make the technical personnel in the art better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without any creative effort should belong to the scope of protection of the present application.
[0027] It should be noted that the terms "first", "second", and the like in the specification and claims of the present application and the above-described drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily have to include only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to the process, method, product or device.
[0028] According to an aspect of the embodiments of the present application, an information updating method is provided. The information updating method is widely applied to smart home, smart home, smart home device ecology, intelligence house ecology and other whole-house intelligent digital control application scenarios. Optionally, in the embodiments, the information updating method can be applied to the hardware environment composed of a terminal device 102 and a server 104 as shown in the figure. Figure 1 As shown in the figure, the server 104 is connected with the terminal device 102 through a network, which can be used to provide services (such as application services, etc.) for the terminal or the client installed on the terminal, a database can be set on the server or independently of the server, which is used to provide data storage services for the server 104, cloud computing and / or edge computing services can be configured on the server or independently of the server, which is used to provide data operation services for the server 104. Figure 1 As shown in the figure, the server 104 is connected with the terminal device 102 through a network, which can be used to provide services (such as application services, etc.) for the terminal or the client installed on the terminal, a database can be set on the server or independently of the server, which is used to provide data storage services for the server 104, cloud computing and / or edge computing services can be configured on the server or independently of the server, which is used to provide data operation services for the server 104.
[0029] The network can include but is not limited to at least one of the following: wired network, wireless network. The wired network can include but is not limited to at least one of the following: wide area network, metropolitan area network, local area network. The wireless network can include but is not limited to at least one of the following: WIFI (Wireless Fidelity), Bluetooth. The terminal device 102 can not be limited to PC, mobile phone, tablet computer, smart air conditioner, smart oven, smart refrigerator, smart oven, smart oven, smart washing machine, smart water heater, smart washing equipment, smart dishwasher, smart projection equipment, smart television, smart clothesline, smart curtain, smart audio and video, smart socket, smart sound, smart sound box, smart fresh air equipment, smart kitchen and bathroom equipment, smart bathroom equipment, smart window cleaning robot, smart mopping robot, smart air purification equipment, smart steamer, smart microwave oven, smart kitchen treasure, smart purifier, smart water dispenser, smart door lock, etc.
[0030] In order to solve the above problems, in the embodiments, an information updating method is provided, which includes but is not limited to being applied to whole-house intelligent digital control application scenarios, Figure 2 is a flow chart of an information updating method according to an embodiment of the present application, the execution subject is a terminal device, and the flow includes the following steps S202-S206:
[0031] Step S202: a first request instruction is sent to a cloud server, and a first key and a target random number sent by the cloud server in response to the first request instruction are obtained, wherein the first request instruction is used to request to add or delete biological information in a target device, and the first key is a key generated by the cloud server using a first preset algorithm according to the target random number and device information of the target device.
[0032] Optionally, the biological information includes, but is not limited to, fingerprint information, face information, iris information, voiceprint information, and palm vein information of the user.
[0033] Optionally, the target device includes, but is not limited to, a smart door lock.
[0034] Optionally, the cloud server generates a unique first key bound to the device by using a first preset algorithm based on the target random number and device information such as a device identifier (ID), a type of the device, and a serial number of the device, wherein the first preset algorithm includes, but is not limited to, a hash algorithm, a key derivation function based on a hash algorithm, and a public key encryption algorithm.
[0035] It should be noted that the first preset algorithm can be one algorithm or a combination of multiple algorithms.
[0036] Optionally, as shown in Figure 3 the user sends a first request instruction to the cloud server through a target application in the terminal device (for example, a target application corresponding to the target device in a mobile phone) to request to add biological information (fingerprint, face, etc.) or delete biological information; after receiving the request, the cloud server generates multiple random numbers, randomly selects one of the multiple random numbers as a target random number, and uses the target random number and specific device information of the target device to generate a first key by using a first preset algorithm to ensure the uniqueness and security of the first key, wherein the target random number can increase the uncertainty and difficulty in the communication process and prevent the communication content from being predicted or replayed.
[0037] Step S204: processing the obtained target biological information based on the first key to obtain encrypted data, wherein the biological information includes the target biological information.
[0038] Step S206: sending a second request instruction to the target device, wherein the second request instruction carries the encrypted data, the target random number, and the first request instruction; the second request instruction is used to instruct the target device to generate a reference key according to the target random number and device information of the target device by using the first preset algorithm, and obtain the target biological information based on the reference key and the encrypted data, and add or delete the target biological information in a biological information list of the target device based on the first request instruction.
[0039] Optionally, as shown in Figure 3As shown, after obtaining the target biological information, the target device checks the format of the target biological information, determines whether the format of the target biological information is consistent with the data format in the biological information list of the target device, and in the case where the format of the target biological information is consistent with the data format in the biological information list of the target device, adds or deletes the target biological information in the biological information list of the target device based on the first request instruction.
[0040] It should be noted that the generation and use of the first key ensure that the encryption and decryption process of the target biological information is only completed among the three trusted endpoints (terminal application, cloud server and target device), avoiding data leakage of intermediate links; the introduction of the target random number increases the uncertainty of the system and the difficulty of attack, improving the security of communication; through the cloud server as an intermediary, the terminal device can remotely and safely manage the biological information of the target device without the user of the terminal device personally operating at the local of the target device, greatly improving the convenience and overall security of the system.
[0041] The above steps process the target biological information by obtaining the first key generated by the cloud server, obtain encrypted data, send the encrypted data to the target device, instruct the target device to obtain the target biological information based on the reference key generated by the target device and the encrypted data, and add or delete the obtained target biological information in the biological list of the target device. By combining the operation instruction with the biological information encryption processing, the biological information is safely added or deleted between different devices, avoiding the entry of biological information only on the target device, thereby solving the problem of strong process limitation of traditional intelligent door lock information entry.
[0042] In one exemplary embodiment, the target biological information obtained based on the first key is processed to obtain encrypted data, which can be achieved by the following steps: using the first key to encrypt the target biological information to obtain the encrypted data; wherein the target device decrypts the encrypted data based on the reference key to obtain the target biological information.
[0043] Alternatively, the terminal device can directly encrypt the obtained target biological information using the first key. When the target device obtains the second request instruction, the reference key is generated using the first preset algorithm based on the target random number carried by the second request instruction and the device information (the same as the device information used by the cloud server to generate the first key) of the target device locally. The reference key is consistent with the first key, so that the target device can decrypt the encrypted data based on the reference key to obtain the target biological information.
[0044] It should be noted that the first preset algorithm is an algorithm agreed by the cloud server and the target device in the pre-setting stage, so the reference key generated by the target device using the first preset algorithm is consistent with the first key generated by the cloud server using the first preset algorithm.
[0045] Optionally, the terminal device encrypts the target biological information using the first key, and the first key is not carried in the second request instruction sent to the target device, ensuring the information security in the transmission process of the encrypted data. Even if the encrypted data is intercepted, the attacker cannot obtain the target biological information without the corresponding first key for decryption, thereby significantly improving the security of remote data transmission.
[0046] In an exemplary embodiment, the target biological information obtained is processed based on the first key to obtain encrypted data, which can be achieved through the following steps S11-S12:
[0047] Step S11: using a second preset algorithm, generating a second key based on the first key and account information of a target account, wherein the target account is an account that sends the first request instruction to the cloud server;
[0048] Optionally, the second preset algorithm includes but is not limited to: symmetric encryption algorithm (such as Advanced Encryption Standard (AES)).
[0049] Optionally, as shown in Figure 3 The terminal device will splice the account information (such as the user's identity) of the target account based on the first key to obtain the second key using the second preset algorithm.
[0050] Step S12: encrypting the target biological information using the second key to obtain the encrypted data; wherein the second request instruction also carries the account information of the target account; the second request instruction is used to instruct the target device to generate the second key based on the reference key and the account information of the target account using the second preset algorithm after generating the reference key, and to decrypt the encrypted data using the second key to obtain the target biological information.
[0051] It should be noted that encrypting the target biological information using the second key is similar to adding an additional security layer to the target biological information. Even if the first key is leaked, the attacker cannot generate the second key without the correct account information of the target account, which increases the difficulty of the attacker to decrypt the encrypted data.
[0052] Optionally, the second request instruction also carries the first key, as shown in Figure 3 As shown, after receiving the second request instruction, the target device first generates a reference key according to the target random number and the device information of the target device using the first preset algorithm, and verifies whether the reference key is consistent with the first key carried in the second request instruction. If consistent, the target device generates a second key based on the reference key and the account information of the target account using the second preset algorithm, and finally uses the second key to decrypt the encrypted data to obtain the target biological information.
[0053] It should be noted that through the generation and use of the second key, it is ensured that only users with correct account information can operate the smart door lock, enhancing the authority control of remote management; the double encryption mechanism encrypts the biological information on the one hand and the operation instruction on the other hand, ensuring the security of data and instructions; through verifying the consistency of the first key and the reference key and using the second key to decrypt, it is ensured that the operation is accurately executed and the data transmission is safe.
[0054] In an exemplary embodiment, after obtaining the encrypted data by processing the target biological information based on the first key, the method further includes the following steps: storing the second request instruction to the target storage area of the terminal device in the case that the terminal device and the target device do not establish a communication connection, wherein the terminal device has a target application thereon, the target account is logged on the target application, and the target application is the application corresponding to the target device, and the target account is the account that sends the first request instruction to the cloud server.
[0055] In an exemplary embodiment, sending the second request instruction to the target device includes the following steps: sending the second request instruction to the target device in the case that the terminal device and the target device establish a communication connection.
[0056] Optionally, as shown in Figure 3 In the case that the terminal device does not establish a communication connection with the target device, the terminal device can locally store the encrypted target biological information and related instructions (including the first key and the target account information). Once the target device (smart door lock) and the terminal device (such as a user's mobile phone) reestablish a communication connection (for example, through Bluetooth or a local area network), the terminal device can send the second request instruction to the target device to request to perform the corresponding biological information management operation.
[0057] It should be noted that through the above steps, the terminal device and the smart door lock can still save the first key and the request instruction without establishing a communication connection, maintaining the availability and security of remote information entry operation, and the above steps can also enable the terminal device to quickly synchronize and process biological information data after restoring the communication connection with the target device even in the scenario of temporarily losing communication capability, ensuring that the remote management of the smart door lock will not be affected by unstable network connection.
[0058] In one exemplary embodiment, after sending the second request instruction to the target device, the method further includes the following steps S21-S22:
[0059] Step S21: obtaining response information sent by the target device in response to the second request instruction;
[0060] Optionally, as shown in the figure, the target device will send response information in response to the second request instruction, and the response information is used to indicate that the target device successfully adds the target biological information in the biological information list, or successfully deletes the target biological information, or fails to add the target biological information, or fails to delete the target biological information. Figure 3
[0061] It should be noted that the terminal device obtains the response information of the target device (smart door lock) in response to the second request instruction, which can confirm whether the addition or deletion operation of the biological information is successfully executed in real time. This provides a timely feedback mechanism for the user and increases the transparency of the operation.
[0062] Step S22: in the case where the response information is used to indicate that the target device successfully adds the target biological information in the biological information list or successfully deletes the target biological information, sending a record instruction to the cloud server, wherein the record instruction is used to instruct the cloud server to record target operation information, and the target operation information includes that the target account adds the target biological information or deletes the target biological information in the target device, and the target account is the account that sends the first request instruction to the cloud server.
[0063] Optionally, in the case where the response information is used to indicate that the target device fails to add the target biological information in the biological information list or fails to delete the target biological information, the terminal device deletes the target biological information locally, sends a prompt information, and the prompt information is used to prompt that the target device fails to add the target biological information in the biological information list or fails to delete the target biological information, and reacquires the target biological information.
[0064] Optionally, the terminal device sends a record instruction to the cloud server within a preset time (e.g., 48 hours) after obtaining the response information.
[0065] It should be noted that by sending the record instruction to the cloud server, the consistency of data between the cloud server and the target device is ensured, and the cloud server can record specific information of each operation, including the initiating account (target account), target device, operation type (adding or deleting biological information), and operation time. These records play an important role in tracking operation history, auditing security events, and restoring system state when needed.
[0066] In an exemplary embodiment, obtaining the first key and the target random number sent by the cloud server in response to the request instruction includes the following steps: obtaining the first key and the target random number sent by the cloud server in response to the request instruction in the case that the target account is verified to be passed, wherein the target account is the account that sends the first request instruction to the cloud server.
[0067] Optionally, as shown in Figure 3 Before obtaining the first key and the target random number sent by the cloud server in response to the request instruction, the terminal device verifies the authority of the target account by the account information of the target account (such as the account identifier of the target account), ensuring that only authorized target accounts can request to remotely add or delete target biological information on the target device. Only in the case that the target account is verified to be passed, the cloud server will send the first key and the target random number, thereby increasing the security of the system.
[0068] Optionally, in the case that the target account is verified to be not passed, a rejection prompt information is sent, which is used to prompt that the target account currently logged in the terminal device is not authorized.
[0069] It should be noted that the above steps enhance the encryption security of remote operation and improve the overall security of the system.
[0070] In an exemplary embodiment, before processing the obtained target biological information based on the first key to obtain encrypted data, the method further includes the following steps S31 or S32:
[0071] Step S31: collecting the target biological information by the terminal device, wherein the terminal device has a target application, the target account is logged in the target application, the target application is the application corresponding to the target device, and the target account is the account that sends the first request instruction to the cloud server.
[0072] Optionally, through step S31, the user installs and logs in a target application on a terminal device (such as a smart phone), the application is an official or matching application of the target device (such as a smart door lock) and is used for managing the biometric information of the door lock, the terminal device is directly involved in the biometric information collection process and provides an intuitive operation interface for the user, and the terminal device is integrated with a biometric information collection module (such as a fingerprint sensor or a facial recognition camera) and is used for capturing biometric feature data of the user.
[0073] Step S32: obtaining the target biometric information sent by a specific account, wherein the specific account is an account corresponding to the target application.
[0074] Optionally, through step S32, other users can send the biometric information to the target account after the specific account collects the biometric information, and the terminal device logged in the target account can send the target biometric information sent by the specific account to the target device. For example, in a scenario of sharing the access permission of a smart door lock among family members, one person can safely transmit the biometric information to the accounts of other family members after collecting the biometric information, and each member does not need to log in the specific account to collect the biometric information. Through the manner of sending the biometric information by the specific account, the convenience of updating or modifying the biometric information is improved.
[0075] Through the above two manners, not only a user-friendly biometric information collection and management process is provided, but also the security and privacy protection of the biometric information are ensured, and an efficient and safe remote operation experience is provided for the user.
[0076] In an exemplary embodiment, the method further includes the following steps: supervising a record log of the cloud server in real time, when the number of target operation information recorded by the record log exceeds a preset number in a preset time length, sending an alarm information, wherein the record log is used for storing a plurality of target operation information recorded by the cloud server, and the alarm information is used for alarming that the target account has a security risk.
[0077] Optionally, for example, within thirty minutes, the terminal device sends encrypted data including the target biometric information to the target device for ten times, and the target device successfully adds the target biometric information each time, the cloud server records the operation successfully, and if the terminal device sends encrypted data to the target device for the eleventh time within the thirty minutes, the terminal device will send an alarm information.
[0078] Obviously, the above-described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. In order to better understand the above method, the above process is described in combination with the embodiments, but is not used to limit the technical solutions of the embodiments of the present application. Optionally, in the case that the terminal device is a smart phone and the target device is a smart door lock:
[0079] When the corresponding application in the mobile phone, the user has bound the smart door lock (wireless network door lock or Bluetooth door lock):
[0080] I. Initiate editing request: the mobile phone application initiates user editing request, including adding, deleting, modifying, etc.
[0081] II. Information collection: if it is adding, modifying, etc., the user information (fingerprint / facial) needs to be collected through the smart device, and the information is saved according to the user's grouping editing, etc. The user information is removed.
[0082] III. Data transmission: the edited information is stored after data encryption, if the mobile phone application and the smart door lock have established communication (remote / Bluetooth), the user decides whether to synchronize the data to the smart door lock immediately, and if the communication is not established, the user is prompted to synchronize the data to the smart door lock when the mobile phone application and the smart door lock are connected.
[0083] IV. Information storage and verification: after the smart door lock receives the fingerprint or face information, it is decrypted and stored again according to the rules, and when verifying, the smart door lock processes the user information (face / fingerprint) trying to unlock according to the rules and compares it with the stored information to decide whether to unlock.
[0084] Specifically, as shown in Figure 3 :
[0085] 1. The application end requests to add / edit users, carrying user identification and other information;
[0086] 2. The cloud server verifies the user's rights according to the user identification;
[0087] 3. The cloud server generates a random number and confirms the target random number, generates an encryption key1 (the first key mentioned above) according to the device factory information and the target random number;
[0088] 4. If the user has no permission, return denied;
[0089] 5. If the user has permission, return allowed, and carry the target random number (random1) and the encryption key1;
[0090] 6. The application end encrypts the key1, concatenates the user identification and other information, performs secondary encryption, and calculates a new encryption key2 (the second key mentioned above);
[0091] 7. The application end initiates user biological information collection and assembles data in a special format, and uses the encryption key2 to perform symmetric encryption on the data;
[0092] 8、In the case of not establishing a communication connection with the smart door lock, the user terminal saves the current collected user information to the local, including the target random number random1, the encryption key1, the encrypted data, etc.
[0093] 9、The subsequent application terminal establishes a communication connection with the smart door lock and starts to execute the subsequent steps.
[0094] 10、The application terminal reads the user information.
[0095] 11、The application terminal transmits the encrypted data, the target random number, and the encryption key1 to the device terminal (the smart door lock).
[0096] 12、The device terminal generates the encryption key according to the encryption method of the cloud terminal in advance through the target random number and the factory information and performs verification.
[0097] 13、If the device terminal encryption key1 verification fails, the device terminal returns a failure information.
[0098] 14、In the case of passing the verification, the device terminal calculates the encryption key2 through the encryption key1 and the agreed encryption method and decrypts the transmitted encrypted data.
[0099] 15、The device terminal decrypts the data, performs unpacking processing, verifies the format, and performs the corresponding addition, deletion, and modification logic according to the data content.
[0100] 16、The device terminal returns the user addition success information.
[0101] 17、The application terminal prompts the user that the addition is successful, waits for the device to synchronize, and the effective period is 48 hours. If the device is not synchronized within 48 hours, the addition will be withdrawn.
[0102] 18、The application terminal edits the user information (including the operation information such as adding biological information) and synchronizes the cloud server (does not include the collected user biological information).
[0103] 19、The cloud server records the operation as unsynchronized. If the synchronization result is not received within 48 hours, the data of this time will be cleaned up.
[0104] 20、The result is synchronized to the cloud server within 48 hours.
[0105] It should be noted that the present application also has the following advantages: the user data is directly collected from the security device, and the collection and synchronization mode through the medium is modified. The user can operate more conveniently and is no longer limited to personally operating in front of the door lock. In the case of not connecting the device, the user can also synchronize afterwards by one key. Moreover, the data is subjected to multiple security verifications, and the security can be guaranteed.
[0106] Those skilled in the art can clearly understand that the method according to the above-mentioned embodiments can be realized by means of software on a general hardware platform as necessary, and of course, can also be realized by hardware, but in many cases, the former is a better implementation. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as a ROM / RAM, a magnetic disk, or an optical disk) and includes a plurality of instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device) to execute the methods of the various embodiments of the present application.
[0107] In the present embodiment, an information updating apparatus is also provided, which is used to implement the above-mentioned embodiments and preferred embodiments, and will not be described again. As used below, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, hardware, or a combination of software and hardware can also be implemented and conceived.
[0108] Figure 4 is a structural block diagram of an information updating apparatus according to an embodiment of the present application, which comprises:
[0109] A first sending module 42 is configured to send a first request instruction to a cloud server and acquire a first key and a target random number sent by the cloud server in response to the first request instruction, wherein the first request instruction is used to request to add or delete biological information in a target device, and the first key is a key generated by the cloud server using a first preset algorithm according to the target random number and device information of the target device;
[0110] A processing module 44 is configured to process the acquired target biological information based on the first key to obtain encrypted data, wherein the biological information includes the target biological information;
[0111] A second sending module 46 is configured to send a second request instruction to the target device, wherein the second request instruction carries the encrypted data, the target random number, and the first request instruction; the second request instruction is used to instruct the target device to generate a reference key using the first preset algorithm according to the target random number and the device information of the target device, and to obtain the target biological information based on the reference key and the encrypted data, and to add or delete the target biological information in a biological information list of the target device based on the first request instruction.
[0112] The device processes the target biological information by obtaining the first key generated by the cloud server, obtains encrypted data, sends the encrypted data to the target device, instructs the target device to obtain the target biological information based on the reference key generated by the target device and the encrypted data, and adds or deletes the obtained target biological information in the biological list of the target device. By combining the operation instruction with the biological information encryption processing, the biological information is safely added or deleted between different devices, avoiding the entry of biological information only on the target device, and solving the problem of strong process limitation of traditional intelligent door lock information entry.
[0113] In an exemplary embodiment, the processing module 44 is further configured to encrypt the target biological information using the first key to obtain the encrypted data; and the target device decrypts the encrypted data using the reference key to obtain the target biological information.
[0114] In an exemplary embodiment, the processing module 44 is further configured to generate a second key using a second preset algorithm based on the first key and account information of a target account, wherein the target account is an account that sends the first request instruction to the cloud server; encrypt the target biological information using the second key to obtain the encrypted data; wherein the second request instruction further carries the account information of the target account; and the second request instruction is used to instruct the target device to generate the second key using the second preset algorithm based on the reference key and the account information of the target account after generating the reference key, and decrypt the encrypted data using the second key to obtain the target biological information.
[0115] In an exemplary embodiment, the device further comprises a storage module configured to, after processing the obtained target biological information based on the first key to obtain encrypted data, store the second request instruction to a target storage area of a terminal device in a case where the terminal device and the target device do not establish a communication connection, wherein the terminal device has a target application, the target application has a target account logged in, the target application is an application corresponding to the target device, and the target account is an account that sends the first request instruction to the cloud server; and the second sending module 46 is further configured to send the second request instruction to the target device in a case where the terminal device and the target device establish a communication connection.
[0116] In an example embodiment, the second sending module 46 is further configured to acquire response information sent by the target device in response to the second request instruction; and the apparatus further includes a sending module configured to send a record instruction to the cloud server in a case where the response information indicates that the target device successfully adds the target biological information or successfully deletes the target biological information from the biological information list, wherein the record instruction is used to instruct the cloud server to record target operation information, and the target operation information includes that the target biological information is added or deleted in the target device by a target account, and the target account is an account that sends the first request instruction to the cloud server.
[0117] In an example embodiment, the first sending module 42 is further configured to acquire a first key and a target random number sent by the cloud server in response to the request instruction in a case where the target account is verified to be valid, wherein the target account is an account that sends the first request instruction to the cloud server.
[0118] In an example embodiment, the apparatus further includes an acquisition module configured to acquire the target biological information by a terminal device, wherein the terminal device has a target application thereon, the target application has a target account logged in, the target application is an application corresponding to the target device, and the target account is an account that sends the first request instruction to the cloud server; or acquire the target biological information sent by a specific account, wherein the specific account is an account corresponding to the target application.
[0119] Embodiments of the present application also provide a computer readable storage medium having a computer program stored therein, wherein the computer program is configured to execute the steps in any of the method embodiments when running.
[0120] Optionally, in the present embodiment, the storage medium can be configured to store a computer program for executing the following steps:
[0121] S1, sending a first request instruction to a cloud server and acquiring a first key and a target random number sent by the cloud server in response to the first request instruction, wherein the first request instruction is used to request to add or delete biological information in a target device, and the first key is a key generated by the cloud server using a first preset algorithm based on the target random number and device information of the target device;
[0122] S2, processing the acquired target biological information based on the first key to obtain encrypted data, wherein the biological information includes the target biological information;
[0123] S3, sending a second request instruction to the target device, wherein the second request instruction carries the encrypted data, the target random number and the first request instruction; the second request instruction is used to instruct the target device to generate a reference key according to the target random number and device information of the target device by using the first preset algorithm, and obtain the target biological information based on the reference key and the encrypted data, and add or delete the target biological information in a biological information list of the target device based on the first request instruction.
[0124] In an example embodiment, the computer readable storage medium described above can include, but is not limited to, a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store computer programs.
[0125] The specific examples in the embodiment can refer to the examples described in the above embodiments and example embodiments, and the embodiment will not be described here.
[0126] The embodiment of the present application also provides an electronic device, as shown in the figure, which includes a memory 502 and a processor 504, the memory 502 stores a computer program, and the processor 504 is configured to execute the steps in any of the above method embodiments by the computer program. Figure 5 The processor 504 can be configured to execute the steps in any of the above method embodiments by the computer program.
[0127] Optionally, in the embodiment, the processor 504 can be configured to execute the following steps by the computer program:
[0128] S1, sending a first request instruction to a cloud server and obtaining a first key and a target random number sent by the cloud server in response to the first request instruction, wherein the first request instruction is used to request to add or delete biological information in a target device, and the first key is a key generated by the cloud server according to the target random number and device information of the target device by using a first preset algorithm;
[0129] S2, processing the obtained target biological information based on the first key to obtain encrypted data, wherein the biological information includes the target biological information;
[0130] S3, sending a second request instruction to the target device, wherein the second request instruction carries the encrypted data, the target random number and the first request instruction; the second request instruction is used to instruct the target device to generate a reference key according to the target random number and device information of the target device by using the first preset algorithm, and obtain the target biological information based on the reference key and the encrypted data, and add or delete the target biological information in a biological information list of the target device based on the first request instruction.
[0131] The specific examples in the embodiments can refer to the examples described in the above embodiments and exemplary embodiments, and will not be repeated here.
[0132] Optionally, those skilled in the art can understand that, Figure 5 The structure shown is only schematic, Figure 5 and does not limit the structure of the electronic device. For example, the electronic device can further include more or less components (such as a network interface, etc.) than those shown, or have a different configuration from that shown. Figure 5 and does not limit the structure of the electronic device. For example, the electronic device can further include more or less components (such as a network interface, etc.) than those shown, or have a different configuration from that shown. Figure 5 and does not limit the structure of the electronic device. For example, the electronic device can further include more or less components (such as a network interface, etc.) than those shown, or have a different configuration from that shown.
[0133] The memory 502 can be used to store software programs and modules, such as program instructions / modules corresponding to the information updating method and device in the embodiments of the present application. The processor 504 performs various functional applications and data processing by running the software programs and modules stored in the memory 502, that is, implements the information updating method described above. The memory 502 can include a high-speed random access memory, and can further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 502 can further include a memory remotely arranged with respect to the processor 504, which can be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof. The memory 502 can be used to store, but is not limited to, system configuration files and other information. As an example, as shown in Figure 5 The memory 502 can be used to store software programs and modules, such as program instructions / modules corresponding to the information updating method and device in the embodiments of the present application. The processor 504 performs various functional applications and data processing by running the software programs and modules stored in the memory 502, that is, implements the information updating method described above. The memory 502 can include a high-speed random access memory, and can further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 502 can further include a memory remotely arranged with respect to the processor 504, which can be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof. The memory 502 can be used to store, but is not limited to, system configuration files and other information. As an example, as shown in
[0134] Optionally, the transmission device 506 is configured to receive or send data via a network. Examples of the network can include a wired network and a wireless network. In one example, the transmission device 506 includes a network interface controller (NIC) which can be connected to other network devices and routers through a network cable to communicate with the Internet or a local area network. In one example, the transmission device 506 is a radio frequency (RF) module which is configured to communicate with the Internet in a wireless manner.
[0135] In addition, the electronic device further includes a display 508 and a connection bus 510 configured to connect various module components in the electronic device.
[0136] Embodiments of the present application also provide a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps in any of the method embodiments described above are implemented.
[0137] Embodiments of the present application also provide another computer program product, which includes a non-volatile computer readable storage medium. The non-volatile computer readable storage medium stores a computer program. When the computer program is executed by a processor, the steps in any of the method embodiments described above are implemented.
[0138] Embodiments of the present application also provide a computer program, which includes computer instructions stored in a computer readable storage medium. A processor of a computer device reads the computer instructions from the computer readable storage medium, and executes the computer instructions, so that the computer device performs the steps in any of the method embodiments described above.
[0139] The specific examples in the embodiments can refer to the examples described in the above embodiments and exemplary embodiments, which will not be described here again.
[0140] Obviously, those skilled in the art should understand that the modules or steps of the present application described above can be realized by general computing devices. They can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices. They can be realized by program codes executable by computing devices, so that they can be stored in storage devices and executed by computing devices. In some cases, the steps shown or described can be executed in different orders from here, or they can be manufactured into individual integrated circuit modules, or multiple modules or steps among them can be manufactured into a single integrated circuit module. Thus, the present application is not limited to any particular hardware and software combination.
[0141] The above merely describes the preferred embodiments of the present application, and it should be pointed out that, for those skilled in the art, some improvements and refinements can be made without departing from the principles of the present application, and these improvements and refinements should also be considered as the protection scope of the present application.
Claims
1. A method of information updating, characterized by, The method comprises: sending a first request instruction to a cloud server and obtaining a first key and a target random number sent by the cloud server in response to the first request instruction, wherein the first request instruction is used to request to add or delete biological information in a target device, and the first key is a key generated by the cloud server using a first preset algorithm based on the target random number and device information of the target device; processing the obtained target biological information based on the first key to obtain encrypted data, wherein the biological information includes the target biological information; sending a second request instruction to the target device, wherein the second request instruction carries the encrypted data, the target random number and the first request instruction; the second request instruction is used to instruct the target device to generate a reference key using the first preset algorithm based on the target random number and the device information of the target device, and to obtain the target biological information based on the reference key and the encrypted data, and to add or delete the target biological information in a biological information list of the target device based on the first request instruction.
2. The method of claim 1, wherein, Processing the obtained target biological information based on the first key to obtain encrypted data comprises: encrypting the target biological information using the first key to obtain the encrypted data; wherein the target device decrypts the encrypted data based on the reference key to obtain the target biological information.
3. The method of claim 1, wherein, Processing the obtained target biological information based on the first key to obtain encrypted data comprises: generating a second key based on the first key and account information of a target account using a second preset algorithm, wherein the target account is an account that sends the first request instruction to the cloud server; encrypting the target biological information using the second key to obtain the encrypted data; wherein the second request instruction also carries the account information of the target account; the second request instruction is used to instruct the target device to generate the second key using the second preset algorithm based on the reference key and the account information of the target account after generating the reference key, and to decrypt the encrypted data using the second key to obtain the target biological information.
4. The method of claim 1, wherein after processing the obtained target biological information based on the first key to obtain encrypted data, the method further comprises: in a case where a terminal device and the target device have not established a communication connection, storing the second request instruction to a target storage area of the terminal device, wherein the terminal device has a target application thereon, the target application has a target account logged in thereon, the target application is an application corresponding to the target device, and the target account is an account that sends the first request instruction to the cloud server; and sending the second request instruction to the target device comprises: in a case where the terminal device and the target device have established a communication connection, sending the second request instruction to the target device. 5. The method of claim 1, wherein, After sending the second request instruction to the target device, the method further comprises: obtaining response information sent by the target device in response to the second request instruction; in the case that the response information is used to indicate that the target device successfully adds the target biological information or successfully deletes the target biological information in the biological information list, sending a record instruction to the cloud server, wherein the record instruction is used to instruct the cloud server to record target operation information, and the target operation information comprises that the target biological information is added or deleted by a target account in the target device, and the target account is an account that sends the first request instruction to the cloud server.
6. The method of claim 1, wherein, obtaining the first key and the target random number sent by the cloud server in response to the request instruction comprises: obtaining the first key and the target random number sent by the cloud server in response to the request instruction in the case that the target account is verified to be passed, wherein the target account is an account that sends the first request instruction to the cloud server.
7. The method of claim 1, wherein, Before processing the obtained target biological information based on the first key to obtain encrypted data, the method further comprises: collecting the target biological information through a terminal device, wherein the terminal device has a target application thereon, a target account is logged in the target application, the target application is an application corresponding to the target device, and the target account is an account that sends the first request instruction to the cloud server; or obtaining the target biological information sent by a specific account, wherein the specific account is an account corresponding to the target application.
8. An information updating apparatus characterized by comprising: comprises: a first sending module configured to send a first request instruction to a cloud server and obtain a first key and a target random number sent by the cloud server in response to the first request instruction, wherein the first request instruction is used to request to add or delete biological information in a target device, and the first key is a key generated by the cloud server using a first preset algorithm according to the target random number and device information of the target device; a processing module configured to process target biological information obtained based on the first key to obtain encrypted data, wherein the biological information comprises the target biological information; a second sending module configured to send a second request instruction to the target device, wherein the second request instruction carries the encrypted data, the target random number and the first request instruction; the second request instruction is used to instruct the target device to generate a reference key using the first preset algorithm according to the target random number and the device information of the target device, and to obtain the target biological information based on the reference key and the encrypted data, and to add or delete the target biological information in a biological information list of the target device based on the first request instruction.
9. A computer readable storage medium, characterized in that, The computer-readable storage medium comprises a stored program, wherein the program executes the method of any one of claims 1 to 7 when running. 10.An electronic device comprising a memory and a processor, the electronic device characterized by, The memory stores a computer program, and the processor is configured to execute the method of any one of claims 1 to 7 by using the computer program.
Citation Information
Patent Citations
Method, device and system for updating vehicle electronic key
CN111402464A
Digital key deleting method, device, equipment, system and storage medium
CN115116162A