An intelligent lock multi-modal permission management and record traceability method and system thereof

Through multimodal permission management and big data analysis technology, smart locks can support multiple identity recognition modes, record and trace lock unlock information, and identify security risks, solving the problems of single and traceability management of existing smart lock permissions, improving security and management efficiency.

CN119728301BActive Publication Date: 2025-06-20深圳市鑫泓佳电子有限公司 +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510221059.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-06-20
Estimated Expiration
2045-02-27

AI Technical Summary

Technical Problem

The existing smart lock has a single permission management method, which is difficult to meet the diverse use needs of modern families. In terms of permission recording and traceability, there are problems such as incomplete records and difficulty in traceability, and it is impossible to accurately identify security risks and abnormal behaviors.

Method used

It adopts a multimodal permission management method, supports multiple identity recognition modes, such as fingerprints, faces, iris, voiceprints, etc., and uses the management APP to enter and encrypt the identity identification information and upload it to smart locks, cloud servers and edge computing nodes. Smart locks automatically record each unlocking information and synchronize it to the cloud in real time. Big data analysis technology is used to build a user behavior model to identify potential security risks and abnormal behaviors.

Benefits of technology

It improves the flexibility of permission management, meets the diversified usage needs of modern families, significantly improves the efficiency and accuracy of problem investigation, and enhances the security and stability of smart locks in complex environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728301B_ABST
    Figure CN119728301B_ABST
Patent Text Reader

Abstract

The present invention provides a multi-modal permission management and record traceability method and system for an intelligent lock, comprising the following steps: Step 1, obtain an intelligent lock, perform initialization settings on the intelligent lock, connect it to a home local area network, and establish a secure communication connection with a cloud server. The present invention greatly improves the flexibility of permission management by supporting multiple identity recognition modes, providing multiple permission types, and also enabling the formulation of permission type combination strategies, meeting the diverse usage needs of modern families; by automatically recording each unlocking information and constructing a user behavior model in combination with big data analysis technology, it can quickly and accurately identify potential security risks and abnormal behavior patterns, improving the efficiency and accuracy of problem troubleshooting; when the intelligent lock faces complex environments or special situations, it will quickly and automatically switch to an emergency mode, effectively enhancing the system's ability to resist malicious attacks and enhancing the security and stability of the intelligent lock in complex environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of smart locks, and in particular to a smart lock multimodal authority management and record tracing method and system thereof. Background Art

[0002] At a time when technology is rapidly iterating, smart home technology is like a rising star, sweeping the entire home furnishing field with its innovation and convenience. From smart air conditioners that can automatically adjust the temperature according to the environment, to smart home appliances that can be remotely controlled, to smart sweeping robots that can automatically clean, various smart home products are constantly being innovated, bringing unprecedented comfort and convenience to people's lives. In the smart home ecosystem, smart locks, as a key line of defense and important entrance for home security, are gradually becoming the standard of modern families with their unique advantages. However, although smart locks have been widely used in the market, there are still many problems that need to be solved in the current smart lock technology.

[0003] 1. The traditional smart lock permission management method is relatively simple, usually only supporting a few unlocking methods such as passwords and fingerprints, and the permission allocation and management are not flexible enough to meet the diverse usage needs of modern families;

[0004] Second, in terms of authority recording and tracing, the existing technology has problems such as inadequate recording and difficulty in tracing, and it is impossible to accurately record the specific circumstances of each unlocking. When security problems occur, it is difficult to quickly and accurately identify the cause;

[0005] 3. The security and stability of existing smart locks need to be further improved when facing complex environments or special situations, such as network failures, malicious attacks, etc.

[0006] To this end, a smart lock multimodal permission management and record tracing method and system are proposed. Summary of the invention

[0007] In view of this, the embodiments of the present invention hope to provide a smart lock multimodal permission management and record tracing method and system thereof to solve or alleviate the technical problems existing in the prior art and at least provide a beneficial option.

[0008] In order to solve the above technical problems, a technical solution adopted by the present application is: a smart lock multimodal permission management and record tracing method, comprising the following steps:

[0009] Step 1: Get a smart lock, initialize the smart lock, connect it to the home LAN, and establish a secure communication connection with the cloud server;

[0010] Step 2: Through the management APP supporting the intelligent lock, after entering various identity recognition information and encrypting it, upload and store it separately in the local storage module of the intelligent lock, the cloud server, and the edge computing node;

[0011] Step 3: Based on the management APP, assign permission types to different users and formulate permission type combination strategies;

[0012] Step 4: When the user performs an unlocking operation, the intelligent lock obtains the corresponding recognition information according to the selected identity recognition method by the user, and performs a preliminary match in the local storage module. If the local match fails, send a request to the cloud server and the edge computing node through a secure channel for remote match verification;

[0013] Step 5: The intelligent lock automatically records the unlocking information of each unlocking operation and stores it in the local storage module of the intelligent lock, and at the same time synchronizes it to the cloud server and the edge computing node in real time;

[0014] Step 6: Obtain the unlocking records from the cloud server or the edge computing node through the management APP, and use big data analysis technology to conduct in-depth mining and analysis to identify potential security risks and abnormal behavior patterns;

[0015] Step 7: When the intelligent lock encounters a network failure, a system failure, or is under a malicious attack, automatically switch to the emergency mode, and perform a limited number of unlocking operations in the emergency mode according to the locally stored permission information and the backup identity recognition method.

[0016] Preferably as a further improvement of the present technical solution, in Step 6, the big data analysis technology uses machine learning algorithms to train the historical unlocking records and construct a user behavior model;

[0017] The method for constructing the user behavior model includes the following steps:

[0018] Step 601: Obtain historical unlocking record data from the cloud server and the edge computing node, and preprocess the historical unlocking record data;

[0019] Step 602: Extract valuable feature data from the preprocessed historical unlocking record data, and divide the feature data into a training set, a validation set, and a test set;

[0020] Step 603: Select decision tree, support vector machine, or deep learning neural network in machine learning algorithms as the basic architecture of the model;

[0021] Step 604: Use the training set and the validation set as inputs, and normal behavior and abnormal behavior as output labels to train the model;

[0022] Step 605: Use the test data set to evaluate the trained model, calculate the accuracy rate, recall rate, and F1 value, and optimize and adjust the model according to the evaluation results.

[0023] Preferably, as a further aspect of the present technical solution, in step four, during the process of performing remote matching verification, a multi-factor authentication mechanism is adopted, and the specific steps are as follows:

[0024] Step 401: By analyzing the user's past unlocking time, unlocking frequency, and commonly used identity recognition methods, establish the user behavior pattern characteristics and obtain the user's historical behavior pattern.

[0025] Step 402: Collaborate with the positioning function of the user device to obtain the user's current geographical location information.

[0026] Step 403: By collecting the hardware information and software information of the device, obtain the device fingerprint information of the user operating the device.

[0027] Step 404: Combine the historical behavior pattern, geographical location information, and device fingerprint information with the identity recognition information, and make a comprehensive judgment according to the preset rules and algorithms.

[0028] Step 405: If all verification conditions are passed, the intelligent lock performs the unlocking operation; if the verification fails, the unlocking is refused, and the detailed information of this abnormal unlocking attempt is recorded.

[0029] Preferably, as a further aspect of the present technical solution, in step one, the intelligent lock supports multiple identity recognition modes, and the identity recognition modes include fingerprint recognition, face recognition, iris recognition, voiceprint recognition, password input, Bluetooth unlocking, NFC card unlocking, and card swiping unlocking; the secure communication connection uses the encryption protocols SSL or TLS.

[0030] Preferably, as a further aspect of the present technical solution, in step five, the unlocking information includes the unlocking time, the identity recognition method of the unlocking user, the identity information, whether the unlocking is successful, the environmental parameters around the intelligent lock during unlocking, and the operation behavior trajectory of the user.

[0031] Preferably, as a further aspect of the present technical solution, in step three, the permission types include permanent permission, temporary permission, periodic permission, and specific scenario permission; the permission type combination strategy includes the combination of multiple identity recognition methods, the combination of different permission types, and the usage restrictions of different identity recognition methods under different permission types.

[0032] As a further preferred solution of the present technical solution, in step two, the identity recognition information includes fingerprint recognition information, facial recognition information, voiceprint recognition information, and iris recognition information; the encryption process uses the Advanced Encryption Standard algorithm to encrypt the identity recognition information, and different keys are used to encrypt the information of different users.

[0033] To solve the above technical problems, another technical solution adopted by this application is: an intelligent lock multi-modal permission management and record traceability system, including: an intelligent lock device module, a management APP module, a cloud server module, an edge computing node module, a multi-factor authentication module, a big data analysis module, and an emergency handling module;

[0034] The intelligent lock device module is used to obtain the user's identity recognition information through multiple built-in identity recognition modes, and perform a preliminary match on the obtained identity recognition information in the local storage module. If the match fails, a remote match verification request is sent to the cloud server module and the edge computing node module through a secure channel for remote match verification;

[0035] The management APP module is used to provide a user operation interface, support the user to enter multiple identity recognition information through this module, and send the entered information to the intelligent lock device module, the cloud server module, and the edge computing node module after encryption processing;

[0036] The cloud server module is used to receive and store the identity recognition information, permission information, and unlocking records uploaded by the intelligent lock device module; provide data access services for the management APP module to obtain the unlocking records within a specified time period;

[0037] The edge computing node module is used to receive the remote match verification request sent by the intelligent lock device module and assist in the match verification of the identity recognition information;

[0038] The multi-factor authentication module is used to obtain historical behavior patterns, geographical location information, and device fingerprint information, combine the identity recognition information, and make a comprehensive judgment according to preset rules and algorithms;

[0039] The big data analysis module is used to obtain historical unlocking record data from the cloud server module and the edge computing node module, and use machine learning algorithms to train the historical unlocking records, construct a user behavior model, and identify potential security risks and abnormal behavior patterns;

[0040] The emergency handling module is used to automatically trigger an emergency mode when the intelligent lock device module encounters a network failure, a system failure, or a malicious attack.

[0041] As a further preference of this technical solution, the local storage module in the intelligent lock device module adopts an encryption storage technology to encrypt the stored identity recognition information, permission information, and unlocking records. The local storage module has a data backup and recovery function; the management APP module has a user behavior analysis function, which is used to analyze the user's operation habits and preferences according to the operation records of the intelligent lock by the user.

[0042] As a further preference of this technical solution, the cloud server module adopts a distributed storage architecture to disperse data storage on multiple storage nodes; in the emergency mode, the emergency processing module sends the operation status and emergency situation of the intelligent lock to the administrator in real time by means of text messages or push notifications.

[0043] Due to the adoption of the above technical solutions in the embodiments of the present invention, it has the following advantages:

[0044] 1. By supporting multiple identity recognition modes, providing multiple permission types, and also being able to formulate permission type combination strategies, the administrator of the present invention can accurately allocate permissions for different users according to the actual situation, greatly improving the flexibility of permission management and meeting the diverse usage needs of modern families;

[0045] 2. By automatically recording each unlocking information and synchronizing it to the cloud server and edge computing nodes in real time, and combining big data analysis technology to build a user behavior model, the present invention can quickly and accurately identify potential security risks and abnormal behavior patterns, providing a strong and accurate basis for finding out the reasons, and significantly improving the efficiency and accuracy of problem troubleshooting;

[0046] 3. When facing complex environments or special situations, the intelligent lock of the present invention will quickly and automatically switch to the emergency mode to ensure the integrity and security of the system, as well as the consistency of data, effectively improving the system's ability to resist malicious attacks and further enhancing the security and stability of the intelligent lock in complex environments.

[0047] The above summary is only for the purpose of the specification and is not intended to be limiting in any way. In addition to the illustrative aspects, embodiments, and features described above, further aspects, embodiments, and features of the present invention will be readily apparent by reference to the drawings and the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0049] Figure 1 This is a schematic flow chart of a multi-modal permission management and record traceability method for an intelligent lock according to the present invention;

[0050] Figure 2 This is a schematic flow chart of a method for constructing a user behavior model according to the present invention;

[0051] Figure 3 This is a schematic flow chart of a method for adopting a multi-factor authentication mechanism according to the present invention;

[0052] Figure 4 This is a schematic diagram of the functional modules of a multi-modal permission management and record traceability system for an intelligent lock according to the present invention. Detailed implementation manners

[0053] The following describes the embodiments of the present disclosure in detail with reference to the accompanying drawings.

[0054] It should be clear that the following illustrates the implementation manners of the present disclosure through specific specific examples, and those skilled in the art can easily understand other advantages and effects of the present disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all of the embodiments. The present disclosure can also be implemented or applied through other different specific implementation manners, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present disclosure without creative efforts belong to the scope of protection of the present disclosure.

[0055] It should be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be obvious that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement the device and / or practice the method. In addition, this device and / or this method can be implemented using other structures and / or functions in addition to one or more of the aspects described herein.

[0056] It should also be noted that the illustrations provided in the following embodiments only schematically illustrate the basic concept of the present disclosure. The diagrams only show the components related to the present disclosure, rather than being drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and proportion of each component in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.

[0057] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.

[0058] Figure 1 It is a schematic flowchart of a multi-modal permission management and record traceability method for an intelligent lock according to an embodiment of the present invention. It should be noted that if there are substantially the same results, the method of the present application is not limited to Figure 1 the process sequence shown. As Figures 1-3 shown: A multi-modal permission management and record traceability method for an intelligent lock includes the following steps:

[0059] Step 1: Obtain an intelligent lock, perform initialization settings on the intelligent lock, connect it to the home local area network, and establish a secure communication connection with the cloud server;

[0060] Specifically, first, the user needs to obtain an intelligent lock device, which is the hardware basis for implementing the entire multi-modal permission management and record traceability function. Install the intelligent lock on the required door to ensure its physical structure is stable and it can perform the basic functions of a lock normally, such as locking and unlocking the door;

[0061] Then, turn on the power of the intelligent lock to make it enter the working state. The user needs to perform a series of initial settings on the intelligent lock, including but not limited to selecting the display language, setting the initial time, etc. These basic settings help the subsequent operations proceed smoothly and provide the necessary time reference for the system;

[0062] Finally, the user needs to enter the name (SSID) and password of the home wireless network on the operation interface of the intelligent lock to enable the intelligent lock to access the home local area network. The importance of this step is to integrate the intelligent lock into the home network environment and lay a foundation for subsequent communication with other intelligent devices and the cloud server; To ensure the security of communication between the intelligent lock and the cloud server, an encryption protocol (such as SSL or TLS) is used to establish a connection. During the connection process, the intelligent lock and the cloud server will exchange encryption keys to ensure that the data transmitted between them cannot be stolen or tampered with. In this way, whether it is subsequent identity recognition information, permission information, or unlocking records and other data, they are in a secure encrypted state during transmission, enhancing the information security of the entire system.

[0063] Step 2: Through the management APP supporting the smart lock, after entering various identity recognition information and encrypting it, upload and store it separately in the local storage module of the smart lock, the cloud server, and the edge computing node;

[0064] Specifically, the user uses the management APP supporting the smart lock to input various identity recognition information, such as fingerprint, facial image, iris image, voiceprint audio, etc. For fingerprint information, the user may need to enter fingerprints of different fingers or different angles of the same finger multiple times to ensure the accuracy of recognition; for facial information, the user may need to enter facial images under different lighting conditions to let the system learn and store the user's facial features; when entering voiceprint information, the user needs to read some specific sentences, and the system will record the user's voice characteristics; for iris information, it needs to be collected at a specific distance and angle to ensure obtaining a clear and accurate iris image; to protect the privacy and information security of users, the entered identity recognition information is encrypted using the Advanced Encryption Standard (AES) algorithm, and the information of different users is encrypted using different keys. In this way, even if the information is stolen, it is difficult to be decrypted, ensuring the security and uniqueness of user information.

[0065] Step 3: Based on the management APP, assign permission types to different users and formulate permission type combination strategies;

[0066] Specifically, the administrator or user can use the management APP to assign permissions to different users. The permission types are divided into multiple types, including:

[0067] Permanent permission: Grant the user long-term and unrestricted unlocking permission, which is applicable to the main members of the family. They can use the smart lock at any time without being restricted by time or other conditions;

[0068] Temporary permission: Provided for temporary visitors or short-term users. The administrator can set a valid time period, for example, set from a certain time to a certain time on a certain day, and the user can only use the smart lock within this time period;

[0069] Periodic permission: Can be set according to the user's daily usage pattern, such as set for specific time periods on weekdays or weekends of each week, and the user can only unlock within these cycles, which is applicable to regular usage scenarios;

[0070] Specific scenario permission: Determine whether to allow unlocking according to specific environmental conditions or events. For example, only when the indoor temperature is within a certain range, the light intensity reaches a certain level, or other smart devices are in a specific state, the user can use the smart lock;

[0071] In addition, the administrator or user can combine different permission types or use multiple identity recognition methods in combination to generate different permission type combination strategies, increasing the flexibility and security of permission management. For example, it can be set that the lock can only be opened when fingerprint recognition and password input are both satisfied, or users with temporary permissions can only use specific identity recognition methods (such as unlocking with an NFC card), etc.

[0072] Step 4: When the user performs an unlocking operation, the smart lock obtains the corresponding recognition information according to the identity recognition method selected by the user and performs a preliminary match in the local storage module. If the local match fails, a request is sent to the cloud server and the edge computing node through a secure channel for remote match verification.

[0073] Specifically, when the user attempts to unlock the lock, they first need to select an identity recognition method, such as using fingerprint, entering a password, or using an NFC card. The smart lock will obtain the identity recognition information provided by the user through corresponding sensors or input devices, such as a fingerprint sensor, a password keypad, or an NFC card reader.

[0074] Then, the smart lock will compare the recognition information entered by the user with the information stored in the local storage module. This process is to quickly verify the user's identity. If the match is successful, the unlocking operation may be performed immediately. If there is no matching information or the match is unsuccessful in the local storage module, a request is sent to the cloud server and the edge computing node through a secure channel for remote match verification.

[0075] Step 5: The smart lock automatically records the unlocking information of each unlocking operation and stores it in the local storage module of the smart lock, while synchronizing it to the cloud server and the edge computing node in real time.

[0076] Specifically, regardless of whether the unlocking operation is successful, the smart lock will record detailed unlocking information, including: unlocking time, identity recognition method of the unlocking user, identity information, whether the unlocking is successful, environmental parameters around the smart lock during unlocking, the operation behavior trajectory of the user, etc. And the above information is stored in the local storage module as a local data backup. At the same time, for the convenience of remote management and data sharing, it is synchronized to the cloud server and the edge computing node in real time to ensure data redundancy and consistency.

[0077] Step 6: Obtain the unlocking records from the cloud server or the edge computing node through the management APP, and use big data analysis technology for in-depth mining and analysis to identify potential security risks and abnormal behavior patterns.

[0078] Specifically, the administrator or user can query the unlocking records from the cloud server or edge computing node through the management APP. These records store all previous unlocking information, providing a data basis for subsequent analysis and management. By using big data analysis technology to process these unlocking records, including training on historical unlocking records to construct a user behavior model, through machine learning algorithms, the system can learn the normal and abnormal behavior patterns of users.

[0079] Step 7: When the intelligent lock encounters a network failure, system failure, or is under a malicious attack, it automatically switches to the emergency mode and performs a limited number of unlocking operations based on the locally stored permission information and alternative identity recognition methods in the emergency mode.

[0080] Specifically, when the intelligent lock encounters a network failure (such as a home network interruption), system failure (such as a problem with the internal software or hardware of the intelligent lock), or is under a malicious attack (such as a hacker attack attempt to crack it), the system will automatically switch to the emergency mode.

[0081] In the emergency mode, the intelligent lock performs a limited number of unlocking operations based on the locally stored permission information and alternative identity recognition methods. The alternative identity recognition methods may include an emergency password, a physical key, etc. These information are stored and encrypted in the local storage module to ensure that users can still enter their homes in special circumstances. At the same time, to prevent abuse, the number of uses is restricted to ensure the security of the system.

[0082] The existence of the emergency mode ensures the basic usability of the intelligent lock in abnormal situations, preventing users from being unable to enter their homes due to network or system problems. At the same time, it also takes security considerations into account to prevent unauthorized unlocking operations. Meanwhile, the intelligent lock continuously attempts to reconnect to the cloud server and edge computing node.

[0083] In one embodiment, specifically: in Step 6, the big data analysis technology uses machine learning algorithms to train the historical unlocking records and construct a user behavior model.

[0084] The method for constructing a user behavior model includes the following steps:

[0085] Step 601: Obtain historical unlocking record data from the cloud server and edge computing node and preprocess the historical unlocking record data.

[0086] Specifically, first, the system needs to obtain a large amount of historical unlocking record data from the cloud server and edge computing nodes. These data contain all previous unlocking operation information, covering the unlocking behaviors of different users at different times and under different conditions, which are the basis for constructing a user behavior model. For example, it may include information such as user A successfully unlocking the door using fingerprint recognition at 8 am on Monday, and user B failing to unlock the door using password input at 9 pm on Wednesday, etc.

[0087] Then, through data cleaning, remove those obviously incorrect or incomplete data. For example, information with incomplete records may be caused by network failures or other reasons. For example, if there is an unlocking record missing key identification information, remove it from the dataset. For the missing data in some records, fill it according to the characteristics of the data. For example, if the environmental temperature information is missing in some records, it may be filled according to the average temperature in other normal records, or more complex methods may be used, such as using time series prediction algorithms to estimate the missing temperature value. And convert different types of data into a unified format. For example, convert time data into timestamps, encode the identity recognition methods (such as fingerprints, passwords, Bluetooth, etc.), so as to facilitate subsequent algorithm processing. For environmental parameters, normalize them to a standard range. For example, convert the temperature from Celsius to a range of 0 to 1 to eliminate the influence of different data magnitudes.

[0088] Step 602: Extract valuable feature data from the preprocessed historical unlocking record data, and divide the feature data into a training set, a validation set, and a test set.

[0089] Specifically, first, extract key features from the preprocessed data. These features will be used as the input of the model to distinguish normal behaviors from abnormal behaviors. For example:

[0090] Time features: Extract the specific time of unlocking, day of the week, whether it is a holiday, whether it is working hours, etc. Because the unlocking behavior of users may have time patterns. For example, users usually unlock the door when going to work in the morning on weekdays, or the unlocking frequency is lower on weekend evenings.

[0091] Identity recognition features: Record the identity recognition methods used (such as fingerprints, passwords, NFC cards, etc.) and the usage frequencies of different identity recognition methods. Some abnormal behaviors may be manifested as frequently changing identity recognition methods.

[0092] Behavior features: Calculate the number of consecutive unlocking failures, the number of unlockings within a short period of time, the unlocking frequency within different time periods, etc. These features can reflect whether the user is performing abnormal operations. For example, multiple attempts to unlock the door within a short period of time may be abnormal behavior.

[0093] Environmental characteristics: Extract environmental parameters when unlocking, such as temperature, humidity, light intensity, etc. Abnormalities in the environment may affect the user's normal unlocking behavior or may be signals of abnormal operations;

[0094] Then, divide the extracted feature data into a training set, a validation set, and a test set. Usually, it is divided according to a certain ratio. For example, 70% is used as the training set, 15% as the validation set, and 15% as the test set. The training set is used to train the model, the validation set is used to adjust the model's parameters during training to prevent overfitting, and the test set is used to finally evaluate the performance of the model; for example, 700 pieces of data are used as the training set, 150 as the validation set, and 150 as the test set.

[0095] Step 603: Select decision tree, support vector machine, or deep learning neural network in machine learning algorithms as the basic architecture of the model;

[0096] Among them, the decision tree algorithm is a classification algorithm based on a tree structure that classifies data through a series of decision rules; for the user behavior model, it can gradually determine whether it is a normal or abnormal behavior according to different features, such as time, identity recognition method, environmental conditions, etc.; for example, first determine whether it is a working day, if so, then determine whether the identity recognition method used is the user's common method, and so on, to construct a tree-like judgment logic; the advantage of the decision tree is that it is easy to understand and interpret, and is suitable for scenarios with clear logical judgments on feature relationships;

[0097] The support vector machine algorithm separates data of different categories by finding a hyperplane. For the user behavior model, the data of normal behavior and abnormal behavior can be regarded as different categories, and the data is mapped to a high-dimensional space through a kernel function to find an optimal hyperplane for classification; for example, for complex data distributions, it can handle non-linear classification problems. When the relationship between user behavior and factors such as environment and time is not a simple linear relationship, the support vector machine can find a better decision boundary;

[0098] The deep learning neural network algorithm contains multiple hidden layers and can automatically learn complex patterns in the data, and has strong learning ability for complex user behavior patterns; for example, it can automatically learn the complex behavior characteristics of users under different environments, different times, and different identity recognition methods, and obtain the final classification result through the calculation of multiple layers of neurons and the processing of activation functions; for a large amount of data and complex behavior patterns, the deep learning neural network may achieve better results, but it requires more computing resources and time for training.

[0099] Step 604: Use the training set and the validation set as inputs, and normal behavior and abnormal behavior as output labels to train the model;

[0100] The specific training process is as follows:

[0101] First, use the feature data in the training set as input, and at the same time label normal behavior or abnormal behavior for each sample as the output label; for example, mark the record of a user successfully unlocking the door with fingerprint in the morning on a weekday as normal behavior, and mark the record of a user failing to unlock the door with password multiple times at 3 am as abnormal behavior;

[0102] Then, use the selected machine learning algorithm to train the model. The model will adjust its own parameters according to the input feature data and the corresponding labels, and learn the feature patterns of normal behavior and abnormal behavior; for example, the decision tree will adjust the decision rules of its branch nodes, the support vector machine will adjust the position of the hyperplane, and the deep learning neural network will adjust the weights and biases of each layer to minimize the prediction error;

[0103] At the same time, during the training process, use the validation set for verification to ensure that the model does not overfit; among them, overfitting means that the model over-learns the details of the training data, resulting in a decline in performance on new data, and the validation set can be used to detect and adjust in time.

[0104] Step 605: Use the test data set to evaluate the trained model, calculate the accuracy rate, recall rate, and F1 value, and optimize and adjust the model according to the evaluation results;

[0105] For the accuracy rate: By inputting the data in the test set into the trained model, calculate the proportion of the number of samples correctly predicted by the model in the total number of samples; for example, there are 100 samples in the test set, and the model correctly predicts 80, so the accuracy rate is 80%;

[0106] For the recall rate: Calculate the proportion of the samples that are actually abnormal behaviors and are correctly predicted as abnormal behaviors; for example, there are actually 20 abnormal behavior samples, and the model correctly predicts 15, so the recall rate is 75%;

[0107] For the F1 value: Considering the accuracy rate and recall rate comprehensively, it is the harmonic mean of the two, used to balance the precision and recall of the model; for example, if the accuracy rate is 80% and the recall rate is 75%, calculate the F1 value through the formula to comprehensively evaluate the model performance; assume there is a test data set with 100 samples, and the model prediction results are as follows:

[0108] There are 30 actual abnormal behavior samples (positive class), 20 of which are correctly predicted as abnormal behaviors by the model, 10 normal behaviors are wrongly predicted as abnormal behaviors, and 10 abnormal behaviors are wrongly predicted as normal behaviors;

[0109] First, calculate the accuracy rate and recall rate:

[0110] ;

[0111] ;

[0112] Then calculate the F1 value:

[0113] ;

[0114] According to the evaluation results, if the model performance does not meet the requirements, the model will be optimized and adjusted;

[0115] For example: for decision trees, the depth of the tree and pruning operations can be adjusted to prevent overfitting; for support vector machines, the parameters of the kernel function can be adjusted; for deep learning neural networks, the number of layers, the number of neurons, the learning rate, etc. of the network can be adjusted; at the same time, feature extraction can also be considered again, or more data can be added for training to continuously optimize the model so that it can accurately identify users' abnormal behaviors in actual applications and improve the security and reliability of the system;

[0116] Through the above process of building the user behavior model, the system can use historical data and machine learning algorithms to accurately identify users' normal and abnormal behaviors, provide more intelligent and effective support for the security management of the intelligent lock, discover potential security risks in advance, and ensure the safety of the family and users.

[0117] In one embodiment, specifically: in step four, during the process of remote matching verification, a multi-factor authentication mechanism is adopted, and the specific steps are as follows:

[0118] Step 401, establish user behavior pattern features by analyzing the user's past unlocking time, unlocking frequency, and commonly used identity recognition methods, and obtain the user's historical behavior pattern;

[0119] Specifically, the system will collect the user's past unlocking operation information from the stored historical unlocking records, including the specific time of each unlocking, the unlocking frequency, and the identity recognition method used; for example, the system will record the unlocking time of the user every day in the past month and may find that the user usually unlocks with fingerprint recognition between 7:30 and 8:00 in the morning, which is a typical user behavior pattern;

[0120] Among them, establishing user behavior pattern features includes: unlocking time pattern, unlocking frequency, and commonly used identity recognition methods;

[0121] Unlocking time pattern: Analyze the distribution of the user's unlocking time, such as whether the user has a fixed unlocking time range, whether it is concentrated on weekdays or weekends, and whether the user unlocks in the morning, at noon, or in the evening, etc.;

[0122] Locking frequency: Count the number of times the user unlocks the lock within a certain period (such as one day, one week, or one month) to determine whether the user's usage frequency is stable and whether there are abnormal situations of frequent or extremely rare unlocking;

[0123] Common identity recognition methods: Determine which identity recognition method the user prefers to use, such as often using fingerprint or password, or whether the user will switch to different identity recognition methods in different scenarios.

[0124] Step 402: Collaborate with the positioning function of the user device to obtain the user's current geographical location information;

[0125] Specifically, the intelligent lock system will collaborate with the positioning function of the user's operating device (such as the user's mobile phone) to obtain the user's current geographical location information; this can be achieved through various positioning technologies, such as GPS positioning, Wi-Fi positioning, or base station positioning; for example, if the user's mobile phone has the GPS function enabled, the intelligent lock system can obtain the longitude and latitude information where the user is located through communication with the mobile phone.

[0126] This information can be used to determine whether the user is unlocking the lock within a reasonable geographical location range; for example, the user usually only uses the intelligent lock near home or the workplace. If the current location is far from the user's usual location, it may be abnormal behavior.

[0127] Step 403: Obtain the device fingerprint information of the user's operating device by collecting the device's hardware information and software information;

[0128] Specifically, first, collect the hardware identifiers of the user's operating device, such as the device's MAC address, IMEI code (for mobile phones), CPU serial number, hard disk serial number, etc. These hardware information are usually unique for each device and can be used as an identifier for the device;

[0129] Then, collect software information such as the operating system version, application version, and software installation list of the user device. Different software versions or applications may be associated with different security risks and can also be used as one of the characteristics of the device;

[0130] Finally, through specific hash operations or feature extraction algorithms on the collected hardware and software information, generate the device fingerprint information. The device fingerprint information can uniquely identify the user's operating device and prevent the user from using unauthorized devices to unlock the lock.

[0131] Step 404: Combine the historical behavior pattern, geographical location information, and device fingerprint information with the identity recognition information, and make a comprehensive judgment according to the preset rules and algorithms;

[0132] Specifically, first, aggregate the historical behavior patterns, geographical location information, device fingerprint information, and identity recognition information (such as fingerprints, passwords, etc.) provided by the current user obtained in the previous steps;

[0133] Among them, the preset rules and algorithms include the following aspects:

[0134] Time rule: Determine whether the current unlocking time conforms to the user's historical behavior pattern. For example, if the user usually does not unlock after 12 o'clock at night and the current operation is at 2 o'clock in the morning, it may trigger an anomaly;

[0135] Location rule: Determine whether the current geographical location is within the user's frequently visited location range. For example, if the user's usual location is the area where the home is located and the current location is in a distant city, there may be risks;

[0136] Device fingerprint rule: Verify whether the device fingerprint of the current operating device matches the device fingerprint used by the user in the past. If not, it may be an operation by a strange device;

[0137] Identity recognition rule: Verify whether the currently provided identity recognition information is consistent with the stored information, and at the same time consider other factors, such as whether the fingerprint is within the user's usual fingerprint range, whether the password is correct and not expired, etc.;

[0138] When making a comprehensive judgment, different weights will be assigned to different factors. For example, the historical behavior pattern accounts for 30% of the weight, the geographical location information accounts for 20%, the device fingerprint information accounts for 30%, and the identity recognition information accounts for 20%. Whether the verification is passed is judged through weighted calculation and threshold setting.

[0139] Step 405: If all verification conditions are passed, the intelligent lock will perform the unlocking operation; if the verification fails, the unlocking will be rejected, and the detailed information of this abnormal unlocking attempt will be recorded;

[0140] Specifically, if the comprehensive judgment result meets the preset safety standard, that is, all verification conditions are passed, the intelligent lock will perform the unlocking operation and allow the user to enter; if the verification fails, the intelligent lock will reject the unlocking and record the detailed information at the same time, including: the time of the attempted unlocking, accurate to the second, for subsequent traceability; the identity recognition method used in the attempt, whether it is fingerprint, password or other methods, to help judge the possible problems; the specific reason for the anomaly, whether it is due to location mismatch, device mismatch or identity recognition error, etc., to provide clues for subsequent security analysis; and store these abnormal information in the local storage module, cloud server or edge computing node for subsequent monitoring and processing by the administrator or system, such as notifying the administrator of an abnormal unlocking attempt or conducting further risk assessment;

[0141] Through this multi-factor authentication mechanism, the intelligent lock system does not solely rely on a single piece of identity recognition information. Instead, it comprehensively considers information from multiple dimensions to form a comprehensive security protection system, greatly enhancing the security of users using the intelligent lock and reducing the risk of being cracked or illegally operated.

[0142] In one embodiment, specifically: In step one, the intelligent lock supports multiple identity recognition modes, including fingerprint recognition, face recognition, iris recognition, voiceprint recognition, password input, Bluetooth unlocking, NFC card unlocking, and card swiping unlocking. Among them, fingerprint recognition identifies the unique texture features of the user's fingerprint, face recognition uses a camera to capture the user's facial features, iris recognition identifies the unique pattern of the user's eye iris, password input requires the user to enter a pre-set password, Bluetooth unlocking allows the user to pair with the intelligent lock via mobile phone Bluetooth to unlock, NFC card unlocking utilizes near-field communication technology, and card swiping unlocking uses a magnetic card or radio frequency card for unlocking operations. These recognition modes each have their own characteristics and advantages, meeting the usage habits and security requirements of different users and providing multiple means of identity verification for subsequent multi-modal permission management.

[0143] The secure communication connection uses the encryption protocols SSL or TLS. Among them, SSL is a protocol developed by Netscape to ensure the security of network communication, and TLS is a subsequent version of SSL, developed on the basis of SSL 3.0. They are similar in function and principle and are usually collectively referred to as SSL / TLS. They operate between the network transport layer and the application layer, providing encryption, identity authentication, and data integrity protection for data transmission.

[0144] Encryption: When the intelligent lock establishes a connection with the cloud server, the SSL / TLS protocol uses symmetric encryption algorithms (such as AES) and asymmetric encryption algorithms (such as RSA) to encrypt the transmitted data. First, an asymmetric encryption algorithm (such as using the server's public key) is used to securely exchange a symmetric encryption key, and then this symmetric key is used to encrypt and decrypt the actual transmitted data. This can ensure the secure transmission of the key while improving the efficiency of data encryption and decryption.

[0145] Identity authentication: The SSL / TLS protocol uses digital certificates to verify the identities of both communication parties. When the intelligent lock communicates with the cloud server, the server sends its digital certificate to the intelligent lock. This certificate is signed by a trusted certificate authority (CA), and the intelligent lock will verify the validity of the certificate, including checking whether the certificate has expired and whether the issuing authority of the certificate is trusted, etc., to confirm the identity of the server. Similarly, in some cases, the intelligent lock may also need to provide its own digital certificate to the server to prove its identity.

[0146] Data Integrity Protection: The SSL / TLS protocol uses a Message Authentication Code (MAC) or a hash function (such as SHA-256) to ensure that data is not tampered with during transmission. The sender calculates the hash value of the data and sends it along with the data to the receiver. After receiving the data, the receiver recalculates the hash value of the data and compares it with the received hash value. If the two hash values are the same, it indicates that the data has not been tampered with during transmission, ensuring the integrity of the data;

[0147] Role in the Smart Lock System:

[0148] Protecting User Data Security: When the smart lock communicates with the cloud server, it transmits sensitive data such as the user's identity information (such as fingerprint, facial recognition information, etc.), permission information, and unlocking records. Using the SSL / TLS protocol to encrypt the transmission of this data can prevent the data from being stolen by hackers during transmission, protecting the privacy and security of users;

[0149] Preventing Man-in-the-Middle Attacks: Through identity authentication and data integrity protection, the SSL / TLS protocol can effectively prevent man-in-the-middle attacks. A man-in-the-middle attack refers to a hacker inserting themselves between the two communicating parties, intercepting, tampering with, and forging communication data. The SSL / TLS protocol verifies the identities of the two communicating parties and ensures the integrity of the data, making it impossible for hackers to carry out man-in-the-middle attacks without being detected;

[0150] Ensuring Communication Reliability: The SSL / TLS protocol can also ensure the reliability of communication. It can detect errors and anomalies during data transmission and take corresponding measures to handle them, such as retransmitting the data, to ensure that the communication between the smart lock and the cloud server can proceed stably and reliably.

[0151] In one embodiment, specifically: In step five, the unlocking information includes the unlocking time, the identity recognition method of the unlocking user, the identity information, whether the unlocking was successful, the environmental parameters around the smart lock during unlocking, and the user's operation behavior trajectory;

[0152] Among them, the unlocking time: precisely records the time when each unlocking operation occurs, usually accurate to seconds or even milliseconds. This helps to establish a time series and provides a time dimension basis for subsequent data analysis and abnormal behavior detection; for example, recording as "2025-01-17 15:30:25.123" can reflect the specific moment when the user unlocks the lock. Subsequently, based on this, the user's daily unlocking habits can be analyzed to determine whether there are abnormal unlocking times. For example, if the user usually unlocks the lock during the day and there is an unlocking record in the early morning one day, it may be an abnormal situation;

[0153] Identity recognition methods of unlocking users: Record the specific identity recognition method used by the user for this unlocking, which may be fingerprint recognition, facial recognition, iris recognition, voiceprint recognition, password input, Bluetooth unlocking, NFC card unlocking, or card swiping unlocking, etc.; This information allows administrators or the system to clearly know which method the user used to attempt unlocking, facilitating the statistics and analysis of the usage frequency and effectiveness of different identity recognition methods; For example, the system can find out whether users prefer fingerprint recognition or password input through statistics, as well as the preferences of different users for different identity recognition methods;

[0154] Identity information: Includes information related to the user's identity, such as the user's unique identifier (which may be the username, user ID, user account, etc.), to distinguish the unlocking operations of different users; For household users, different members have different identity information. By recording the identity information, it is possible to track which family member performed the unlocking operation, which is very important for permission management and tracing of abnormal behaviors; For example, in a smart lock system for a family with multiple users, it is possible to determine whether it was the parents or the child who performed the unlocking operation based on the identity information;

[0155] Whether the unlocking was successful: Record the result of this unlocking operation, whether it was successful or failed. If the unlocking fails, the system can further analyze the reasons, which may be that the user entered the wrong password, the identity recognition information did not match, or other abnormal situations; For failed unlocking operations, it can be an important basis for subsequent security analysis. For example, multiple consecutive failures may mean there are abnormal attempts, perhaps someone is trying to crack the password or using the wrong identity recognition information;

[0156] Environmental parameters around the smart lock during unlocking: The environmental parameters around the smart lock are usually obtained through built-in sensors, including but not limited to:

[0157] Temperature: Measured by a temperature sensor, for example recorded as "25°C". Temperature may affect the performance of the smart lock or the user's operation. Extreme temperatures may cause the performance of some components to decline, and at the same time may also affect the user's normal unlocking behavior. For example, the recognition effect of the fingerprint sensor may become worse at low temperatures;

[0158] Humidity: Measured using a humidity sensor, such as "60%RH". Humidity may affect the performance of the device's electronic components and can also be used as a basis for judging abnormal behaviors. For example, unlocking operations under abnormally high humidity may need attention;

[0159] Light intensity: Obtained through a light sensor, such as "500 lux". Light intensity can reflect the environmental conditions at that time. For example, unlocking in extremely dark or extremely bright environments may be an abnormal situation, or sudden strong light irradiation at night may imply that someone is deliberately interfering with the environment;

[0160] Air pressure: Measured by an air pressure sensor, it may affect certain specific smart lock functions or environmental perception. Abnormal air pressure changes may be a signal of abnormal environment;

[0161] Trajectory of user's operation behavior: The trajectory of user's operation behavior can be obtained in various ways. For example:

[0162] Location information: If the smart lock is associated with the user's device (such as a mobile phone), the location and movement trajectory of the user before unlocking can be obtained through the location information of the mobile phone to determine where the user approaches the door from and whether the user leaves after unlocking;

[0163] Proximity sensor information: The smart lock can be equipped with a proximity sensor to judge the time and speed at which the user approaches the smart lock. For example, whether the user stays in front of the door for a long time or approaches and leaves abnormally quickly, which may imply different behavior patterns;

[0164] Operation sequence information: Record the operations performed by the user before and after unlocking, such as whether other operations (such as pressing other buttons) were attempted before unlocking, or whether the door was immediately opened or the user stayed in front of the door for a period of time after unlocking.

[0165] In one embodiment, specifically: In step three, the permission types include permanent permission, temporary permission, periodic permission, and specific scenario permission;

[0166] Among them, the permanent permission is a type of permission that is valid for a long time and is usually granted to the main members of the family, such as the owner of the house or the family members who live there for a long time; Users with permanent permission can use the smart lock to unlock at any time and in any environment, without being restricted by time or other conditions; For example, the owner of the house has permanent permission, and they can freely enter and leave the house day or night, on weekdays or weekends, through various identity recognition methods (such as fingerprint, face recognition, etc.) of the smart lock; This type of permission provides the greatest convenience for the main users and meets their daily living needs;

[0167] The temporary permission is mainly used to meet the needs of temporary visitors or short-term use; The administrator can accurately set the effective start time and end time of the temporary permission, as well as the allowed number of unlocking times, through the management APP supporting the smart lock; For example, when a friend comes to visit and stays for a few days, the administrator can set a temporary permission for him, starting at 10 am on a certain day and ending at 5 pm a few days later, and setting the allowed number of unlocking times to 10 times; In this way, the visitor can use the smart lock within the specified time and number of times, and the permission will automatically expire after the time or number of times, ensuring the security of the family and the flexibility of permission management;

[0168] Periodic permissions are a type of permissions set according to the user's usage patterns; administrators can set the period (such as weekly or monthly) and specific time ranges, and users can only use the smart lock within the specified time ranges during the specified period; for example, for office workers with fixed working hours at home, the administrator can set that they have the unlocking permission from 7:00 to 9:00 in the morning and from 6:00 to 8:00 in the evening from Monday to Friday every week, and they cannot use the smart lock at other times; this type of permission can be customized according to the different living and working patterns of users, improving the accuracy and rationality of permission management;

[0169] Specific-scenario permissions are determined by specific environmental conditions or events to decide whether to grant users the unlocking permission; the smart lock can judge whether to allow users to unlock by collecting data through built-in environmental sensors (such as temperature and humidity sensors, light sensors, air pressure sensors), or linkage information with other smart home devices, combined with preset scenario conditions (such as temperature range, light intensity range, specific device status); for example, when the indoor temperature is too high or too low, only specific maintenance personnel with specific-scenario permissions can unlock and enter for equipment inspection; or when the home security system detects an abnormality, only the specific permissions of the owner or security personnel can unlock the smart lock; this type of permission increases the security and applicability of the smart lock in different scenarios;

[0170] The permission type combination strategy includes the combination of multiple identity recognition methods, the combination of different permission types, and the usage restrictions of different identity recognition methods under different permission types;

[0171] Combination of multiple identity recognition methods: To improve security, the permission type combination strategy can set the combination of multiple identity recognition methods; for example, set two-factor authentication, requiring users to enter the password first and then perform fingerprint recognition to unlock; or in specific security scenarios, such as at night or after multiple consecutive unlocking failures, force users to use face recognition and NFC card unlocking at the same time; through the combination of multiple identity recognition methods, the difficulty of illegal unlocking is increased, improving the security of the smart lock;

[0172] Combination of different permission types: Different permission types can be combined to meet more complex usage requirements; for example, when setting temporary permissions for temporary visitors, combine specific-scenario permissions to stipulate that visitors can only use the smart lock during the day and when the indoor temperature is normal; or when setting periodic permissions for family members, according to different time periods or scenarios, match different combinations of identity recognition methods to further refine permission management; this combination method can flexibly adjust permission settings according to different users and scenarios, improving the diversity and adaptability of permission management;

[0173] Usage restrictions of different identity recognition methods under different permission types: Different permission types can impose usage restrictions on different identity recognition methods. For example, users with permanent permissions can use all identity recognition methods; while users with temporary permissions may only be able to use specific identity recognition methods, such as card swiping to unlock or password input, for convenient management and control; or in periodic permissions, it is stipulated that only fingerprint recognition can be used during certain time periods, and face recognition can be used during other time periods, etc. Such restrictions can reasonably allocate the usage permissions of different identity recognition methods according to the characteristics of the permission types and security requirements, optimizing the user experience and security.

[0174] In one embodiment, specifically: In step two, the identity recognition information includes fingerprint recognition information, face recognition information, voiceprint recognition information, and iris recognition information. Among them, the fingerprint recognition information is a unique feature representation of the user's fingerprint, collected through the fingerprint sensor of the smart lock; the face recognition information is an image or feature representation of the user's face, collected through the camera of the smart lock; the voiceprint recognition information is a feature representation of the user's voice, collected through the microphone of the smart lock; the iris recognition information is a unique pattern feature of the user's eye iris, collected through the iris recognition sensor of the smart lock.

[0175] The encryption process uses the Advanced Encryption Standard (AES) algorithm to encrypt the identity recognition information, and different keys are used to encrypt the information of different users. Among them, the Advanced Encryption Standard (AES) algorithm is a widely used symmetric encryption algorithm that uses the same key for both encryption and decryption operations. For the encryption of identity recognition information, different keys are used for different users to ensure that even if the information of a certain user is leaked, it will not affect the information security of other users. When storing and transmitting the identity recognition information, the above-mentioned fingerprint recognition information, face recognition information, voiceprint recognition information, and iris recognition information will be encrypted using the corresponding keys. For example, for the fingerprint information of User A, AES encryption is performed using Key A, and for the face recognition information of User B, AES encryption is performed using Key B. The AES algorithm has different key lengths (such as 128 bits, 192 bits, or 256 bits), and a longer key length provides higher security. During the encryption process, the original identity recognition information is used as plaintext and converted into ciphertext through the key and the AES algorithm. The ciphertext appears as a sequence of disordered characters and cannot directly identify the user's original information. Only by using the corresponding key can the ciphertext be restored to the original identity recognition information. When these encrypted identity recognition information is stored in the local storage module of the smart lock, the cloud server, or the edge computing node, even if these storage devices are illegally accessed, since the information is encrypted, it is difficult for attackers to obtain the user's true identity recognition information, ensuring the security and privacy of the user's identity recognition information. At the same time, during the information transmission process, the encrypted information can also prevent the information from being stolen and tampered with, improving the security of the entire system.

[0176] In summary, the multi-modal permission management and record traceability method for a smart lock provided by the embodiments of the present invention organically combines functions such as identity recognition, permission management, operation record, security verification, and emergency handling through the collaborative work of multiple steps to form a complete system, improving the security, convenience, and manageability of the smart lock, solving many problems existing in traditional smart locks, and providing a more comprehensive and intelligent solution for home security.

[0177] Figure 4 It is a schematic diagram of the functional modules of a multi-modal permission management and record traceability system for a smart lock according to an embodiment of the present application. As Figure 4 shown, a multi-modal permission management and record traceability system for a smart lock includes: a smart lock device module, a management APP module, a cloud server module, an edge computing node module, a multi-factor authentication module, a big data analysis module, and an emergency handling module;

[0178] An intelligent lock device module, which is used to obtain the user's identity recognition information through multiple built-in identity recognition modes, and perform preliminary matching of the obtained identity recognition information in the local storage module. If the matching fails, a remote matching verification request is sent to the cloud server module and the edge computing node module through a secure channel for remote matching verification;

[0179] A management APP module, which is used to provide a user operation interface, support the user to enter multiple identity recognition information through this module, and encrypt the entered information and then send it to the intelligent lock device module, the cloud server module, and the edge computing node module;

[0180] A cloud server module, which is used to receive and store the identity recognition information, permission information, and unlocking records uploaded by the intelligent lock device module; provide data access services for the management APP module, and obtain the unlocking records within a specified time period;

[0181] An edge computing node module, which is used to receive the remote matching verification request sent by the intelligent lock device module and assist in the matching verification of the identity recognition information;

[0182] A multi-factor authentication module, which is used to obtain historical behavior patterns, geographical location information, and device fingerprint information, combine the identity recognition information, and make a comprehensive judgment according to the preset rules and algorithms;

[0183] A big data analysis module, which is used to obtain historical unlocking record data from the cloud server module and the edge computing node module, and use machine learning algorithms to train the historical unlocking records, construct a user behavior model, and identify potential security risks and abnormal behavior patterns;

[0184] An emergency handling module, which is used to automatically trigger the emergency mode when the intelligent lock device module encounters network failures, system failures, or malicious attacks.

[0185] In one embodiment, specifically: The local storage module in the intelligent lock device module uses encrypted storage technology to encrypt the stored identity recognition information, permission information, and unlocking records. The local storage module has data backup and recovery functions; The management APP module has a user behavior analysis function, which is used to analyze the user's operation habits and preferences according to the user's operation records of the intelligent lock.

[0186] In one embodiment, specifically: The cloud server module adopts a distributed storage architecture and disperses the data storage on multiple storage nodes; In the emergency mode, the emergency handling module sends the operation status and emergency situation of the intelligent lock to the administrator in real time by means of text messages or push notifications.

[0187] In summary, for the intelligent lock multi-modal permission management and record traceability system provided by the embodiments of the present invention, the intelligent lock device module acquires and matches user identity recognition information, the management APP module realizes the entry and encrypted transmission of user identity recognition information, the cloud server module stores relevant data and provides data access for the management APP, the edge computing node module assists in remote matching and verification, the multi-factor authentication module comprehensively judges the user identity, the big data analysis module constructs a user behavior model to identify potential risks, and the emergency handling module triggers the emergency mode in case of anomalies; specifically, the local storage module of the intelligent lock device module uses encrypted storage and has backup and recovery functions, the management APP module can analyze user operation habits and preferences, the cloud server module adopts a distributed storage architecture, and the emergency handling module notifies the administrator of the intelligent lock operation status and emergency situation by text message or push in the emergency mode, comprehensively improving the security, convenience and management efficiency of the intelligent lock system.

[0188] Regarding other details of the technical solutions implemented by each module in the above-mentioned intelligent lock multi-modal permission management and record traceability system of the embodiment, reference can be made to the description in the above-mentioned intelligent lock multi-modal permission management and record traceability method in the above-mentioned embodiment, which will not be elaborated here.

[0189] It should be noted that the embodiments in this specification are all described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For system-type embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments.

[0190] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be pointed out that the advantages, advantages, effects, etc. mentioned in the present disclosure are only examples and not limitations. It cannot be considered that these advantages, advantages, effects, etc. are essential for each embodiment of the present disclosure. In addition, the above-mentioned specific details of the disclosure are only for the purposes of illustration and easy understanding, rather than limitations. The above details do not limit the present disclosure to necessarily adopt the above specific details to implement.

[0191] In this disclosure, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. The block diagrams of the devices, apparatuses, equipment, and systems involved in this disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended words, meaning "including but not limited to", and can be used interchangeably with each other. The words "or" and "and" used herein refer to the word "and / or" and can be used interchangeably with it, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to" and can be used interchangeably with it.

[0192] In addition, as used herein, "or" in the listing of items starting with "at least one" indicates a disjunctive listing, so that for example, the listing of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the term "exemplary" does not mean that the examples described are preferred or better than other examples.

[0193] It should also be noted that in the systems and methods of this disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of this disclosure.

[0194] Various changes, substitutions, and alterations to the technologies described herein can be made without departing from the teachings defined by the appended claims. In addition, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and acts described above. Current or later-developed processes, machines, manufactures, compositions of events, means, methods, or acts that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Thus, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or acts within their scope.

[0195] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects are very obvious to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

[0196] The foregoing description has been presented for purposes of illustration and description. Furthermore, this description is not intended to limit embodiments of the present disclosure to the form disclosed herein. Although several example aspects and embodiments have been discussed above, those skilled in the art will recognize some variations, modifications, alterations, additions, and sub-combinations thereof.

Claims

1. A smart lock multi-modal permission management and record tracing method, characterized in that: The following steps are involved: Step 1: Get a smart lock, initialize the smart lock, connect it to the home LAN, and establish a secure communication connection with the cloud server; Step 2: Enter various identity information through the management APP of the smart lock, encrypt it, and then upload it to the local storage module of the smart lock, the cloud server, and the edge computing node; Step 3: Assign permission types to different users based on the management APP and formulate a permission type combination strategy; Step 4: When the user unlocks the lock, the smart lock obtains the corresponding identification information according to the identification method selected by the user, and performs a preliminary match in the local storage module. If the local match fails, a request is sent to the cloud server and edge computing node through a secure channel for remote matching verification; Step 5: The smart lock automatically records the unlocking information of each unlocking operation and stores it in the local storage module of the smart lock, and synchronizes it to the cloud server and edge computing node in real time; Step 6: Obtain unlocking records from cloud servers or edge computing nodes through the management app, and use big data analysis technology to conduct in-depth mining and analysis to identify potential security risks and abnormal behavior patterns; Step 7. When the smart lock encounters a network failure, system failure or is attacked by a malicious attack, it automatically switches to emergency mode and performs a limited number of unlocking operations in emergency mode based on the locally stored permission information and backup identity recognition methods.

2. According to claim 1, a smart lock multi-modal authority management and record tracing method is characterized by: In step six, the big data analysis technology uses a machine learning algorithm to train historical unlocking records and build a user behavior model; The method for constructing a user behavior model comprises the following steps: Step 601: Obtain historical unlocking record data from the cloud server and the edge computing node, and pre-process the historical unlocking record data; Step 602: extract valuable feature data from the pre-processed historical unlocking record data, and divide the feature data into a training set, a verification set, and a test set; Step 603: Select a decision tree, support vector machine or deep learning neural network in the machine learning algorithm as the basic architecture of the model; Step 604: Use the training set and the validation set as input, and use normal behavior and abnormal behavior as output labels to train the model; Step 605: Use the test data set to evaluate the trained model, calculate the accuracy, recall rate, and F1 value, and optimize the model according to the evaluation results; the accuracy is obtained by inputting the data in the test set into the trained model, and calculating the ratio of the number of samples correctly predicted by the model to the total number of samples; the recall rate is obtained by calculating the ratio of samples that are actually abnormal behaviors but are correctly predicted to be abnormal behaviors; the F1 value comprehensively considers the accuracy and recall rate, and is the harmonic mean of the two.

3. According to claim 1, a smart lock multi-modal authority management and record tracing method is characterized by: In step 4, during the remote matching verification process, a multi-factor authentication mechanism is adopted. The specific steps are as follows: Step 401: Establish user behavior pattern characteristics by analyzing the user's previous unlocking time, unlocking frequency, and common identity recognition methods, and obtain the user's historical behavior pattern; Step 402: Acquire the user's current geographical location information by cooperating with the positioning function of the user's device; Step 403: Obtain device fingerprint information of the user operating the device by collecting the hardware information and software information of the device; Step 404: Combine historical behavior patterns, geographic location information, and device fingerprint information with identity information to make a comprehensive judgment based on preset rules and algorithms; Step 405: If all verification conditions are met, the smart lock performs an unlocking operation; If the verification fails, unlocking will be refused and detailed information of this abnormal unlocking attempt will be recorded.

4. According to claim 1, a smart lock multi-modal authority management and record tracing method is characterized by: In step one, the smart lock supports multiple identity recognition modes, including fingerprint recognition, facial recognition, iris recognition, voiceprint recognition, password input, Bluetooth unlocking, NFC card unlocking and card swiping unlocking; the secure communication connection uses encryption protocols SSL or TLS.

5. According to claim 1, a smart lock multi-modal authority management and record tracing method is characterized by: In step five, the unlocking information includes the unlocking time, the identification method of the unlocking user, the identity information, whether the unlocking is successful, the environmental parameters around the smart lock when unlocking, and the user's operation behavior trajectory.

6. According to claim 1, a smart lock multi-modal authority management and record tracing method is characterized by: In step 3, the permission types include permanent permission, temporary permission, periodic permission and specific scenario permission; The permission type combination strategy includes a combination of multiple identity identification methods, a combination of different permission types, and usage restrictions of different identity identification methods under different permission types.

7. According to claim 1, a smart lock multi-modal authority management and record tracing method is characterized by: In step 2, the identity recognition information includes fingerprint recognition information, facial recognition information, voiceprint recognition information and iris recognition information; the encryption process uses an advanced encryption standard algorithm to encrypt the identity recognition information, and uses different keys to encrypt information of different users.

8. A smart lock multimodal authority management and record tracing system, applied to a smart lock multimodal authority management and record tracing method according to any one of claims 1 to 7, characterized in that: include: Smart lock device module, management APP module, cloud server module, edge computing node module, multi-factor authentication module, big data analysis module and emergency response module; The smart lock device module is used to obtain the user's identity information through the built-in multiple identity recognition modes, and perform a preliminary match on the obtained identity information in the local storage module. If the match fails, a remote matching verification request is sent to the cloud server module and the edge computing node module through a secure channel for remote matching verification; The management APP module is used to provide a user operation interface, support users to enter a variety of identity identification information through the management APP module, and encrypt the entered information and send it to the smart lock device module, the cloud server module and the edge computing node module; The cloud server module is used to receive and store the identity information, authority information, and unlocking records uploaded by the smart lock device module; provide data access services for the management APP module to obtain unlocking records within a specified time period; The edge computing node module is used to receive a remote matching verification request sent by the smart lock device module and assist in matching verification of identity information; The multi-factor authentication module is used to obtain historical behavior patterns, geographic location information and device fingerprint information, and make comprehensive judgments based on preset rules and algorithms in combination with identity recognition information; The big data analysis module is used to obtain historical unlocking record data from the cloud server module and the edge computing node module, and use machine learning algorithms to train historical unlocking records, build user behavior models, and identify potential security risks and abnormal behavior patterns; The emergency processing module is used to automatically trigger the emergency mode when the smart lock device module encounters a network failure, a system failure or is attacked by a malicious attack.

9. The smart lock multimodal authority management and record tracing system according to claim 8, characterized in that: The local storage module in the smart lock device module adopts encrypted storage technology to encrypt the stored identity information, authority information and unlocking records. The local storage module has data backup and recovery functions; the management APP module has a user behavior analysis function, which is used to analyze the user's operating habits and preferences based on the user's operation records of the smart lock.

10. The smart lock multi-modal authority management and record tracing system according to claim 8, characterized in that: The cloud server module adopts a distributed storage architecture to store data in multiple storage nodes in a dispersed manner; in emergency mode, the emergency processing module sends the operating status and emergency situation of the smart lock to the administrator in real time via text messages or push notifications.

Citation Information

Patent Citations

  • Intelligent lock management system and method based on behavior recognition

    CN118820736A

  • Intelligent memory door lock integrated system based on AI and biological recognition technology

    CN118972428A