Internet of Things lockset system and control method thereof
Through the lock system and control method for wired power supply and data interaction, combined with the three-level verification mechanism, the existing smart locks are solved with high cost and poor stability in low-voltage metering cabinet scenarios, and the improvement of safety and operation and maintenance efficiency is achieved.
Patent Information
- Application Number
- CN202510418179.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-07-04
AI Technical Summary
The existing intelligent IoT security locks have problems such as high manufacturing cost, high stability risks, and low operation and maintenance efficiency in low-voltage metering cabinet scenarios, and their marketing is hindered.
The architecture of wired power supply and data interaction is adopted, combined with the three-level verification mechanism of the main station-mobile terminal-lock, and the power supply and data exchange of the lock are realized through the wired interface, ensuring the precise control of unlocking permissions, and recording the operation history.
It reduces the manufacturing cost and maintenance difficulty of locks, improves system stability and operation and maintenance efficiency, enhances unlocking safety and traceability, and is suitable for cost-sensitive low-voltage metering cabinet scenarios.
Smart Images

Figure CN120260161A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet of Things devices, and particularly to an Internet of Things lock system and a control method thereof. Background Art
[0002] As a new type of security protection device, the intelligent Internet of Things security lock realizes precise control of unlocking permissions and time and traceability of operation records by equipping each operator with a unique ID number and implementing hierarchical authorization management, effectively improving the security protection level of devices such as metering cabinets. The existing State Grid standard locks adopt a full-scenario general design. Although they have high-level mechanical protection performance (such as temperature change resistance, corrosion resistance, etc.) and comprehensive monitoring functions, they expose significant limitations in specific application scenarios: First, the contradiction between function redundancy and cost: The standard lock is designed for the full scenario and integrates complex wireless communication, multiple encryption authentication and other functions, resulting in high manufacturing costs. For the power low-voltage side metering cabinet scenario with the largest stock, its over-protective design features (such as high-strength mechanical structure) exceed the actual requirements, causing waste of resources. Second, the market promotion is blocked: The high selling price leads to low market acceptance and an extended product iteration cycle. In the stage when the technology is not yet fully mature, the complex system architecture further exacerbates the product stability risk. The problem of inability to open the box due to lock failure feedback from the pilot substation area forces maintenance personnel to take destructive opening measures, resulting in equipment damage and economic losses. Third, the operation and maintenance efficiency is low: The intelligent functions of the existing locks rely on complex wireless communication protocols, and communication interruptions are likely to occur in scenarios with weak signal coverage, resulting in the failure of unlocking instructions. At the same time, the lag of lock status feedback affects the operation and maintenance management efficiency. Summary of the Invention
[0003] The purpose of the embodiments of the present invention is to provide an Internet of Things lock system and a control method thereof. By adopting a wired power supply and data interaction architecture, on the premise of ensuring the basic security protection ability, the manufacturing cost and maintenance difficulty are significantly reduced, which is particularly suitable for cost-sensitive scenarios such as low-voltage metering cabinets. It also realizes precise control of unlocking permissions through a three-level verification mechanism of the master station-mobile terminal-lock, and at the same time retains the key operation record traceability function, providing a high-cost-effective solution for the industry while meeting the intelligent management requirements.
[0004] To solve the above technical problems, the first aspect of the embodiments of the present invention provides an Internet of Things lock system, including: a master station, a lock, and a mobile terminal;
[0005] The lock includes: a lock body, a control module, and a wired interface, and the control module is electrically connected to the wired interface and the lock body respectively;
[0006] The mobile terminal is detachably connected to the wired interface in a wired manner, and the control module and the lock body are only powered and exchange data through the wired interface;
[0007] After the wired interface is connected to the mobile terminal in a wired manner, the control module receives the unlocking key information obtained by the mobile terminal from the master station. After verifying the unlocking key information, the control module controls the opening or closing of the lock body according to the unlocking key comparison result.
[0008] Further, before the mobile terminal is connected to the lock, it sends lock opening application information to the corresponding master station of the lock in a wired or wireless manner. The lock opening application information includes: lock ID number, user account number, usage time, and number of unlocking times;
[0009] The master station encrypts and signs the first unlocking key corresponding to the lock ID number according to the lock opening application information to generate the unlocking key information, and sends the encrypted and signed unlocking key information to the mobile terminal. The unlocking key information includes: mobile terminal ID number, lock ID number, master station ID number, unlocking time, number of unlocking times, and the first unlocking key corresponding to the lock.
[0010] Further, the control module performs key verification and master station signature verification on the unlocking key information. After the verification is passed, the first unlocking key in the unlocking key information is obtained, and the unlocking key is compared with the second unlocking key stored in the control module itself. If the first unlocking key and the second unlocking key are the same, the lock body is opened; if they are different, the control module controls the lock body to remain closed, and records the mobile terminal serial number, master station serial number, and mobile terminal connection time information.
[0011] Further, after the key verification and master station signature verification are passed, the control module obtains the mobile terminal ID number, lock ID number, master station ID number, unlocking time, and number of unlocking times in the unlocking key information and checks them in sequence. After the check is correct, the first unlocking key and the second unlocking key are checked and the unlocking process is carried out.
[0012] Further, the master station encrypts the first unlocking key corresponding to the lock by using the SM2 encryption method and signs the mobile terminal account information and the master station authorization information to obtain the unlocking key information.
[0013] Further, the mobile terminal and the master station perform data interaction in a wireless manner.
[0014] Further, after the lock is connected to the mobile terminal and powered on and started, the lock sends lock information to the mobile terminal, and the mobile terminal sends encrypted and signed unlocking key information with a time limit and a limited number of times for unlocking to the lock based on the lock information.
[0015] Further, the lock information further includes: the mobile terminal ID number corresponding to the last unlocking, the unlocking time, and the operation process information;
[0016] After the mobile terminal disconnects from the connection this time, it wirelessly sends the lock information received this time to the master station.
[0017] Further, the lock body is a padlock structure, a rotary structure, a hook structure, or a bolt structure.
[0018] Correspondingly, a second aspect of the embodiments of the present invention provides an Internet of Things lock system control method for controlling the Internet of Things lock system, including the following steps:
[0019] After the lock is connected to the mobile terminal in a wired manner and powered on, control the lock to obtain unlocking key information;
[0020] After the control module of the lock verifies the unlocking key information, obtain the first unlocking key in the unlocking key information and compare it with the second unlocking key stored in the control module;
[0021] If the first unlocking key is the same as the second unlocking key, open the lock body;
[0022] If the first unlocking key is different from the second unlocking key, control the lock body to remain in the closed state, and record the mobile terminal serial number, the master station serial number, and the mobile terminal connection time information.
[0023] The above technical solutions of the embodiments of the present invention have the following beneficial technical effects:
[0024] 1. Enhance the unlocking security and traceability. The Internet of Things lock system ensures unlocking security through multiple verification mechanisms. The mobile terminal obtains the encrypted and signed unlocking key information processed by the master station. The control module performs key verification and master station signature verification on it, and also checks multiple information such as the mobile terminal ID number, and then compares the first and second unlocking keys. If the verification fails, the lock body remains closed and relevant information is recorded, realizing the traceability of unlocking information, effectively preventing illegal unlocking, and improving the security of lock use;
[0025] 2. Reduce costs and adapt to specific scenarios. By adopting the method of wired connection between the mobile terminal and the lock for power supply and data exchange, complex wireless communication and other designs are avoided, and the structure of the lock is simplified. This makes the functions of the lock more in line with the requirements of specific scenarios such as low-voltage user metering boxes, reduces unnecessary functions, thereby reducing costs, improving the applicability of the product in specific scenarios, and facilitating its promotion in the industry;
[0026] 3. Achieve intelligent management and information interaction. After the mobile terminal passes the verification, the lock can send lock information including the last unlocking and other information to it, and the mobile terminal then feeds back this information to the master station. At the same time, the mobile terminal can send unlocking and locking control instructions based on the lock information, and the master station can also generate unlocking key information according to the application information, realizing the intelligent management of the lock and improving the management efficiency and convenience. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Figure 1 is a schematic diagram of the principle of the Internet of Things lock system provided by an embodiment of the present invention;
[0028] Figure 2 is a flowchart of the control method of the Internet of Things lock system provided by an embodiment of the present invention;
[0029] Figure 3 is a schematic diagram of the lock initialization process provided by an embodiment of the present invention;
[0030] Figure 4 is a schematic diagram of data interaction between the mobile terminal and the master station provided by an embodiment of the present invention;
[0031] Figure 5 is a schematic diagram of data interaction between the mobile terminal and the lock provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0032] To make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below in conjunction with the specific embodiments and with reference to the accompanying drawings. It should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present invention. In addition, in the following descriptions, the descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present invention.
[0033] Please refer to Figure 1, in the first aspect of the embodiment of the present invention, an Internet of Things lock system is provided, including: a master station, a lock, and a mobile terminal; the lock includes: a lock body, a control module, and a wired interface, and the control module is electrically connected to the wired interface and the lock body respectively; the mobile terminal is detachably connected to the wired interface in a wired manner, and the control module and the lock body are powered and data-exchanged only through the wired interface; after the wired interface is connected to the mobile terminal in a wired manner, the control module receives the unlocking key information obtained by the mobile terminal from the master station, and after verifying the unlocking key information, controls the opening or closing of the lock body according to the unlocking key comparison result.
[0034] First of all, the above technical solution improves the unlocking security. By adopting the cooperation mode of the master station, the mobile terminal and the lock, the unlocking requires the master station to generate the unlocking key information, and then it is transmitted to the lock control module by the mobile terminal for verification; multiple verification links greatly improve the unlocking security, prevent illegal unlocking, and ensure the property and information security in the lock usage scenario. For example, in the scenario of the power low-voltage side metering cabinet, it can effectively prevent unauthorized personnel from opening the cabinet for damage or information theft. Secondly, the mobile terminal and the lock are connected through a wired interface, which can not only supply power to the control module and the lock, but also conduct data exchange. Compared with wireless connection, wired connection avoids problems such as signal interference and limited coverage, ensures stable power supply and accurate data transmission, reduces the unlocking failure caused by communication failures, and improves the overall stability and reliability of the system. Finally, the lock only needs to be equipped with a control module, a wired interface and a lock body, without complex devices such as wireless communication modules, which greatly simplifies the lock structure; not only reduces the manufacturing cost of the lock, but also reduces the maintenance cost and the probability of failures, especially suitable for cost-sensitive scenarios. For example, when replacing the locks of a large number of existing power low-voltage side metering cabinets, a large amount of expenses can be saved.
[0035] Among them, the main station is mainly used for: saving the lock files, recording the lock UUID, secret key, and area division; saving user files, role permissions, area division and other information; maintaining information such as the position of the power distribution area, area division, and responsibility division; providing necessary file information of the locks authorized by a certain user through the API for the mobile APP to obtain; the mobile APP can obtain the limited-time unlocking secret key of the lock, and the mobile phone can obtain the signature and the limited-time unlocking secret key for use without network; the main station needs to perform account authentication and authorization with the mobile APP; the private key of the main station is used for signing the ciphertext of the unlocking. The mobile terminal is mainly used for: powering the wired lock of the mobile phone, and detecting the power-on state of the lock by listening to the serial port power-on instruction; after the lock is powered on and notified, the APP sends the ciphertext signature of the unlocking and the ciphertext of the unlocking key; after the unlocking is successful, according to the information returned by the lock, upload the operation log to the main station for recording, etc. The lock is mainly used for: storing the public key of the main station, the private key of the lock, the unlocking key, the last unlocking account, the unlocking time, etc.; after obtaining power supply, start up and send a start command and listen to the serial port unlocking instruction; verify the signature using the public key of the main station, decrypt the ciphertext of the limited-time unlocking key using the private key of the lock to obtain the unlocking key, and compare whether the unlocking key is consistent with the locally recorded unlocking key; perform unlocking, and feedback the unlocking result to the mobile app and feedback relevant information.
[0036] Further, before the mobile terminal connects to the lock, it sends lock opening application information to the corresponding main station of the lock in a wired or wireless manner. The lock opening application information includes: lock ID number, user account, use time, and number of unlocking times; the main station encrypts and signs the first unlocking key corresponding to the lock ID number according to the lock opening application information, generates unlocking key information, and sends the encrypted and signed unlocking key information to the mobile terminal. The unlocking key information includes: mobile terminal ID number, lock ID number, main station ID number, unlocking time, number of unlocking times, and the first unlocking key corresponding to the lock.
[0037] By sending an unlocking application containing information such as the lock ID number, user account, use time, and number of unlocking times through the mobile terminal, and the main station generates unlocking key information based on this, precise authorization of the unlocking behavior is achieved. Only the mobile terminal that has passed the review of the main station and obtained the correct key information can unlock the lock, which clarifies the user permissions and usage rules, prevents unauthorized unlocking operations, and improves the standardization and security of lock management. For example, in the scenario of the metering cabinet on the low-voltage side of the power grid, the unlocking permissions of personnel can be effectively controlled.
[0038] The main station encrypts and signs the first unlocking key, and the generated unlocking key information contains multiple key identifiers and limiting information such as time and number of times. The encryption process prevents the key from being stolen or tampered with during transmission, and the signature ensures the authenticity and integrity of the information source. Even if the data is intercepted during transmission, attackers cannot crack and forge valid unlocking information, ensuring the data security of the unlocking process.
[0039] In addition, the unlocking key information includes the mobile terminal ID number, lock ID number, master station ID number, unlocking time and unlocking times, etc. The above information provides a complete record of the unlocking behavior. In subsequent management, the details of each unlocking operation can be clearly traced, such as the user, usage time, usage times, etc. When an abnormal situation occurs, the problem can be quickly located, which facilitates responsibility identification and safety audits, and enhances the traceability and management efficiency of lock use.
[0040] Specifically, the control module performs key verification and master station signature verification on the unlocking key information, obtains the first unlocking key in the unlocking key information after the verification is passed, and compares the unlocking key with the second unlocking key stored in the control module itself. If the first unlocking key and the second unlocking key are the same, the lock body is opened; if they are different, the lock body is controlled to remain closed, and the mobile terminal serial number, master station serial number and mobile terminal connection time information are recorded.
[0041] Based on the control module, the unlocking key information is verified by key verification and master station signature verification, realizing a dual security mechanism. Key verification can ensure the accuracy of the unlocking key, and master station signature verification can confirm the authenticity of the information source. Only after these two verifications can the unlocking key be further compared. Through this strict verification process, illegal unlocking attempts can be effectively prevented, ensuring that only mobile terminals holding legal unlocking keys can open the lock body, greatly improving the safety of lock use.
[0042] The first unlocking key in the unlocking key information is compared with the second unlocking key stored in the control module itself, and the opening or closing of the lock body is accurately controlled based on the comparison result. This precise control method avoids the occurrence of accidental or illegal unlocking, ensuring that the unlocking operation is performed only when the two keys are completely consistent, making the use of the lock more reliable. When the first unlocking key and the second unlocking key do not match, the control module will record the mobile terminal serial number, the master station serial number, and the mobile terminal connection time information. These records provide an important basis for subsequent security audits and problem tracing. Once an abnormal unlocking attempt occurs, the manager can quickly locate the problem and find out the cause by checking these records, strengthen the supervision of the use of the lock, and improve the overall security management level.
[0043] Furthermore, after the key verification and the main station signature verification are passed, the control module obtains the mobile terminal ID number, lock ID number, main station ID number, unlocking time, and unlocking times in the unlocking key information and verifies them in sequence. After the verification is correct, the first unlocking key and the second unlocking key are verified and the unlocking process is carried out.
[0044] After completing the verification of the key and signature, the control module further checks the mobile terminal ID number, lock ID number, master station ID number, unlocking time, and unlocking times, constructing a multi-dimensional and multi-level security protection system. This series of strict checking processes can accurately identify abnormal or illegal unlocking requests, greatly reducing the risks of illegal intrusion and malicious unlocking, comprehensively ensuring the safe use of the lock, and making users feel more at ease when using the lock. By checking the unlocking time and unlocking times, the system can ensure that the unlocking operation complies with the pre-set rules and permissions. For example, only within the specified time range and when the unlocking times do not exceed the limit, will the subsequent unlocking process continue. This helps to standardize the unlocking behavior of users, avoid unauthorized use or abuse of unlocking permissions, and ensure that the use of the lock always follows the established management rules.
[0045] Furthermore, the master station encrypts the corresponding first unlocking key of the lock through the SM2 encryption method and signs the mobile terminal account information and the master station authorization information to obtain the unlocking key information. The SM2 encryption algorithm is an elliptic curve public key cryptography algorithm with high-strength encryption characteristics. By using this algorithm to encrypt the first unlocking key and then sign the mobile terminal account information and the master station authorization information, the master station can prevent the information from being stolen or tampered with during the transmission process. Even if the data is intercepted during transmission, it is difficult for attackers to crack valuable information, ensuring that the unlocking key information is transmitted from the master station to the mobile terminal safely and correctly, laying a foundation for the security of the entire unlocking process. Using high-strength encryption for the core unlocking information improves the anti-attack ability of the entire Internet of Things lock system. The encrypted unlocking key information is difficult to crack, effectively resisting various forms of network attacks, such as man-in-the-middle attacks and brute-force cracking. This makes it difficult for illegal personnel to obtain legitimate unlocking keys, thereby enhancing the security of the lock and protecting the property and information security in the entire system and various lock usage scenarios.
[0046] Furthermore, the mobile terminal and the master station perform data interaction wirelessly. The wireless data interaction method between the mobile terminal and the master station enables operations such as unlocking applications and key acquisition to be completed remotely. For example, maintenance personnel do not need to visit the master station site in person. They can submit unlocking requests and receive encrypted key information in real time through the mobile terminal, greatly improving the operation efficiency. This is especially suitable for the scenario of widely distributed power metering cabinets, supporting maintenance personnel to quickly complete unlocking authorization outdoors and reducing the operation complexity.
[0047] Furthermore, after the lock is powered on and started while connected to the mobile terminal, it sends lock information to the mobile terminal, and the mobile terminal sends the signed and encrypted unlocking key information with time limit and times limit for unlocking to the lock based on the lock information.
[0048] After the lock is connected to the mobile terminal, powered on and started, it sends lock information (such as the current status, historical operation records, etc.) to the mobile terminal, enabling the mobile terminal to obtain the device status in real time. Based on this information, the mobile terminal generates and sends a signed and encrypted unlocking key information with a time limit and a limited number of times. For example, when the lock is already in the open state, the mobile terminal can automatically skip the unlocking instruction, reducing invalid operations. Through two-way data interaction, the master station can indirectly obtain the real-time status of the lock (such as the last unlocking time, terminal ID, etc.) through the mobile terminal, realizing remote monitoring of the device. The operation and maintenance personnel can remotely judge whether the lock is abnormal based on this information and send instructions to intervene through the mobile terminal, such as forced locking or temporary authorization, improving the emergency response ability. At the same time, as an intermediate hub, the mobile terminal reduces the complexity of direct communication between the master station and the lock, improving system stability. The mobile terminal sends instructions based on the lock information, avoiding misoperations caused by communication delays or status out-of-sync. For example, if the lock is not fully closed due to mechanical failure, the mobile terminal can refuse to send the unlocking instruction again and prompt an abnormality, reducing equipment wear caused by repeated operations. At the same time, the real-time status feedback can also help users intuitively confirm the operation result, enhancing the user experience.
[0049] Furthermore, the lock information also includes: the mobile terminal ID number corresponding to the last unlocking, the unlocking time, and the operation process information; after the mobile terminal disconnects from this connection, it wirelessly sends the lock information received this time to the master station. The mobile terminal ID, time, and operation process information corresponding to the last unlocking contained in the lock information form a closed-loop record with the unlocking key information generated by the master station. When the mobile terminal disconnects, this data is synchronized to the master station wirelessly, constructing a complete unlocking operation log. For example, if an electric energy metering cabinet is illegally opened, the operation and maintenance personnel can quickly locate the terminal ID, time, and process of the abnormal operation through the master station, identifying the responsible entity and tracing the event chain. The mobile terminal automatically uploads the lock information after disconnecting, which can also ensure that the master station always obtains the latest device status (such as the last unlocking time, terminal ID, etc.). Even if the lock is offline, the master station can still judge whether it is in a normal working state through historical data. For example, if the lock has not been legally opened for several consecutive days, but the record shows that there are abnormal connection attempts, the system can automatically trigger an early warning mechanism. In addition, by analyzing the historical data in the lock information (such as high-frequency unlocking areas, time periods), the master station can dynamically adjust the inspection plan or optimize the authorization policy. For example, if the locks in a certain power distribution area are frequently accessed during non-working hours, the system can automatically reduce the temporary unlocking permissions in this area, reducing security risks. The mobile terminal wirelessly uploads the lock information after disconnecting, combined with the master station's encryption and signature mechanism for the unlocking key information, ensuring that the data cannot be tampered with during transmission. For example, if an attacker attempts to forge an unlocking record, the master station can quickly identify data anomalies by comparing the correlation between the lock information and the historical key.
[0050] Further, the lock body is a padlock structure, a rotary structure, a hook structure or a bolt structure.
[0051] The lock body adopts a standardized padlock design, which is adapted to the padlock holes of existing equipment such as power metering cabinets. It can be quickly replaced without modifying the box body, reducing the deployment cost. For example, in the transformation of existing low-voltage metering boxes, the padlock structure can be compatible with the installation method of the original mechanical lock, shortening the construction period. The rotary structure realizes the expansion and retraction of the lock tongue by rotating the cam, with high mechanical strength, and is suitable for scenarios that need to be opened and closed frequently and have high anti-destruction requirements (such as the cabinet doors of industrial equipment); in addition, the rotary structure can resist external force impacts, and cooperate with the encryption verification of the control module to form a dual protection of physical and electronic. The hook structure uses a spring hook to achieve quick locking, with convenient operation, and is suitable for scenarios that require instant response (such as emergency equipment boxes). The hook design can reduce the unlocking time and improve the operation and maintenance efficiency. The bolt structure is a vertical insertion bolt body design, which is adapted to equipment that requires axial locking (such as cable distribution boxes) to prevent the lock structure from being damaged by lateral forces.
[0052] The diversified design of the lock body structure, by decoupling the electronic control module from the replaceable mechanical structure, while maintaining the core intelligent functions (such as encryption verification, operation traceability), can flexibly adapt to the needs of different industries. For example, for the low-voltage metering boxes in the power industry, the padlock structure can realize the transformation of existing equipment at low cost; for military equipment with high security requirements, the rotary structure combined with high-strength materials provides physical protection. This design strategy not only reduces the product development and deployment costs, but also reserves interfaces for subsequent function upgrades (such as adding biometric modules), reflecting the forward-looking nature of modular design.
[0053] Correspondingly, please refer to Figure 2 , the second aspect of the embodiment of the present invention provides an Internet of Things lock system control method for controlling an Internet of Things lock system, including the following steps:
[0054] Step S100, after the lock is connected to the mobile terminal in a wired manner and powered on, control the lock to obtain the unlocking key information.
[0055] First of all, the lock has no self-power supply ability and must be powered on through a wired connection with the mobile terminal, cutting off the possibility of remote attacks from the physical level. For example, attackers cannot forge unlocking instructions through wireless signals and must actually contact the lock and insert an authorized terminal to trigger an operation, which is suitable for scenarios highly sensitive to remote intrusion such as power metering boxes and bank vaults. As the power supply carrier, the mobile terminal can synchronously perform terminal identity authentication (such as digital certificate verification) during connection to ensure that only authorized devices can power the lock and initiate operations. For example, power operation and maintenance personnel need to use a dedicated mobile terminal (with an embedded encryption chip) to activate the lock to prevent illegal devices from pretending to supply power.
[0056] Secondly, the lock does not require a built-in battery, a charging module, or a wireless communication module, significantly reducing the manufacturing cost and failure rate. For example, in the scenario of low-voltage metering boxes, the cost of the lock can be reduced to 1 / 3 of that of traditional wireless locks, making it suitable for large-scale replacement. Moreover, wired power supply avoids problems such as battery aging and insufficient power. Especially in extreme environments such as high temperature and low temperature, the stable power supply of the mobile terminal ensures the continuous availability of the lock. For example, in winter in Northeast China, traditional battery-powered locks often fail due to low temperature, while the wired power supply solution can ensure normal operation.
[0057] Thirdly, after being powered on, the lock can independently complete local key verification (without the need to be connected to the network in real time), which is suitable for remote areas or scenarios with poor network coverage. For example, mountain power equipment can still be unlocked through a pre-authorized mobile terminal when the network is disconnected, and the operation records are synchronized to the master station after the network is restored.
[0058] Step S200, after the control module of the lock verifies the unlocking key information, obtain the first unlocking key in the unlocking key information and compare it with the second unlocking key stored in the control module.
[0059] Through a dual-key verification mechanism (master station signature verification + local key comparison), the legitimacy and uniqueness of the unlocking instruction are ensured. Even if an attacker steals the encryption key, without the corresponding master station signature or the second key stored locally, the lock cannot be opened.
[0060] Step S300, if the first unlocking key and the second unlocking key are the same, open the lock body.
[0061] Instant unlocking response can ensure that legitimate users can quickly complete the operation after verification. For example, in the scenario of emergency repair, maintenance personnel can quickly obtain the key through the mobile terminal and open the equipment, reducing the fault handling time.
[0062] Step S400, if the first unlocking key and the second unlocking key are not the same, control the lock body to remain closed, and record the mobile terminal serial number, the master station serial number, and the mobile terminal connection time information.
[0063] The failure record function (mobile terminal serial number, master station serial number, connection time) provides key evidence for security auditing. For example, if a certain mobile terminal attempts to unlock illegally multiple times, the master station can quickly lock the abnormal device and revoke its permissions by analyzing the records. Combined with the SM2 encryption mechanism of the master station, the unlocking key information is difficult to be cracked during the transmission process, preventing man-in-the-middle attacks.
[0064] Even when the master station cannot be verified in real time due to network failures, the control module of the lock body can still unlock the door using the second key stored locally (synchronization required in advance), ensuring the continuity of critical scenarios. For example, power equipment in remote areas can still be operated through pre-authorized mobile terminals when the network is down.
[0065] Please refer to Figure 3 , the initialization of the lock is as Figure 3 shown, and the specific process is as follows: 1. The mobile terminal requests the master station to create a lock file (UUID, area division), and after obtaining the lock serial number, manufacturer model, etc. from the lock, uploads them to the master station. 2. Use the sm2 algorithm to generate a lock key pair, write the lock private key into the lock, and upload the lock public key to the master station. 3. Obtain the master station public key and write it into the lock; (the master station key pair also uses the sm2 algorithm, which is generated during the construction of the master station, and the master station private key must be strictly stored in accordance with industry or enterprise key management requirements to prevent theft). 4. After the lock is deployed to the meter box, verify the area where the lock is used and notify the master station of the relevant information to update the relevant information of the lock on the master station. 5. Use sm1 to perform a hash operation on the lock serial number + random number to generate an unlocking key, write it into the lock respectively, and upload it to the master station.
[0066] Please refer to Figure 4 , the process for the mobile terminal to obtain the unlocking key of the lock needs to first communicate with the master station to obtain the key of the corresponding lock. The specific process is as follows: 1. The mobile terminal requests the master station to apply for time-limited unlocking key information with signature and encryption, and the parameters include the user account, usage time, unlocking limit times, etc. 2. The master station encrypts the unlocking key using the lock public key to obtain the ciphertext of the unlocking key. The encryption of the unlocking key refers to the subsequent description. 3. The master station generates the plaintext M of the time-limited encrypted unlocking key information = ciphertext of the unlocking key || account for generating the unlocking ciphertext || permitted unlocking time range T1 (t1, t2, and t2 - t1 < 24 hours) || application ciphertext generation time t (t < t2) || maximum unlocking times (cnt < 5). 4. The master station signs M using the master station private key to obtain the time-limited unlocking key information with signature and encryption; the signature algorithm process refers to the subsequent description. 5. The master station returns the time-limited unlocking key information with signature and encryption to the mobile terminal.
[0067] Please refer to Figure 5, after the lock is initialized and the mobile terminal and the master station complete the usage authorization process, connect the lock to the mobile terminal through a wired port to supply power to the lock. The unlocking process after the lock is powered on is as follows: 1. The mobile terminal connects to the magnetic head interface of the lock through the magnetic head TypeC interface cable, starts to supply power to the lock, and monitors the lock startup status through the serial port. 2. After the lock is powered on, it actively notifies the mobile terminal of its own status (open / closed, last unlocking account, unlocking time, etc.). 3. The mobile terminal sends signed and encrypted time-limited unlocking key information, etc. (which can also include Beidou positioning, system time, etc.) to the lock. 4. The lock verifies the Beidou positioning and the difference between the system time and the time recorded last time, and records abnormal events. 5. The lock performs signature verification. After the signature verification is successful, it decrypts the unlocking key. If the unlocking key is consistent with the locally saved key and the unlocking time and the encryption time are within a reasonable range, it executes the unlocking. 6. The lock records this unlocking event (time, account, status, positioning, system time, etc.). 7. The lock uploads the historical operation records and logs of the mobile terminal. Note: The operator needs to pass the authentication and authorization of the master station account when using the mobile terminal (computer / mobile phone APP / palm device) before performing the above operations.
[0068] In an embodiment of the control method, the processes of unlocking and locking the lock are as follows:
[0069] Unlocking:
[0070] 1. The user opens the palm device or the mobile phone operation and maintenance APP for login authentication, enters the unlocking interface, the mobile phone APP obtains the necessary information related to the master station, waits for unlocking, and monitors the startup message of the serial port device.
[0071] 2. The user inserts the mobile phone into the connection cable and places it properly, for example, puts it in the pocket.
[0072] 3. The user picks up the wired terminal with one hand, removes the dust plug at the lower end of the lock body to achieve the connection of the wire and the terminal; after the lock body is powered on, it starts and sends a startup command to the mobile phone APP; after the mobile phone APP monitors the startup of the lock body, it sends an unlocking command; the lock body receives the unlocking command and decrypts the unlocking, controls the electro-mechanical components to unlock, and feeds back that the unlocking action is executed successfully. The unlocking is displayed on the mobile phone interface and notifies the master station to record.
[0073] 4. The user takes down the padlock and places it properly, for example, puts it in the pocket.
[0074] 5. The user unpluggs the connection cable and places it properly, for example, puts it in the pocket.
[0075] Locking:
[0076] 1. The user ensures that the box door is closed and closes the lock nose.
[0077] 2. The user hangs the hanging ring of the lock body on the lock nose and presses the hanging ring with one hand to hold the closing device.
[0078] 3. The user ensures that the dust and waterproof plug is in a closed state and the overall box lock state is correct. After taking a photo and saving it through the mobile phone APP, the user leaves. When the network of the mobile phone APP is normal, it uploads corresponding operation and maintenance records such as the location positioning of the saved records on the main station.
[0079] An embodiment of the present invention aims to protect an Internet of Things lock system and its control method. The Internet of Things lock system includes: a main station, a lock, and a mobile terminal; the lock includes: a lock body, a control module, and a wired interface, and the control module is electrically connected to the wired interface and the lock body respectively; the mobile terminal is detachably connected to the wired interface in a wired manner, and the control module and the lock body are only powered and exchange data through the wired interface; after the wired interface is wired-connected to the mobile terminal, the control module receives the unlocking key information obtained by the mobile terminal from the main station. After verifying the unlocking key information, it controls the opening or closing of the lock body according to the comparison result of the unlocking keys. The above technical solution has the following effects:
[0080] 1. Enhance unlocking security and traceability. This Internet of Things lock system ensures unlocking security through multiple verification mechanisms. The mobile terminal obtains the unlocking key information encrypted and signed by the main station, and the control module verifies the key and the main station signature, and also checks multiple information such as the mobile terminal ID number. Then, it compares the first and second unlocking keys. If the verification fails, the lock body remains closed and records relevant information, realizing the traceability of unlocking information, effectively preventing illegal unlocking, and improving the security of lock use.
[0081] 2. Reduce costs and adapt to specific scenarios. By using the wired connection between the mobile terminal and the lock for power supply and data exchange, complex wireless communication and other designs are avoided, and the structure of the lock is simplified. This makes the lock function more suitable for the needs of specific scenarios such as low-voltage user metering boxes, reduces unnecessary functions, thereby reducing costs, improving the applicability of the product in specific scenarios, and facilitating promotion in the industry.
[0082] 3. Realize intelligent management and information interaction. After the mobile terminal verifies the lock, the lock can send lock information including the last unlocking and other information to the mobile terminal, and the mobile terminal then feeds back this information to the main station. At the same time, the mobile terminal can send unlocking and locking control instructions based on the lock information, and the main station can also generate unlocking key information according to the application information, realizing the intelligent management of the lock and improving the management efficiency and convenience.
[0083] It should be understood that the above specific embodiments of the present invention are only for illustrative or explanatory purposes of the principles of the present invention, and do not constitute a limitation to the present invention. Therefore, any modifications, equivalent substitutions, improvements, etc. made without departing from the spirit and scope of the present invention shall be included within the protection scope of the present invention. In addition, the appended claims of the present invention are intended to cover all variations and modifications that fall within the scope and boundaries of the appended claims, or equivalent forms of such scope and boundaries.
Claims
1. An Internet of Things lock system, characterized in that, Comprising: A main station, a lock, and a mobile terminal; The lock comprises: a lock body, a control module, and a wired interface, and the control module is electrically connected to the wired interface and the lock body respectively; The mobile terminal is detachably connected to the wired interface in a wired manner, and the control module and the lock body are only powered and exchange data through the wired interface; After the wired interface is connected to the mobile terminal in a wired manner, the control module receives the unlocking key information obtained by the mobile terminal from the main station, and after verifying the unlocking key information, controls the opening or closing of the lock body according to the unlocking key comparison result.
2. The Internet of Things lock system according to claim 1, wherein Before the mobile terminal is connected to the lock, it sends lock opening application information to the corresponding main station of the lock in a wired or wireless manner, and the lock opening application information includes: a lock ID number, a user account number, a usage time, and the number of unlocking times; The main station encrypts and signs the first unlocking key corresponding to the lock ID number according to the lock opening application information to generate the unlocking key information, and sends the encrypted and signed unlocking key information to the mobile terminal. The unlocking key information includes: a mobile terminal ID number, a lock ID number, a main station ID number, an unlocking time, the number of unlocking times, and the first unlocking key corresponding to the lock.
3. The Internet of Things lock system according to claim 2, wherein The control module performs key verification and main station signature verification on the unlocking key information. After the verification is passed, it obtains the first unlocking key in the unlocking key information, and compares the unlocking key with the second unlocking key stored by the control module itself. If the first unlocking key and the second unlocking key are the same, the lock body is opened. If they are different, the lock body is controlled to remain closed, and the mobile terminal serial number, the main station serial number, and the mobile terminal connection time information are recorded.
4. The Internet of Things lock system according to claim 3, wherein After the key verification and the main station signature verification are passed, the control module obtains the mobile terminal ID number, the lock ID number, the main station ID number, the unlocking time, and the number of unlocking times in the unlocking key information and checks them in sequence. After the check is correct, the first unlocking key and the second unlocking key are checked and the unlocking process is carried out.
5. The Internet of Things lock system according to claim 2, wherein The main station encrypts the first unlocking key corresponding to the lock by using the SM2 encryption method and signs the mobile terminal account information and the main station authorization information to obtain the unlocking key information.
6. The Internet of Things lock system according to claim 2, wherein The mobile terminal and the main station perform data interaction in a wireless manner.
7. The Internet of Things lock system according to claim 1, wherein After the lock is connected to the mobile terminal, powered on and started, it sends lock information to the mobile terminal, and the mobile terminal sends encrypted and signed unlocking key information with time limit and limited times for unlocking to the lock based on the lock information.
8. The Internet of Things lock system according to claim 7, wherein The lock information further includes: the mobile terminal ID number corresponding to the last unlocking, the unlocking time and the operation process information; After the mobile terminal disconnects from the connection this time, it wirelessly sends the lock information received this time to the master station.
9. The Internet of Things lock system according to any one of claims 1-8, wherein The lock body is a padlock structure, a rotary structure, a hook structure or a bolt structure.
10. A control method for an Internet of Things lock system, characterized in that, For controlling the Internet of Things lock system according to any one of claims 1-9, it includes the following steps: After the lock is connected to the mobile terminal in a wired manner and powered on, control the lock to obtain the unlocking key information; After verifying the unlocking key information based on the control module of the lock, obtain the first unlocking key in the unlocking key information and compare it with the second unlocking key stored in the control module; If the first unlocking key and the second unlocking key are the same, open the lock body; If the first unlocking key and the second unlocking key are different, control the lock body to remain closed, and record the mobile terminal serial number, the master station serial number and the mobile terminal connection time information.