Intelligent lock system and control method and device
Through multi-protocol communication and intelligent lock system converted into electrical energy, the problem of limited functions and insufficient battery life in the event of gateway failure is solved, offline emergency network and collaborative operation are realized, and the flexibility and battery life of the lock are improved.
Patent Information
- Application Number
- CN202510515464.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-07-04
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional smart locks rely highly on the gateway to operate online, resulting in limited functions when the gateway fails, and the coordinated operation between fast lock unlocking and locks cannot be achieved, and the battery life is insufficient and maintenance costs are high.
The gateway module, smart lock cluster and hybrid power supply module adopting multi-protocol communication support the independent networking of Mesh networks, elect the master node through the improved RAFT algorithm, realize the offline emergency network, and reduce battery dependence through the conversion of mechanical energy into electricity.
In the event of a gateway failure, the smart lock can independently form an offline emergency network, realize information sharing and coordinated operation, improve the flexibility and adaptability of responding to emergencies, and extend battery life.
Smart Images

Figure CN120260167A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of power Internet of Things, and particularly to an intelligent lock system, a control method and a device. Background Art
[0002] Traditional intelligent locks highly rely on online control of the cloud or gateway during operation. Once the gateway goes offline due to network failures, equipment maintenance or other reasons, many functions of the locks will be severely restricted. For example, in case of an emergency, rapid unlocking operations cannot be achieved, which may delay emergency rescue or the execution of important tasks. At the same time, the collaborative operations between locks cannot be carried out properly, resulting in a significant decline in the operating efficiency and reliability of the entire system. Most current intelligent locks use continuous wireless communication for data transmission and status updates, which leads to high power consumption of the locks. Especially for passive locks that rely on key power supply, their battery life is severely insufficient. In actual use, frequently replacing batteries or charging not only increases the maintenance cost, but also may cause the locks to malfunction due to battery depletion, affecting the normal operation of the system. There is a lack of effective information interaction ability among existing intelligent locks. During normal operation, locks mainly rely on the gateway for centralized management and instruction issuance. Once the gateway fails, the locks cannot autonomously form an emergency network to achieve information sharing and collaborative operations. This isolated operation mode makes the system lack flexibility and adaptability in the face of emergencies and is difficult to meet the usage requirements in complex environments. Summary of the Invention
[0003] The present invention provides an intelligent lock system, a control method and a device to solve the problems raised in the above background art.
[0004] In a first aspect, an embodiment of the present invention provides an intelligent lock system, including:
[0005] A gateway module, equipped with an intelligent terminal Internet of Things operating system, configured to perform lightweight edge computing tasks and support multi-protocol adaptive communication including TCP / IP protocol, MQTT protocol and LoRa protocol;
[0006] An intelligent lock cluster, including multiple intelligent locks with wireless communication units, each intelligent lock further including a distributed decision-making unit and a dynamic power consumption management unit, and the wireless communication unit is configured to establish a mesh-type self-organizing network when the gateway module is offline;
[0007] A hybrid power supply module, including a mechanical energy-electric energy conversion component, a capacitor and a replaceable battery component, the mechanical energy-electric energy conversion component drives a micro-generator to generate electric energy through the lock mechanical transmission mechanism, and the capacitor is configured to store the electric energy generated by the mechanical energy-electric energy conversion component;
[0008] The trusted security module is built based on the trusted execution environment TEE and is configured to perform static trusted boot verification and dynamic runtime security verification at the hardware level.
[0009] Optionally, the distributed decision-making unit specifically includes:
[0010] The consensus algorithm execution module is configured to, when detecting that the gateway module is offline, construct a distributed decision-making cluster using an improved RAFT consensus algorithm;
[0011] The primary node election module is configured to elect a primary node lock within a response time of no more than 3 seconds, and the primary node lock performs system management functions including permission allocation, log synchronization, and operation conflict coordination;
[0012] The log management module is used to store the current operation log information.
[0013] Optionally, the dynamic power management unit includes:
[0014] The dual-mode switching controller is configured to switch between the active mode and the sleep mode according to the connection state of the gateway module, where the operating current in the active mode does not exceed 2 mA and the standby current in the sleep mode does not exceed 0.5 μA;
[0015] The wake-up circuit is integrated with a vibration sensor and a timer and is configured to maintain a listening power consumption of no more than 10 μA during the inactive period.
[0016] Optionally, the trusted security module includes:
[0017] The boot verification unit is configured to verify the integrity of the hardware firmware, the operating system kernel, and the application program through a three-level hash chain;
[0018] The runtime protection unit is configured to perform a process space hash calculation every 30 seconds and compare and verify it with a pre-stored reference value in the gateway module.
[0019] In a second aspect, an embodiment of the present invention further provides an intelligent lock control method, which is applied to an intelligent lock system provided in the first aspect above. The method includes the following steps:
[0020] S101. When it is detected that the offline duration of the gateway module exceeds a preset threshold T, trigger a distributed networking process, and elect a primary node lock through an improved RAFT consensus algorithm;
[0021] S102. In the trusted execution environment TEE of the primary node lock, perform permission verification on the received unlocking request, and generate a temporarily encrypted operation token using the SM4 algorithm after the verification passes;
[0022] S103. Broadcast the temporary operation token to the target lock via the WAPI secure wireless protocol. After the target lock completes decryption and verification, it performs the unlocking operation and saves the current operation log information to the log service module.
[0023] S104. When it is detected that the gateway module resumes connection, synchronize the operation log information of the log service module to the gateway module via the mesh network and perform decryption and archiving processing.
[0024] Optionally, the process of electing the master node lock includes:
[0025] Establish a multi-dimensional evaluation matrix including node priority, remaining battery power, and signal strength.
[0026] Obtain the comprehensive score of each node through weighted calculation and select the node with the highest score as the master node lock.
[0027] Optionally, the steps for generating the temporary operation token include:
[0028] Generate a token plaintext containing a timestamp, an operation ID, and the address of the target lock in the TEE environment.
[0029] Encrypt it using the SM4-CBC mode and append the HMAC-SM3 message authentication code.
[0030] Set a self-destruction timer with a validity period of 60 seconds.
[0031] Optionally, the process of saving the current operation log information to the log service module includes:
[0032] Each intelligent lock encrypts the local operation log using AES-128.
[0033] Transmit the encrypted log to the master node lock in the mesh network through a frequency hopping mechanism.
[0034] The master node lock generates a data packet to be synchronized after sorting the logs by timestamp and detecting conflicts.
[0035] Optionally, the dynamic power management unit includes:
[0036] Maintain a heartbeat packet with a 10-second cycle when the gateway module is online.
[0037] When the gateway module is offline, turn off the radio frequency transmission module and only retain the low-frequency receiving circuit.
[0038] When a predetermined vibration feature is detected or the timing wake-up time window is reached, activate the complete communication module.
[0039] In a third aspect, an embodiment of the present invention further provides an intelligent lock device, which adopts an intelligent lock system provided in the first aspect above.
[0040] The intelligent lock system, control method and device provided by the embodiments of the present invention at least have the following beneficial effects:
[0041] The intelligent lock system provided by the embodiments of the present invention includes a gateway module, an intelligent lock cluster, a hybrid power supply module and a trusted security module. The system supports multi-protocol communication, autonomously forms a network through the Mesh network when the gateway is offline, and uses an improved RAFT algorithm to elect a master node. It has dynamic power consumption management and trusted security verification, realizing that when the gateway fails, each lock can autonomously form an offline emergency network. Through the elected master node lock, information sharing and collaborative operation of other locks are realized, improving the response flexibility and adaptability of the intelligent lock in the face of emergencies. In addition, the intelligent lock system in the present invention realizes two power supply modes, active and passive, by setting a hybrid power supply module, and reduces the dependence on the battery by converting mechanical energy during the unlocking process into electrical energy, improving the battery life of the lock. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required to be used in the embodiments of the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.
[0043] Figure 1 is a scenario connection block diagram of an intelligent lock system provided by an embodiment of the present invention;
[0044] Figure 2 is a system block diagram of an intelligent lock system provided by an embodiment of the present invention;
[0045] Figure 3 is a flowchart of a control method for an intelligent lock system provided by another embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] In order to make the purpose, technical solutions and advantages of the present invention clearer, the following further describes the present invention in detail with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention, and are not used to limit the present invention.
[0047] Embodiments of the present invention will be described in detail below. Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary only for explaining the present invention and should not be construed as limiting the present invention.
[0048] In the description of the present invention, it should be understood that for the orientation description, such as up, down, front, back, left, right, etc., the orientation or positional relationship indicated is based on the orientation or positional relationship shown in the accompanying drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as limiting the present invention.
[0049] In the description of the present invention, the meaning of several is one or more, the meaning of multiple is two or more, greater than, less than, exceeding, etc. are understood as not including the original number, and above, below, within, etc. are understood as including the original number. If the first and second are described only for the purpose of distinguishing technical features, they should not be understood as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features or the sequence relationship of the indicated technical features.
[0050] In the description of the present invention, unless otherwise clearly defined, words such as setting, installing, connecting, etc. should be understood in a broad sense, and those skilled in the art can reasonably determine the specific meaning of the above words in the present invention in combination with the specific content of the technical solution.
[0051] The Power Hongmeng system is an intelligent terminal IoT operating system customized and developed for the energy and power industry. Based on the open-source Hongmeng (Open Harmony) technical architecture, it has been deeply optimized for the characteristics and requirements of the power industry. This system is mainly developed by energy enterprises such as State Grid, aiming to promote the digital transformation of the power industry and achieve device intelligence, interconnection, and efficient collaboration. The Power Hongmeng system mainly has the following characteristics:
[0052] I. Independent and controllable
[0053] Based on the open-source Hongmeng technology, combined with the needs of the power industry for secondary development, to achieve the independent control of core technologies and ensure the security of energy infrastructure.
[0054] II. Full-scenario compatibility
[0055] It supports full-scenario coverage from power terminal devices (such as smart meters, sensors) to edge gateways and master station systems, and is compatible with multiple hardware architectures (ARM, RISC-V, etc.).
[0056] III. High real-time performance and reliability
[0057] Optimized for the power industrial control scenario, it meets the requirements of millisecond-level real-time response and adapts to high-precision and high-reliability scenarios such as power grid regulation and fault handling.
[0058] IV. Unified Ecosystem and Interconnectivity
[0059] Break the "fragmentation" problem of traditional power equipment and achieve seamless coordination of equipment in the power generation, transmission, transformation, distribution, and utilization links through unified protocols and interface standards.
[0060] V. Enhanced Security
[0061] Built-in national cryptographic algorithms, support device identity authentication and encrypted data transmission, and comply with the power industry network security protection specifications and shutdown protection requirements.
[0062] In order to solve the problems existing in the prior art, an embodiment of the present invention provides an intelligent lock system, a control method, and a device.
[0063] First, the intelligent lock system and the intelligent lock device provided by the embodiment of the present invention will be introduced below.
[0064] Such as Figure 1 - Figure 2As shown in the figure, the intelligent lock system 1 in this embodiment mainly includes a gateway module 100 (abbreviated as gateway), an intelligent lock cluster 200, a hybrid power supply module 300, and a trusted security module 400. The gateway module 100 is equipped with the Power Harmony operating system, supports lightweight edge computing, and supports multi-protocol adaptive communication including TCP / IP protocol, MQTT protocol, and LoRa protocol. It supports the east-west interaction and offline autonomy functions between locks. The intelligent lock cluster 200 includes multiple intelligent locks with wireless communication units. Each intelligent lock also includes a distributed decision-making unit and a dynamic power consumption management unit. Specifically, the distributed decision-making unit specifically includes a consensus algorithm execution module, a master node election module, and a log management module. The consensus algorithm execution module is configured to construct a distributed decision-making cluster using an improved RAFT consensus algorithm when it detects that the gateway module is offline. The master node election module is configured to elect a master node lock within a response time of no more than 3 seconds. The master node lock performs system management functions including permission allocation, log synchronization, and operation conflict coordination. The log management module is used to store the current operation log information. The wireless communication unit is configured to establish a mesh-type self-organizing network when the gateway module 100 is offline. The hybrid power supply module 300 includes a mechanical energy-electric energy conversion component, a capacitor, and a replaceable battery component. The mechanical energy-electric energy conversion component drives a micro-generator to generate electric energy through the lock mechanical transmission mechanism. The capacitor is configured to store the electric energy generated by the mechanical energy-electric energy conversion component. The trusted security module 400 based on the trusted execution environment TEE is configured to perform hardware-level static trusted boot verification and dynamic runtime security verification. Among them, the intelligent lock cluster 200 monitors the network status of the gateway module 100 in real time through the built-in wireless communication unit. It can be understood that the wireless communication unit uses WAPI communication. The gateway module 100 has two modes: an online mode and an offline mode. When the gateway module 100 is in the online mode, the gateway module 100 can implement function controls such as unlocking and locking for each intelligent lock. When the gateway module 100 is in the offline state, the intelligent lock cluster 200 autonomously forms a network through the built-in Mesh network, elects a master node using an improved RAFT algorithm, has dynamic power consumption management and trusted security verification, realizes that when the gateway fails, each lock can autonomously form an offline emergency network, and through the elected master node lock, realizes information sharing and cooperative operation for other locks, improving the response flexibility and adaptability of the intelligent lock in the face of emergencies. In addition, the intelligent lock system 1 in this embodiment realizes two power supply modes, active and passive, by setting the hybrid power supply module 300, converts the mechanical energy during the unlocking process into electric energy, reduces the dependence on the battery, and improves the battery life of the lock.
[0065] The RAFT algorithm (Randomized Aggregation for Fault Tolerance) is a consensus algorithm for distributed systems proposed by Diego Ongaro and John Ousterhout in 2013, aiming to provide a simple, understandable and efficient consensus mechanism for distributed systems. The RAFT algorithm is mainly used in distributed systems where multiple nodes need to reach an agreement on a series of values, even if some nodes fail or messages are lost. The RAFT algorithm ensures that the system can reliably reach a consensus when most nodes are working properly, guaranteeing data consistency and availability.
[0066] Taking the operation and maintenance scenario of the power system as an example, the operator needs to perform an emergency operation on the target cabinet. However, at this time, the Power Harmony gateway is offline due to network interruption and cannot issue an unlocking command through the conventional method. At this time, the WAPI communication network built into each intelligent lock detects the offline status of the gateway module 100, and at the same time forms an autonomous network through the WAPI communication to complete the election of the master node lock within the preset time. Among them, the basis for the election is the priority of each intelligent lock and the current battery status. It is not difficult to understand that the intelligent locks elected as the master node locks are sorted first by the intelligent locks with high priority and sufficient current battery, followed by the intelligent locks with high priority but low current battery, and finally the intelligent locks with low priority but sufficient current battery. The master node lock is responsible for coordinating the subsequent unlocking operations.
[0067] After the master node lock is elected, the operator uses the security intelligent key to initiate an unlocking request to the master node lock. After receiving the request, the master node lock starts the local permission verification process. Based on the security mechanism of the Power Harmony TEE (Trusted Execution Environment), the identity information of the operator is verified. After the verification is passed, the master lock generates a temporary operation token using the national secret SM4 algorithm and stores the encrypted temporary operation token in the local security storage area. The master node lock broadcasts the encrypted temporary operation token to each target lock through the WAPI network. After receiving the temporary operation token, each target lock performs a decryption operation using the pre-stored key. After the decryption is successful, the target lock performs the unlocking action and temporarily stores the unlocking log in the local storage unit. At the same time, the target lock feeds back the unlocking status to the master node lock through the WAPI network, and the master node lock records the log information of the entire unlocking process.
[0068] When the gateway module 100 equipped with the Power HarmonyOS resumes online, the intelligent lock cluster 200 automatically starts the log synchronization program. Each intelligent lock uploads the encrypted logs temporarily stored locally to the master node lock through the Mesh network. After the master node lock aggregates them, all the log information is synchronized to the gateway module 100. The gateway decrypts the log information to restore the detailed process of the offline unlocking operation this time, ensuring the traceability of each offline unlocking operation and providing data support for subsequent operation and maintenance management.
[0069] To improve the battery life of the intelligent lock system 1, in the embodiment of the present invention, a hybrid power supply module 300, a dual-mode switching controller, and a wake-up circuit are provided. The hybrid power supply module 300 includes a mechanical energy-electric energy conversion component, a capacitor, and a replaceable battery component. The mechanical energy-electric energy conversion component drives a micro-generator to generate electric energy through the lock mechanical transmission mechanism. The capacitor is configured to store the electric energy generated by the mechanical energy-electric energy conversion component. The dual-mode switching controller is configured to switch between the active mode and the sleep mode according to the connection state of the gateway module 100, where the operating current in the active mode does not exceed 2 mA, and the standby current in the sleep mode does not exceed 0.5 μA. The wake-up circuit integrates a vibration sensor and a timer and is configured to maintain a listening power consumption not exceeding 10 μA during the inactive period.
[0070] Specifically, during the unlocking process of the intelligent lock, a built-in piezoelectric power generation device is triggered by mechanical actions (such as unlocking rotation). The electric energy generated by each unlocking rotation is about 5 mJ and is stored in the super capacitor inside the intelligent lock through an energy conversion circuit. The energy stored in the super capacitor is mainly used to power the vibration sensor of the lock, reducing the dependence on the replaceable battery component and extending the battery life of the intelligent lock cluster 200. The vibration sensor is used to detect external vibrations when the intelligent lock is in the inactive period. Once an abnormal vibration is detected, the intelligent lock is immediately awakened to the active state, further improving the security and reliability of the intelligent lock.
[0071] In addition, the intelligent lock system 1 in this embodiment also has a dynamic power consumption management function, mainly through the WAPI network in the intelligent lock to monitor the gateway module 100 and the intelligent lock cluster 200 in real time. When it is detected that the gateway module 100 is in the online mode and each intelligent lock is in the active state, each intelligent lock sends a heartbeat packet to the gateway module 100 every 10 seconds to maintain a low-power communication state. At this time, the power consumption of each intelligent lock is maintained at about 2 mA. The heartbeat packet is not only used to confirm the network connection state between each intelligent lock and the gateway module 100, but also carries the corresponding priority information, power information, and status information of each intelligent lock, etc., facilitating the gateway module 100 to centrally manage and monitor each intelligent lock.
[0072] When it is detected that the gateway module 100 is in an offline state or the intelligent lock cluster 200 has no operation requirements for a period of time, each intelligent lock automatically enters the sleep mode. At this time, each intelligent lock turns off the radio frequency module and only keeps the RTC (Real-Time Clock) module running, so that the current power consumption is reduced to no more than 0.5 μA. The RTC module is used to maintain the basic time synchronization function of each intelligent lock, ensuring that the intelligent lock can accurately measure time in the sleep state and providing a time reference for subsequent wake-up operations.
[0073] The RTC module, namely the Real-Time Clock module, is an integrated circuit that usually includes a clock chip and related support circuits. Its main function is to provide accurate real-time time, including information such as year, month, day, hour, minute, and second. Even when the system power is off, it can continue to measure time relying on a backup battery. The RTC module is widely used in many electronic devices, such as computers, industrial control devices, intelligent instruments and meters, automotive electronic systems, smart home devices, etc. In these devices, the RTC module can provide an accurate time reference for the system, and is used for functions such as time stamps for data recording, execution of scheduled tasks, and sequential sorting of events.
[0074] The trusted security module 400 in this embodiment includes a startup verification unit and a runtime protection unit. The startup verification unit is configured to verify the integrity of the hardware firmware, the operating system kernel, and the application program through a three-level hash chain. Specifically, each intelligent lock implements a trusted startup mechanism at the startup stage. Through the hardware security features of Power Harmony TEE, it is ensured that the initial startup environment of the lock is trusted. During the system startup process, from the hardware to the operating system, and then to the application program, the key components of each layer will be strictly verified for their hash (HASH) values. These hash values are pre-stored in the secure storage area of the TEE as trusted benchmarks. Only when the hash value of the current startup environment exactly matches the pre-stored trusted hash value, the system will continue to start, thus ensuring that the entire startup link from hardware to software has not been tampered with, laying a solid foundation for the secure operation of the lock. This static trusted mechanism ensures the trustworthiness of the initial state of the lock from the source, preventing malicious software or tampered firmware from sneaking into the system during the startup stage.
[0075] During runtime, the protection unit ensures that during the operation of each intelligent lock, the hash value of each intelligent lock is calculated regularly through the TEE, and the result is sent to the gateway module 100 for verification. As a trusted third party, the gateway module 100 stores the trusted hash values of each process of the intelligent lock. When the intelligent lock is running, the TEE monitors the status of each process in real time. Once it detects that the hash value of a process has changed, it immediately triggers the verification process. After receiving the hash values sent by each intelligent lock, the gateway module 100 compares them with the pre-stored trusted hash values. If it is found that the hash values do not match, it indicates that the running program of the intelligent lock may have been tampered with or is under an illegal man-in-the-middle attack. The gateway module 100 will immediately take measures, such as issuing an alarm, suspending relevant processes, or triggering the self-protection mechanism of the intelligent lock, such as automatic locking. This dynamic trusted mechanism can monitor the running status of each intelligent lock in real time, detect and block potential security threats in a timely manner, and ensure that the intelligent lock is always in a trusted state during operation.
[0076] By combining the static trusted trusted boot mechanism with the dynamic trusted runtime verification, the local privilege verification based on the Power Harmony TEE not only ensures the security of the entire process from the startup to the operation of the intelligent lock, but also realizes the all-round trusted authentication of the running program of the intelligent lock, effectively resists illegal man-in-the-middle attacks, and provides reliable lock security for the safe operation of the power system.
[0077] An embodiment of the present invention also provides an intelligent lock device, which adopts the above intelligent lock system.
[0078] In another embodiment of the present invention, a control method for an intelligent lock is also provided, as Figure 3 shown. This control method mainly includes the following steps:
[0079] S101. When it is detected that the offline duration of the gateway module 100 exceeds the preset threshold T, trigger the distributed networking process, and elect the master node lock through the improved RAFT consensus algorithm;
[0080] Triggering the distributed networking process means communicating and networking with each intelligent lock through the wireless communication unit configured by the intelligent lock cluster 200 to form an autonomous offline emergency network. Through the elected master node lock, information sharing and collaborative operation of other locks are realized, improving the response flexibility and adaptability of the intelligent lock in the face of emergencies.
[0081] Among them, the election process of the master node lock includes:
[0082] S1011. Establish a multi-dimensional evaluation matrix including node priority, remaining power, and signal strength;
[0083] S1012. Obtain the comprehensive scores of each node through weighted calculation, and select the node with the highest score as the main node lock.
[0084] S102. In the trusted execution environment TEE of the main node lock, verify the unlocking request received. After the verification passes, generate a temporarily operating token encrypted by the SM4 algorithm.
[0085] The specific steps for generating the temporarily operating token include:
[0086] S1021. Generate a token plaintext containing a timestamp, an operation ID, and the address of the target lock in the TEE environment.
[0087] S1022. Encrypt using the SM4-CBC mode and attach the HMAC-SM3 message authentication code.
[0088] S1023. Set a self-destruction timer with a validity period of 60 seconds.
[0089] Among them, by setting a self-destruction timer with a validity period of 60 seconds, the validity of the temporarily operating token within a certain period can be guaranteed. When the preset time is exceeded, the temporarily operating token will be automatically damaged and invalidated, and feedback will be sent to the main node lock. At this time, the main node lock will regenerate a new temporarily operating token to ensure that each target lock can receive the temporarily operating token, further improving the success rate of the unlocking operation.
[0090] S103. Broadcast the temporarily operating token to the target lock through the WAPI secure wireless protocol. After the target lock completes decryption verification, it performs the unlocking operation, and at the same time saves the current operation log information to the log service module.
[0091] S104. When it is detected that the gateway module 100 resumes connection, synchronize the operation log information of the log service module to the gateway module 100 through the mesh network, and perform decryption and archiving processing. Among them, saving the current operation log information to the log service module includes that each intelligent lock encrypts the local operation log using AES-128, and transmits the encrypted log to the main node lock through the frequency hopping mechanism in the mesh network. The main node lock performs timestamp sorting and conflict detection on the log and then generates a data packet to be synchronized.
[0092] The embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0093] Those of ordinary skill in the art will understand that all or some of the steps and systems disclosed in the methods above can be implemented as software, firmware, hardware, and appropriate combinations thereof. Some or all of the physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or as hardware, or as an integrated circuit, such as an application specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic storage devices storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those of ordinary skill in the art, communication media typically includes computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery medium.
[0094] It should also be understood that the various embodiments provided by the embodiments of the present invention can be combined arbitrarily to achieve different technical effects. The above is a specific description of the preferred embodiments of the present invention, but the present invention is not limited to the above embodiments. Those skilled in the art can also make various equivalent deformations or substitutions without departing from the spirit of the present invention.
Claims
1. An intelligent lock system, characterized in that, Including: A gateway module, equipped with an intelligent terminal IoT operating system, configured to perform lightweight edge computing tasks and support multi-protocol adaptive communication including TCP / IP protocol, MQTT protocol, and LoRa protocol; An intelligent lock cluster, including multiple intelligent locks with wireless communication units. Each of the intelligent locks further includes a distributed decision-making unit and a dynamic power consumption management unit. The wireless communication unit is configured to establish a mesh-type self-organizing network when the gateway module is offline; A hybrid power supply module, including a mechanical energy-electric energy conversion component, a capacitor, and a replaceable battery component. The mechanical energy-electric energy conversion component drives a micro-generator to generate electric energy through a lock mechanical transmission mechanism, and the capacitor is configured to store the electric energy generated by the mechanical energy-electric energy conversion component; A trusted security module, built based on the trusted execution environment TEE, configured to perform hardware-level static trusted boot verification and dynamic runtime security verification.
2. An intelligent lock system according to claim 1, wherein The distributed decision-making unit specifically includes: A consensus algorithm execution module, configured to, when detecting that the gateway module is offline, construct a distributed decision-making cluster using an improved RAFT consensus algorithm; A primary node election module, configured to elect a primary node lock within a response time of no more than 3 seconds. The primary node lock performs system management functions including permission allocation, log synchronization, and operation conflict coordination; A log management module, used to store current operation log information.
3. An intelligent lock system according to claim 1, characterized in that, The dynamic power consumption management unit includes: A dual-mode switching controller, configured to switch between an active mode and a sleep mode according to the connection status of the gateway module. The working current in the active mode does not exceed 2 mA, and the standby current in the sleep mode does not exceed 0.5 μA; A wake-up circuit, integrated with a vibration sensor and a timer, configured to maintain a listening power consumption of no more than 10 μA during the inactive period.
4. An intelligent lock system according to claim 1, characterized in that, The trusted security module includes: A boot verification unit, configured to verify the integrity of the hardware firmware, the operating system kernel, and the application program through a three-level hash chain; A runtime protection unit, configured to perform a process space hash calculation every 30 seconds and compare it with a pre-stored reference value in the gateway module for verification.
5. A method for controlling an intelligent lock, applied to an intelligent lock system according to any one of the above claims 1-4, characterized in that, Including the following steps: S101. When detecting that the offline duration of the gateway module exceeds a preset threshold T, trigger a distributed networking process, and elect a primary node lock through an improved RAFT consensus algorithm; S102. In the trusted execution environment TEE of the primary node lock, perform permission verification on the received unlocking request. After verification passes, generate a temporary operation token encrypted by the SM4 algorithm; S103. Broadcast the temporary operation token to the target lock through the WAPI secure wireless protocol. After the target lock completes decryption verification, perform the unlocking operation, and at the same time save the current operation log information to the log service module; S104. When detecting that the gateway module resumes connection, synchronize the operation log information of the log service module to the gateway module through the mesh network, and perform decryption and archiving processing.
6. The intelligent lock control method according to claim 6, wherein The main node lock selection process includes: Establish a multi-dimensional evaluation matrix including node priority, remaining power, and signal strength; Obtain the comprehensive scores of each node through weighted calculation, and select the node with the highest score as the main node lock.
7. An intelligent lock control method according to claim 6, characterized in that, The steps for generating the temporary operation token include: Generate a plaintext token including a timestamp, an operation ID, and the target lock address in the TEE environment; Encrypt it using the SM4-CBC mode and append the HMAC-SM3 message authentication code; Set a self-destruct timer with a validity period of 60 seconds.
8. An intelligent lock control method according to claim 6, characterized in that, The step of saving the current operation log information to the log service module includes: Each intelligent lock encrypts the local operation log using AES-128; Transmit the encrypted log to the main node lock in the mesh network through a frequency hopping mechanism; The main node lock generates a data packet to be synchronized after timestamp sorting and conflict detection of the logs.
9. The intelligent lock control method according to claim 6, wherein The dynamic power consumption management unit includes: Maintain a heartbeat packet with a 10-second cycle when the gateway module is in the online state; When the gateway module is in the offline state, turn off the radio frequency transmission module and only retain the low-frequency receiving circuit; Activate the complete communication module when a predetermined vibration feature is detected or the timed wake-up time window is reached.
10. An intelligent lock device, characterized in that, An intelligent lock system according to any one of claims 1-4 above is adopted.
Citation Information
Patent Citations
MESH network-based door lock control system
CN106570957A
Access control method and system based on Bluetooth MESH networking core technology
CN107393069A
Bluetooth repeater, intelligent lock, intelligent lock system and networking method
CN109714741A
Safe starting method and device, electronic equipment and storage medium
CN114880048A
Raft consensus mechanism improvement method based on node past behavior analysis
CN115022022A