Remote intelligent lock control method based on cloud platform

Through the remote intelligent lock control method of the cloud platform, combining multi-band acoustic signal feedback and real-time signal quality indicators, the optimal transmission path is dynamically calculated, which solves the signal instability problem of traditional intelligent locks in complex environments, and realizes the reliable transmission and security improvement of control instructions.

CN120472567AActive Publication Date: 2025-08-12HEFEI ZHIHUI SPACE TECH CO LTD

Patent Information

Application Number
CN202510553598.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-08-12
Estimated Expiration
2045-04-29

AI Technical Summary

Technical Problem

Traditional remote intelligent locks are unstable in complex electromagnetic environments or obstruction scenarios, and the communication interruption rate is high, making it difficult to ensure the reliable transmission of control instructions.

Method used

The remote intelligent lock control method based on the cloud platform, through triple verification of user identity legality, operation permission grading and instruction compliance, combined with multi-band acoustic signal feedback and real-time signal quality indicators, the optimal transmission path is dynamically calculated, dynamic encryption instructions are generated and sent through the final communication path.

Benefits of technology

In complex electromagnetic environments or obstacle blocking scenarios, the reliable transmission of control instructions is ensured, the communication interruption rate is reduced, the security and stability of the system are enhanced, and the needs of multiple users are adapted to the needs of multiple users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120472567A_ABST
    Figure CN120472567A_ABST
Patent Text Reader

Abstract

The invention provides a remote intelligent lock control method based on a cloud platform, and relates to the technical field of artificial intelligence, and the method comprises the steps that the cloud platform issues a sound wave signal emission instruction to a target intelligent lock, and triggers the intelligent lock to send multi-band sound wave signals to a preset auxiliary signal enhancement device deployment position A and a preset auxiliary signal enhancement device deployment position B; and the cloud platform receives sound wave feedback signals returned by the position A and the position B, calculates a final communication path based on signal propagation time delay, frequency band interference intensity and attenuation parameters in combination with a real-time signal quality index reported by the remote communication module, and sends a dynamic encryption instruction to the remote communication module through the final communication path. According to the method, the optimal transmission path is dynamically calculated, the traditional single channel transmission limitation is broken through, reliable transmission of the control instruction can still be guaranteed in a complex electromagnetic environment or an obstacle shielding scene, and the communication interruption rate is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology, and in particular to a remote smart lock control method based on a cloud platform. Background Art

[0002] Some traditional remote smart locks rely on a single wireless communication protocol such as Wi-Fi and Bluetooth. Their physical layer characteristics have some defects in complex environments:

[0003] For example, Wi-Fi (2.4GHz / 5GHz): The 2.4GHz band shares spectrum resources with devices such as microwave ovens and cordless phones. In high-density residential environments (such as apartment buildings with more than 10 households per floor), the Wi-Fi channel overlap rate of adjacent residents can reach over 60%, causing the signal-to-noise ratio (SNR) to drop below -20dB and the bit error rate (BER) to soar to 10. -3 Level (normal communication requires BER < 10 -5 Although the 5GHz frequency band is more resistant to interference, it has penetration loss, and concrete walls attenuate it by 15-20dB per floor, resulting in the smart lock signal strength for residents on the third floor and above being lower than -75dBm (the Wi-Fi communication critical value is -80dBm).

[0004] It operates in the 2.4GHz ISM band and uses frequency hopping technology to combat interference, but its transmission range is limited (theoretical maximum 100 meters, actual indoor environment <15 meters). In a metal-framed loft apartment, the steel beams reflect up to 25dB of Bluetooth signal loss, and signal multipath effects cause a packet loss rate (PLR) exceeding 30%, requiring the unlock command to be retransmitted at least five times before it is successful. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to provide a remote smart lock control method based on a cloud platform, which dynamically calculates the optimal transmission path. This solution breaks through the limitations of traditional single-channel transmission and can still ensure the reliable transmission of control instructions in complex electromagnetic environments or obstacle obstruction scenarios, thereby reducing the communication interruption rate.

[0006] In order to solve the above technical problems, the technical solutions of the present invention are as follows:

[0007] A remote smart lock control method based on a cloud platform, the method comprising:

[0008] Step S1: The user terminal sends a remote control request to the cloud platform, which carries user authentication information, a unique identifier of the target smart lock, and an operation instruction type;

[0009] Step S2: After receiving the remote control request, the cloud platform performs a triple verification of the legitimacy of the user identity, the operating permission scope of the target smart lock, and the compliance of the operation instruction type based on the pre-stored user-smart lock binding relationship and permission classification strategy;

[0010] Step S3: If the triple verification passes, the cloud platform generates a dynamic encrypted instruction containing a timestamp, the operation instruction type, and the validity period of the temporary permission, and determines the associated remote communication module based on the unique identifier of the target smart lock;

[0011] Step S4: The cloud platform sends an acoustic signal transmission instruction to the target smart lock, triggering the smart lock to send multi-band acoustic signals to the preset auxiliary signal enhancement device deployment positions A and B; the cloud platform receives the acoustic feedback signals returned by positions A and B, and calculates the final communication path based on the signal propagation delay, frequency band interference intensity and attenuation parameters, combined with the real-time signal quality indicators reported by the remote communication module, and the dynamic encryption instruction is sent to the remote communication module through the final communication path.

[0012] Furthermore, after receiving the remote control request, the cloud platform performs a triple verification of the legitimacy of the user's identity, the scope of the target smart lock's operating permissions, and the compliance of the operation instruction type based on the pre-stored user-smart lock binding relationship and permission classification strategy, including:

[0013] Step S31: Parse the remote control request and verify whether the request contains the three required fields: user identity information, target smart lock unique identifier, and operation instruction type. If any field is missing, the verification is terminated and an error response is returned;

[0014] Step S32: Convert the user identity information, the target smart lock unique identifier, and the operation instruction type into a standard data format to generate a structured request object;

[0015] Step S33: Based on the user identity information in the structured request object, the user database is queried to match a valid account. If the account has enabled the enhanced verification policy, a secondary authentication process is triggered. At the same time, the account status and historical login behavior characteristics are analyzed to intercept abnormal login requests and generate a first verification result.

[0016] Step S34: Based on the first verification result and the unique identifier of the target smart lock, the user-lock binding relationship table is retrieved for a list of locks bound to the user. If the target lock does not exist in the list, the verification is terminated. Based on the user role identifier and the operation instruction type, the corresponding operation permission status is matched in the permission matrix. If the permission is exceeded, an audit log containing the violation record of the operation type is generated and a second verification result is returned.

[0017] Step S35: Based on the second verification result and combined with the current environmental context data, if the operation instruction involves the granting of temporary permissions, the validity period and the remaining available times of the temporary permissions are checked, and the final operation scope verification conclusion is generated to complete the triple verification.

[0018] Furthermore, the cloud platform sends an acoustic signal transmission instruction to the target smart lock, triggering the smart lock to send multi-band acoustic signals to the preset auxiliary signal enhancement device deployment positions A and B; the cloud platform receives the acoustic feedback signals returned by positions A and B, and calculates the final communication path based on the signal propagation delay, frequency band interference intensity and attenuation parameters, combined with the real-time signal quality indicators reported by the remote communication module, and sends the dynamic encryption instruction to the remote communication module through the final communication path, including:

[0019] Step S41: Based on the final operation scope verification conclusion, the cloud platform generates a unique timestamp and encapsulates the operation instruction type and the temporary permission validity period into plain text instruction data;

[0020] Step S42: The cloud platform calls a pre-installed hardware security module, generates a temporary symmetric encryption key based on the current session parameters, encrypts the plaintext instruction data to generate ciphertext, and binds the key identifier to the ciphertext to establish a key association;

[0021] Step S43: The cloud platform uses the private key in the hardware security module to digitally sign the ciphertext data and generate a dynamic encryption instruction containing a timestamp, ciphertext and signature;

[0022] Step S44: The cloud platform calculates the interference intensity distribution and path attenuation parameters of the multi-band sound waves in the environment based on the sound wave feedback signals returned by location A and location B, and builds a communication path quality assessment model based on the signal strength, bit error rate, and network delay indicators reported in real time by the remote communication module;

[0023] Step S45: The cloud platform selects the communication link with interference intensity lower than the preset threshold and delay meeting the operation instruction requirements as the final communication path based on the communication path quality evaluation model, and sends the dynamic encryption instruction to the remote communication module of the target smart lock through the final communication path.

[0024] Furthermore, in step S41, based on the final operation scope verification conclusion, the cloud platform generates a unique timestamp and encapsulates the operation instruction type and the temporary permission validity period to form plain text instruction data, including:

[0025] Step S411: Based on the final operation range verification conclusion, the cloud platform obtains the system predefined operation code corresponding to the operation instruction type and generates a unique timestamp with millisecond-level precision and random number extension based on Coordinated Universal Time;

[0026] Step S412: Convert the temporary permission validity period into a time interval format of a start time and an end time, and perform field standardization processing with the operation instruction type and the timestamp to generate a structured data unit;

[0027] Step S413: Perform integrity check on the operation instruction type field, timestamp field, and validity period field in the structured data unit. If there is an undefined operation code or a time interval conflict, the data reconstruction process is triggered;

[0028] Step S414: Encapsulate the verified structured data unit into a plaintext instruction data packet including a header identifier, a data payload, and a check code according to a preset protocol.

[0029] Furthermore, in step S42, the cloud platform calls a preset hardware security module, generates a temporary symmetric encryption key based on the current session parameters, encrypts the plaintext instruction data to generate ciphertext, and binds the key identifier to the ciphertext to establish a key association, including:

[0030] Step S421: The cloud platform extracts the communication protocol version of the current session, the unique identifier of the target smart lock, and the timestamp as session parameters to generate a key derivation seed;

[0031] Step S422: calling the preset key generation interface of the hardware security module, inputting the key derivation seed and the preset hardware-level random number, and generating a temporary symmetric encryption key bound to the current session;

[0032] Step S423: Using a temporary symmetric encryption key to encrypt the plaintext instruction data packet in blocks, using padding rules to resist length analysis attacks, and generating an encrypted ciphertext data block sequence;

[0033] Step S424: associate and encode the key identifier assigned by the hardware security module with the ciphertext data block sequence to generate binding metadata including the key version number and encryption algorithm identifier;

[0034] Step S425: Append the binding metadata to the ciphertext header to form a complete ciphertext data unit, and mark the life cycle of the temporary symmetric encryption key as a single-time valid state and store it in the key management audit log.

[0035] Furthermore, in step S43, the cloud platform uses the private key in the hardware security module to digitally sign the ciphertext data, generating a dynamic encryption instruction containing a timestamp, ciphertext, and signature, including:

[0036] Step S431: extracting the ciphertext header and ciphertext data block sequence from the complete ciphertext data unit, and associating them with the timestamp to generate the original data digest;

[0037] Step S432: calling the signature engine of the hardware security module, using the private key to perform asymmetric encryption operation on the original data digest to generate digital signature data;

[0038] Step S433: Assemble the digital signature data, the timestamp, the ciphertext header, and the ciphertext data block sequence according to a preset format to generate a complete dynamic encryption instruction including a protocol version identifier and an operation type code;

[0039] Step S434: Perform hash verification on the dynamic encryption instruction. If the verification fails, the key rotation mechanism is triggered to regenerate a temporary symmetric encryption key and repeat steps S42 to S43;

[0040] Step S435: Logically bind the dynamic encryption instruction with the link identifier of the final communication path to match the instruction transmission process with the path selection result.

[0041] Furthermore, in step S44, the cloud platform calculates the interference intensity distribution and path attenuation parameters of the multi-band sound waves in the environment based on the sound wave feedback signals returned from location A and location B, and constructs a communication path quality assessment model based on the signal strength, bit error rate, and network delay indicators reported in real time by the remote communication module, including:

[0042] Step S441: Analyze the acoustic feedback signals returned from position A and position B to extract the propagation delay, phase offset, and signal amplitude parameters of the multi-band acoustic waves;

[0043] Step S442: Calculate the Wi-Fi frequency band interference intensity distribution map in the environment based on the frequency band distribution and signal amplitude parameters of the multi-band sound waves, and analyze the attenuation coefficient of each path;

[0044] Step S443: Receive communication quality indicators reported in real time by the remote communication module, including signal strength, bit error rate, and network delay data, and associate them with the physical location of the target smart lock for regional cluster analysis;

[0045] Step S444: performing multi-dimensional feature fusion on the interference intensity distribution map, the path attenuation coefficient, and the clustered communication quality index to generate a communication quality feature vector including a frequency band weight factor and a path stability score;

[0046] Step S445: Based on the preset communication path evaluation rule set, the communication quality feature vectors are prioritized and dynamically threshold matched to construct a communication path quality evaluation model that supports multi-objective optimization.

[0047] Furthermore, step S442: based on the frequency band distribution and signal amplitude parameters of the multi-band sound waves, a Wi-Fi frequency band interference intensity distribution map in the environment is calculated, and the attenuation coefficient of each path is analyzed, including:

[0048] Step S4421: Decomposing the frequency distribution of the multi-band sound waves according to a preset Wi-Fi channel frequency range, and extracting the sound wave frequency bands that overlap with the Wi-Fi frequency bands as interference detection targets;

[0049] Step S4422: Calculate the difference between the acoustic signal energy in each target frequency band and the noise energy in the corresponding Wi-Fi frequency band based on the signal amplitude parameter to generate a real-time interference strength index.

[0050] Step S4423: Parse the acoustic wave feedback signal data packets at position A and position B to extract the acoustic wave propagation delay, phase offset, and received signal strength difference; call a preset acoustic wave propagation velocity model to calculate the deviation between the actual propagation velocity and the theoretical velocity of the acoustic wave path based on the propagation delay and the physical distance between positions A and B; calculate the reflection loss coefficient caused by the number of reflections in the path based on the phase offset and received signal strength difference, combined with the acoustic wave frequency characteristics; based on the actual propagation velocity deviation and the reflection loss coefficient, dynamically correct the attenuation effect of ambient humidity and temperature parameters on the acoustic wave energy using the dielectric absorption attenuation formula to generate the dielectric absorption attenuation coefficient;

[0051] Step S4424: performing weighted fusion of the real-time interference intensity index, the reflection loss, and the medium absorption attenuation coefficient to generate an attenuation coefficient matrix including the path priority score and the anti-interference capability;

[0052] Step S4425: Based on the attenuation coefficient matrix and the physical location topology of the target smart lock, a multi-dimensional Wi-Fi frequency band interference intensity distribution map covering the target area is drawn, and high interference risk path identifiers are marked.

[0053] Furthermore, step S443: receiving communication quality indicators reported in real time by the remote communication module, including signal strength, bit error rate and network delay data, and correlating them with the physical location of the target smart lock to perform regional cluster analysis, including:

[0054] Step S4431: The cloud platform receives the original data of the communication quality indicators reported by the remote communication module, and analyzes the numerical range and acquisition timestamp of the signal strength, bit error rate and network delay;

[0055] Step S4432: Based on the physical location coordinates of the target smart lock, the communication quality index is mapped to the preset geographic grid division rule to generate a communication quality dataset with geographic tags;

[0056] Step S4433: Clean the communication quality data set for outliers, remove data points that exceed the device physical performance threshold or network protocol specifications, and form standardized input data;

[0057] Step S4434: The cloud platform maps the signal strength and network delay in the standardized input data into coordinate points in the multidimensional feature space, and defines the cluster core object based on the preset neighborhood radius threshold and the minimum sample number threshold; traverses the coordinate points in the multidimensional feature space, expands the neighborhood range of the core object according to the density accessibility judgment rule, and forms an initial geographic area cluster; filters the noise data of the coordinate points in the initial geographic area cluster, removes isolated points with a density lower than the preset threshold, and re-executes the neighborhood expansion to optimize the cluster boundary; verifies whether the variance of the signal strength and network delay in the optimized geographic area cluster meets the preset communication stability condition. If the condition is exceeded, the neighborhood radius dynamic adjustment mechanism is triggered; assigns a unique identifier to the finally divided geographic area cluster, and associates it with the physical location coordinates of the target smart lock within its coverage area to generate a clustering result of the geographic area cluster with communication quality consistency characteristics;

[0058] Step S4435: Associating and mapping the clustering results of the geographical area clusters with the Wi-Fi frequency band interference intensity distribution map to generate a cluster analysis result including regional communication quality level labels.

[0059] Furthermore, step S45: the cloud platform selects a communication link whose interference intensity is lower than a preset threshold and whose delay meets the operation instruction requirements as the final communication path based on the communication path quality evaluation model, and sends the dynamic encryption instruction to the remote communication module of the target smart lock through the final communication path, including:

[0060] Step S451: Obtain interference strength values, path stability scores, and network delay data of all candidate communication links from the communication path quality assessment model, and extract their corresponding physical path identifiers;

[0061] Step S452: Based on the preset interference intensity threshold and the delay tolerance parameter corresponding to the operation instruction type, a set of candidate communication links whose interference intensity is lower than the threshold and whose delay meets the instruction real-time requirement is screened;

[0062] Step S453: Based on the path stability scores of the candidate communication link sets and the communication quality level labels of the geographical area cluster sets, the links are prioritized in terms of anti-interference capability and reliability;

[0063] Step S454: Select the communication link with the highest priority as the final communication path, and verify whether its current connection status with the target smart lock remote communication module is active and available;

[0064] Step S455: Inject the dynamic encryption instruction into the data transmission queue of the final communication path and attach a path selection audit tag.

[0065] The above solution of the present invention includes at least the following beneficial effects:

[0066] Through the triple verification mechanism of user identity legitimacy verification, operation authority hierarchical verification and instruction compliance, a full-link security barrier is built from user to device, effectively preventing the risks of illegal access, unauthorized operation and malicious instruction injection. Dynamic encryption instructions are combined with timestamps and temporary validity period design to achieve "one-time one-key" encrypted communication, eliminate instruction replay attacks, and enhance the system's anti-cracking capabilities.

[0067] By analyzing the propagation delay, frequency band interference and attenuation characteristics of the acoustic wave feedback signals at deployment locations A / B, and combining them with the signal quality indicators (such as signal-to-noise ratio and packet loss rate) reported in real time by the remote communication module, the optimal transmission path is dynamically calculated. This solution breaks through the limitations of traditional single-channel transmission and can still ensure the reliable transmission of control commands in complex electromagnetic environments or scenarios where obstacles are blocked, thereby reducing the communication interruption rate.

[0068] The multi-band detection mechanism of acoustic signals can actively perceive the characteristics of physical spaces (such as wall materials and spatial layout), and combined with cloud platform algorithms to adjust communication strategies in real time, enabling the system to adapt to the environment. The real-time signal quality feedback mechanism of the remote communication module forms a "perception-decision-execution" closed loop, ensuring that the optimal transmission path is always selected under dynamic network conditions.

[0069] Pre-existing binding relationships and permission classification strategies support differentiated control in multi-user scenarios (for example, administrators can set temporary visitor permissions), meeting the needs of multiple scenarios such as home, office, and sharing economy. Compliance verification of operation instruction types can prevent misoperation (such as unauthorized unlocking instructions) and improve system fault tolerance.

[0070] As an auxiliary communication means, acoustic signals can serve as a backup transmission channel when wireless signals are interfered with or the network is interrupted, enhancing system robustness. The dynamic path selection mechanism can automatically bypass faulty nodes or high-interference areas to ensure the accessibility of critical control instructions. BRIEF DESCRIPTION OF THE DRAWINGS

[0071] Figure 1 This is a flow chart of a remote smart lock control method based on a cloud platform provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0072] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art.

[0073] like Figure 1As shown, an embodiment of the present invention provides a remote smart lock control method based on a cloud platform, the method comprising the following steps:

[0074] Step S1: The user terminal sends a remote control request to the cloud platform, which carries user authentication information, a unique identifier of the target smart lock, and an operation instruction type;

[0075] Step S2: After receiving the remote control request, the cloud platform performs a triple verification of the legitimacy of the user identity, the operating permission scope of the target smart lock, and the compliance of the operation instruction type based on the pre-stored user-smart lock binding relationship and permission classification strategy;

[0076] Step S3: If the triple verification passes, the cloud platform generates a dynamic encrypted instruction containing a timestamp, the operation instruction type, and the validity period of the temporary permission, and determines the associated remote communication module based on the unique identifier of the target smart lock;

[0077] Step S4: The cloud platform sends an acoustic signal transmission instruction to the target smart lock, triggering the smart lock to send multi-band acoustic signals to the preset auxiliary signal enhancement device deployment positions A and B; the cloud platform receives the acoustic feedback signals returned by positions A and B, and calculates the final communication path based on the signal propagation delay, frequency band interference intensity and attenuation parameters, combined with the real-time signal quality indicators reported by the remote communication module, and the dynamic encryption instruction is sent to the remote communication module through the final communication path.

[0078] In an embodiment of the present invention, in step S1, the user does not need to be near the smart lock to operate, and can send a control request to the cloud platform anytime and anywhere through a terminal device (such as a mobile phone), which greatly improves the convenience of using the smart lock. For example, if the user forgets to lock the door while going out, he can immediately send a door lock instruction through the mobile phone. Determine the control target and intention: Carrying the unique identifier and operation instruction type of the target smart lock allows the cloud platform to accurately identify which smart lock the user wants to control and the specific operation requirements, avoiding control confusion. For example, in a large apartment building, there are many smart locks, and the unique identifier can ensure that the instruction is accurately delivered to the target lock. User identity authentication information is the basis for subsequent identity legitimacy verification, ensuring that only legitimate users can initiate control requests, thereby enhancing the security of the system.

[0079] Step S2 verifies the legitimacy of the user's identity to prevent illegal users from impersonating legitimate users to initiate control requests, thereby preventing the smart lock from being illegally operated. For example, it prevents hackers from controlling the smart lock by stealing user information. Based on the pre-stored user-smart lock binding relationship and the authority classification strategy, the operating authority scope of the target smart lock is verified, and refined management of different operating authorities for different smart locks is achieved. For example, the owner can have all operating authorities, while temporary visitors may only have unlocking authorities. The compliance of the operation instruction type is verified to ensure that the operation instructions sent by the user comply with the rules set by the system. For example, the system may prohibit certain operations during a specific time period, and illegal operations can be avoided through verification.

[0080] Step S3, generates a dynamic encryption instruction, combined with a timestamp and a temporary permission validity period, making the instruction difficult to crack and forge. Even if the instruction is intercepted during transmission, due to its dynamic nature and timeliness, the attacker cannot use the instruction to perform illegal operations. The setting of the temporary permission validity period meets the needs of some scenarios where smart locks are used temporarily. For example, temporary visitors have the right to unlock the door within a specific time period, and the permission will automatically expire after the time period, which improves security. The remote communication module associated with the target smart lock is determined based on its unique identifier to ensure that the dynamic encryption instruction can be sent to the target smart lock accurately, thereby ensuring the accuracy of communication.

[0081] Step S4, by sending multi-band acoustic wave signals and analyzing the feedback signals, combined with real-time signal quality indicators, it is possible to comprehensively consider factors such as signal propagation delay, frequency band interference intensity and attenuation parameters to calculate the optimal final communication path. In this way, paths with large signal interference and severe attenuation can be avoided, improving the stability and reliability of communication. For example, in a complex building environment, find the path with the strongest signal and the least interference to transmit instructions. By using multi-band acoustic wave signals and auxiliary signal enhancement equipment, the system can work normally even in a complex electromagnetic environment. Even in areas with a large amount of electromagnetic interference, the normal transmission of instructions can be guaranteed by adjusting the communication path. By dynamically adjusting the communication path, the interference and attenuation during signal propagation are reduced, thereby improving the signal quality, reducing the error rate of instruction transmission, and ensuring that the smart lock can accurately receive and execute instructions.

[0082] In another preferred embodiment of the present invention, in step S1 above, the user terminal sends a remote control request to the cloud platform. The request carries user authentication information, a unique identifier of the target smart lock, and an operation instruction type, which may include:

[0083] The user opens the smart lock control app on a terminal device (such as a mobile app or a website) and enters the pre-registered account and password. The app encrypts this information (for example, using a common hash algorithm such as SHA-256) to ensure security during transmission.

[0084] If biometric technologies such as fingerprint or facial recognition are used, the terminal device's sensor will collect the user's fingerprint or facial image data. This data will be locally extracted and encrypted to form encrypted information representing the user's identity.

[0085] When a user successfully logs in for the first time, the cloud platform generates a unique token for the user. When the user subsequently initiates a request, the terminal device reads the token from local storage as authentication information.

[0086] The user manually enters the number or other unique identification information of the target smart lock in the control application. For example, in a shared apartment scenario, the user may need to enter the smart lock number corresponding to the room. If the terminal device and the smart lock support near-field communication (such as Bluetooth), the terminal can automatically scan nearby smart locks and obtain their unique identifiers. For example, when the user enters the vicinity of the home door, the mobile phone automatically identifies the identification of the smart lock at the door through Bluetooth connection. The user selects the type of operation instruction by clicking the corresponding button or option on the operation interface of the terminal application. Common operation instruction types include unlocking, locking, and viewing unlocking records. For example, if the user clicks the "Unlock" button, the application will determine that the operation instruction type is unlocking. For some terminal applications that support voice interaction, users can speak operation instructions through voice, such as "open the door lock", and the application will convert the voice information into the corresponding operation instruction type.

[0087] In a preferred embodiment of the present invention, after receiving a remote control request, the cloud platform performs a triple verification of the legitimacy of the user's identity, the scope of the target smart lock's operating permissions, and the compliance of the operation instruction type based on the pre-stored user-smart lock binding relationship and the permission classification policy, including:

[0088] Step S31: Parse the remote control request and verify whether the request contains the three required fields of user identity information, target smart lock unique identifier and operation instruction type. If any field is missing, the verification is terminated and an error response is returned. Specifically, after the cloud platform receives the remote control request, it first parses it according to the data format adopted by the request (such as JSON, XML, etc.). For requests in JSON format, use the corresponding JSON parsing library to convert the request data into an operable data object; check whether the three fields of user identity information, target smart lock unique identifier and operation instruction type are included in the parsed data object. The verification can be completed by judging whether the fields exist and are not empty. If any field is found to be missing, the cloud platform immediately terminates the subsequent verification process and returns a response containing an error message to the user terminal, such as "Required fields are missing in the request. Please check and resend."

[0089] Step S32: Convert the user identity information, the target smart lock unique identifier, and the operation instruction type into a standard data format to generate a structured request object. Specifically, since the request data sent by the user terminal may have different formats, the cloud platform needs to convert the user identity information, the target smart lock unique identifier, and the operation instruction type into a unified standard data format. For example, the user identity information is uniformly converted to a string type, and the target smart lock unique identifier is converted to a fixed-length encoding format. The converted data is organized according to a specific structure to generate a structured request object. This object can be a custom class instance containing attributes such as the user identity information, the target smart lock unique identifier, and the operation instruction type.

[0090] Step S33: Based on the user identity information in the structured request object, the user database is queried to match a valid account. If the account has enabled the enhanced verification policy, a secondary authentication process is triggered. At the same time, the account status and historical login behavior characteristics are analyzed to intercept abnormal login requests and generate a first verification result. Specifically, the following steps are performed: using the user identity information in the structured request object to query the user database to find a valid account that matches it. If a matching account is found, the subsequent verification is continued. If not found, the user identity is determined to be illegal and a first verification result of failed verification is generated. For accounts with enhanced verification policy enabled, the cloud platform will trigger a secondary authentication process, which includes sending a verification code to the user's mobile phone, requiring the user to perform fingerprint or facial recognition, etc. Only when the user passes the secondary authentication will the subsequent verification continue. The account status (such as whether it is frozen, expired, etc.) and historical login behavior characteristics (such as login time, login location, etc.) are analyzed. If abnormal login behavior is found, such as logging in from a different location or multiple login attempts in a short period of time, the cloud platform will intercept the request and generate a first verification result of failed verification.

[0091] Step S34: Based on the first verification result, combined with the unique identifier of the target smart lock, the list of locks bound to the user is retrieved from the user-lock binding relationship table. If the target lock does not exist in the list, the verification is terminated; based on the user role identifier and the operation instruction type, the corresponding operation permission status is matched in the authority matrix. If the authority is exceeded, an audit log containing the operation type violation record is generated and a second verification result is returned, specifically including: if the first verification result is verification passed, the cloud platform retrieves the list of locks bound to the user from the user-lock binding relationship table based on the unique identifier of the target smart lock. Check whether the target smart lock exists in the list. If not, the verification process is terminated and an error response is returned to the user terminal. Based on the user role identifier and the operation instruction type, the corresponding operation permission status is searched in the authority matrix. The authority matrix records the permission status of different user roles for different operation instructions. If the operation instruction exceeds the user's authority range, the cloud platform will generate an audit log containing the operation type violation record, recording the violating user, operation instruction type, time and other information, and generate a second verification result of verification failure.

[0092] Step S35: Based on the second verification result and in combination with the current environmental context data, if the operation instruction involves granting temporary permissions, the validity period and remaining available times of the temporary permissions are checked, and a final operation scope verification conclusion is generated to complete the triple verification process. Specifically, the current environmental context data may include information such as time, location, and system status. During the final verification, the cloud platform will make a comprehensive judgment based on this data. If the operation instruction involves granting temporary permissions, the cloud platform will check the validity period and remaining available times of the temporary permissions. If the temporary permissions have expired or the remaining available times are zero, the operation instruction is deemed illegal and a final operation scope verification conclusion indicating verification failure is generated. After the verification steps above are completed, the cloud platform generates the final operation scope verification conclusion, completing the triple verification process. If the verification passes, the cloud platform will continue with subsequent operations, such as generating dynamic encryption instructions. If the verification fails, a corresponding error response will be returned to the user terminal.

[0093] In an embodiment of the present invention, by verifying required fields, the cloud platform ensures that requests received contain the key information required for subsequent verification, avoiding verification errors or system anomalies caused by missing data. Requests with missing fields are detected and processed early in the verification process, avoiding unnecessary subsequent verification operations and improving overall verification efficiency. Converting request data to a standard data format enables the cloud platform to more easily process and compare requests sent by different user terminals, improving the accuracy and consistency of data processing. Generating a structured request object provides a clear data structure for subsequent verification steps, making code implementation more concise and easier to maintain. By querying the user database, triggering a secondary authentication process, and analyzing account status and historical login behavior characteristics, the cloud platform effectively prevents illegal user logins and operations, ensuring the security of user accounts. It can promptly detect and intercept abnormal login requests, reducing security risks and protecting the interests of users and the system. By retrieving the user-lock binding relationship table and permission matrix, it ensures that users can only perform legal operations on their bound smart locks, preventing unauthorized operations. Generating an audit log containing records of operation type violations provides an important basis for subsequent security audits and management, helping to discover and address potential security issues. For operation instructions involving the granting of temporary permissions, the validity period and the remaining available times are verified to ensure the rational use of temporary permissions and avoid the abuse of temporary permissions. Verification is performed in combination with the current environmental context data, making the verification results more consistent with the actual situation and improving the accuracy and security of verification.

[0094] In a preferred embodiment of the present invention, the cloud platform sends an acoustic signal transmission instruction to the target smart lock, triggering the smart lock to send a multi-band acoustic signal to the preset auxiliary signal enhancement device deployment location A and location B; the cloud platform receives the acoustic feedback signals returned by location A and location B, and calculates the final communication path based on the signal propagation delay, frequency band interference intensity and attenuation parameters, combined with the real-time signal quality index reported by the remote communication module, and sends the dynamic encryption instruction to the remote communication module through the final communication path, including:

[0095] Step S41: Based on the final operation scope verification conclusion, the cloud platform generates a unique timestamp and encapsulates the operation instruction type and the temporary permission validity period into plain text instruction data;

[0096] Step S42: The cloud platform calls a pre-installed hardware security module, generates a temporary symmetric encryption key based on the current session parameters, encrypts the plaintext instruction data to generate ciphertext, and binds the key identifier to the ciphertext to establish a key association;

[0097] Step S43: The cloud platform uses the private key in the hardware security module to digitally sign the ciphertext data and generate a dynamic encryption instruction containing a timestamp, ciphertext and signature;

[0098] Step S44: The cloud platform calculates the interference intensity distribution and path attenuation parameters of the multi-band sound waves in the environment based on the sound wave feedback signals returned by location A and location B, and builds a communication path quality assessment model based on the signal strength, bit error rate, and network delay indicators reported in real time by the remote communication module;

[0099] Step S45: The cloud platform selects the communication link with interference intensity lower than the preset threshold and delay meeting the operation instruction requirements as the final communication path based on the communication path quality evaluation model, and sends the dynamic encryption instruction to the remote communication module of the target smart lock through the final communication path.

[0100] In the embodiment of the present invention, a unique timestamp is bound to the validity period of temporary permissions to establish a "time-permission" dual-factor constraint, effectively resisting replay attacks (ReplayAttack). Even if the ciphertext is intercepted, the instruction will automatically become invalid after the timeout, significantly reducing the risk of unauthorized operation; a hardware security module (HSM) is used to generate temporary symmetric keys to achieve physical isolation protection for key generation, storage, and use. The key identifier binding mechanism supports key lifecycle management and provides a technical basis for key rotation and emergency revocation; a digital signature based on the HSM private key forms a "command-signature-timestamp" three-in-one authentication system, ensuring that the instruction source is credible (anti-counterfeiting), the content is complete (anti-tampering), and the timeliness is controllable (anti-replay), meeting financial-grade security standards. Breaking through the limitations of traditional single-parameter path selection, the system innovatively constructs a three-dimensional evaluation model based on acoustic propagation delay (ToF), frequency band interference intensity (RSSI), and path loss coefficient (PathLoss). This model, combined with signal quality indicators (SNR, BER, and latency) reported in real time by the remote communication module, forms dynamic environmental awareness capabilities. Through dual screening using threshold comparison (interference intensity < preset threshold) and QoS constraints (latency < operational response requirements), the system ensures reliable transmission of control commands and reduces communication interruption rates even in complex electromagnetic interference scenarios (such as urban canyons and industrial environments). Acoustic wave-assisted detection can detect physical anomalies (such as illegal signal-blocking equipment). Combined with integrity verification of encrypted commands, the system forms a three-dimensional "air interface defense + data encryption" protection system, effectively defending against man-in-the-middle (MITM) attacks and signal jamming attacks.

[0101] Multi-band acoustic wave detection (such as 20kHz-40kHz ultrasound) can penetrate common obstacles (wood, glass). Combined with the signal attenuation model, it can automatically perceive changes in spatial topology (such as furniture movement and new obstructions), dynamically adjust communication strategies, and improve the stability of the system in dynamic environments. Through the parallel processing of rapid acoustic signal detection (response time <500ms) and encrypted command transmission, while ensuring security, the end-to-end control delay is controlled at an industry-leading level (usually <2 seconds), meeting real-time requirements such as emergency unlocking. The key identifier binding mechanism reserves an interface for future access to cutting-edge technologies such as quantum encryption, and the communication path evaluation model can be expanded to support the integration of heterogeneous networks such as 5G / WiFi6, building a future-oriented smart lock control system architecture.

[0102] In a preferred embodiment of the present invention, step S41: based on the final operation range verification conclusion, the cloud platform generates a unique timestamp and encapsulates the operation instruction type and the temporary permission validity period to form plain text instruction data, including:

[0103] Step S411: Based on the final operation range verification conclusion, the cloud platform obtains the system predefined operation code corresponding to the operation instruction type, and generates a unique timestamp with millisecond precision and random number extension based on the coordinated universal time, specifically including: the cloud platform matches the corresponding unique identifier (for example, "UNL-001" represents the unlock instruction) from the system predefined operation code list according to the verified operation instruction type (such as "unlock" and "authorize temporary authority"); obtains the current time based on the coordinated universal time (UTC), accurate to the millisecond level (such as "2025-04-26T14:30:45.123Z"); and adds a random number extension (such as "-RND-8527") to ensure that each timestamp is unique and unpredictable within the system by mixing fixed time and random factors.

[0104] Step S412: Convert the validity period of the temporary permission into a time interval format of the start time and the end time, and perform field standardization processing with the operation instruction type and timestamp to generate a structured data unit, specifically including: converting the validity period of the temporary permission (such as "2 hours") into a specific time interval, such as the start time "2025-04-26T14:30:00Z" and the end time "2025-04-26T16:30:00Z". Unify the operation instruction type (string), timestamp (UTC format with random extension), and validity period (start / end time fields) into a standard format recognizable by the system (such as ISO8601 time format and fixed-length operation code); and combine them into a structured data unit, for example: {operation code: UNL-001, timestamp: 2025-04-26T14:30:45.123-RND-8527, start time: 2025-04-26T14:30:00Z, end time: 2025-04-26T16:30:00Z}.

[0105] Step S413: Perform integrity check on the operation instruction type field, timestamp field and validity period field in the structured data unit. If there is an undefined operation code or a time interval conflict, the data reconstruction process is triggered, specifically including: verifying whether the operation code in the structured data exists in the system predefined list. For example, if an unregistered operation code "DEL-999" is received (assuming it represents deleting user permissions), an error prompt is triggered and packaging is rejected. Check whether the start time is later than the end time (such as the start time is 16:00 and the end time is 15:00). If there is a conflict, it is judged as invalid data; for non-temporary permission instructions (such as permanent authorization), skip the time interval check and directly mark it as "no validity period limit". If it is found that the operation code is undefined or the time interval conflicts, the system automatically backtracks to the data generation link to re-acquire the correct operation instruction type or validity period parameters.

[0106] Step S414: Encapsulate the verified structured data unit into a plaintext instruction data packet containing a header identifier, data payload and check code according to the preset protocol, specifically including: inserting a fixed identifier (such as "LOCK-CTRL-01") at the front end of the data packet, so that the smart lock end can quickly identify the instruction type and call the corresponding parsing module. Fill the structured data unit (operation code, timestamp, validity period) into the main part of the data packet. Calculate the data payload through a hash algorithm (such as SHA-1) to generate a check code (such as "3a5f2d7c8b"), which is used to verify the integrity of the data during transmission. Form a plaintext data packet similar to "header identifier | data payload | check code".

[0107] In an embodiment of the present invention, millisecond-level timestamps and random number extensions make each instruction unique, preventing hackers from intercepting old instructions and sending them repeatedly (replay attacks). For example, an attacker cannot use an unlocking instruction from 10 minutes ago to open the current door lock. Based on UTC time, time zone conversion errors are avoided, which is suitable for multi-regional deployment scenarios (such as cross-border shared apartments), ensuring that the validity period of instructions is uniform in different regions. Temporary permissions are converted into clear time intervals (such as "today 14:30-16:30") to avoid the window period vulnerability caused by the traditional "hourly authorization" (for example, the original scheme of authorizing 1 hour may cover unnecessary time periods). Standardized field formats reduce the cost of connecting devices from different manufacturers. For example, whether the smart lock is from brand A or brand B, a unified timestamp and operation code format can be recognized. Operation codes and time intervals are verified before packaging to avoid confusion in permission logic caused by front-end input errors (such as the user mistakenly selecting "end time is earlier than start time"), for example, to prevent temporary permissions from being mistakenly set to "valid period - 1 hour". Record exception logs for undefined opcodes or conflicting data, making it easier for administrators to later troubleshoot illegal operation attempts (such as forged "DEL-999" delete instructions).

[0108] The header identifier enables the smart lock to quickly locate the parsing module (e.g., unlocking commands call unlocking logic, authorization commands call permission management logic), reducing command processing delays (measured reductions of 20-30ms in parsing time). A checksum mechanism detects data tampering during transmission due to signal interference (e.g., a timestamp field mistakenly transmitted as "2025-04-26T14:30:45.123-RND-8528"), ensuring that the commands executed by the smart lock are identical to those issued by the cloud platform.

[0109] In a preferred embodiment of the present invention, step S42: the cloud platform calls a preset hardware security module, generates a temporary symmetric encryption key based on the current session parameters, encrypts the plaintext instruction data to generate ciphertext, and binds the key identifier to the ciphertext to establish a key association, including:

[0110] Step S421: The cloud platform extracts the communication protocol version, target smart lock unique identifier, and timestamp of the current session as session parameters to generate a key derivation seed. Specifically, the cloud platform extracts three core parameters from the current communication session:

[0111] Communication protocol version: such as HTTPS / 2.0, MQTTv5, etc., used to match compatible encryption algorithms;

[0112] Unique identifier of the target smart lock: such as "LOCK-001234", to ensure that the key is bound to a specific lock;

[0113] Timestamp: the UTC time with random extension generated in step S411 (such as "2025-04-26T14:30:45.123-RND-8527").

[0114] Concatenate the three parameters in a fixed order (such as "protocol version, lock ID, and timestamp") to form a 256-bit key derivation seed (for example, "HTTPS / 2.0LOCK-0012342025-04-26T14:30:45.123-RND-8527");

[0115] Step S422: Call the preset hardware security module's key generation interface, input the key derivation seed and the preset hardware-level random number, and generate a temporary symmetric encryption key bound to the current session. Specifically, it includes: connecting to a physically isolated HSM device through a dedicated line or encrypted channel to ensure that the key generation process is not attacked at the software level, generating a true random number (such as a random number sequence based on quantum noise) inside the HSM, mixing it with the externally input key derivation seed, and generating a temporary symmetric encryption key (such as an AES-256 key) through a key derivation function (KDF). When generating the key, the session identifier (such as the UUID "a1b2c3d4-e5f6-7g8h-9i0j") is embedded to ensure that the key is only used for the current request and cannot be reused across sessions.

[0116] Step S423: Use a temporary symmetric encryption key to encrypt the plaintext instruction data packet in blocks, use padding rules to resist length analysis attacks, and generate an encrypted ciphertext data block sequence, specifically including: dividing the plaintext instruction data packet (such as the "header identifier | data payload | check code" generated in step S414) into multiple data blocks according to a fixed length (such as 128-bit blocks of AES); using a temporary symmetric key to encrypt each data block, using a block cipher mode (such as CBC mode), and the previous ciphertext block participates in the encryption of the next plaintext block to ensure the dependency between data blocks; filling the last data block that is less than the block length with special characters (such as ASCII0x01-0x0F), and the padding content includes a padding length identifier, which is automatically removed during decryption to prevent attackers from inferring the plaintext structure through the ciphertext length.

[0117] Step S424: The key identifier assigned by the hardware security module is associated and encoded with the ciphertext data block sequence to generate binding metadata including the key version number and encryption algorithm identifier. Specifically, the HSM assigns a unique identifier (such as "KEY-20250426-1430-001") to the generated temporary key, which contains three parts of information:

[0118] Version number: such as "V3", identifies the key generation algorithm version;

[0119] Algorithm identifier: such as "AES256-CBC", indicating the algorithm required for decryption;

[0120] Timestamp: key generation time (e.g., "2025-04-26T14:30:45Z");

[0121] Associate the key identifier with the ciphertext data block sequence using JSON format.

[0122] Step S425: Attach the binding metadata to the ciphertext header to form a complete ciphertext data unit, and mark the life cycle of the temporary symmetric encryption key as a single-use valid state and store it in the key management audit log, specifically including: serializing the binding metadata (JSON format) and attaching it to the ciphertext header to form a complete ciphertext data unit in the format of "metadata|encrypted data block"; recording the life cycle of the temporary key as "single use" in the key management system, that is, the key automatically expires after the current instruction transmission is completed and cannot be used for subsequent communications; generate an audit log containing the key identifier, usage time, and target lock ID, and store it in read-only media for security compliance inspection.

[0123] In this embodiment of the present invention, the key derivation seed for each session includes a real-time timestamp and the lock's unique identifier, ensuring that keys for different locks at different times are completely distinct, thus avoiding the risk of traditional static keys being used for multiple purposes (e.g., a leaked static key in a shared apartment could lead to multiple locks being cracked). Generating a seed based on the communication protocol version dynamically adapts to the encryption requirements of different protocols (e.g., using TLS encryption for HTTPS and AES-CCM mode for MQTT), enhancing system flexibility.

[0124] Generate keys through HSM and utilize its physical security protection mechanisms (such as tamper-proof chips and real-time monitoring circuits) to prevent the key generation process from being stolen by malware (compared to traditional software-generated keys, HSM can resist memory dump attacks).

[0125] The CBC mode is combined with block processing to generate different ciphertext blocks from the same plaintext block (because the initial vector IV is randomly generated), thus resisting statistical analysis attacks (for example, attackers cannot infer the plaintext content from repeated ciphertext blocks). Through PKCS#7 padding, even if the ciphertext length is intercepted, the attacker cannot determine the original plaintext length (for example, the ciphertext length padded with 1 byte is the same as the ciphertext length padded with 16 bytes), thus avoiding padding oracle attacks such as OAEP. The key identifier carries algorithm and version information, and the smart lock can automatically call the corresponding decryption module (for example, when receiving the "AES256-CBC" identifier, it directly loads the CBC mode decryption function), reducing manual configuration costs. The version number records the iteration of the key generation logic (such as upgrading from V1 to V3). When a vulnerability is found in the old version of the algorithm, the affected key can be quickly located and forced to update.

[0126] A key is only usable once. Even if an attacker intercepts the ciphertext and key identifier, they cannot use that key to decrypt the next instruction. (Traditional solutions allow static keys to be reused repeatedly, resulting in a replay attack success rate of up to 60%.) Audit logs record the entire key usage process, meeting compliance requirements such as GDPR and ISO27001. (For example, a financial institution was fined $2 million by regulators for failing to trace key usage records. This solution mitigates this risk.)

[0127] In a preferred embodiment of the present invention, step S43: the cloud platform uses the private key in the hardware security module to digitally sign the ciphertext data and generate a dynamic encryption instruction containing a timestamp, ciphertext and signature, including:

[0128] Step S431: Extract the ciphertext header and ciphertext data block sequence from the complete ciphertext data unit, and associate the timestamp to generate the original data summary, specifically including: separating the ciphertext header (including metadata such as key identifier, algorithm identifier, etc.) and the ciphertext data block sequence (encrypted instruction content) from the complete ciphertext data unit generated in step S425. Obtain the unique timestamp generated in step S411 (such as "2025-04-26T14:30:45.123-RND-8527") and concatenate it with the ciphertext header and ciphertext data block in a fixed order to form the original data. Use a hash algorithm (such as SHA-256) to operate on the original data to generate a fixed-length hash value (such as a 256-bit summary) as the input basis for the digital signature.

[0129] Step S432: Call the signature engine of the hardware security module, use the private key to perform asymmetric encryption operations on the original data summary, and generate digital signature data, specifically including: sending a signature request to the hardware security module (HSM) through a secure channel, triggering its built-in asymmetric encryption engine, and the HSM uses the private key bound to the cloud platform (stored in the hardware encryption chip and cannot be read by external systems) to encrypt the original data summary and generate digital signature data (such as a 512-bit signature value); each signature is associated with a unique timestamp and ciphertext data to ensure that signatures of different instructions cannot be reused.

[0130] Step S433: Assemble the digital signature data, the timestamp, the ciphertext header, and the ciphertext data block sequence according to a preset format to generate a complete dynamic encryption instruction including a protocol version identifier and an operation type code, specifically comprising: assembling the following content according to a preset format:

[0131] Digital signature data: the signature value generated in step S432;

[0132] Timestamp: UTC time with random extension;

[0133] Ciphertext header: contains metadata such as key identifier and algorithm identifier;

[0134] Ciphertext data block sequence: encrypted instruction content.

[0135] Protocol and operation code added:

[0136] Insert the protocol version identifier (such as "V4.2") in the instruction header to indicate the communication protocol version used by the smart lock; add the operation type code (such as "OP-UNL" for unlocking operation) to facilitate the smart lock to quickly call the corresponding execution logic.

[0137] Step S434: Perform hash check on the dynamic encryption instruction. If the check fails, the key rotation mechanism is triggered to regenerate a temporary symmetric encryption key and repeat steps S42 to S43, specifically including: performing hash operation on the assembled dynamic encryption instruction again to generate a check code (such as SHA-256 value), and comparing the newly generated check code with the original data summary of step S431. If they are inconsistent, it is determined that the instruction has been tampered with or damaged during the assembly process. If the check fails, the system automatically discards the current temporary symmetric encryption key and regenerates a new key and ciphertext from step S421 to avoid using keys that may have been leaked or damaged.

[0138] Step S435: Logically bind the dynamic encryption instruction with the link identifier of the final communication path so that the instruction transmission process matches the path selection result, specifically including: extracting the path identifier (such as "PATH-A-20250426-1430") from the result of step S4 (final communication path calculation), representing the optimal communication path (such as transmission through the acoustic wave relay device at position A); adding a path identifier field in the instruction metadata to establish a mapping relationship between the dynamic encryption instruction and the communication path; when the smart lock receives the instruction, it verifies whether the path identifier matches the currently available path. If it does not match, it refuses to receive it to prevent the instruction from being transmitted through an unauthorized path.

[0139] In an embodiment of the present invention, hash digest generation ensures that the original data (ciphertext and timestamp) of a dynamically encrypted instruction has not been tampered with before signing. For example, if an attacker modifies the expiration date field in the ciphertext, the hash value will change significantly and be intercepted during subsequent verification. The digest is bound to the timestamp, providing undeniable time evidence for subsequent digital signatures (e.g., a user cannot deny initiating a specific operation at a certain point in time). The private key is stored in the HSM hardware, avoiding the risks of traditional software storing private keys (e.g., private key theft due to memory leaks). The digital signature proves that the instruction was legally issued by the cloud platform, making it impossible for attackers to forge a valid signature (the mathematical properties of asymmetric encryption ensure that only the corresponding public key can verify the signature, and the private key is held only by the cloud platform). The protocol version identifier and operation type encoding ensure cross-vendor compatibility of the instructions. For example, smart locks of different brands can identify unlock instructions through the "OP-UNL" code, eliminating the need for developing additional adapter interfaces. The operation type code directly links the smart lock's internal execution logic (e.g., unlock instructions correspond to the motor drive module, and authorization instructions correspond to permissions database operations), reducing parsing time by approximately 15-20ms. If an attacker attempts to tamper with the ciphertext (such as modifying the operation type in the instruction through a man-in-the-middle attack), the failure of the hash verification will trigger key rotation, automatically blocking the attack chain. Actual tests show that this mechanism can detect and respond to tampering attacks within 50ms. By forcibly discarding keys that fail verification and avoiding the use of keys that may have been exposed, the risk window after key leakage can be shortened from "several hours" to "single session" compared to traditional static key schemes. Binding instructions to paths ensures that they can only be transmitted through the optimal path calculated by the cloud platform, preventing attackers from inducing instructions to take vulnerable paths (such as unencrypted legacy communication protocol paths). In a test of a certain warehousing scenario, this mechanism reduced the success rate of path hijacking attacks from 42% to 3%. Path identification assists smart locks in quickly locating receiving channels (such as giving priority to using acoustic relay paths rather than congested Wi-Fi channels), improving transmission success rates in complex environments (such as from 68% to 95% in underground garage scenarios).

[0140] In a preferred embodiment of the present invention, step S44: the cloud platform calculates the interference intensity distribution and path attenuation parameters of the multi-band sound waves in the environment based on the sound wave feedback signals returned by location A and location B, and constructs a communication path quality assessment model based on the signal strength, bit error rate, and network delay indicators reported in real time by the remote communication module, including:

[0141] Step S441: Analyze the sound wave feedback signals returned from position A and position B, and extract the propagation delay, phase offset and signal amplitude parameters of the multi-band sound waves, specifically including: the cloud platform receives the sound wave feedback signals from position A and position B, first performs preliminary filtering on the signals to remove noise interference and improve the clarity and accuracy of the signals; uses signal processing technology to extract the propagation delay, phase offset and signal amplitude parameters of the multi-band sound waves from the pre-processed sound wave feedback signals. The propagation delay can be obtained by measuring the time difference from the signal emitted from the smart lock to the return from positions A and B; the phase offset can be determined by comparing the phase changes of the transmitted signal and the feedback signal; and the signal amplitude parameters are directly obtained from the signal strength.

[0142] Step S442: Calculate the Wi-Fi frequency band interference intensity distribution map in the environment based on the frequency band distribution and signal amplitude parameters of the multi-band sound waves, and analyze the attenuation coefficient of each path;

[0143] Step S443: Receive communication quality indicators reported in real time by the remote communication module, including signal strength, bit error rate, and network delay data, and associate them with the physical location of the target smart lock for regional cluster analysis;

[0144] Step S444: Perform multi-dimensional feature fusion on the interference intensity distribution map, the path attenuation coefficient, and the clustered communication quality index to generate a communication quality feature vector including a frequency band weight factor and a path stability score, specifically including:

[0145] Interference intensity data for key frequency bands is selected from the interference intensity distribution map as features. For example, among common communication frequency bands, the interference values of frequency bands that are most affected by interference and have a significant impact on communication quality are selected. For example, in smart home scenarios, the interference intensity of the 2.4GHz and 5GHz bands is very critical.

[0146] Path attenuation coefficient, directly selects the attenuation coefficient of each possible communication path as a feature. The attenuation coefficient of different paths reflects the energy loss of the signal when it propagates on the path, which has a direct impact on the communication quality.

[0147] From the clustered communication quality indicators, we selected signal strength, bit error rate, and network latency as key features. Signal strength determines whether the receiver can stably receive the signal, bit error rate affects the accuracy of data transmission, and network latency affects the real-time nature of communication.

[0148] For each selected feature, its value range is determined separately. For example, the value range of interference strength may be 0-100dBm, and the value range of signal strength may be -100 to 0dBm.

[0149] A linear transformation method is used to map the value of each feature to a uniform scale range, usually the interval [0,1]. The purpose of this is to eliminate the differences in dimensions and value ranges between different features, and to prevent certain features from dominating the subsequent fusion process due to their large numerical range.

[0150] Depending on the actual situation, a weighted summation method can be used. This method assigns a weight to each normalized feature and then adds them together to produce a composite value. The weighted summation method is used to fuse the normalized features to generate a communication quality feature vector. Within this vector, the frequency band weight factor is calculated by comprehensively calculating the relevant features of each frequency band, reflecting the importance of each frequency band in the overall communication process. The path stability score, which comprehensively considers factors such as path attenuation coefficient and signal strength stability, reflects the stability of each communication path.

[0151] Step S445: Based on a preset communication path evaluation rule set, the communication quality feature vectors are prioritized and dynamically thresholded, constructing a communication path quality evaluation model that supports multi-objective optimization. Specifically, the communication path evaluation rule set is defined in detail based on different application scenarios and requirements. For example, in a real-time video surveillance scenario, paths with low network latency and high signal strength may be prioritized; whereas in a file sharing scenario with high data transmission volume, path bandwidth and stability may be more important.

[0152] Communication quality feature vectors are prioritized according to a preset set of rules. Paths that meet the rule's priority criteria are prioritized first, while those that do not are prioritized later. For example, if the rule prioritizes paths with low interference, low attenuation, and high signal strength, a comprehensive comparison of each path's interference strength, attenuation coefficient, and signal strength is performed to determine their priority order.

[0153] Dynamic thresholds are set for each indicator in the communication quality feature vector. These thresholds are not fixed but are dynamically adjusted based on the actual communication environment and historical data. For example, different signal strength thresholds and bit error rate thresholds can be set based on communication conditions in different time periods and regions.

[0154] The system monitors the indicator values in the communication quality feature vector in real time. When a certain indicator exceeds or falls below a set threshold, the priority of the path is adjusted accordingly. For example, if the signal strength of a path suddenly falls below the threshold, its priority is lowered; if the bit error rate suddenly increases, its priority is also lowered.

[0155] Through the aforementioned priority sorting and dynamic threshold matching operations, a preliminary communication path quality assessment model has been established. This model can evaluate and rank different communication paths based on communication quality feature vectors. During actual communication, new data is continuously collected, and the model is continuously adjusted and optimized based on this data. For example, based on communication conditions over a period of time, the rule set can be fine-tuned and the dynamic thresholds reset, allowing the model to better adapt to different communication scenarios and environmental changes, achieving multi-objective optimization capabilities.

[0156] In an embodiment of the present invention, by extracting propagation delay, phase offset, and signal amplitude parameters of multi-band sound waves, the cloud platform can more accurately understand the propagation of sound waves in the environment. The extracted parameters of the frequency band sound waves can cope with different environmental interference and obstacles. Plotting the Wi-Fi frequency band interference intensity distribution map enables the cloud platform to clearly understand the interference situation in the environment, thereby selecting frequency bands with less interference for communication and improving communication reliability. Calculating the attenuation coefficient of each path helps the cloud platform select paths with less attenuation for communication, reducing signal energy loss and improving communication quality. Regionalized cluster analysis allows the cloud platform to understand the communication quality status of different regions, optimize and adjust according to the characteristics of different regions, and improve overall communication efficiency. Real-time reception of communication quality indicators reported by remote communication modules enables the cloud platform to promptly identify communication problems and take appropriate measures to ensure communication stability. The communication quality feature vector generated by multi-dimensional feature fusion comprehensively considers multiple factors such as interference intensity, path attenuation, and communication quality indicators, and can more comprehensively and accurately evaluate the quality of communication paths. The frequency band weight factor and path stability score provide important decision-making basis for the cloud platform to select the optimal communication path, thereby improving communication reliability and efficiency. The communication path quality assessment model that supports multi-objective optimization can balance and optimize multiple objectives. For example, it can minimize costs or improve efficiency while ensuring communication quality. Dynamic threshold matching can enable the assessment model to be adjusted in real time according to actual communication conditions, adapt to environmental changes, and improve the flexibility and adaptability of the model.

[0157] In a preferred embodiment of the present invention, step S442: calculating the Wi-Fi frequency band interference intensity distribution map in the environment based on the frequency band distribution and signal amplitude parameters of the multi-band sound waves, and analyzing the attenuation coefficient of each path, includes:

[0158] Step S4421: Decompose the frequency band distribution of the multi-band sound waves according to the preset Wi-Fi channel frequency range, and extract the sound wave frequency bands that overlap with the Wi-Fi frequency band as interference detection targets. Specifically, the cloud platform divides the frequency band distribution of the multi-band sound waves according to the preset Wi-Fi channel frequency range. Common Wi-Fi frequency bands include 2.4GHz and 5GHz. The cloud platform classifies the frequency bands of the multi-band sound waves based on this standard, and finds the sound wave frequency bands that overlap with the Wi-Fi frequency bands from the divided frequency bands. These overlapping frequency bands may interfere with Wi-Fi communications, so they are determined as target frequency bands for interference detection.

[0159] Step S4422: Based on the signal amplitude parameter, the difference between the acoustic signal energy in each target frequency band and the noise energy in the corresponding Wi-Fi frequency band is calculated to generate a real-time interference strength index, which specifically includes:

[0160] The cloud platform extracts the signal amplitude parameters of each target frequency band (i.e., the acoustic frequency band overlapping with the Wi-Fi band) from the acoustic feedback signals returned by locations A and B. These parameters are expressed as the voltage or power values received by the sensor (for example, signal strength values in decibel milliwatts (dBm)), reflecting the strength of the acoustic signal within that frequency band.

[0161] The original signal amplitude is denoised (e.g., abnormal fluctuations are eliminated); the cloud platform determines the effective duration of the acoustic signal within the target frequency band:

[0162] Extracting the start and end timestamps of the signal from the acoustic feedback signal (for example, determining the start and end points by detecting when the signal amplitude exceeds a noise threshold);

[0163] The time difference is calculated to obtain the duration of the signal in the frequency band (e.g., from 14:30:00.123Z to 14:30:00.456Z, for 0.333 seconds).

[0164] Energy integral calculation

[0165] Over the duration, the energy of the signal amplitude parameter is accumulated to obtain the total energy:

[0166] Divide the duration into multiple small time intervals (e.g., one interval per millisecond);

[0167] The signal amplitude (reflecting instantaneous energy) within each time interval is sampled and the total energy of the frequency band is calculated by summing all the sampled values. Example logic: If a frequency band contains 333 millisecond-level sampling points within 0.333 seconds, and the amplitude corresponding to each point is E1, E2, …, E333, then the total energy is E1 + E2 + … + E333.

[0168] Frequency dimension processing:

[0169] Frequency band subdivision and energy distribution analysis:

[0170] Divide the target frequency band (e.g., 2.400-2.4835 GHz for Wi-Fi 2.4 GHz) into multiple sub-bands (e.g., 5 MHz per sub-band) and analyze the energy distribution of each sub-band:

[0171] Extract statistics such as signal amplitude peak value and mean value in each sub-band;

[0172] Compare the energy intensity of each sub-band to determine whether the energy is concentrated in the center or at the edge of the band (for example, the amplitude of the sub-band near the center 2.440 GHz is significantly higher than that at the edges 2.400 GHz and 2.4835 GHz).

[0173] Determination of effective energy range:

[0174] Based on the energy distribution characteristics, the effective energy range that may cause substantial interference to Wi-Fi communications is screened out:

[0175] Uniform distribution scenario: If the energy of each sub-band is similar, the entire target frequency band is considered to be a valid range;

[0176] Non-uniform distribution scenario: Only sub-bands with energy exceeding a threshold (such as 1.5 times the average energy) are retained as valid ranges (for example, only sub-bands within the center ±10 MHz are considered valid).

[0177] Comprehensive energy value generation:

[0178] Fusion of time and frequency dimensions:

[0179] For each sub-frequency band within the effective energy range, calculate its total energy within the duration (according to the time dimension integration method); add up the total energy of all effective sub-frequency bands to obtain the sound wave signal energy value of the target frequency band.

[0180] Unit conversion:

[0181] Joule (J) conversion: Based on the physical mapping relationship between signal amplitude and energy (such as sensor calibration parameters), the accumulated energy value is converted to joule units;

[0182] Decibel energy unit conversion: If the decibel system (such as dBm) is used, the energy value is converted to decibel units using a preset conversion rule (such as logarithmic operation based on the reference power). This facilitates direct comparison with Wi-Fi noise energy (usually in dBm).

[0183] The cloud platform retrieves historical statistical data for the corresponding time period from the pre-stored noise database based on the current time (e.g., 14:30, April 26, 2025) and the geographic location of the target area (e.g., the third floor of an apartment building):

[0184] The database is stored by date (weekday / weekend), hour (such as morning peak, noon, evening peak), floor height and other dimensions;

[0185] Extract the average noise energy value of the Wi-Fi frequency band (such as 2.4 GHz) during the time period (for example, historical statistics show that the average noise energy in the area at 2 pm is -75 dBm).

[0186] Real-time data collection and processing

[0187] Real-time sensor sampling: Wireless sensors deployed at Location A (e.g., corridor ceiling) and Location B (e.g., stairwell) collect ambient noise signals in the target Wi-Fi frequency band 100 times per second and obtain real-time signal amplitudes (in dBm).

[0188] Filtering and denoising: Using a sliding average filtering algorithm, it removes sudden outliers (such as instantaneous spike interference) and retains stable noise data (for example, filtering out instantaneous strong interference signals caused by elevator operation);

[0189] Statistical calculation: Calculate the root mean square (RMS) value of the filtered real-time data to obtain the real-time noise energy baseline value of the frequency band (for example, the RMS value calculated after 10 seconds of continuous sampling is -72 dBm).

[0190] Data Fusion:

[0191] The cloud platform combines historical statistical data with real-time data to generate a comprehensive noise energy value:

[0192] If the difference between historical data and real-time data is within ±5dBm, take the average of the two (e.g., historical -75dBm and real-time -72dBm are combined to get -73.5dBm).

[0193] If the difference exceeds a threshold (such as ±5dBm), the real-time data is used as the primary value (for example, if the real-time data suddenly changes to -65dBm due to temporary device startup, this value is directly used).

[0194] Interference intensity index calculation process:

[0195] Energy unit alignment

[0196] Unify the acoustic signal energy value and Wi-Fi noise energy value in the target frequency band into the same unit (such as dBm):

[0197] If the acoustic signal energy is in joules (J), it is converted to dBm using the sensor calibration parameters (for example, 10mW corresponds to 10dBm, and 1mW corresponds to 0dBm);

[0198] Make sure that both values are compared in the same unit (for example, both are power values in dBm).

[0199] Energy difference calculation

[0200] Perform a subtraction operation: acoustic signal energy minus Wi-Fi noise energy to obtain the energy difference:

[0201] Example 1: The acoustic signal energy is -60dBm, the noise energy is -73.5dBm, and the energy difference is +13.5dBm (indicating that the acoustic signal is 13.5dBm stronger than the noise).

[0202] Example 2: The sound wave signal energy is -80dBm, the noise energy is -75dBm, and the energy difference is -5dBm (indicating that the sound wave signal is 5dBm weaker than the noise).

[0203] Index mapping and calibration

[0204] According to the energy difference range, it is linearly mapped to the exponential range of 0-100:

[0205] Set the threshold:

[0206] Strong interference threshold: Energy difference ≥ +10dBm, corresponding to index 80-100;

[0207] Medium interference threshold: +3dBm≤energy difference<+10dBm, corresponding to index 50-80;

[0208] Low interference threshold: -5dBm≤energy difference<+3dBm, corresponding to index 20-50;

[0209] No interference threshold: energy difference <-5dBm, corresponding to index 0-20.

[0210] Example mapping:

[0211] Energy difference + 13.5 dBm → Index = 80 + (13.5 - 10) / (100 - 80) × 20 ≈ 83.5 (rounded to 84, marked as strong interference);

[0212] Energy difference -5dBm → Index = 20 (the threshold between low interference and no interference).

[0213] Interference affects correlation

[0214] High index (>70): For example, an index of 84 indicates that the energy of the acoustic signal in this frequency band is significantly higher than the Wi-Fi noise, which may cause the Wi-Fi signal's signal-to-noise ratio (SNR) to fall below a critical value (e.g., 10 dB), causing data transmission errors (bit error rate > 10 dB). -3 ), the transmission rate drops (e.g. from 100Mbps to 20Mbps);

[0215] Low index (<30): For example, an index of 20 indicates that the acoustic signal energy is lower than the noise level or close to the background level, and the impact on Wi-Fi communication is negligible (bit error rate <10 -5 ), this frequency band can be used for smart lock command transmission first.

[0216] Dynamic adjustment mechanism

[0217] Real-time update frequency: The interference strength index is recalculated every second to track environmental changes (such as a user turning on a microwave or a neighbor adding a new Wi-Fi device).

[0218] Outlier handling: If the index fluctuation obtained from three consecutive calculations exceeds 20 units (for example, a sudden change from 30 to 55), an environmental interference warning is triggered and an alternative communication path is automatically activated (for example, switching from Wi-Fi to Bluetooth).

[0219] Step S4423: Analyze the acoustic wave feedback signal data packets at position A and position B, extract the acoustic wave propagation delay, phase offset, and received signal strength difference; call the preset acoustic wave propagation velocity model, and calculate the deviation between the actual propagation velocity and the theoretical velocity of the acoustic wave path based on the propagation delay and the physical distance between positions A / B; calculate the reflection loss coefficient caused by the number of reflections in the path based on the phase offset and received signal strength difference, combined with the acoustic wave frequency characteristics; based on the actual propagation velocity deviation and the reflection loss coefficient, dynamically correct the attenuation effect of ambient humidity and temperature parameters on the acoustic wave energy through the dielectric absorption attenuation formula to generate the dielectric absorption attenuation coefficient, specifically including:

[0220] The cloud platform receives acoustic feedback signal packets from Location A and Location B. It first performs a preliminary check on these packets to confirm their integrity, such as checking the packet length and header information to ensure they conform to the predefined format. If a packet is damaged or incomplete, it attempts to retransmit it or discards it. After preliminary processing, the platform then performs a detailed analysis of the packets to extract three key pieces of information: acoustic propagation delay, phase offset, and received signal strength difference.

[0221] Sound wave propagation delay: This is determined by comparing the time a signal is sent and received. For example, the exact time a signal is sent from location A is recorded, and then the time it is received at location B is recorded. The difference between the two times is the propagation delay of the sound wave from A to B.

[0222] Phase offset: Compare the phase of the received sound wave signal with the phase of the original transmitted signal, and calculate the phase change, which is the phase offset.

[0223] Received signal strength difference: Get the received signal strength values at location A and location B respectively, and then calculate the difference between the two.

[0224] Calculation of actual propagation speed deviation:

[0225] Actual propagation speed calculation

[0226] Call the preset sound wave propagation speed model, combine the previously extracted sound wave propagation delay and the known physical distance between positions A and B, divide the physical distance between positions A and B by the sound wave propagation delay, and get the actual propagation speed of the sound wave on this path.

[0227] Deviation value calculation

[0228] The actual propagation speed calculated is compared with the theoretical propagation speed of the sound wave in the environment. The theoretical speed is pre-set based on the basic parameters of the environment (such as temperature, air pressure, etc.). The deviation value between the two is obtained by subtracting the theoretical speed from the actual propagation speed.

[0229] Reflection loss coefficient calculation

[0230] Reflection analysis

[0231] The extracted phase offset and received signal strength difference, combined with the frequency characteristics of the sound wave, are used to analyze the reflections of the sound wave during its propagation. Different reflection times and reflection interfaces result in different phase offsets and signal strength variations. For example, a large phase offset and a significant decrease in signal strength may indicate that the sound wave has experienced multiple reflections.

[0232] Reflection loss coefficient calculation

[0233] Phase offset analysis: Assuming that the phase offset increases by 180 degrees with each reflection (an ideal hard-reflecting interface), the cloud platform calculates the number of reflections based on the actual phase offset (e.g., a total offset of 540 degrees) as 540° ÷ 180° = 3.

[0234] Signal strength difference verification: If the received signal strength difference is 15dB, and the single reflection loss is known to be approximately 5dB (an empirical value that can be preset based on the environment and material), the theoretical number of reflections is 15dB ÷ 5dB = 3 times, which is consistent with the phase offset calculation result, confirming that the number of reflections is 3 times. Based on the frequency characteristics of the sound wave (for example, high-frequency sound waves have higher reflection loss), set the single reflection loss value for different frequency bands:

[0235] Low frequency band (<1kHz): single reflection loss 3dB;

[0236] Mid-frequency band (1-4kHz): single reflection loss 5dB;

[0237] High frequency band (>4kHz): single reflection loss 8dB.

[0238] Example: If the current sound wave frequency is 2kHz (mid-frequency band), the single reflection loss is 5dB.

[0239] Total reflection loss calculation

[0240] Total reflection loss = number of reflections × single reflection loss;

[0241] Example: 3 reflections × 5dB single loss = 15dB, which means the reflection loss coefficient is 15dB (indicating an energy loss of approximately 97%, as dB is logarithmically related to power).

[0242] Dielectric absorption attenuation coefficient generation process

[0243] Calculation of ambient temperature impact

[0244] Theoretical sound speed calculation

[0245] Based on the ideal gas law, the theoretical sound speed formula is:

[0246] V0 = 331.4 + 0.6 × T (T is Celsius temperature, unit: °C); Example: If the preset ambient temperature is 20 °C, then the theoretical sound speed V0 = 331.4 + 0.6 × 20 = 343.4 m / s.

[0247] Actual sound speed calculation

[0248] Actual sound speed v = physical distance between position A and B ÷ propagation delay

[0249] Example: The distance between positions A and B is 10 meters, the propagation delay is 0.03 seconds, and the actual sound speed v = 10 ÷ 0.03 ≈ 333.3 m / s.

[0250] Temperature deviation derivation

[0251] Speed deviation Δv = v - v0 = 333.3 - 343.4 = -10.1 m / s

[0252] According to the linear relationship between the speed of sound and temperature (0.6m / s / °C), the temperature deviation ΔT = Δv ÷ 0.6 ≈ **-16.8°C**, that is, the actual ambient temperature is 16.8°C lower than the preset value, and the current temperature T = 20-16.8 = 3.2°C.

[0253] Temperature attenuation factor

[0254] In low temperature environments, air viscosity increases and sound wave absorption is enhanced. The preset temperature attenuation coefficient is:

[0255] At 0℃, the attenuation is 0.1dB / m·kHz;

[0256] For every 1°C decrease in temperature, the attenuation increases by 0.02dB / m·kHz.

[0257] Example: The current temperature is 3.2°C, and the attenuation coefficient = 0.1 + (0 - 3.2) × 0.02 = 0.164 dB / m·kHz.

[0258] Calculation of the impact of ambient humidity

[0259] Humidity detection value acquisition

[0260] The temperature and humidity sensors deployed at locations A / B are used to obtain the real-time humidity RH=40% (assumed).

[0261] Humidity attenuation factor

[0262] Preset formula for the effect of humidity on the attenuation of high-frequency sound waves (>2kHz):

[0263] For every 10% increase in humidity, high-frequency attenuation increases by 0.05dB / m·kHz (the low-frequency effect can be ignored).

[0264] Example: The current humidity is 40% and the reference humidity is 50% (preset standard). The humidity attenuation adjustment value = (50% - 40%) × 0.05 = -0.005 dB / m·kHz (the negative sign indicates that the attenuation is slightly reduced as the humidity decreases).

[0265] Comprehensive attenuation coefficient generation

[0266] Frequency parameter substitution

[0267] Assume that the current sound wave frequency f=3kHz (medium-high frequency) and the propagation distance d=10 meters.

[0268] Temperature and humidity joint attenuation calculation

[0269] Total attenuation caused by temperature = temperature attenuation coefficient × f × d = 0.164 × 3 × 10 = 4.92 dB

[0270] Total attenuation caused by humidity = humidity attenuation factor × f × d = (-0.005) × 3 × 10 = -0.15 dB (negligible, take 0)

[0271] Total dielectric absorption attenuation = temperature attenuation + humidity attenuation ≈ 4.92 dB, that is, the dielectric absorption attenuation coefficient is 4.92 dB (indicating an energy loss of approximately 49.2% per meter of propagation distance).

[0272] Step S4424: The real-time interference intensity index is weighted and integrated with the reflection loss and the medium absorption attenuation coefficient to generate an attenuation coefficient matrix including the path priority score and the anti-interference capability, which specifically includes:

[0273] Scenario classification and weight preset, home / office scenario (mainly Wi-Fi interference):

[0274] Real-time interference intensity index: weight 50% (interference has the greatest impact on communication quality);

[0275] Reflection loss coefficient: weight 30% (wall reflection is a secondary factor);

[0276] Dielectric absorption attenuation coefficient: weight 20% (air humidity / temperature has little effect).

[0277] Industrial / warehouse scenarios (with many metal obstacles and complex environments):

[0278] Reflection loss coefficient: weight 40% (metal reflection causes significant multipath effect);

[0279] Dielectric absorption attenuation coefficient: weight 35% (dust and high temperature environment affect sound wave propagation);

[0280] Real-time interference intensity index: weight 25% (industrial equipment has its own communication frequency band, and Wi-Fi interference is less).

[0281] Dynamic weight adjustment mechanism

[0282] If the calculated value of a coefficient exceeds the threshold (e.g., interference index > 80) for three consecutive times, its weight will be automatically increased by 10% (e.g., if the interference index suddenly increases in a home scenario, the weight will be increased from 50% to 60%).

[0283] When the data of environmental monitoring sensors (such as temperature, humidity, and dust concentration) suddenly changes, the weight of the medium absorption attenuation coefficient is adjusted accordingly (for example, if the humidity is detected to be greater than 80%, the weight is increased from 20% to 30%).

[0284] Convert coefficients of different dimensions to a uniform range (such as 0-100) to facilitate weighted calculation:

[0285] Real-time interference strength index (normalized): directly use the index value of 0-100 (such as the calculated result is 84).

[0286] Return loss coefficient (dB converted to index):

[0287] The preset maximum reflection loss is 30dB (corresponding to index 100), and no loss is 0dB (corresponding to index 0);

[0288] Linear mapping formula: Return loss index = (loss value ÷ 30) × 100;

[0289] Example: Reflection loss 15dB → 15÷30×100=50.

[0290] Dielectric absorption attenuation coefficient (dB / m converted to index):

[0291] The preset maximum attenuation is 10dB / m (corresponding to index 100), and the minimum attenuation is 0dB / m (corresponding to index 0);

[0292] Linear mapping formula: Absorption attenuation index = (attenuation value ÷ 10) × 100

[0293] Example: Attenuation 4.92 dB / m → 4.92 ÷ 10 × 100 = 49.2 (rounded to 49).

[0294] Comprehensive score = interference index × W1 + reflection loss index × W2 + absorption attenuation index × W3

[0295] (W1, W2, W3 are the weights of each coefficient, the total is 100%)

[0296] Scenario-based computing example (home scenario)

[0297] Known:

[0298] Interference index = 84, weight W1 = 50%;

[0299] Return loss index = 50, weight W2 = 30%;

[0300] Absorption attenuation index = 49, weight W3 = 20%.

[0301] calculate:

[0302] Comprehensive score = 84×0.5+50×0.3+49×0.2=42+15+9.8=66.8 (rounded to 67).

[0303] Anti-interference ability classification

[0304] According to the comprehensive rating, the grades are:

[0305] 0-30: strong anti-interference ability (preferred);

[0306] 31-60: medium anti-interference ability;

[0307] 61-100: Weak anti-interference ability (need to be avoided).

[0308] Example: Overall score 67 → Anti-interference ability level is "Medium".

[0309] Attenuation coefficient matrix generation:

[0310] Matrix structure definition

[0311] Each matrix element corresponds to a communication path and contains the following fields:

[0312] Path ID: such as "PATH-A-20250426-1430";

[0313] Real-time interference index: 0-100 value;

[0314] Reflection loss index: 0-100 value;

[0315] Absorption attenuation index: 0-100 value;

[0316] Comprehensive score: 0-100 numerical value;

[0317] Priority score: sorted in descending order of comprehensive score (the lower the score, the higher the priority);

[0318] Anti-interference level: strong / medium / weak, as shown in Table 1 below, example matrix fragment:

[0319] Table 1 Example matrix fragment

[0320]

[0321] Prioritization:

[0322] Arranged in ascending order by comprehensive score, priority 1 (score 26) > priority 2 (56.5) > priority 3 (67); the cloud platform preferentially selects the path with priority 1 (PATH-B) for instruction transmission.

[0323] Step S4425: Based on the attenuation coefficient matrix and the physical location topology relationship of the target smart lock, a multi-dimensional Wi-Fi frequency band interference intensity distribution map covering the target area is drawn, and high interference risk path identifiers are marked. Specifically, the cloud platform combines the attenuation coefficient matrix with the physical location topology relationship of the target smart lock. The physical location topology relationship describes the distribution of the target smart lock in space. By associating it with the attenuation coefficient matrix, the interference situation at different locations can be understood more accurately.

[0324] Based on these combined results, a multi-dimensional Wi-Fi frequency band interference intensity distribution map covering the target area is created. This map not only displays interference intensity at different locations but also identifies paths with high interference risk. These identifiers help users quickly identify paths that may have interference issues and take appropriate measures.

[0325] In a preferred embodiment of the present invention, step S443: receiving communication quality indicators reported in real time by the remote communication module, including signal strength, bit error rate, and network delay data, and correlating them with the physical location of the target smart lock to perform regional cluster analysis, including:

[0326] Step S4431: The cloud platform receives the original data of the communication quality indicators reported by the remote communication module, and analyzes the numerical range and acquisition timestamp of the signal strength, bit error rate and network delay. Specifically, the cloud platform opens the data receiving port and waits for the remote communication module to report the original data of the communication quality indicators. The remote communication module will send the data to the cloud platform at a certain time interval (such as every minute); the cloud platform analyzes the received raw data. First, identify the numerical part of the signal strength, bit error rate and network delay in the data, and determine its specific numerical range. At the same time, extract the acquisition timestamp in the data. This timestamp records the acquisition time of each communication quality indicator.

[0327] Step S4432: Based on the physical location coordinates of the target smart lock, the communication quality indicators are mapped to the preset geographic grid division rules to generate a communication quality data set with geo-tags, specifically including: the cloud platform obtains the physical location coordinates of the target smart lock from a pre-stored database. These coordinates are usually expressed in the form of longitude and latitude. The cloud platform divides the target area into multiple geographic grids of equal size according to the preset geographic grid division rules. For example, the entire area is divided into small rectangular grids according to certain longitude and latitude intervals, and the communication quality indicators obtained by parsing are mapped to the divided geographic grids. Specifically, according to the physical location coordinates of the target smart lock, the geographic grid to which it belongs is determined, and then the communication quality indicators corresponding to the smart lock are associated with this geographic grid, thereby generating a communication quality data set with geo-tags.

[0328] Step S4433: Clean the communication quality data set for outliers, remove data points that exceed the device physical performance threshold or network protocol specifications, and form standardized input data. Specifically, the cloud platform determines the reasonable numerical range of signal strength, bit error rate, and network delay based on the device's physical performance and network protocol specifications, as the device physical performance threshold and network protocol specifications. For example, the signal strength is generally between -100dBm and -30dBm, and the bit error rate should be less than 1%. The communication quality data set with geo-tags is traversed to check whether the signal strength, bit error rate, and network delay values of each data point exceed the preset threshold range. If the value of a data point exceeds the threshold, it is determined to be an outlier, and all data points determined to be outliers are removed from the data set to form standardized input data to ensure that the data used in subsequent analysis are reasonable and valid.

[0329] Step S4434: The cloud platform maps the signal strength and network delay in the standardized input data into coordinate points in the multidimensional feature space, and defines the cluster core object based on the preset neighborhood radius threshold and the minimum sample number threshold; traverses the coordinate points in the multidimensional feature space, expands the neighborhood range of the core object according to the density accessibility judgment rule, and forms an initial geographic area cluster; filters the noise data of the coordinate points in the initial geographic area cluster, removes isolated points with a density lower than the preset threshold, and re-executes the neighborhood expansion to optimize the cluster boundary; verifies whether the variance of the signal strength and network delay in the optimized geographic area cluster meets the preset communication stability condition. If the condition is exceeded, the neighborhood radius dynamic adjustment mechanism is triggered; assigns a unique identifier to the finally divided geographic area cluster, and associates it with the physical location coordinates of the target smart lock within its coverage area, and generates a clustering result of the geographic area cluster with communication quality consistency characteristics, which specifically includes:

[0330] The cloud platform maps the signal strength and network delay in the standardized input data to coordinate points in a multidimensional feature space. In this multidimensional feature space, each coordinate point represents the communication quality of a smart lock. Its horizontal coordinate can represent the signal strength, and its vertical coordinate can represent the network delay. The clustering core object is defined according to the preset neighborhood radius threshold and the minimum sample number threshold. The neighborhood radius threshold specifies the size of the neighborhood range centered on a certain coordinate point, and the minimum sample number threshold specifies the minimum number of samples that must be included in this neighborhood range. If the number of samples contained in the neighborhood of a certain coordinate point is greater than or equal to the minimum sample number threshold, then this coordinate point is defined as a clustering core object.

[0331] All coordinate points in the multidimensional feature space are traversed, and the neighborhood of the cluster core object is expanded according to the density reachability rule. The density reachability rule states that if a coordinate point is within the neighborhood of another coordinate point and can be connected by a series of core objects, then the two coordinate points are considered density reachable. By continuously expanding the neighborhood of the core object, density reachable coordinate points are merged together to form an initial geographic area cluster.

[0332] The coordinate points in the initial geographic clusters are filtered for noise. The cloud platform checks the density of coordinate points within each cluster based on a preset density threshold. If the density of a particular point falls below the preset threshold, the point is considered an outlier and removed from the cluster.

[0333] After removing isolated points, the neighborhood expansion operation is re-executed to optimize the cluster boundaries and make the cluster division more reasonable. The variance of signal strength and network latency within the optimized geographic cluster is then verified to ensure that it meets the preset communication stability requirements. The variance reflects the degree of data dispersion. If the variance exceeds the preset range, the communication quality within the cluster is unstable.

[0334] If the communication stability within a cluster in a certain geographic area does not meet the requirements, the cloud platform will trigger a dynamic adjustment mechanism for the neighborhood radius. By adjusting the neighborhood radius threshold, cluster analysis will be re-performed until the communication stability requirements are met within all clusters in the geographic area.

[0335] The resulting geographic clusters are assigned unique identifiers to facilitate subsequent management and query. Each cluster is then associated with the physical location coordinates of the target smart lock within its coverage area, generating clusters with consistent communication quality.

[0336] Step S4435: Associating and mapping the clustering results of the geographic area clusters with the Wi-Fi frequency band interference intensity distribution map to generate a cluster analysis result containing regional communication quality level annotations, specifically including: associating and mapping the clustering results of the geographic area clusters with the previously generated Wi-Fi frequency band interference intensity distribution map. The cloud platform finds the corresponding area in the Wi-Fi frequency band interference intensity distribution map based on the geographical location and coverage of the geographic area cluster and associates the two; based on the results of the association, the regional communication quality level is labeled for each geographic area cluster. The cloud platform combines communication quality indicators (signal strength, bit error rate, network delay) and Wi-Fi frequency band interference intensity to comprehensively evaluate the communication quality of each area, divide it into different levels, such as excellent, good, medium, poor, etc., and finally generates a cluster analysis result containing regional communication quality level annotations.

[0337] In a preferred embodiment of the present invention, step S45: the cloud platform selects a communication link with an interference intensity lower than a preset threshold and a delay that meets the operation instruction requirements as the final communication path based on the communication path quality evaluation model, and sends the dynamic encryption instruction to the remote communication module of the target smart lock through the final communication path, including:

[0338] Step S451: The cloud platform obtains the interference intensity values, path stability scores, and network latency data for all candidate communication links from the communication path quality assessment model and extracts their corresponding physical path identifiers. Specifically, the cloud platform accesses the communication path quality assessment model and obtains relevant data for all candidate communication links. This data includes the interference intensity value, which reflects the degree of external interference on the link; the path stability score, which reflects the link's ability to maintain stable communication over a period of time; and network latency data, which represents the time it takes for a signal to travel across the link. From this acquired data, the cloud platform extracts the physical path identifier corresponding to each candidate communication link. This identifier uniquely identifies each communication link and facilitates subsequent identification and management of the link.

[0339] Step S452: Based on the preset interference intensity threshold and the delay tolerance parameter corresponding to the operation instruction type, a set of candidate communication links with interference intensity lower than the threshold and delays that meet the real-time requirements of the instructions are screened. Specifically, the cloud platform determines the interference intensity threshold and the delay tolerance parameter corresponding to the operation instruction type according to preset rules. Different operation instructions, such as unlocking instructions and status query instructions, have different tolerances for delays and therefore have different delay tolerance parameters. The cloud platform traverses all candidate communication links, compares the interference intensity value of each link with the preset interference intensity threshold, and compares its network delay data with the delay tolerance parameter corresponding to the operation instruction type. Only those candidate communication links with interference intensity lower than the threshold and delays that meet the real-time requirements of the instructions will be retained to form the candidate communication link set.

[0340] Step S453: Based on the path stability scores of the candidate communication link set and the communication quality ratings of the geographic cluster set, the links are prioritized based on their anti-interference capabilities and reliability. Specifically, the cloud platform evaluates the anti-interference capabilities and reliability of the links based on the path stability scores of the candidate communication link set and the communication quality ratings of the geographic cluster set. A higher path stability score indicates a more stable link; a higher communication quality rating of the geographic cluster indicates a better regional communication environment for the link. Based on these evaluation results, the candidate communication links are prioritized. Links with greater anti-interference capabilities and higher reliability are given higher priority.

[0341] Step S454: Select the communication link with the highest priority as the final communication path, and verify whether its current connection status with the target smart lock remote communication module is in an active and available state, specifically including: the cloud platform selects the communication link with the highest priority from the sorted candidate communication links as the final communication path. The cloud platform verifies whether the current connection status between the final communication path and the target smart lock remote communication module is in an active and available state. This can be achieved by sending a simple test signal to the target smart lock remote communication module and observing whether a response is received. If the connection status is inactive or unavailable, the cloud platform will return to step S453, select the communication link with the second highest priority, and repeat the verification process until an active and available final communication path is found.

[0342] Step S455: The cloud platform injects the dynamic encryption instruction into the data transmission queue of the final communication path and attaches a path selection audit tag. Specifically, the cloud platform injects the dynamic encryption instruction into the data transmission queue of the final communication path. Dynamic encryption instructions are encrypted operation instructions to ensure communication security. The data transmission queue transmits the instructions in a specific order. The cloud platform attaches a path selection audit tag to the dynamic encryption instruction injected into the data transmission queue. This tag records relevant information about the communication path selection, such as the selection time and selection basis.

[0343] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.

Claims

1. A remote smart lock control method based on a cloud platform, characterized in that: The method comprises: Step S1: The user terminal sends a remote control request to the cloud platform, which carries user authentication information, a unique identifier of the target smart lock, and an operation instruction type; Step S2: After receiving the remote control request, the cloud platform performs a triple verification of the legitimacy of the user identity, the operating authority scope of the target smart lock, and the compliance of the operating instruction type based on the pre-stored user-smart lock binding relationship and the authority classification strategy; Step S3: If the triple verification passes, the cloud platform generates a dynamic encrypted instruction containing a timestamp, the operation instruction type, and the validity period of the temporary permission, and determines the associated remote communication module based on the unique identifier of the target smart lock; Step S4: The cloud platform sends an acoustic signal transmission instruction to the target smart lock, triggering the smart lock to send multi-band acoustic signals to the preset auxiliary signal enhancement device deployment positions A and B; the cloud platform receives the acoustic feedback signals returned by positions A and B, and calculates the final communication path based on the signal propagation delay, frequency band interference intensity and attenuation parameters, combined with the real-time signal quality indicators reported by the remote communication module, and the dynamic encryption instruction is sent to the remote communication module through the final communication path.

2. The remote smart lock control method based on the cloud platform according to claim 1 is characterized in that: After receiving the remote control request, the cloud platform performs a triple verification of the legitimacy of the user's identity, the scope of the target smart lock's operating permissions, and the compliance of the operation instruction type based on the pre-stored user-smart lock binding relationship and permission classification strategy, including: Step S31: Parse the remote control request and verify whether the request contains the three required fields: user identity information, target smart lock unique identifier, and operation instruction type. If any field is missing, the verification is terminated and an error response is returned; Step S32: Convert the user identity information, the target smart lock unique identifier, and the operation instruction type into a standard data format to generate a structured request object; Step S33: Based on the user identity information in the structured request object, the user database is queried to match a valid account. If the account has enabled the enhanced verification policy, a secondary authentication process is triggered. At the same time, the account status and historical login behavior characteristics are analyzed to intercept abnormal login requests and generate a first verification result. Step S34: Based on the first verification result and the unique identifier of the target smart lock, the user-lock binding relationship table is retrieved for a list of locks bound to the user. If the target lock does not exist in the list, the verification is terminated. Based on the user role identifier and the operation instruction type, the corresponding operation permission status is matched in the permission matrix. If the permission is exceeded, an audit log containing the violation record of the operation type is generated and a second verification result is returned. Step S35: Based on the second verification result and combined with the current environmental context data, if the operation instruction involves the granting of temporary permissions, the validity period and the remaining available times of the temporary permissions are checked, and the final operation scope verification conclusion is generated to complete the triple verification.

3. The remote smart lock control method based on the cloud platform according to claim 2 is characterized in that: The cloud platform sends an acoustic signal transmission instruction to the target smart lock, triggering the smart lock to send multi-band acoustic signals to the preset auxiliary signal enhancement device deployment locations A and B. The cloud platform receives the acoustic feedback signals returned by locations A and B, and calculates the final communication path based on the signal propagation delay, frequency band interference intensity and attenuation parameters, combined with the real-time signal quality indicators reported by the remote communication module. The dynamic encryption instruction is sent to the remote communication module through the final communication path, including: Step S41: Based on the final operation scope verification conclusion, the cloud platform generates a unique timestamp and encapsulates the operation instruction type and the temporary permission validity period into plain text instruction data; Step S42: The cloud platform calls a pre-installed hardware security module, generates a temporary symmetric encryption key based on the current session parameters, encrypts the plaintext instruction data to generate ciphertext, and binds the key identifier to the ciphertext to establish a key association; Step S43: The cloud platform uses the private key in the hardware security module to digitally sign the ciphertext data and generate a dynamic encryption instruction containing a timestamp, ciphertext and signature; Step S44: The cloud platform calculates the interference intensity distribution and path attenuation parameters of the multi-band sound waves in the environment based on the sound wave feedback signals returned by location A and location B, and builds a communication path quality assessment model based on the signal strength, bit error rate, and network delay indicators reported in real time by the remote communication module; Step S45: The cloud platform selects the communication link with interference intensity lower than the preset threshold and delay meeting the operation instruction requirements as the final communication path based on the communication path quality evaluation model, and sends the dynamic encryption instruction to the remote communication module of the target smart lock through the final communication path.

4. The remote smart lock control method based on the cloud platform according to claim 3 is characterized in that: Step S41: Based on the final operation scope verification conclusion, the cloud platform generates a unique timestamp and encapsulates the operation instruction type and the temporary permission validity period to form plain text instruction data, including: Step S411: Based on the final operation range verification conclusion, the cloud platform obtains the system predefined operation code corresponding to the operation instruction type and generates a unique timestamp with millisecond-level precision and random number extension based on Coordinated Universal Time; Step S412: Convert the temporary permission validity period into a time interval format of a start time and an end time, and perform field standardization processing with the operation instruction type and the timestamp to generate a structured data unit; Step S413: Perform integrity check on the operation instruction type field, timestamp field, and validity period field in the structured data unit. If there is an undefined operation code or a time interval conflict, the data reconstruction process is triggered; Step S414: Encapsulate the verified structured data unit into a plaintext instruction data packet including a header identifier, a data payload, and a check code according to a preset protocol.

5. The remote smart lock control method based on the cloud platform according to claim 4 is characterized in that: Step S42: The cloud platform calls a pre-installed hardware security module, generates a temporary symmetric encryption key based on the current session parameters, encrypts the plaintext instruction data to generate ciphertext, and binds the key identifier to the ciphertext to establish a key association, including: Step S421: The cloud platform extracts the communication protocol version of the current session, the unique identifier of the target smart lock, and the timestamp as session parameters to generate a key derivation seed; Step S422: calling the preset key generation interface of the hardware security module, inputting the key derivation seed and the preset hardware-level random number, and generating a temporary symmetric encryption key bound to the current session; Step S423: Using a temporary symmetric encryption key to encrypt the plaintext instruction data packet in blocks, using padding rules to resist length analysis attacks, and generating an encrypted ciphertext data block sequence; Step S424: associate and encode the key identifier assigned by the hardware security module with the ciphertext data block sequence to generate binding metadata including the key version number and encryption algorithm identifier; Step S425: Append the binding metadata to the ciphertext header to form a complete ciphertext data unit, and mark the life cycle of the temporary symmetric encryption key as a single-time valid state and store it in the key management audit log.

6. The remote smart lock control method based on the cloud platform according to claim 5 is characterized in that: Step S43: The cloud platform uses the private key in the hardware security module to digitally sign the ciphertext data and generate a dynamic encryption instruction containing a timestamp, ciphertext, and signature, including: Step S431: extracting the ciphertext header and ciphertext data block sequence from the complete ciphertext data unit, and associating them with the timestamp to generate the original data digest; Step S432: calling the signature engine of the hardware security module, using the private key to perform asymmetric encryption operation on the original data digest to generate digital signature data; Step S433: Assemble the digital signature data, the timestamp, the ciphertext header, and the ciphertext data block sequence according to a preset format to generate a complete dynamic encryption instruction including a protocol version identifier and an operation type code; Step S434: Perform hash verification on the dynamic encryption instruction. If the verification fails, the key rotation mechanism is triggered to regenerate a temporary symmetric encryption key and repeat steps S42 to S43; Step S435: Logically bind the dynamic encryption instruction with the link identifier of the final communication path to match the instruction transmission process with the path selection result.

7. The cloud platform-based remote smart lock control method according to claim 6, characterized in that: Step S44: The cloud platform calculates the interference intensity distribution and path attenuation parameters of the multi-band sound waves in the environment based on the sound wave feedback signals returned by location A and location B. Furthermore, the cloud platform constructs a communication path quality assessment model based on the signal strength, bit error rate, and network delay indicators reported in real time by the remote communication module, including: Step S441: Analyze the acoustic feedback signals returned from position A and position B to extract the propagation delay, phase offset, and signal amplitude parameters of the multi-band acoustic waves; Step S442: Calculate the Wi-Fi frequency band interference intensity distribution map in the environment based on the frequency band distribution and signal amplitude parameters of the multi-band sound waves, and analyze the attenuation coefficient of each path; Step S443: Receive communication quality indicators reported in real time by the remote communication module, including signal strength, bit error rate, and network delay data, and associate them with the physical location of the target smart lock for regional cluster analysis; Step S444: performing multi-dimensional feature fusion on the interference intensity distribution map, the path attenuation coefficient, and the clustered communication quality index to generate a communication quality feature vector including a frequency band weight factor and a path stability score; Step S445: Based on the preset communication path evaluation rule set, the communication quality feature vectors are prioritized and dynamically threshold matched to construct a communication path quality evaluation model that supports multi-objective optimization.

8. The remote smart lock control method based on the cloud platform according to claim 7 is characterized in that: Step S442: Based on the frequency distribution and signal amplitude parameters of the multi-band sound waves, a Wi-Fi frequency band interference intensity distribution map in the environment is calculated, and the attenuation coefficient of each path is analyzed, including: Step S4421: Decomposing the frequency distribution of the multi-band sound waves according to a preset Wi-Fi channel frequency range, and extracting the sound wave frequency bands that overlap with the Wi-Fi frequency bands as interference detection targets; Step S4422: Calculate the difference between the acoustic signal energy in each target frequency band and the noise energy in the corresponding Wi-Fi frequency band based on the signal amplitude parameter to generate a real-time interference strength index. Step S4423: Parse the acoustic wave feedback signal data packets at position A and position B to extract the acoustic wave propagation delay, phase offset, and received signal strength difference; call a preset acoustic wave propagation velocity model to calculate the deviation between the actual propagation velocity and the theoretical velocity of the acoustic wave path based on the propagation delay and the physical distance between positions A and B; calculate the reflection loss coefficient caused by the number of reflections in the path based on the phase offset and received signal strength difference, combined with the acoustic wave frequency characteristics; based on the actual propagation velocity deviation and the reflection loss coefficient, dynamically correct the attenuation effect of ambient humidity and temperature parameters on the acoustic wave energy using the dielectric absorption attenuation formula to generate the dielectric absorption attenuation coefficient; Step S4424: performing weighted fusion of the real-time interference intensity index, the reflection loss, and the medium absorption attenuation coefficient to generate an attenuation coefficient matrix including the path priority score and the anti-interference capability; Step S4425: Based on the attenuation coefficient matrix and the physical location topology of the target smart lock, a multi-dimensional Wi-Fi frequency band interference intensity distribution map covering the target area is drawn, and high interference risk path identifiers are marked.

9. The cloud platform-based remote smart lock control method according to claim 8, characterized in that: Step S443: Receive the communication quality indicators reported in real time by the remote communication module, including signal strength, bit error rate, and network delay data, and associate them with the physical location of the target smart lock to perform regional cluster analysis, including: Step S4431: The cloud platform receives the original data of the communication quality indicators reported by the remote communication module, and analyzes the numerical range and acquisition timestamp of the signal strength, bit error rate and network delay; Step S4432: Based on the physical location coordinates of the target smart lock, the communication quality index is mapped to the preset geographic grid division rule to generate a communication quality dataset with geographic tags; Step S4433: Clean the communication quality data set for outliers, remove data points that exceed the device physical performance threshold or network protocol specifications, and form standardized input data; Step S4434: The cloud platform maps the signal strength and network delay in the standardized input data into coordinate points in the multidimensional feature space, and defines the cluster core object based on the preset neighborhood radius threshold and the minimum sample number threshold; traverses the coordinate points in the multidimensional feature space, expands the neighborhood range of the core object according to the density accessibility judgment rule, and forms an initial geographic area cluster; filters the noise data of the coordinate points in the initial geographic area cluster, removes isolated points with a density lower than the preset threshold, and re-executes the neighborhood expansion to optimize the cluster boundary; verifies whether the variance of the signal strength and network delay in the optimized geographic area cluster meets the preset communication stability condition. If the condition is exceeded, the neighborhood radius dynamic adjustment mechanism is triggered; assigns a unique identifier to the finally divided geographic area cluster, and associates it with the physical location coordinates of the target smart lock within its coverage area to generate a clustering result of the geographic area cluster with communication quality consistency characteristics; Step S4435: Associating and mapping the clustering results of the geographical area clusters with the Wi-Fi frequency band interference intensity distribution map to generate a cluster analysis result including regional communication quality level labels.

10. The remote smart lock control method based on the cloud platform according to claim 9 is characterized in that: Step S45: The cloud platform selects a communication link with an interference intensity lower than a preset threshold and a delay that meets the operation instruction requirements as the final communication path based on the communication path quality evaluation model, and sends the dynamic encryption instruction to the remote communication module of the target smart lock through the final communication path, including: Step S451: Obtain interference strength values, path stability scores, and network delay data of all candidate communication links from the communication path quality assessment model, and extract their corresponding physical path identifiers; Step S452: Based on the preset interference intensity threshold and the delay tolerance parameter corresponding to the operation instruction type, a set of candidate communication links whose interference intensity is lower than the threshold and whose delay meets the instruction real-time requirement is screened; Step S453: Based on the path stability scores of the candidate communication link sets and the communication quality level labels of the geographical area cluster sets, the links are prioritized in terms of anti-interference capability and reliability; Step S454: Select the communication link with the highest priority as the final communication path, and verify whether its current connection status with the target smart lock remote communication module is active and available; Step S455: Inject the dynamic encryption instruction into the data transmission queue of the final communication path and attach a path selection audit tag.

Citation Information

Patent Citations

  • Intelligent door lock control method, device and system

    CN112348997A

  • Parking space lock communication load allocation method and system, storage medium and computer equipment

    CN113660170A

  • Parcel storing and taking system and method of intelligent cabinet based on Internet of Things

    CN116913011A

  • Business processing method, server, vehicle and system

    CN117544618A

  • Vehicle locking method and device and medium

    CN118748780A

Cited By

  • Sound environment imaging method based on sound array

    CN121028097A

  • Cloud platform remote permission configuration method, system and device for door lock management

    CN121462255A

  • Cloud platform remote permission configuration method, system and device for door lock management

    CN121462255B

  • Controllable and adjustable cleaning method and system for unmanned aerial vehicle

    CN121797522A