A cloud platform-based remote intelligent lock control method

By using a remote smart lock control method on a cloud platform, combined with user authentication and multi-band acoustic signals, the optimal transmission path is dynamically calculated, solving the signal instability problem of traditional smart locks in complex environments, and achieving reliable control command transmission and enhanced security.

CN120472567BActive Publication Date: 2026-03-31HEFEI ZHIHUI SPACE TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

Traditional remote smart locks suffer from unstable signal transmission in complex electromagnetic environments or when obstructed by obstacles, resulting in a high rate of communication interruption and making it difficult to guarantee the reliable transmission of control commands.

Method used

The cloud-based remote smart lock control method uses triple verification of user identity, operation permissions, and command compliance, combined with multi-band acoustic signals and real-time signal quality indicators, to dynamically calculate the optimal transmission path and achieve reliable transmission of encrypted commands.

Benefits of technology

In complex electromagnetic environments, it reduces communication interruption rates, improves the reliability and security of control commands, supports differentiated control in multi-user scenarios, and enhances the robustness and fault tolerance of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120472567B_ABST
    Figure CN120472567B_ABST
Patent Text Reader

Abstract

This invention provides a remote smart lock control method based on a cloud platform, relating to the field of artificial intelligence technology. The method includes: the cloud platform sending a sound wave signal transmission command to the target smart lock, triggering the smart lock to send multi-band sound wave signals to preset auxiliary signal enhancement device deployment locations A and B; the cloud platform receiving sound wave feedback signals from locations A and B, calculating the final communication path based on signal propagation delay, frequency band interference intensity, and attenuation parameters, combined with real-time signal quality indicators reported by the remote communication module; and dynamically encrypting the command and sending it to the remote communication module through the final communication path. This invention dynamically calculates the optimal transmission path, breaking through the limitations of traditional single-channel transmission. Even in complex electromagnetic environments or obstacle-blocked scenarios, it can still ensure reliable transmission of control commands and reduce communication interruption rates.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of artificial intelligence technology, and in particular to a remote smart lock control method based on a cloud platform. Background Technology

[0002] Traditional remote smart locks sometimes rely on single wireless communication protocols such as Wi-Fi and Bluetooth, and their physical layer characteristics have some shortcomings in complex environments:

[0003] For example, Wi-Fi (2.4GHz / 5GHz): The 2.4GHz band shares spectrum resources with devices such as microwave ovens and cordless phones. In high-density residential environments (such as apartment buildings with more than 10 households per floor), the Wi-Fi channel overlap rate between adjacent households can reach over 60%, causing the signal-to-noise ratio (SNR) to drop below -20dB and the bit error rate (BER) to soar to 10. -3 Level (normal communication requires BER < 10) -5 While the 5GHz band offers stronger anti-interference capabilities, it suffers from penetration loss, with concrete walls attenuating the signal by 15-20 dB per floor. This results in smart lock signal strength for residents on the third floor and above falling below -75 dBm (the critical value for Wi-Fi communication is -80 dBm).

[0004] Operating in the 2.4GHz ISM band, it employs frequency hopping technology to combat interference, but its transmission distance is limited (theoretically up to 100 meters, but in actual indoor environments, it is less than 15 meters). In a loft apartment with a metal frame structure, the steel beams cause a 25dB loss in Bluetooth signal reflection, and the signal multipath effect results in a packet loss rate (PLR) exceeding 30%, requiring more than 5 retransmissions for the unlock command to succeed. Summary of the Invention

[0005] The technical problem to be solved by the present invention is to provide a remote smart lock control method based on a cloud platform, which dynamically calculates the optimal transmission path. This solution breaks through the limitations of traditional single-channel transmission and can still ensure the reliable transmission of control commands and reduce the communication interruption rate in complex electromagnetic environments or obstacle-blocked scenarios.

[0006] To solve the above-mentioned technical problems, the technical solution of the present invention is as follows:

[0007] A remote smart lock control method based on a cloud platform, the method comprising:

[0008] Step S1: The user terminal sends a remote control request to the cloud platform, which includes user authentication information, the unique identifier of the target smart lock, and the type of operation instruction.

[0009] Step S2: After receiving the remote control request, the cloud platform performs triple verification on the user's identity, the scope of the target smart lock's operating permissions, and the compliance of the operation command type based on the pre-stored user-smart lock binding relationship and permission level policy.

[0010] Step S3: If the triple verification passes, the cloud platform generates a dynamic encrypted instruction containing a timestamp, operation instruction type, and temporary permission validity period, and determines the associated remote communication module based on the unique identifier of the target smart lock.

[0011] Step S4: The cloud platform sends an acoustic signal transmission command to the target smart lock, triggering the smart lock to send multi-band acoustic signals to the preset auxiliary signal enhancement device deployment locations A and B; the cloud platform receives the acoustic feedback signals returned by locations A and B, and calculates the final communication path based on the signal propagation delay, frequency band interference intensity and attenuation parameters, combined with the real-time signal quality indicators reported by the remote communication module. The dynamically encrypted command is sent to the remote communication module through the final communication path.

[0012] Furthermore, after receiving a remote control request, the cloud platform performs triple verification based on the pre-stored user-smart lock binding relationship and permission hierarchy policy, verifying the legitimacy of the user's identity, the scope of the target smart lock's operating permissions, and the compliance of the operating command type. This includes:

[0013] Step S31: Parse the remote control request and verify whether the request contains three required fields: user identity information, target smart lock unique identifier, and operation command type. If any field is missing, the verification will be terminated and an error response will be returned.

[0014] Step S32: Convert the user identity information, the target smart lock's unique identifier, and the operation instruction type into a standard data format to generate a structured request object;

[0015] Step S33: Based on the user identity information in the structured request object, query the user database to match valid accounts. If the account has enabled the enhanced authentication strategy, trigger the secondary authentication process. At the same time, analyze the account status and historical login behavior characteristics, intercept abnormal login requests and generate the first verification result.

[0016] Step S34: Based on the first verification result and the unique identifier of the target smart lock, retrieve the list of locks bound to the user in the user-lock binding relationship table. If the target lock does not exist in the list, terminate the verification. Based on the user role identifier and the operation instruction type, match the corresponding operation permission status in the permission matrix. If the permission is exceeded, generate an audit log containing operation type violation records and return the second verification result.

[0017] Step S35: Based on the second verification result and combined with the current environment context data, if the operation instruction involves granting temporary permissions, verify the validity period and remaining number of times the temporary permissions can be used, and generate the final operation scope verification conclusion to complete the triple verification.

[0018] Furthermore, the cloud platform sends an acoustic signal transmission command to the target smart lock, triggering the smart lock to send multi-band acoustic signals to the preset auxiliary signal enhancement equipment deployment locations A and B. The cloud platform receives the acoustic feedback signals returned from locations A and B, and calculates the final communication path based on signal propagation delay, frequency band interference intensity, and attenuation parameters, combined with the real-time signal quality indicators reported by the remote communication module. The dynamically encrypted command is then sent to the remote communication module through the final communication path, including:

[0019] Step S41: Based on the final operation scope verification conclusion, the cloud platform generates a unique timestamp and encapsulates the operation instruction type and temporary permission validity period to form plaintext instruction data;

[0020] Step S42: The cloud platform calls the preset hardware security module to generate a temporary symmetric encryption key based on the current session parameters, encrypts the plaintext command data to generate ciphertext, and binds the key identifier to the ciphertext to establish a key association;

[0021] Step S43: The cloud platform uses the private key in the hardware security module to digitally sign the ciphertext data, generating a dynamic encryption command containing a timestamp, ciphertext, and signature;

[0022] Step S44: Based on the acoustic feedback signals returned from location A and location B, the cloud platform calculates the interference intensity distribution and path attenuation parameters of multi-band acoustic waves in the environment, and combines the signal strength, bit error rate and network latency indicators reported in real time by the remote communication module to construct a communication path quality assessment model.

[0023] Step S45: The cloud platform selects communication links with interference intensity below a preset threshold and delay that meet the operation command requirements as the final communication path based on the communication path quality assessment model, and sends the dynamic encryption command to the remote communication module of the target smart lock through the final communication path.

[0024] Further, in step S41: based on the final operation scope verification conclusion, the cloud platform generates a unique timestamp and encapsulates the operation instruction type and temporary permission validity period to form plaintext instruction data, including:

[0025] Step S411: Based on the final operation range verification conclusion, the cloud platform obtains the system predefined operation code corresponding to the operation instruction type, and generates a unique timestamp with millisecond-level precision and random number extension based on Coordinated Universal Time;

[0026] Step S412: Convert the temporary permission validity period into a time interval format of start time and end time, and perform field standardization processing with operation instruction type and timestamp to generate structured data units;

[0027] Step S413: Perform integrity checks on the operation instruction type field, timestamp field, and validity period field in the structured data unit. If there is an undefined operation code or a time interval conflict, trigger the data reconstruction process.

[0028] Step S414: Encapsulate the verified structured data units into plaintext instruction data packets containing header identifiers, data payloads, and checksums according to a preset protocol.

[0029] Further, in step S42: the cloud platform calls the pre-configured hardware security module to generate a temporary symmetric encryption key based on the current session parameters, encrypts the plaintext command data to generate ciphertext, and binds the key identifier to the ciphertext to establish a key association, including:

[0030] Step S421: The cloud platform extracts the communication protocol version, the unique identifier of the target smart lock, and the timestamp of the current session as session parameters to generate a key derivation seed;

[0031] Step S422: Call the key generation interface of the preset hardware security module, input the key derivation seed and the preset hardware-level random number, and generate a temporary symmetric encryption key bound to the current session;

[0032] Step S423: Use a temporary symmetric encryption key to encrypt the plaintext instruction data packet in blocks, employ padding rules to resist length analysis attacks, and generate an encrypted ciphertext data block sequence;

[0033] Step S424: Associate the key identifier assigned by the hardware security module with the ciphertext data block sequence to generate binding metadata containing the key version number and encryption algorithm identifier;

[0034] Step S425: Append the binding metadata to the ciphertext header to form a complete ciphertext data unit, and mark the lifecycle of the temporary symmetric encryption key as a single valid state and store it in the key management audit log.

[0035] Further, in step S43: the cloud platform uses the private key in the hardware security module to digitally sign the ciphertext data, generating a dynamic encryption instruction containing a timestamp, ciphertext, and signature, including:

[0036] Step S431: Extract the ciphertext header and ciphertext data block sequence from the complete ciphertext data unit, and generate the original data digest by associating it with the timestamp;

[0037] Step S432: Call the signature engine of the hardware security module, use the private key to perform asymmetric encryption operation on the original data digest, and generate digital signature data;

[0038] Step S433: Assemble the digital signature data with the timestamp, ciphertext header and ciphertext data block sequence according to the preset format to generate a complete dynamic encryption instruction containing the protocol version identifier and operation type code;

[0039] Step S434: Perform hash verification on the dynamic encryption command. If the verification fails, trigger the key rotation mechanism to regenerate the temporary symmetric encryption key and repeat steps S42 to S43.

[0040] Step S435: Logically bind the dynamic encryption command to the link identifier of the final communication path so that the command transmission process matches the path selection result.

[0041] Further, in step S44: Based on the acoustic feedback signals returned from location A and location B, the cloud platform calculates the interference intensity distribution and path attenuation parameters of multi-band acoustic waves in the environment, and combines this with the signal strength, bit error rate, and network latency indicators reported in real time by the remote communication module to construct a communication path quality assessment model, including:

[0042] Step S441: Analyze the acoustic feedback signals returned from position A and position B, and extract the propagation delay, phase shift and signal amplitude parameters of the multi-band acoustic waves;

[0043] Step S442: Based on the frequency band distribution and signal amplitude parameters of multi-band sound waves, calculate the Wi-Fi band interference intensity distribution map in the environment and analyze the attenuation coefficient of each path;

[0044] Step S443: Receive the communication quality indicators reported in real time by the remote communication module, including signal strength, bit error rate and network latency data, and perform regional clustering analysis in association with the physical location of the target smart lock;

[0045] Step S444: Perform multi-dimensional feature fusion on the interference intensity distribution map, path attenuation coefficient and clustered communication quality indicators to generate a communication quality feature vector that includes frequency band weight factors and path stability scores;

[0046] Step S445: Based on the preset communication path evaluation rule set, prioritize and dynamically match the communication quality feature vectors to construct a communication path quality evaluation model that supports multi-objective optimization.

[0047] Further, step S442: Based on the frequency band distribution and signal amplitude parameters of multi-band sound waves, calculate the Wi-Fi band interference intensity distribution map in the environment, and analyze the attenuation coefficient of each path, including:

[0048] Step S4421: Decompose the frequency band distribution of the multi-band sound waves according to the preset Wi-Fi channel frequency range, and extract the sound wave frequency bands that overlap with the Wi-Fi frequency bands as interference detection targets;

[0049] Step S4422: Based on the signal amplitude parameters, calculate the difference between the acoustic signal energy of each target frequency band and the noise energy of the corresponding Wi-Fi frequency band, and generate a real-time interference intensity index;

[0050] Step S4423: Analyze the acoustic feedback signal data packets at positions A and B, extracting the acoustic propagation delay, phase offset, and difference in received signal strength; call the preset acoustic propagation speed model, and calculate the deviation between the actual propagation speed and the theoretical speed of the acoustic path based on the propagation delay and the physical distance between positions A and B; based on the phase offset and the difference in received signal strength, and combined with the acoustic frequency characteristics, calculate the reflection loss coefficient caused by the number of reflections in the path; based on the actual propagation speed deviation and the reflection loss coefficient, dynamically correct the influence of environmental humidity and temperature parameters on the attenuation of acoustic energy using the medium absorption attenuation formula, and generate the medium absorption attenuation coefficient;

[0051] Step S4424: The real-time interference intensity index is weighted and fused with reflection loss and medium absorption attenuation coefficient to generate an attenuation coefficient matrix that includes path priority score and anti-interference capability.

[0052] Step S4425: Based on the attenuation coefficient matrix and the physical location topology of the target smart lock, draw a multi-dimensional Wi-Fi band interference intensity distribution map covering the target area and mark high interference risk paths.

[0053] Further, step S443: Receive communication quality indicators reported in real time by the remote communication module, including signal strength, bit error rate, and network latency data, and perform regional clustering analysis in association with the physical location of the target smart lock, including:

[0054] Step S4431: The cloud platform receives the raw data of communication quality indicators reported by the remote communication module, and analyzes the numerical range and collection timestamp of signal strength, bit error rate and network latency.

[0055] Step S4432: Based on the physical location coordinates of the target smart lock, map the communication quality indicators to the preset geographic grid division rules to generate a geographically labeled communication quality dataset.

[0056] Step S4433: Perform outlier cleaning on the communication quality dataset, removing data points that exceed the physical performance threshold of the device or the network protocol specifications to form standardized input data;

[0057] Step S4434: The cloud platform maps the signal strength and network latency in the standardized input data to coordinate points in a multi-dimensional feature space, and defines clustering core objects based on preset neighborhood radius thresholds and minimum sample number thresholds; it traverses the coordinate points in the multi-dimensional feature space, expands the neighborhood range of the core objects according to density reachability judgment rules, and forms initial geographic region clusters; it filters noisy data for the coordinate points in the initial geographic region clusters, removes isolated points with a density lower than the preset threshold, and re-executes neighborhood expansion to optimize the cluster boundaries; it verifies whether the variance of signal strength and network latency within the optimized geographic region clusters meets the preset communication stability conditions, and if the conditions are exceeded, it triggers a neighborhood radius dynamic adjustment mechanism; it assigns a unique identifier to the finally divided geographic region clusters and associates them with the physical location coordinates of target smart locks within their coverage area, generating clustering results of geographic region clusters with consistent communication quality characteristics;

[0058] Step S4435: Associate and map the clustering results of the geographical area clusters with the Wi-Fi band interference intensity distribution map to generate clustering analysis results that include regional communication quality level labels.

[0059] Further, in step S45: the cloud platform, based on the communication path quality assessment model, selects communication links with interference intensity below a preset threshold and latency meeting the operation command requirements as the final communication path, and sends the dynamic encryption command to the remote communication module of the target smart lock through the final communication path, including:

[0060] Step S451: Obtain the interference intensity value, path stability score and network delay data of all candidate communication links from the communication path quality assessment model, and extract their corresponding physical path identifiers;

[0061] Step S452: Based on the preset interference intensity threshold and the delay tolerance parameter corresponding to the operation command type, filter the set of candidate communication links whose interference intensity is lower than the threshold and whose delay meets the real-time requirements of the command.

[0062] Step S453: Based on the path stability score of the candidate communication link set and combined with the communication quality level label of the geographical region cluster set, prioritize the anti-interference capability and reliability of the links.

[0063] Step S454: Select the highest priority communication link as the final communication path, and verify whether its current connection status with the target smart lock remote communication module is active and available.

[0064] Step S455: Inject the dynamic encryption instruction into the data transmission queue of the final communication path and attach a path selection audit tag.

[0065] The above-described solution of the present invention has at least the following beneficial effects:

[0066] By employing a triple verification mechanism of user identity legitimacy verification, hierarchical operation permission verification, and instruction compliance verification, a full-link security barrier is constructed from user to device, effectively preventing risks of unauthorized access, unauthorized operation, and malicious instruction injection. Dynamically encrypted instructions combined with timestamps and temporary validity periods achieve "one-time password" encrypted communication, eliminating instruction replay attacks and enhancing the system's anti-cracking capabilities.

[0067] By analyzing the propagation delay, frequency band interference, and attenuation characteristics of the acoustic feedback signals deployed at locations A and B, and combining this with the signal quality indicators (such as signal-to-noise ratio and packet loss rate) reported in real time by the remote communication module, the optimal transmission path is dynamically calculated. This solution breaks through the limitations of traditional single-channel transmission and can still ensure the reliable transmission of control commands and reduce the communication interruption rate in complex electromagnetic environments or obstacle-blocked scenarios.

[0068] The multi-band detection mechanism of acoustic signals can actively sense the physical characteristics of the space (such as wall material and spatial layout), and adjust the communication strategy in real time in combination with cloud platform algorithms, so that the system has environmental self-adaptation capability. The real-time signal quality feedback mechanism of the remote communication module forms a "perception-decision-execution" closed loop, ensuring that the optimal transmission path is always selected under dynamic network conditions.

[0069] Pre-stored binding relationships and permission hierarchical policies support differentiated control in multi-user scenarios (such as administrators setting temporary visitor permissions), meeting the needs of multiple scenarios such as home, office, and sharing economy. Operation command type compliance verification can prevent accidental operations (such as unauthorized unlocking commands) and improve system fault tolerance.

[0070] Acoustic signals, as an auxiliary communication method, can serve as a backup transmission channel when wireless signals are interfered with or the network is interrupted, thereby enhancing system robustness. The dynamic path selection mechanism can automatically bypass faulty nodes or high-interference areas, ensuring the accessibility of critical control commands. Attached Figure Description

[0071] Figure 1 This is a flowchart illustrating a remote smart lock control method based on a cloud platform, provided by an embodiment of the present invention. Detailed Implementation

[0072] Exemplary embodiments of the present disclosure will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete, and will fully convey the scope of the disclosure to those skilled in the art.

[0073] like Figure 1As shown, an embodiment of the present invention proposes a remote smart lock control method based on a cloud platform, the method comprising the following steps:

[0074] Step S1: The user terminal sends a remote control request to the cloud platform, which includes user authentication information, the unique identifier of the target smart lock, and the type of operation instruction.

[0075] Step S2: After receiving the remote control request, the cloud platform performs triple verification on the user's identity, the scope of the target smart lock's operating permissions, and the compliance of the operation command type based on the pre-stored user-smart lock binding relationship and permission level policy.

[0076] Step S3: If the triple verification passes, the cloud platform generates a dynamic encrypted instruction containing a timestamp, operation instruction type, and temporary permission validity period, and determines the associated remote communication module based on the unique identifier of the target smart lock.

[0077] Step S4: The cloud platform sends an acoustic signal transmission command to the target smart lock, triggering the smart lock to send multi-band acoustic signals to the preset auxiliary signal enhancement device deployment locations A and B; the cloud platform receives the acoustic feedback signals returned by locations A and B, and calculates the final communication path based on the signal propagation delay, frequency band interference intensity and attenuation parameters, combined with the real-time signal quality indicators reported by the remote communication module. The dynamically encrypted command is sent to the remote communication module through the final communication path.

[0078] In this embodiment of the invention, in step S1, the user does not need to operate near the smart lock. They can send control requests to the cloud platform anytime, anywhere via a terminal device (such as a mobile phone), greatly improving the convenience of using the smart lock. For example, if a user forgets to lock the door while out, they can immediately send a lock command via their mobile phone. Determining the control target and intent: Carrying the unique identifier of the target smart lock and the type of operation command allows the cloud platform to accurately identify which smart lock the user wants to control and the specific operation requirement, avoiding control confusion. For example, in a large apartment building with numerous smart locks, the unique identifier ensures that the command is accurately delivered to the target lock. User authentication information serves as the basis for subsequent identity verification, ensuring that only legitimate users can initiate control requests, thus enhancing system security.

[0079] Step S2 verifies the legitimacy of the user's identity to prevent unauthorized users from impersonating legitimate users and initiating control requests, thus avoiding unauthorized operation of the smart lock. For example, it prevents hackers from controlling the smart lock by stealing user information. Based on pre-stored user-smart lock binding relationships and permission hierarchical policies, the scope of operation permissions for the target smart lock is verified, enabling fine-grained management of different users having different operation permissions for different smart locks. For example, the owner may have all operation permissions, while temporary visitors may only have unlocking permissions. The compliance of operation command types is also verified to ensure that user-sent operation commands conform to the rules set by the system. For example, the system may prohibit certain operations during specific time periods; verification prevents unauthorized operations.

[0080] Step S3 generates a dynamically encrypted command. Combined with a timestamp and temporary permission validity period, this makes the command difficult to crack or forge. Even if the command is intercepted during transmission, its dynamic and time-sensitive nature prevents attackers from using it for illegal operations. The temporary permission validity period addresses the needs of scenarios requiring temporary use of smart locks. For example, temporary visitors may have unlocking privileges for a specific time period, after which the privileges automatically expire, improving security. The remote communication module associated with the target smart lock is determined based on its unique identifier, ensuring that the dynamically encrypted command is accurately sent to the target smart lock, guaranteeing communication accuracy.

[0081] Step S4 involves sending multi-band acoustic signals and analyzing feedback signals. By combining real-time signal quality indicators, factors such as signal propagation delay, frequency interference intensity, and attenuation parameters are comprehensively considered to calculate the optimal final communication path. This avoids paths with high signal interference and severe attenuation, improving communication stability and reliability. For example, in complex building environments, it finds the path with the strongest signal and least interference to transmit commands. Utilizing multi-band acoustic signals and auxiliary signal enhancement equipment allows the system to function normally in complex electromagnetic environments. Even in areas with significant electromagnetic interference, adjusting the communication path ensures normal command transmission. By dynamically adjusting the communication path, interference and attenuation during signal propagation are reduced, thereby improving signal quality, lowering the error rate of command transmission, and ensuring the smart lock can accurately receive and execute commands.

[0082] In another preferred embodiment of the present invention, step S1 above, in which the user terminal sends a remote control request to the cloud platform, the request carrying user authentication information, a unique identifier of the target smart lock, and an operation instruction type, may include:

[0083] Users open the smart lock control application on their terminal device (such as a mobile app or web browser) and enter their pre-registered account and password. The application encrypts this information (for example, using a common hash algorithm such as SHA-256) to ensure security during transmission.

[0084] If biometric technologies such as fingerprint or facial recognition are used, the terminal device's sensors will collect the user's fingerprint or facial image data. This data will then undergo feature extraction and encryption locally to form encrypted information representing the user's identity.

[0085] When a user successfully logs in for the first time, the cloud platform generates a unique token for the user. Subsequent times the user makes a request, the terminal device retrieves this token from local storage as authentication information.

[0086] Users manually input the target smart lock's number or other unique identifier in the control application. For example, in a shared apartment scenario, the user might need to input the smart lock number corresponding to the room. If the terminal device and the smart lock support near-field communication (such as Bluetooth), the terminal can automatically scan nearby smart locks and obtain their unique identifiers. For instance, when a user enters the vicinity of their home, their phone automatically identifies the smart lock at their door via Bluetooth. On the terminal application's interface, users select the operation command type by clicking corresponding buttons or options. Common operation command types include unlocking, locking, and viewing unlocking records. For example, if a user clicks the "unlock" button, the application will determine that the operation command type is unlocking. Some terminal applications that support voice interaction allow users to speak operation commands, such as "unlock the door," and the application will convert the voice information into the corresponding operation command type.

[0087] In a preferred embodiment of the present invention, after receiving a remote control request, the cloud platform performs triple verification on the user's identity legitimacy, the target smart lock's operating permission scope, and the compliance of the operating command type based on the pre-stored user-smart lock binding relationship and permission hierarchy policy. This includes:

[0088] Step S31: Parse the remote control request and verify that the request contains three required fields: user identity information, target smart lock unique identifier, and operation command type. If any field is missing, the verification process terminates and an error response is returned. Specifically, after receiving the remote control request, the cloud platform first parses it according to the data format (e.g., JSON, XML). For JSON format requests, the appropriate JSON parsing library is used to convert the request data into an operable data object. The parsed data object is then checked to see if it contains the three fields: user identity information, target smart lock unique identifier, and operation command type. Verification is performed by checking if the fields exist and are not empty. If any field is found to be missing, the cloud platform immediately terminates the subsequent verification process and returns a response containing error information to the user terminal, such as "The request is missing necessary fields. Please check and resend."

[0089] Step S32: Convert the user identity information, the target smart lock's unique identifier, and the operation command type into a standard data format to generate a structured request object. Specifically, this includes: Since the request data sent by the user terminal may have different formats, the cloud platform needs to convert the user identity information, the target smart lock's unique identifier, and the operation command type into a unified standard data format. For example, convert the user identity information into a string type and the target smart lock's unique identifier into a fixed-length encoding format. Organize the converted data according to a certain structure to generate a structured request object. This object can be a custom class instance containing attributes such as user identity information, the target smart lock's unique identifier, and the operation command type.

[0090] Step S33: Based on the user identity information in the structured request object, query the user database to match valid accounts. If the account has an enhanced authentication policy enabled, a secondary authentication process is triggered. Simultaneously, analyze the account status and historical login behavior characteristics to intercept abnormal login requests and generate a first verification result. Specifically, this includes: using the user identity information in the structured request object to query the user database to find a matching valid account. If a matching account is found, subsequent verification continues; if not found, the user's identity is deemed illegitimate, and a first verification result of verification failure is generated. For accounts with enhanced authentication policies enabled, the cloud platform triggers a secondary authentication process, including sending a verification code to the user's mobile phone and requiring the user to perform fingerprint or facial recognition. Subsequent verification only continues after the user passes the secondary authentication. Analyze the account status (e.g., whether it is frozen, whether it has expired, etc.) and historical login behavior characteristics (e.g., login time, login location, etc.). If abnormal login behavior is detected, such as login from a different location or multiple login attempts within a short period, the cloud platform intercepts the request and generates a first verification result of verification failure.

[0091] Step S34: Based on the first verification result and the unique identifier of the target smart lock, retrieve the list of locks bound to the user in the user-lock binding relationship table. If the target lock does not exist in the list, the verification is terminated. Based on the user role identifier and operation instruction type, match the corresponding operation permission status in the permission matrix. If the permission is exceeded, generate an audit log containing operation type violation records and return the second verification result. Specifically, if the first verification result is successful, the cloud platform retrieves the list of locks bound to the user in the user-lock binding relationship table based on the unique identifier of the target smart lock. Check if the target smart lock exists in the list. If it does not exist, terminate the verification process and return an error response to the user terminal. Based on the user role identifier and operation instruction type, find the corresponding operation permission status in the permission matrix. The permission matrix records the permission status of different user roles for different operation instructions. If the operation instruction exceeds the user's permission scope, the cloud platform generates an audit log containing operation type violation records, recording the violating user, operation instruction type, time, and other information, and generates a second verification result indicating verification failure.

[0092] Step S35: Based on the second verification result and combined with the current environment context data, if the operation command involves granting temporary permissions, the validity period and remaining available uses of the temporary permissions are verified, and a final operation scope verification conclusion is generated to complete the triple verification. Specifically, the current environment context data may include information such as time, location, and system status. During the final verification, the cloud platform will comprehensively judge based on this data. If the operation command involves granting temporary permissions, the cloud platform will check the validity period and remaining available uses of the temporary permissions. If the temporary permissions have expired or the remaining available uses are zero, the operation command is deemed invalid, and a final operation scope verification conclusion of verification failure is generated. After the verification of the above steps, the cloud platform generates the final operation scope verification conclusion, completing the triple verification process. If the verification passes, the cloud platform will continue with subsequent operations, such as generating dynamic encryption commands; if the verification fails, a corresponding error response will be returned to the user terminal.

[0093] In this embodiment of the invention, by verifying required fields, it is ensured that the requests received by the cloud platform contain the key information required for subsequent verification, avoiding verification errors or system anomalies caused by missing data. Requests with missing fields are detected and processed early in the verification process, avoiding unnecessary subsequent verification operations and improving overall verification efficiency. Converting request data into a standard data format allows the cloud platform to more easily process and compare requests sent by different user terminals, improving the accuracy and consistency of data processing. Generating structured request objects provides a clear data structure for subsequent verification steps, making the code implementation more concise and easier to maintain. By querying the user database, triggering the secondary authentication process, and analyzing account status and historical login behavior characteristics, unauthorized user logins and operations are effectively prevented, ensuring user account security. Abnormal login requests can be detected and intercepted in a timely manner, reducing security risks and protecting the interests of users and the system. By retrieving the user-lock binding relationship table and permission matrix, it is ensured that users can only perform legitimate operations on their bound smart locks, preventing unauthorized operations. An audit log containing records of operation type violations is generated, providing important evidence for subsequent security audits and management, and helping to discover and handle potential security issues. For operation commands involving the granting of temporary permissions, the validity period and remaining available uses are verified to ensure the reasonable use of temporary permissions and prevent their abuse. Verification is also performed in conjunction with the current environment context data, making the verification results more consistent with the actual situation and improving the accuracy and security of the verification.

[0094] In a preferred embodiment of the present invention, the cloud platform sends an acoustic signal transmission command to the target smart lock, triggering the smart lock to send multi-band acoustic signals to preset auxiliary signal enhancement device deployment locations A and B; the cloud platform receives acoustic feedback signals returned from locations A and B, calculates the final communication path based on signal propagation delay, frequency band interference intensity, and attenuation parameters, combined with real-time signal quality indicators reported by the remote communication module, and sends a dynamically encrypted command to the remote communication module through the final communication path, including:

[0095] Step S41: Based on the final operation scope verification conclusion, the cloud platform generates a unique timestamp and encapsulates the operation instruction type and temporary permission validity period to form plaintext instruction data;

[0096] Step S42: The cloud platform calls the preset hardware security module to generate a temporary symmetric encryption key based on the current session parameters, encrypts the plaintext command data to generate ciphertext, and binds the key identifier to the ciphertext to establish a key association;

[0097] Step S43: The cloud platform uses the private key in the hardware security module to digitally sign the ciphertext data, generating a dynamic encryption command containing a timestamp, ciphertext, and signature;

[0098] Step S44: Based on the acoustic feedback signals returned from location A and location B, the cloud platform calculates the interference intensity distribution and path attenuation parameters of multi-band acoustic waves in the environment, and combines the signal strength, bit error rate and network latency indicators reported in real time by the remote communication module to construct a communication path quality assessment model.

[0099] Step S45: The cloud platform selects communication links with interference intensity below a preset threshold and delay that meet the operation command requirements as the final communication path based on the communication path quality assessment model, and sends the dynamic encryption command to the remote communication module of the target smart lock through the final communication path.

[0100] In this embodiment of the invention, a "time-permission" dual-factor constraint is constructed by binding a unique timestamp with the validity period of temporary permissions, effectively resisting replay attacks. Even if the ciphertext is intercepted, the instruction automatically expires after the timeout, significantly reducing the risk of unauthorized operations. A hardware security module (HSM) is used to generate a temporary symmetric key, achieving physical isolation protection for key generation, storage, and use. The key identifier binding mechanism supports key lifecycle management, providing a technical foundation for key rotation and emergency revocation. A digital signature based on the HSM private key forms a "command-signature-timestamp" three-in-one authentication system, ensuring that the source of the instruction is trustworthy (anti-forgery), the content is complete (anti-tampering), and the timeliness is controllable (anti-replay), meeting financial-grade security standards. Breaking through the limitations of traditional single-parameter path selection, this system innovatively constructs a three-dimensional evaluation model based on acoustic propagation time delay (ToF), frequency band interference intensity (RSSI), and path loss coefficient. Combined with real-time signal quality indicators (SNR, BER, Latency) reported by the remote communication module, it forms a dynamic environment perception capability. Through dual screening using threshold comparison (interference intensity < preset threshold) and QoS constraints (latency < operation response requirements), it can still ensure reliable transmission of control commands in complex electromagnetic interference scenarios (such as urban canyons and industrial environments), reducing communication interruption rates. Acoustic-assisted detection can detect physical space anomalies (such as illegal signal shielding devices). Combined with the integrity verification of encrypted commands, it forms a three-dimensional protection system of "air interface defense + data encryption," effectively resisting man-in-the-middle (MITM) attacks and signal interference attacks.

[0101] Multi-band acoustic wave detection (such as 20kHz-40kHz ultrasound) can penetrate common obstacles (wood, glass). Combined with a signal attenuation model, it automatically senses changes in spatial topology (such as furniture movement or new obstructions), dynamically adjusts communication strategies, and improves system stability in dynamic environments. Through the parallel processing of rapid acoustic signal detection (response time <500ms) and encrypted command transmission, it ensures security while keeping end-to-end control latency at an industry-leading level (typically <2 seconds), meeting real-time requirements such as emergency unlocking. The key identifier binding mechanism reserves interfaces for future integration with cutting-edge technologies such as quantum encryption, and the communication path evaluation model can be expanded to support the convergence of heterogeneous networks such as 5G / WiFi 6, constructing a future-oriented smart lock control system architecture.

[0102] In a preferred embodiment of the present invention, step S41: Based on the final operation scope verification conclusion, a unique timestamp is generated by the cloud platform, and the operation instruction type and temporary permission validity period are data-encapsulated to form plaintext instruction data, including:

[0103] Step S411: Based on the final operation scope verification conclusion, the cloud platform obtains the system predefined operation code corresponding to the operation instruction type, and generates a unique timestamp with millisecond precision and random number extension based on Coordinated Universal Time (UTC). Specifically, the cloud platform matches the corresponding unique identifier (e.g., "UNL-001" represents the unlock instruction) from the system predefined operation code list according to the verified operation instruction type (e.g., "unlock" or "authorize temporary permission"); obtains the current time based on UTC, accurate to the millisecond level (e.g., "2025-04-26T14:30:45.123Z"); and adds a random number extension (e.g., "-RND-8527"). By mixing fixed time and random factors, each timestamp is ensured to be unique and unpredictable within the system.

[0104] Step S412: Convert the temporary permission validity period into a time interval format of start time and end time, and perform field standardization processing with operation instruction type and timestamp to generate structured data units. Specifically, this includes converting the temporary permission validity period (e.g., "2 hours") into a specific time interval, such as start time "2025-04-26T14:30:00Z" and end time "2025-04-26T16:30:00Z". Unify the operation instruction type (string), timestamp (UTC format with random extension), and validity period (start / end time field) into a standard format that the system can recognize (such as ISO8601 time format, fixed-length opcode); combine them into structured data units, for example: {opcode:UNL-001, timestamp:2025-04-26T14:30:45.123-RND-8527, start time:2025-04-26T14:30:00Z, end time:2025-04-26T16:30:00Z}.

[0105] Step S413: Perform integrity checks on the operation instruction type field, timestamp field, and validity period field in the structured data unit. If an undefined operation code or time interval conflict exists, trigger the data reconstruction process. Specifically, this includes: verifying whether the operation code in the structured data exists in the system's predefined list. For example, if an unregistered operation code "DEL-999" (assuming it represents deleting user permissions) is received, an error message is triggered and encapsulation is rejected. Check if the start time is later than the end time (e.g., start time is 16:00, end time is 15:00). If there is a conflict, the data is deemed invalid. For non-temporary permission instructions (e.g., permanent authorization), skip the time interval check and directly mark it as "no validity period limit". If an undefined operation code or time interval conflict is found, the system automatically backtracks to the data generation stage to re-obtain the correct operation instruction type or validity period parameter.

[0106] Step S414: Encapsulate the verified structured data units into plaintext instruction data packets containing a header identifier, data payload, and checksum according to a preset protocol. Specifically, this includes: inserting a fixed identifier (e.g., "LOCK-CTRL-01") at the beginning of the data packet for the smart lock to quickly identify the instruction type and call the corresponding parsing module; filling the structured data units (opcode, timestamp, validity period) into the main body of the data packet; calculating the data payload using a hash algorithm (e.g., SHA-1) to generate a checksum (e.g., "3a5f2d7c8b") for verifying data integrity during transmission; and forming a plaintext data packet resembling "header identifier|data payload|checksum".

[0107] In this embodiment of the invention, millisecond-level timestamps and random number extensions ensure the uniqueness of each instruction, preventing hackers from intercepting old instructions and resending them (replay attacks). For example, an attacker cannot use an unlocking instruction from 10 minutes ago to open the current door lock. Using UTC time avoids time zone conversion errors, making it suitable for multi-regional deployment scenarios (such as multinational shared apartments), ensuring that instruction validity is consistent across different regions. Temporary permissions are converted into explicit time intervals (e.g., "today 14:30-16:30"), avoiding the window period vulnerability caused by traditional "hourly authorization" (e.g., the original scheme's 1-hour authorization may cover unnecessary periods). Standardized field formats reduce the cost of interfacing with devices from different manufacturers; for example, regardless of whether the smart lock is from brand A or brand B, a unified timestamp and operation code format can be recognized. Operation codes and time intervals are verified before encapsulation to avoid permission logic confusion caused by front-end input errors (e.g., users mistakenly selecting "end time earlier than start time"), for example, preventing temporary permissions from being incorrectly set to "validity period -1 hour". Recording exception logs for undefined operation codes or conflicting data helps administrators to investigate unauthorized operation attempts (such as forged "DEL-999" delete commands).

[0108] The header identifier enables the smart lock to quickly locate the parsing module (e.g., unlocking commands call the unlocking logic, authorization commands call the permission management logic), reducing command processing latency (actual tests show a reduction of 20-30ms in parsing time). The verification code mechanism can detect whether the data has been tampered with during transmission due to signal interference (e.g., the timestamp field is mistakenly transmitted as "2025-04-26T14:30:45.123-RND-8528"), ensuring that the commands executed by the smart lock are completely consistent with those issued by the cloud platform.

[0109] In a preferred embodiment of the present invention, step S42: the cloud platform calls a preset hardware security module to generate a temporary symmetric encryption key based on the current session parameters, encrypts the plaintext command data to generate ciphertext, and binds the key identifier to the ciphertext to establish a key association, including:

[0110] Step S421: The cloud platform extracts the communication protocol version, the unique identifier of the target smart lock, and the timestamp of the current session as session parameters to generate a key derivation seed. Specifically, the cloud platform extracts three core parameters from the current communication session:

[0111] Communication protocol version: such as HTTPS / 2.0, MQTTv5, etc., to match compatible encryption algorithms;

[0112] The target smart lock has a unique identifier, such as "LOCK-001234", to ensure that the key is bound to a specific lock.

[0113] Timestamp: The UTC time with random extension generated in step S411 (e.g., “2025-04-26T14:30:45.123-RND-8527”).

[0114] The three parameters are concatenated in a fixed order (e.g., "protocol version, lock ID and timestamp") to form a key derivation seed of 256 bits (e.g., "HTTPS / 2.0LOCK-0012342025-04-26T14:30:45.123-RND-8527").

[0115] Step S422: Call the key generation interface of the preset hardware security module, input the key derivation seed and the preset hardware-level random number, and generate a temporary symmetric encryption key bound to the current session. Specifically, this includes: connecting to a physically isolated HSM device via a dedicated line or encrypted channel to ensure that the key generation process is not subject to software-level attacks; generating true random numbers (such as random number sequences based on quantum noise) internally in the HSM and mixing them with the externally input key derivation seed; generating a temporary symmetric encryption key (such as an AES-256 key) through a key derivation function (KDF); embedding a session identifier (such as UUID "a1b2c3d4-e5f6-7g8h-9i0j") during key generation to ensure that the key is only used for the current request and cannot be reused across sessions.

[0116] Step S423: Encrypt the plaintext instruction data packet in blocks using a temporary symmetric encryption key, employing padding rules to resist length analysis attacks, and generating an encrypted sequence of ciphertext data blocks. Specifically, this includes: dividing the plaintext instruction data packet (such as the "header identifier|data payload|checksum" generated in step S414) into multiple data blocks of a fixed length (such as a 128-bit block in AES); encrypting each data block using a temporary symmetric key in a block cipher mode (such as CBC mode), with the previous ciphertext block participating in the encryption of the next plaintext block to ensure the dependency between data blocks; padding the last data block that is not long enough with special characters (such as ASCII 0x01-0x0F), the padding content including a padding length identifier, which is automatically removed during decryption to prevent attackers from inferring the plaintext structure through the ciphertext length.

[0117] Step S424: Associate the key identifier assigned by the hardware security module with the ciphertext data block sequence to generate binding metadata containing the key version number and encryption algorithm identifier. Specifically, the HSM assigns a unique identifier to the generated temporary key (e.g., "KEY-20250426-1430-001"), which contains three parts of information:

[0118] Version number: such as "V3", indicating the version of the key generation algorithm;

[0119] Algorithm identifier: such as "AES256-CBC", indicating the algorithm required for decryption;

[0120] Timestamp: Key generation time (e.g., "2025-04-26T14:30:45Z");

[0121] Associate the key identifier with the sequence of ciphertext data blocks using JSON format.

[0122] Step S425: Append the binding metadata to the ciphertext header to form a complete ciphertext data unit, and mark the lifecycle of the temporary symmetric encryption key as a single-use state and store it in the key management audit log. Specifically, this includes: serializing the binding metadata (JSON format) and appending it to the ciphertext header to form a complete ciphertext data unit in the format "metadata|encrypted data block"; recording the lifecycle of the temporary key in the key management system as "single-use", that is, the key automatically expires after this instruction transmission is completed and cannot be used for subsequent communication; generating an audit log containing the key identifier, usage time, and target lock ID, and storing it on a read-only medium for security compliance checks.

[0123] In this embodiment of the invention, the key derivation seed for each session includes a real-time timestamp and a unique lock identifier, ensuring that keys for different times and different locks are completely different, avoiding the risk of "one key for multiple uses" in traditional static keys (such as the leakage of a shared apartment's static key leading to the cracking of multiple locks). The seed is generated according to the communication protocol version, dynamically matching the encryption requirements of different protocols (such as using TLS encryption in HTTPS scenarios and AES-CCM mode in MQTT scenarios), improving system flexibility.

[0124] By generating keys through HSM, its physical security mechanisms (such as tamper-proof chips and real-time monitoring circuits) can be used to prevent the key generation process from being stolen by malicious software (compared to traditional software-generated keys, HSM can resist memory dump attacks).

[0125] CBC mode, combined with block processing, generates different ciphertext blocks for the same plaintext block (due to the random generation of the Initialization Vector (IV)), resisting statistical analysis attacks (such as attackers being unable to infer the plaintext content from recurring ciphertext blocks). Through PKCS#7 padding, even if the ciphertext length is intercepted, attackers cannot determine the original plaintext length (e.g., padding with 1 byte results in the same ciphertext length as padding with 16 bytes), avoiding padding oracle attacks such as OAEP. The key identifier carries algorithm and version information, allowing the smart lock to automatically call the corresponding decryption module (e.g., upon receiving the "AES256-CBC" identifier, directly loading the CBC mode decryption function), reducing manual configuration costs. The version number records the iteration of the key generation logic (e.g., upgrading from V1 to V3). When a vulnerability is found in an older version algorithm, the affected key can be quickly located and a forced update can be implemented.

[0126] The key can only be used once. Even if an attacker intercepts the ciphertext and key identifier, they cannot use the key to decrypt the next instruction (in traditional solutions, static keys can be reused repeatedly, resulting in a replay attack success rate as high as 60%). The audit log records the entire key usage process, meeting compliance requirements such as GDPR and ISO27001 (for example, a financial institution was fined $2 million by regulators for being unable to trace key usage records; this solution can avoid such risks).

[0127] In a preferred embodiment of the present invention, step S43: The cloud platform uses the private key in the hardware security module to digitally sign the ciphertext data, generating a dynamic encryption instruction containing a timestamp, ciphertext, and signature, including:

[0128] Step S431: Extract the ciphertext header and ciphertext data block sequence from the complete ciphertext data unit, and generate the original data digest by associating it with a timestamp. Specifically, this includes: separating the ciphertext header (containing metadata such as key identifier and algorithm identifier) ​​and the ciphertext data block sequence (encrypted instruction content) from the complete ciphertext data unit generated in step S425. Obtain the unique timestamp generated in step S411 (e.g., "2025-04-26T14:30:45.123-RND-8527"), and concatenate it with the ciphertext header and ciphertext data blocks in a fixed order to form the original data. Use a hash algorithm (e.g., SHA-256) to operate on the original data to generate a fixed-length hash value (e.g., a 256-bit digest), which serves as the input basis for the digital signature.

[0129] Step S432: Invoke the signature engine of the hardware security module, use the private key to perform asymmetric encryption on the original data digest, and generate digital signature data. Specifically, this includes: sending a signature request to the hardware security module (HSM) through a secure channel, triggering its built-in asymmetric encryption engine, and the HSM using the private key bound to the cloud platform (stored in the hardware encryption chip and cannot be read by external systems) to encrypt the original data digest and generate digital signature data (such as a 512-bit signature value); each signature is associated with a unique timestamp and ciphertext data to ensure that signatures for different instructions cannot be reused.

[0130] Step S433: Assemble the digital signature data, timestamp, ciphertext header, and ciphertext data block sequence according to a preset format to generate a complete dynamic encryption instruction containing a protocol version identifier and operation type code. Specifically, this includes assembling the following content according to a preset format:

[0131] Digital signature data: The signature value generated in step S432;

[0132] Timestamp: UTC time with random extension;

[0133] Ciphertext header: Contains metadata including key identifier and algorithm identifier;

[0134] Ciphertext data block sequence: the encrypted instruction content.

[0135] Protocol and operation encoding added:

[0136] Insert a protocol version identifier (such as "V4.2") into the instruction header to indicate the communication protocol version used by the smart lock; add an operation type code (such as "OP-UNL" to represent the unlocking operation) to facilitate the smart lock to quickly call the corresponding execution logic.

[0137] Step S434: Perform hash verification on the dynamic encryption command. If the verification fails, trigger the key rotation mechanism to regenerate the temporary symmetric encryption key and repeat steps S42 to S43. Specifically, this includes: performing hash operation on the assembled dynamic encryption command again to generate a checksum (such as a SHA-256 value), comparing the newly generated checksum with the original data digest of step S431. If they do not match, it is determined that the command has been tampered with or damaged during the assembly process. If the verification fails, the system automatically discards the current temporary symmetric encryption key and regenerates a new key and ciphertext starting from step S421 to avoid using a key that may have been leaked or damaged.

[0138] Step S435: Logically bind the dynamic encryption command to the link identifier of the final communication path to match the command transmission process with the path selection result. Specifically, this includes: extracting the path identifier (e.g., "PATH-A-20250426-1430") from the result of step S4 (final communication path calculation), representing the optimal communication path (e.g., transmission through the acoustic relay device at location A); adding a path identifier field to the command metadata to establish a mapping relationship between the dynamic encryption command and the communication path; when the smart lock receives the command, it verifies whether the path identifier matches the currently available path. If they do not match, it rejects the command to prevent the command from being transmitted through an unauthorized path.

[0139] In this embodiment of the invention, hash digest generation ensures that the original data (ciphertext and timestamp) of the dynamically encrypted command is not tampered with before signing. For example, if an attacker modifies the validity period field in the ciphertext, the hash value will change significantly and be intercepted in subsequent verification. The digest is bound to the timestamp, providing irrefutable time evidence for subsequent digital signatures (e.g., the user cannot deny initiating a specific operation at a certain point in time). The private key is stored in the HSM hardware, avoiding the risks of traditional software-stored private keys (e.g., memory leaks leading to stolen private keys). The digital signature proves that the command is legally issued by the cloud platform, and attackers cannot forge valid signatures (the mathematical properties of asymmetric encryption ensure that only the corresponding public key can verify the signature, while the private key is held only by the cloud platform). Protocol version identification and operation type encoding enable cross-vendor compatibility of the command. For example, smart locks of different brands can all recognize the unlocking command through "OP-UNL" encoding without the need for additional development of adaptation interfaces. The operation type encoding is directly associated with the internal execution logic of the smart lock (e.g., the unlocking command corresponds to the motor drive module, and the authorization command corresponds to the permission database operation), reducing parsing time by approximately 15-20ms. If an attacker attempts to tamper with the ciphertext (e.g., by modifying the operation type in the command through a man-in-the-middle attack), a failed hash verification will trigger key rotation, automatically blocking the attack chain. Real-world testing shows that this mechanism can detect and respond to tampering attacks within 50ms. Forced discarding of keys that fail verification avoids the use of potentially exposed keys, shortening the risk window after key leakage from "several hours" to "a single session" compared to traditional static key schemes. Command-path binding ensures that commands can only be transmitted through the optimal path calculated by the cloud platform, preventing attackers from inducing commands to take vulnerable paths (such as unencrypted older communication protocol paths). In a warehouse scenario test, this mechanism reduced the success rate of path hijacking attacks from 42% to 3%. Path identification assists smart locks in quickly locating the receiving channel (e.g., prioritizing acoustic relay paths over congested Wi-Fi channels), improving transmission success rates in complex environments (e.g., from 68% to 95% in underground parking garage scenarios).

[0140] In a preferred embodiment of the present invention, step S44: Based on the acoustic feedback signals returned from location A and location B, the cloud platform calculates the interference intensity distribution and path attenuation parameters of multi-band acoustic waves in the environment, and combines this with the signal strength, bit error rate, and network latency indicators reported in real time by the remote communication module to construct a communication path quality assessment model, including:

[0141] Step S441: Analyze the acoustic feedback signals returned from positions A and B, and extract the propagation delay, phase shift, and signal amplitude parameters of the multi-band acoustic waves. Specifically, this includes: the cloud platform receives the acoustic feedback signals from positions A and B, performs preliminary filtering on the signals to remove noise interference and improve signal clarity and accuracy; using signal processing technology, the propagation delay, phase shift, and signal amplitude parameters of the multi-band acoustic waves are extracted from the pre-processed acoustic feedback signals. The propagation delay can be obtained by measuring the time difference between the signal being emitted from the smart lock and the return from positions A and B; the phase shift can be determined by comparing the phase changes of the transmitted signal and the feedback signal; and the signal amplitude parameters are directly obtained from the signal strength.

[0142] Step S442: Based on the frequency band distribution and signal amplitude parameters of multi-band sound waves, calculate the Wi-Fi band interference intensity distribution map in the environment and analyze the attenuation coefficient of each path;

[0143] Step S443: Receive the communication quality indicators reported in real time by the remote communication module, including signal strength, bit error rate and network latency data, and perform regional clustering analysis in association with the physical location of the target smart lock;

[0144] Step S444: The interference intensity distribution map, path attenuation coefficient, and clustered communication quality indicators are fused using multi-dimensional features to generate a communication quality feature vector that includes frequency band weighting factors and path stability scores. Specifically, this includes:

[0145] Interference intensity data of key frequency bands are selected as features from the interference intensity distribution map. For example, among common communication frequency bands, interference values ​​of bands that are significantly affected by interference and have a substantial impact on communication quality are screened out. In smart home scenarios, the interference intensity of the 2.4GHz and 5GHz bands is particularly critical.

[0146] The path attenuation coefficient is a feature that directly selects the attenuation coefficient of each possible communication path. The attenuation coefficient of different paths reflects the energy loss of the signal when it propagates along that path, and has a direct impact on the communication quality.

[0147] From the clustered communication quality metrics, signal strength, bit error rate, and network latency were selected as core features. Signal strength determines whether the receiver can stably receive the signal, bit error rate affects the accuracy of data transmission, and network latency relates to the real-time performance of communication.

[0148] For each selected feature, its value range is determined. For example, the value range of interference intensity may be 0-100dBm, and the value range of signal intensity may be -100 to 0dBm, etc.

[0149] A linear transformation method is used to map the value of each feature to a uniform scale range, usually the [0,1] interval. The purpose of this is to eliminate the differences in the units and value ranges between different features and to prevent certain features from dominating the subsequent fusion process due to their large numerical range.

[0150] Depending on the actual situation, a weighted summation method is selected. This method assigns a weight to each normalized feature and then sums them to obtain a comprehensive value. The weighted summation method is used to fuse the normalized features, generating a communication quality feature vector. In this vector, the frequency band weight factor is calculated by comprehensively considering the relevant features of each frequency band, reflecting the importance of different frequency bands in the entire communication process; the path stability score is obtained by comprehensively considering factors such as path attenuation coefficient and signal strength stability, reflecting the stability of each communication path.

[0151] Step S445: Based on the preset communication path evaluation rule set, prioritize and dynamically match the communication quality feature vectors to construct a communication path quality evaluation model that supports multi-objective optimization. Specifically, this includes defining the communication path evaluation rule set in detail according to different application scenarios and requirements. For example, in real-time video surveillance scenarios, paths with low network latency and high signal strength may be given priority; while in file sharing scenarios with large data transfer volumes, bandwidth and stability of the path may be more important.

[0152] According to a preset set of rules, the communication quality feature vectors are prioritized. Paths that meet the priority conditions in the rules are ranked first, and those that do not are ranked last. For example, if the rule is to prioritize paths with less interference, lower attenuation, and higher signal strength, then the interference intensity, attenuation coefficient, and signal strength of each path are comprehensively compared to determine their priority order.

[0153] Dynamic thresholds are set for each indicator in the communication quality feature vector. These thresholds are not fixed but are dynamically adjusted based on the actual communication environment and historical data. For example, different signal strength thresholds and bit error rate thresholds are set according to the communication conditions in different time periods and regions.

[0154] The system monitors the indicator values ​​in the communication quality feature vector in real time. When an indicator exceeds or falls below a set threshold, the priority of that path is adjusted accordingly. For example, if the signal strength of a path suddenly falls below the threshold, its priority is reduced; if the bit error rate suddenly increases, its priority is also lowered.

[0155] Through the prioritization and dynamic threshold matching operations described above, a preliminary communication path quality assessment model is constructed. This model can evaluate and rank different communication paths based on communication quality feature vectors. During actual communication processes, new data is continuously collected, and the model is continuously adjusted and optimized based on this data. For example, the rule set is fine-tuned based on communication conditions over a period of time, and the dynamic threshold is reset, enabling the model to better adapt to different communication scenarios and environmental changes, achieving multi-objective optimization capabilities.

[0156] In this embodiment of the invention, by extracting the propagation delay, phase shift, and signal amplitude parameters of multi-band sound waves, the cloud platform can more accurately understand the propagation of sound waves in the environment. The extraction of frequency band sound wave parameters can address different environmental interferences and obstacles. Plotting the Wi-Fi frequency band interference intensity distribution map allows the cloud platform to clearly understand the interference situation in the environment, thereby selecting frequency bands with less interference for communication and improving communication reliability. Calculating the attenuation coefficient of each path helps the cloud platform select paths with less attenuation for communication, reducing signal energy loss and improving communication quality. Regional clustering analysis allows the cloud platform to understand the communication quality status of different regions, optimize and adjust for the characteristics of different regions, and improve overall communication efficiency. Real-time reception of communication quality indicators reported by the remote communication module enables the cloud platform to promptly detect communication problems and take corresponding measures to ensure communication stability. The communication quality feature vector generated by multi-dimensional feature fusion comprehensively considers multiple factors such as interference intensity, path attenuation, and communication quality indicators, enabling a more comprehensive and accurate assessment of the quality of the communication path. Frequency band weighting factors and path stability scores can provide important decision-making basis for the cloud platform to select the optimal communication path, improving communication reliability and efficiency. Communication path quality assessment models that support multi-objective optimization can weigh and optimize among multiple objectives, such as minimizing costs or improving efficiency while ensuring communication quality. Dynamic threshold matching allows the assessment model to be adjusted in real time according to actual communication conditions, adapting to environmental changes and improving the model's flexibility and adaptability.

[0157] In a preferred embodiment of the present invention, step S442: based on the frequency band distribution and signal amplitude parameters of multi-band sound waves, calculate the Wi-Fi band interference intensity distribution map in the environment, and analyze the attenuation coefficient of each path, including:

[0158] Step S4421: Decompose the frequency distribution of multi-band sound waves according to the preset Wi-Fi channel frequency range, and extract the sound wave frequency bands that overlap with the Wi-Fi frequency bands as interference detection targets. Specifically, the cloud platform meticulously divides the frequency distribution of multi-band sound waves according to the preset Wi-Fi channel frequency range. Common Wi-Fi frequency bands include 2.4GHz and 5GHz, etc. The cloud platform uses these as standards to classify the frequency bands of multi-band sound waves, and finds the sound wave frequency bands that overlap with the Wi-Fi frequency bands from the divided frequency bands. These overlapping frequency bands may interfere with Wi-Fi communication, so they are identified as the target frequency bands for interference detection.

[0159] Step S4422: Based on the signal amplitude parameters, calculate the difference between the acoustic signal energy of each target frequency band and the noise energy of the corresponding Wi-Fi frequency band, and generate a real-time interference intensity index, specifically including:

[0160] The cloud platform extracts the signal amplitude parameters of each target frequency band (i.e., the acoustic frequency band that overlaps with the Wi-Fi frequency band) from the acoustic feedback signals returned from location A and location B. These parameters are expressed as the voltage or power values ​​received by the sensor (e.g., signal strength values ​​in dBm), reflecting the strength of the acoustic signal in that frequency band.

[0161] The original signal amplitude is denoised (e.g., abnormal fluctuation values ​​are removed); the cloud platform determines the effective duration of the acoustic signal within the target frequency band.

[0162] Extract the start and end timestamps of the signal from the acoustic feedback signal (e.g., determine the start and end points by detecting when the signal amplitude exceeds the noise threshold);

[0163] The duration of the signal in that frequency band is obtained by calculating the time difference (e.g., from 14:30:00.123Z to 14:30:00.456Z, lasting 0.333 seconds).

[0164] Energy integral calculation

[0165] Over the duration, the signal amplitude parameters are summed to obtain the total energy:

[0166] Divide the duration into multiple small time intervals (e.g., each millisecond is one interval);

[0167] The signal amplitude (reflecting instantaneous energy) is sampled within each time interval, and the total energy of the frequency band is obtained by summing all the sampled values. Example logic: If a frequency band contains 333 millisecond-level sampling points within 0.333 seconds, and the amplitude of each point corresponds to the energy E1, E2...E333 respectively, then the total energy is E1+E2+...+E333.

[0168] Frequency dimension processing:

[0169] Frequency band subdivision and energy distribution analysis:

[0170] The target frequency band (e.g., 2.400-2.4835GHz of Wi-Fi 2.4GHz) is divided into multiple sub-bands (e.g., each sub-band is 5MHz), and the energy distribution of each sub-band is analyzed:

[0171] Extract statistical parameters such as peak value and mean value of signal amplitude within each sub-frequency band;

[0172] Compare the energy intensity of each sub-band to determine whether the energy is concentrated in the center or edge of the band (for example, the amplitude of the sub-band near the center 2.440 GHz is significantly higher than that at the edge 2.400 GHz and 2.4835 GHz).

[0173] Effective energy range determined:

[0174] Based on energy distribution characteristics, the effective energy range that may cause substantial interference to Wi-Fi communication was selected:

[0175] Uniformly distributed scenario: If the energy of each sub-band is similar, then the entire target frequency band is considered to be within the effective range;

[0176] Non-uniform distribution scenario: Only sub-bands with energy exceeding a threshold (e.g., 1.5 times the average energy) are retained as valid range (e.g., only sub-bands within ±10MHz of the center are considered valid).

[0177] Overall energy value generation:

[0178] Integration of time and frequency dimensions:

[0179] For each sub-band within the effective energy range, calculate its total energy over the duration (using the time-dimension integration method); sum the total energy of all effective sub-bands to obtain the acoustic signal energy value of the target frequency band.

[0180] Unit conversion:

[0181] Joule (J) conversion: Based on the physical mapping relationship between signal amplitude and energy (such as sensor calibration parameters), the accumulated energy value is converted into Joule units;

[0182] Decibel energy unit conversion: If decibels (such as dBm) are used, the energy value is converted to decibels through a preset conversion rule (such as logarithmic operation based on reference power) for easy comparison with Wi-Fi noise energy (usually in dBm).

[0183] The cloud platform retrieves historical statistical data for the corresponding time period from a pre-stored noise database based on the current time (e.g., 14:30 on April 26, 2025) and the geographical location of the target area (e.g., the 3rd floor of an apartment building).

[0184] The database is categorized and stored according to dimensions such as date (weekday / weekend), hour (e.g., morning peak, noon peak, evening peak), and floor level;

[0185] Extract the average noise energy value of the Wi-Fi band (e.g., 2.4GHz) during that period (for example, historical statistics show that the average noise energy of this area at 2 pm is -75dBm).

[0186] Real-time data acquisition and processing

[0187] Real-time sensor sampling: Wireless sensors deployed at location A (e.g., corridor ceiling) and location B (e.g., stairwell) collect ambient noise signals of the target Wi-Fi band at a frequency of 100 times per second to obtain real-time signal amplitude (unit: dBm);

[0188] Filtering and noise reduction: By using a moving average filtering algorithm, sudden outliers (such as instantaneous spike interference) are eliminated, while stable noise data is retained (for example, filtering out instantaneous strong interference signals generated by elevator operation).

[0189] Statistical calculation: Calculate the root mean square (RMS) value of the filtered real-time data to obtain the real-time noise energy reference value for this frequency band (for example, the RMS value is calculated to be -72dBm after 10 consecutive seconds of sampling).

[0190] Data fusion:

[0191] The cloud platform combines historical statistical data with real-time data to generate a comprehensive noise energy value:

[0192] If the difference between historical data and real-time data is within ±5dBm, take the average of the two (e.g., historical -75dBm and real-time -72dBm are merged to get -73.5dBm).

[0193] If the difference exceeds the threshold (e.g., ±5dBm), the real-time data takes precedence (for example, if the real-time data suddenly changes to -65dBm due to the temporary device being turned on, then that value is used directly).

[0194] Interference intensity index calculation process:

[0195] Energy unit alignment

[0196] The energy values ​​of acoustic signals in the target frequency band and Wi-Fi noise energy values ​​are standardized to the same unit (e.g., dBm):

[0197] If the energy of the sound wave signal is in joules (J), it can be converted to dBm through the sensor calibration parameters (for example, 10mW corresponds to 10dBm, and 1mW corresponds to 0dBm);

[0198] Ensure that the two are compared in the same units (e.g., power values ​​in dBm).

[0199] Energy difference calculation

[0200] Perform the difference calculation: Sound wave signal energy - Wi-Fi noise energy, to obtain the energy difference:

[0201] Example 1: The sound wave signal energy is -60dBm, the noise energy is -73.5dBm, and the energy difference is +13.5dBm (meaning the sound wave signal is 13.5dBm stronger than the noise).

[0202] Example 2: The sound wave signal energy is -80dBm, the noise energy is -75dBm, and the energy difference is -5dBm (meaning the sound wave signal is 5dBm weaker than the noise).

[0203] Exponential mapping and calibration

[0204] Based on the energy difference range, it is linearly mapped to the exponential range of 0-100:

[0205] Set threshold:

[0206] Strong interference threshold: energy difference ≥ +10dBm, corresponding to an index of 80-100;

[0207] Medium interference threshold: +3dBm≤energy difference<+10dBm, corresponding to an index of 50-80;

[0208] Low interference threshold: -5dBm≤energy difference<+3dBm, corresponding to an index of 20-50;

[0209] No interference threshold: energy difference < -5dBm, corresponding to an index of 0-20.

[0210] Example mapping:

[0211] Energy difference + 13.5dBm → Exponent = 80 + (13.5-10) / (100-80)×20≈83.5 (rounded to 84, marked as strong interference);

[0212] Energy difference -5dBm → Exponent = 20 (the critical value between low interference and no interference).

[0213] Interference affects correlation

[0214] High index (>70): For example, an index of 84 indicates that the energy of the acoustic signal in this frequency band is significantly higher than that of Wi-Fi noise, which may cause the signal-to-noise ratio (SNR) of the Wi-Fi signal to fall below the critical value (e.g., 10dB), leading to data transmission errors (bit error rate >10). -3 ), transmission rate decrease (e.g., from 100Mbps to 20Mbps);

[0215] Low index (<30): For example, an index of 20 indicates that the acoustic signal energy is below noise or close to the background level, and its impact on Wi-Fi communication is negligible (bit error rate <10). -5 This frequency band can be prioritized for smart lock command transmission.

[0216] Dynamic adjustment mechanism

[0217] Real-time update frequency: The interference intensity index is recalculated every second to track environmental changes (such as a user turning on a microwave oven or a neighbor adding a Wi-Fi device);

[0218] Outlier handling: If the index fluctuations obtained from three consecutive calculations exceed 20 units (e.g., a sudden change from 30 to 55), an environmental interference warning is triggered, and an alternative communication path is automatically activated (e.g., switching from Wi-Fi to Bluetooth).

[0219] Step S4423: Analyze the acoustic feedback signal data packets at positions A and B, extracting the acoustic propagation delay, phase offset, and difference in received signal strength; call the preset acoustic propagation speed model, and calculate the deviation between the actual and theoretical propagation speeds of the acoustic path based on the propagation delay and the physical distance between positions A and B; based on the phase offset and the difference in received signal strength, and combined with the acoustic frequency characteristics, calculate the reflection loss coefficient caused by the number of reflections in the path; based on the actual propagation speed deviation and the reflection loss coefficient, dynamically correct the influence of environmental humidity and temperature parameters on the attenuation of acoustic energy using the medium absorption attenuation formula, generating a medium absorption attenuation coefficient, specifically including:

[0220] The cloud platform receives acoustic feedback signal data packets from locations A and B. First, it performs a preliminary check on these data packets to confirm their integrity, such as checking the packet length and header information to ensure they conform to the preset format. If a data packet is corrupted or incomplete, it will attempt to retransmit or discard the packet. The pre-processed data packets are then analyzed in detail to extract three key pieces of information: acoustic propagation delay, phase offset, and the difference in received signal strength.

[0221] Sound wave propagation delay: determined by comparing the transmission and reception times of the signal. For example, record the precise time when the signal is emitted from location A, and then record the time when the signal is received at location B; the time difference between the two is the sound wave propagation delay from A to B.

[0222] Phase offset: The phase of the received sound wave signal is compared with the phase of the original transmitted signal, and the change in phase is calculated. This change in phase is the phase offset.

[0223] Received signal strength difference: Obtain the signal strength values ​​received at location A and location B respectively, and then calculate the difference between the two.

[0224] Calculation of actual propagation speed deviation:

[0225] Calculation of actual propagation speed

[0226] The preset sound wave propagation speed model is invoked, and combined with the previously extracted sound wave propagation delay and the known physical distance between positions A and B, the actual propagation speed of the sound wave on the path is obtained by dividing the physical distance between positions A and B by the sound wave propagation delay.

[0227] Deviation calculation

[0228] The calculated actual propagation speed is compared with the theoretical propagation speed of sound waves in this environment. The theoretical speed is preset based on the basic parameters of the environment (such as temperature, air pressure, etc.). The deviation between the two is obtained by subtracting the theoretical speed from the actual propagation speed.

[0229] Calculation of reflection loss coefficient

[0230] Reflection analysis

[0231] Based on the extracted phase shift and the difference in received signal strength, combined with the frequency characteristics of the sound wave, the reflection of the sound wave during propagation is analyzed. Different numbers of reflections and reflection interfaces will lead to different phase shifts and signal strength changes. For example, if the phase shift is large and the signal strength is significantly reduced, it may mean that the sound wave has undergone multiple reflections.

[0232] Calculation of reflection loss coefficient

[0233] Phase offset analysis: Assume that the phase offset increases by 180 degrees for each reflection of the sound wave (ideal hard reflective interface). The cloud platform calculates the number of reflections as 540° ÷ 180° = 3 times based on the actual phase offset (e.g., the total offset detected is 540 degrees).

[0234] Signal strength difference verification: If the received signal strength difference is 15dB, and the known single reflection loss is approximately 5dB (an empirical value, which can be preset based on environmental materials), then the theoretical number of reflections is 15dB ÷ 5dB = 3 times, consistent with the phase offset calculation result, confirming that the number of reflections is 3 times. Based on the sound wave frequency characteristics (e.g., higher frequency sound waves have higher reflection loss), set single reflection loss values ​​for different frequency bands:

[0235] Low frequency band (<1kHz): Single reflection loss 3dB;

[0236] Mid-frequency band (1-4kHz): Single reflection loss 5dB;

[0237] High frequency band (>4kHz): Single reflection loss 8dB.

[0238] Example: If the current sound wave frequency is 2kHz (mid frequency band), then the single reflection loss is taken as 5dB.

[0239] Total reflection loss calculation

[0240] Total reflection loss = Number of reflections × Single reflection loss;

[0241] Example: 3 reflections × 5dB loss per reflection = 15dB, that is, the reflection loss coefficient is 15dB (meaning that the energy loss is about 97%, because dB has a logarithmic relationship with power).

[0242] The process of generating the dielectric absorption attenuation coefficient

[0243] Calculation of the influence of ambient temperature

[0244] Theoretical speed of sound calculation

[0245] Based on the ideal gas law, the theoretical formula for the speed of sound is:

[0246] V0 = 331.4 + 0.6 × T (T is the temperature in degrees Celsius, unit ℃); Example: If the preset ambient temperature is 20℃, then the theoretical speed of sound V0 = 331.4 + 0.6 × 20 = 343.4 m / s.

[0247] Actual speed of sound calculation

[0248] Actual speed of sound v = physical distance between positions A and B ÷ propagation delay

[0249] Example: The distance between locations A and B is 10 meters, the propagation delay is 0.03 seconds, and the actual speed of sound v = 10 ÷ 0.03 ≈ 333.3 m / s.

[0250] Derivation of temperature deviation

[0251] Velocity deviation Δv = v - v0 = 333.3 - 343.4 = -10.1 m / s

[0252] Based on the linear relationship between sound speed and temperature (0.6 m / s / ℃), the temperature deviation ΔT = Δv ÷ 0.6 ≈ **-16.8℃**, meaning the actual ambient temperature is 16.8℃ lower than the preset value. The current temperature T = 20 - 16.8 = 3.2℃.

[0253] Temperature decay factor

[0254] At low temperatures, air viscosity increases, leading to enhanced sound wave absorption. The preset temperature attenuation coefficient is:

[0255] At 0℃, the attenuation is 0.1 dB / m·kHz;

[0256] For every 1°C decrease, the attenuation increases by 0.02 dB / m·kHz.

[0257] Example: Current temperature 3.2℃, attenuation coefficient = 0.1 + (0 - 3.2) × 0.02 = 0.164 dB / m·kHz.

[0258] Calculation of the impact of environmental humidity

[0259] Humidity measurement value acquisition

[0260] The real-time humidity is obtained by deploying temperature and humidity sensors at locations A and B, RH = 40% (assuming).

[0261] Humidity attenuation factor

[0262] Formula for the effect of preset humidity on the attenuation of high-frequency sound waves (>2kHz):

[0263] For every 10% increase in humidity, high-frequency attenuation increases by 0.05 dB / m·kHz (the effect on low frequencies is negligible).

[0264] Example: If the current humidity is 40% and the baseline humidity is 50% (preset standard), then the humidity attenuation adjustment value = (50% - 40%) × 0.05 = -0.005 dB / m·kHz (the negative sign indicates that the attenuation is slightly reduced when the humidity decreases).

[0265] Generation of comprehensive attenuation coefficient

[0266] Substitute frequency parameters

[0267] Assume the current sound wave frequency f = 3kHz (mid-high frequency) and the propagation distance d = 10 meters.

[0268] Combined temperature and humidity attenuation calculation

[0269] Total attenuation due to temperature = temperature attenuation coefficient × f × d = 0.164 × 3 × 10 = 4.92 dB

[0270] Total attenuation due to humidity = Humidity attenuation factor × f × d = (-0.005) × 3 × 10 = -0.15 dB (negligible, take 0)

[0271] Total absorption attenuation of the medium = temperature attenuation + humidity attenuation ≈ 4.92dB, that is, the medium absorption attenuation coefficient is 4.92dB (meaning that the energy loss per meter of propagation distance is about 49.2%).

[0272] Step S4424: Weight and fuse the real-time interference intensity index with the reflection loss and the medium absorption attenuation coefficient to generate an attenuation coefficient matrix that includes path priority score and anti-interference capability, specifically including:

[0273] Scene classification and weight preset, home / office scenario (mainly Wi-Fi interference):

[0274] Real-time interference intensity index: weight 50% (interference has the greatest impact on communication quality);

[0275] Reflection loss coefficient: weighted at 30% (wall reflection is a secondary factor);

[0276] Medium absorption attenuation coefficient: weight 20% (air humidity / temperature has little effect).

[0277] Industrial / warehousing scenarios (numerous metal obstacles, complex environment):

[0278] Reflection loss coefficient: weighted at 40% (metal reflection causes significant multipath effects);

[0279] Medium absorption attenuation coefficient: weighted at 35% (dust and high-temperature environments affect sound wave propagation);

[0280] Real-time interference intensity index: weight 25% (industrial equipment has its own communication frequency band, with less Wi-Fi interference).

[0281] Dynamic weight adjustment mechanism

[0282] If a coefficient's calculated value exceeds the threshold three times consecutively (e.g., interference index > 80), its weight will be automatically increased by 10% (e.g., in a home setting, if the interference index suddenly increases, the weight will be increased from 50% to 60%).

[0283] When environmental monitoring sensor data (such as temperature, humidity, dust concentration) changes abruptly, the weight of the medium absorption attenuation coefficient is adjusted accordingly (e.g., if humidity > 80% is detected, the weight is increased from 20% to 30%).

[0284] Convert coefficients of different dimensions to a uniform range (e.g., 0-100) to facilitate weighted calculations.

[0285] Real-time interference intensity index (normalized): Directly use the index value of 0-100 (e.g., the calculated result is 84).

[0286] Reflection loss coefficient (dB converted to exponential):

[0287] The maximum preset reflection loss is 30dB (corresponding to index 100), and the lossless loss is 0dB (corresponding to index 0).

[0288] Linear mapping formula: Reflection loss index = (loss value ÷ 30) × 100;

[0289] Example: Reflection loss 15dB → 15÷30×100=50.

[0290] Medium absorption attenuation coefficient (dB / m converted to exponential):

[0291] The maximum preset attenuation is 10dB / m (corresponding to exponent 100), and the minimum preset attenuation is 0dB / m (corresponding to exponent 0).

[0292] Linear mapping formula: Absorption attenuation index = (attenuation value ÷ 10) × 100

[0293] Example: Attenuation 4.92dB / m → 4.92÷10×100=49.2 (rounded to 49).

[0294] Overall score = Interference index × W1 + Reflection loss index × W2 + Absorption attenuation index × W3

[0295] (W1, W2, and W3 are the weights of each coefficient, and the sum is 100%)

[0296] Scenario-based computing example (home scenario)

[0297] Given:

[0298] Interference index = 84, weight W1 = 50%;

[0299] Reflection loss index = 50, weight W2 = 30%;

[0300] Absorption attenuation index = 49, weight W3 = 20%.

[0301] calculate:

[0302] Overall score = 84×0.5 + 50×0.3 + 49×0.2 = 42 + 15 + 9.8 = 66.8 (rounded to 67).

[0303] Anti-interference capability classification

[0304] The grades are determined based on the overall score:

[0305] 0-30: Strong anti-interference ability (preferred choice);

[0306] 31-60: Moderate anti-interference capability;

[0307] 61-100: Weak anti-interference ability (should be avoided).

[0308] Example: Overall score 67 → Interference resistance level is "Medium".

[0309] Attenuation coefficient matrix generation:

[0310] Matrix structure definition

[0311] Each matrix element corresponds to a communication path and includes the following fields:

[0312] Path ID: e.g., "PATH-A-20250426-1430";

[0313] Real-time interference index: 0-100;

[0314] Reflection loss index: 0-100;

[0315] Absorption attenuation index: 0-100;

[0316] Overall score: 0-100;

[0317] Priority rating: Sorted in descending order of overall score (lower score, higher priority);

[0318] Anti-interference level: Strong / Medium / Weak, as shown in Table 1 below, example matrix fragment:

[0319] Table 1 Example Matrix Fragment

[0320]

[0321] Priority sorting:

[0322] Arranged in ascending order of comprehensive score, priority 1 (score 26) > priority 2 (56.5) > priority 3 (67); the cloud platform prioritizes the path (PATH-B) of priority 1 for command transmission.

[0323] Step S4425: Based on the attenuation coefficient matrix and the physical location topology of the target smart lock, draw a multi-dimensional Wi-Fi band interference intensity distribution map covering the target area and mark high interference risk paths. Specifically, the cloud platform combines the attenuation coefficient matrix with the physical location topology of the target smart lock. The physical location topology describes the spatial distribution of the target smart lock. By associating it with the attenuation coefficient matrix, the interference situation at different locations can be understood more accurately.

[0324] Based on the combined results above, a multi-dimensional Wi-Fi band interference intensity distribution map of the target coverage area was created. The map not only displays the interference intensity at different locations but also marks high-interference-risk paths. These markers help users quickly identify paths that may have interference problems so that appropriate measures can be taken.

[0325] In a preferred embodiment of the present invention, step S443: receiving communication quality indicators reported in real time by the remote communication module, including signal strength, bit error rate, and network latency data, and performing regional clustering analysis in association with the physical location of the target smart lock, including:

[0326] Step S4431: The cloud platform receives the raw communication quality indicator data reported by the remote communication module, and parses the numerical range and collection timestamp of signal strength, bit error rate, and network latency. Specifically, the cloud platform opens the data receiving port and waits for the remote communication module to report the raw communication quality indicator data. The remote communication module sends data to the cloud platform at certain time intervals (e.g., every minute); the cloud platform parses the received raw data. First, it identifies the numerical components of signal strength, bit error rate, and network latency in the data and determines their specific numerical ranges. Simultaneously, it extracts the collection timestamp from the data, which records the collection time for each communication quality indicator.

[0327] Step S4432: Based on the physical location coordinates of the target smart lock, the communication quality indicators are mapped to preset geographic grid division rules to generate a geographically labeled communication quality dataset. Specifically, the cloud platform retrieves the physical location coordinates of the target smart lock from a pre-stored database. These coordinates are typically represented in latitude and longitude. The cloud platform divides the target area into multiple equally sized geographic grids according to preset geographic grid division rules. For example, the entire area is divided into small rectangular grids at certain latitude and longitude intervals. The parsed communication quality indicators are then mapped to the divided geographic grids. Specifically, based on the physical location coordinates of the target smart lock, its corresponding geographic grid is determined, and then the communication quality indicators corresponding to the smart lock are associated with this geographic grid, thereby generating a geographically labeled communication quality dataset.

[0328] Step S4433: Clean the communication quality dataset for outliers, removing data points that exceed device physical performance thresholds or network protocol specifications to form standardized input data. Specifically, the cloud platform determines reasonable ranges for signal strength, bit error rate (BER), and network latency based on device physical performance and network protocol specifications, using these as the device physical performance thresholds and network protocol specifications. For example, signal strength is generally between -100dBm and -30dBm, and the BER should be less than 1%. The geographically tagged communication quality dataset is iterated through, checking whether the signal strength, BER, and network latency values ​​of each data point exceed the preset threshold range. If a data point exceeds the threshold, it is identified as an outlier, and all identified outliers are removed from the dataset to form standardized input data, ensuring that the data used in subsequent analysis is reasonable and valid.

[0329] Step S4434: The cloud platform maps the signal strength and network latency in the standardized input data to coordinate points in a multi-dimensional feature space, and defines clustering core objects based on preset neighborhood radius thresholds and minimum sample number thresholds; it traverses the coordinate points in the multi-dimensional feature space, expands the neighborhood range of the core objects according to density reachability judgment rules, and forms initial geographic region clusters; it filters noisy data for the coordinate points in the initial geographic region clusters, removes isolated points with a density lower than the preset threshold, and re-executes neighborhood expansion to optimize the cluster boundaries; it verifies whether the variance of signal strength and network latency within the optimized geographic region clusters meets the preset communication stability conditions, and if the conditions are exceeded, it triggers a dynamic adjustment mechanism for the neighborhood radius; it assigns a unique identifier to the finally divided geographic region clusters and associates it with the physical location coordinates of target smart locks within its coverage area, generating clustering results of geographic region clusters with consistent communication quality characteristics, specifically including:

[0330] The cloud platform maps signal strength and network latency in standardized input data to coordinate points in a multi-dimensional feature space. In this space, each coordinate point represents the communication quality of a smart lock, with the horizontal axis representing signal strength and the vertical axis representing network latency. Clustering core objects are defined based on preset neighborhood radius thresholds and minimum sample number thresholds. The neighborhood radius threshold specifies the size of the neighborhood centered at a given coordinate point, and the minimum sample number threshold specifies the minimum number of samples that must be included within that neighborhood. If the number of samples within the neighborhood of a given coordinate point is greater than or equal to the minimum sample number threshold, then that coordinate point is defined as a clustering core object.

[0331] The algorithm iterates through all coordinate points in the multidimensional feature space and expands the neighborhood of the cluster core objects according to the density reachability criterion. The density reachability criterion states that if one coordinate point is within the neighborhood of another coordinate point, and these two coordinate points can be connected by a series of core objects, then these two coordinate points are considered density reachable. By continuously expanding the neighborhood of the core objects, density reachable coordinate points are merged together to form the initial geographic region cluster.

[0332] The cloud platform filters out noisy data from the coordinate points in the initial geographic region clusters. Based on a preset density threshold, it checks the density of coordinate points within each region cluster. If the density of a coordinate point's region is lower than the preset threshold, that coordinate point is considered an isolated point and removed from the region cluster.

[0333] After removing outliers, the neighborhood expansion operation is re-executed to optimize the boundaries of the regional clusters, making the cluster division more reasonable. The results are then used to verify whether the variance of signal strength and network latency within the optimized geographical regional clusters meets the preset communication stability conditions. Variance reflects the degree of data dispersion; if the variance exceeds the preset range, it indicates that the communication quality within the regional cluster is unstable.

[0334] If the communication stability within a certain geographic region cluster does not meet the requirements, the cloud platform will trigger a dynamic neighborhood radius adjustment mechanism. By adjusting the neighborhood radius threshold, the clustering analysis will be re-performed until the communication stability within all geographic region clusters meets the requirements.

[0335] Each geographic region cluster is assigned a unique identifier to facilitate subsequent management and querying. Simultaneously, each geographic region cluster is associated with the physical location coordinates of target smart locks within its coverage area, generating clustering results for geographic region clusters with consistent communication quality characteristics.

[0336] Step S4435: Associate the clustering results of geographical region clusters with the Wi-Fi band interference intensity distribution map to generate clustering analysis results containing regional communication quality level labels. Specifically, this includes: associating the clustering results of geographical region clusters with the previously generated Wi-Fi band interference intensity distribution map. The cloud platform locates the corresponding region in the Wi-Fi band interference intensity distribution map based on the geographical location and coverage of the geographical region clusters, and associates the two; based on the association result, it labels the regional communication quality level for each geographical region cluster. The cloud platform combines communication quality indicators (signal strength, bit error rate, network latency) and Wi-Fi band interference intensity to comprehensively evaluate the communication quality of each region, classifying it into different levels, such as excellent, good, medium, and poor, ultimately generating clustering analysis results containing regional communication quality level labels.

[0337] In a preferred embodiment of the present invention, step S45: the cloud platform, based on the communication path quality assessment model, selects communication links with interference intensity below a preset threshold and delay meeting the operation command requirements as the final communication path, and sends the dynamic encryption command to the remote communication module of the target smart lock through the final communication path, including:

[0338] Step S451: Obtain the interference intensity values, path stability scores, and network latency data of all candidate communication links from the communication path quality assessment model, and extract their corresponding physical path identifiers. Specifically, this includes: the cloud platform accessing the communication path quality assessment model to obtain relevant data for all candidate communication links. This data includes interference intensity values, which reflect the degree of external interference to the link; path stability scores, which reflect the link's ability to maintain stable communication over a period of time; and network latency data, which is the time it takes for a signal to transmit in the link. The cloud platform extracts the physical path identifier corresponding to each candidate communication link from the acquired data. This identifier is a unique identifier for each communication link, facilitating subsequent link identification and management.

[0339] Step S452: Based on the preset interference intensity threshold and the delay tolerance parameter corresponding to the operation command type, a set of candidate communication links is selected where the interference intensity is below the threshold and the delay meets the real-time requirements of the command. Specifically, the cloud platform determines the interference intensity threshold and the delay tolerance parameter corresponding to the operation command type according to preset rules. Different operation commands, such as unlocking commands and status query commands, have different tolerance levels for delay, and therefore different delay tolerance parameters. The cloud platform traverses all candidate communication links, compares the interference intensity value of each link with the preset interference intensity threshold, and simultaneously compares its network delay data with the delay tolerance parameter corresponding to the operation command type. Only those candidate communication links where the interference intensity is below the threshold and the delay meets the real-time requirements of the command are retained, forming a set of candidate communication links.

[0340] Step S453: Based on the path stability score of the candidate communication link set and the communication quality level label of the geographic region cluster set, prioritize the links according to their anti-interference capability and reliability. Specifically, the cloud platform evaluates the anti-interference capability and reliability of the links by combining the path stability score of the candidate communication link set and the communication quality level label of the geographic region cluster set. A higher path stability score indicates a more stable link; a higher communication quality level of the geographic region cluster indicates a better communication environment in which the link is located. Based on the above evaluation results, prioritize the candidate communication links. Links with stronger anti-interference capability and higher reliability have higher priority.

[0341] Step S454: Select the highest priority communication link as the final communication path and verify whether its current connection status with the target smart lock's remote communication module is active and available. Specifically, the cloud platform selects the highest priority communication link from the sorted candidate communication links as the final communication path. The cloud platform verifies whether the final communication path and the target smart lock's remote communication module are active and available. This can be achieved by sending a simple test signal to the target smart lock's remote communication module and observing whether a response is received. If the connection status is inactive or unavailable, the cloud platform returns to step S453, selects the next highest priority communication link, and repeats the verification process until an active and available final communication path is found.

[0342] Step S455: Inject the dynamic encryption command into the data transmission queue of the final communication path and attach a path selection audit tag. Specifically, the cloud platform injects the dynamic encryption command into the data transmission queue of the final communication path. The dynamic encryption command is an encrypted operation command to ensure communication security. The data transmission queue transmits the commands in a specific order, and the cloud platform attaches a path selection audit tag to the dynamic encryption command injected into the data transmission queue. This tag records relevant information about the selection of the communication path, such as the selection time and selection criteria.

[0343] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.

Claims

1. A cloud platform-based remote intelligent lock control method, characterized in that, The method comprises: Step S1: the user terminal sends a remote control request to the cloud platform, and the request carries user identity authentication information, a unique identifier of the target smart lock, and an operation instruction type; Step S2: after receiving the remote control request, the cloud platform performs threefold verification on the user identity legality, the operation permission range of the target smart lock, and the compliance of the operation instruction type based on the pre-stored user-smart lock binding relationship and the permission grading strategy; Step S3: if the threefold verification is passed, the cloud platform generates a dynamic encryption instruction containing a timestamp, an operation instruction type, and a temporary permission validity period, and determines the remote communication module associated with the target smart lock according to the unique identifier of the target smart lock; Step S4: the cloud platform issues a sound wave signal transmission instruction to the target smart lock, triggers the smart lock to send multi-band sound wave signals to the preset auxiliary signal enhancement equipment deployment positions A and B, receives the sound wave feedback signals returned by positions A and B, calculates the final communication path based on the signal propagation time delay, frequency band interference intensity, and attenuation parameters, and combines the real-time signal quality indicators reported by the remote communication module, and sends the dynamic encryption instruction to the remote communication module through the final communication path, comprising: Step S41: based on the final operation range verification conclusion, the cloud platform generates a unique timestamp, and encapsulates the operation instruction type and the temporary permission validity period to form plaintext instruction data; Step S42: the cloud platform calls the preset hardware security module, generates a temporary symmetric encryption key according to the current session parameters, encrypts the plaintext instruction data to generate ciphertext, and binds the key identifier and the ciphertext to establish a key association; Step S43: the cloud platform uses the private key in the hardware security module to digitally sign the ciphertext data to generate a dynamic encryption instruction containing a timestamp, ciphertext, and a signature; Step S44: based on the sound wave feedback signals returned by positions A and B, the cloud platform calculates the interference intensity distribution and path attenuation parameters of the multi-band sound wave in the environment, and combines the signal strength, error rate, and network delay indicators reported by the remote communication module in real time to construct a communication path quality evaluation model, comprising: Step S441: analyze the sound wave feedback signals returned by positions A and B, and extract the propagation time delay, phase shift, and signal amplitude parameters of the multi-band sound wave; Step S442: based on the frequency band distribution and signal amplitude parameters of the multi-band sound wave, calculate the Wi-Fi frequency band interference intensity distribution map in the environment, and analyze the attenuation coefficients of each path; Step S443: receive the real-time communication quality indicators reported by the remote communication module, including signal strength, error rate, and network delay data, and perform regionalized clustering analysis by associating the physical position of the target smart lock; Step S444: perform multi-dimensional feature fusion on the interference intensity distribution map, the path attenuation coefficient, and the clustered communication quality indicators to generate a communication quality feature vector containing a frequency band weight factor and a path stability score; Step S445: based on the preset communication path evaluation rule set, perform priority sorting and dynamic threshold matching on the communication quality feature vector to construct a communication path quality evaluation model supporting multi-objective optimization; Step S45: The cloud platform screens a communication link with low interference intensity and delay satisfying the operation instruction requirement as the final communication path according to the communication path quality evaluation model, and sends the dynamic encryption instruction to the remote communication module of the target smart lock through the final communication path. 2.The cloud platform-based remote intelligent lock control method of claim 1, wherein, After receiving the remote control request, the cloud platform performs three verifications on the legality of the user identity, the operation permission range of the target smart lock, and the compliance of the operation instruction type based on the pre-stored user-smart lock binding relationship and the permission grading strategy, including: Step S31: Analyze the remote control request and verify whether the request contains three mandatory fields: user identity information, target smart lock unique identifier, and operation instruction type. If any field is missing, terminate the verification and return an error response; Step S32: Convert the user identity information, target smart lock unique identifier, and operation instruction type into a standard data format to generate a structured request object; Step S33: Based on the user identity information in the structured request object, query the user database to match the valid account. If the account enables the enhanced verification strategy, trigger the secondary authentication process. At the same time, analyze the account state and historical login behavior characteristics, intercept abnormal login requests, and generate the first verification result; Step S34: According to the first verification result, combined with the target smart lock unique identifier, search the lock list bound by the user in the user-lock binding relationship table. If the target lock does not exist in the list, terminate the verification. According to the user role identifier and the operation instruction type, match the corresponding operation permission state in the permission matrix. If the permission is exceeded, generate an audit log containing operation type violation records and return the second verification result; Step S35: Based on the second verification result, combined with the current environment context data, if the operation instruction involves temporary permission granting, check the validity period and remaining available times of the temporary permission, and generate the final operation range verification conclusion to complete the three verifications. 3.The cloud platform-based remote intelligent lock control method of claim 2, wherein, Step S41: Based on the final operation range verification conclusion, the cloud platform generates a unique timestamp, and encapsulates the operation instruction type and the temporary permission validity period into data to form plaintext instruction data, including: Step S411: According to the final operation range verification conclusion, the cloud platform obtains the system pre-defined operation code corresponding to the operation instruction type, and generates a unique timestamp based on coordinated universal time, including millisecond-level precision and random number extension; Step S412: Convert the temporary permission validity period into a time interval format of start time and end time, and perform field standardization processing on the operation instruction type, timestamp, and validity period to generate a structured data unit; Step S413: Perform integrity check on the operation instruction type field, timestamp field, and validity period field in the structured data unit. If there is an undefined operation code or time interval conflict, trigger the data reconstruction process; Step S414: Encapsulate the structured data unit that passes the verification into a plaintext instruction data packet containing a header identifier, data payload, and a check code according to the preset protocol. 4.The cloud platform-based remote intelligent lock control method of claim 3, wherein, Step S42: The cloud platform calls the preset hardware security module, generates a temporary symmetric encryption key according to the current session parameters, encrypts the plaintext instruction data to generate ciphertext, and binds the key identifier with the ciphertext to establish key association, including: Step S421: The cloud platform extracts the communication protocol version of the current session, the unique identifier of the target smart lock, and the timestamp as the session parameters, generates a key derivation seed; Step S422: Call the key generation interface of the preset hardware security module, input the key derivation seed and the preset hardware-level random number, generate a temporary symmetric encryption key bound with the current session; Step S423: Use the temporary symmetric encryption key to block encrypt the plaintext instruction data packet, use the padding rule to resist length analysis attack, generate the encrypted ciphertext data block sequence; Step S424: Associate and encode the key identifier allocated by the hardware security module with the ciphertext data block sequence to generate the binding metadata containing the key version number and the encryption algorithm identifier; Step S425: Attach the binding metadata to the ciphertext header to form a complete ciphertext data unit, and store the single-use state of the life cycle of the temporary symmetric encryption key in the key management audit log. 5.The cloud platform based remote intelligent lock control method of claim 4, wherein, Step S43: The cloud platform uses the private key in the hardware security module to digitally sign the ciphertext data to generate a dynamic encryption instruction containing the timestamp, the ciphertext and the signature, including: Step S431: Extract the ciphertext header and the ciphertext data block sequence from the complete ciphertext data unit, and generate an original data digest associated with the timestamp; Step S432: Call the signature engine of the hardware security module, use the private key to perform asymmetric encryption operation on the original data digest to generate digital signature data; Step S433: Assemble the digital signature data, the timestamp, the ciphertext header and the ciphertext data block sequence in a preset format to generate a complete dynamic encryption instruction containing the protocol version identifier and the operation type code; Step S434: Hash check the dynamic encryption instruction, if the check fails, trigger the key rotation mechanism to regenerate the temporary symmetric encryption key and repeat steps S42 to S43; Step S435: Logically bind the dynamic encryption instruction with the link identifier of the final communication path to match the instruction transmission process with the path selection result. 6.The cloud platform-based remote intelligent lock control method of claim 5, wherein, Step S442: Based on the frequency band distribution and signal amplitude parameters of the multi-frequency sound wave, calculate the Wi-Fi frequency band interference intensity distribution map in the environment, and analyze the attenuation coefficients of each path, including: Step S4421: Perform frequency band decomposition on the frequency band distribution of the multi-frequency sound wave according to the preset Wi-Fi channel frequency range, extract the sound wave frequency band overlapping with the Wi-Fi frequency band as the interference detection target; Step S4422: Based on the signal amplitude parameter, calculate the difference between the sound wave signal energy of each target frequency band and the corresponding Wi-Fi frequency band noise energy to generate a real-time interference intensity index; Step S4423: Analyze the sound wave feedback signal data packets of position A and position B, extract the sound wave propagation time delay, phase shift and received signal strength difference; call the preset sound wave propagation speed model, calculate the deviation value of the actual propagation speed of the sound wave path from the theoretical speed according to the propagation time delay and the physical distance between position A / B; based on the phase shift and the received signal strength difference, combined with the sound wave frequency characteristics, calculate the reflection loss coefficient caused by the reflection times in the path; according to the actual propagation speed deviation value and the reflection loss coefficient, dynamically correct the influence of environmental humidity and temperature parameters on the attenuation of sound wave energy through the medium absorption attenuation formula, and generate the medium absorption attenuation coefficient; Step S4424: Weight and fuse the real-time interference intensity index, reflection loss and medium absorption attenuation coefficient to generate an attenuation coefficient matrix containing path priority score and anti-interference ability; Step S4425: Based on the attenuation coefficient matrix and the physical position topology relationship of the target intelligent lock, draw a multi-dimensional Wi-Fi frequency band interference intensity distribution map covering the target area, and mark the high interference risk path identifier.

7. The cloud platform based remote intelligent lock control method according to claim 6, wherein, Step S443: Receive the communication quality indicators reported by the remote communication module in real time, including signal strength, error rate and network delay data, and perform regionalized cluster analysis by associating the physical position of the target intelligent lock, including: Step S4431: The cloud platform receives the communication quality index original data reported by the remote communication module, and analyzes the numerical range and collection timestamp of signal strength, error rate and network delay; Step S4432: Based on the physical position coordinates of the target intelligent lock, map the communication quality indicators to the preset geographical grid division rule to generate a communication quality data set with geographical labels; Step S4433: Perform outlier cleaning on the communication quality data set, remove data points that exceed the device physical performance threshold or network protocol specification, and form standardized input data; Step S4434: The cloud platform maps the signal strength and network delay in the standardized input data to coordinate points in a multi-dimensional feature space, and defines a cluster core object based on a preset neighborhood radius threshold and a minimum sample number threshold; traverse the coordinate points in the multi-dimensional feature space, expand the neighborhood range of the core object according to the density accessibility judgment rule, and form an initial geographical area cluster; filter noise data for coordinate points in the initial geographical area cluster, remove isolated points with a density lower than a preset threshold, and re-execute neighborhood expansion to optimize cluster boundaries; verify whether the variance of signal strength and network delay in the optimized geographical area cluster meets the preset communication stability condition, and if it exceeds the condition, trigger the neighborhood radius dynamic adjustment mechanism; assign a unique identifier to the finally divided geographical area cluster, and associate its target intelligent lock physical position coordinates to generate a clustering result of geographical area clusters with communication quality consistency characteristics; Step S4435: Associate and map the clustering result of the geographical area cluster with the Wi-Fi frequency band interference intensity distribution map to generate a clustering analysis result containing regional communication quality level labels. 8.The cloud platform based remote intelligent lock control method of claim 7, wherein, Step S45: The cloud platform screens a communication link with interference intensity lower than a preset threshold and delay satisfying the operation instruction requirement as the final communication path according to the communication path quality evaluation model, and sends the dynamic encryption instruction to the remote communication module of the target smart lock through the final communication path, including: Step S451: Obtain the interference intensity value, path stability score and network delay data of all candidate communication links from the communication path quality evaluation model, and extract the corresponding physical path identifier; Step S452: According to the preset interference intensity threshold and the delay tolerance parameter corresponding to the operation instruction type, screen the candidate communication link set with interference intensity lower than the threshold and delay satisfying the instruction real-time requirement; Step S453: Based on the path stability score of the candidate communication link set, combined with the communication quality level label of the geographical region cluster set, the priority of the link is sorted in terms of anti-interference ability and reliability; Step S454: Select the communication link with the highest priority as the final communication path, and verify whether the current connection state with the remote communication module of the target smart lock is in the active available state; Step S455: Inject the dynamic encryption instruction into the data transmission queue of the final communication path, and attach the path selection audit label.

Citation Information

Patent Citations

  • Intelligent door lock control method, device and system

    CN112348997A

  • Parking space lock communication load allocation method and system, storage medium and computer equipment

    CN113660170A

  • Intelligent door lock control method and device based on Internet of Things, electronic equipment and storage medium

    CN118781688A

  • Communication system and method for diabetes outpatient service user management

    CN119561857A