Equipment processing method and device, equipment, computer readable medium and program product

Through the challenge data authentication and verification mechanism of near-field communication devices, the security and interaction methods of smart devices are solved, and efficient and secure device unlocking and interaction are achieved.

CN120475362APending Publication Date: 2025-08-12SHENZHEN ADDX INNOVATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510832440.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-08-12

AI Technical Summary

Technical Problem

The security protection measures of existing smart devices are not perfect enough and are vulnerable to malicious attacks, resulting in data leakage and illegal access to functions. At the same time, the interaction between the device and the user is single, complex in operation, affecting user experience and efficiency.

Method used

The near-field communication device uses static random memory to store challenge data, send it to the target device for authentication, listen to response data packets, and verify it with pre-stored device authentication keys, ensuring that unlocking processing is automatically performed after secure authentication.

Benefits of technology

It realizes efficient and secure interaction between devices and users, prevents malicious attacks, and improves the security and user experience of devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120475362A_ABST
    Figure CN120475362A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an equipment processing method and device, equipment, a computer readable medium and a program product. A specific embodiment of the method comprises the following steps: responding to a situation that a built-in near field communication module of near field communication equipment is activated by target equipment with a near field communication function, and sending challenge data stored in a static random access memory to the target equipment; monitoring a response data packet which is sent by the target device and responds to the challenge data, and performing correctness and validity verification on the response data packet by using a pre-stored device authentication key to obtain a first verification result; in response to the fact that the first verification result is correct and effective, unlocking processing of the target equipment is executed; and in response to the condition that the target equipment is in the unlocking state, automatically executing a set processing operation of the unlocking event. According to the embodiment, on the basis that authentication safety is guaranteed, efficient unlocking of the equipment is achieved through the near field communication technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the field of computer technology, and more particularly to a device processing method, apparatus, device, computer-readable medium, and program product. Background Art

[0002] With the rapid development of the Internet of Things (IoT) and the increasing use of smart devices, device security and user experience have become key concerns. Existing technologies lack robust security measures, making devices vulnerable to malicious attacks, leading to data leaks and unauthorized access to device functions. Furthermore, the interaction between devices and users is relatively simple and complex, impacting user experience and resulting in cumbersome and inefficient device usage.

[0003] The above information disclosed in this Background section is only for enhancement of understanding of the background of the inventive concept and therefore it may contain information that does not form the prior art that is already known in this country to a person of ordinary skill in the art. Summary of the Invention

[0004] The content of this disclosure is used to briefly introduce concepts that will be described in detail in the detailed description section below. The content of this disclosure is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0005] Some embodiments of the present disclosure provide device processing methods, apparatuses, devices, computer-readable media, and program products to solve one or more of the technical problems mentioned in the above background technology section.

[0006] In the first aspect, some embodiments of the present disclosure provide a device processing method, which is applied to a near-field communication device, and the method also includes: in response to the above-mentioned near-field communication device being activated by a target device with a near-field communication function by a built-in near-field communication module, sending the challenge data stored in the static random access memory to the above-mentioned target device; monitoring the response data packet sent by the above-mentioned target device in response to the above-mentioned challenge data, using a pre-stored device authentication key to verify the correctness and validity of the above-mentioned response data packet to obtain a first verification result; in response to the above-mentioned first verification result being correct and valid, executing the unlocking processing of the above-mentioned target device; in response to the above-mentioned target device being in an unlocked state, automatically executing the setting processing operation of the unlocking event.

[0007] Optionally, the above method also includes: obtaining the challenge value currently generated by the microcontroller periodically; determining the above challenge value, random number and timestamp as adjustment data, wherein the above random number is a value generated by the above microcontroller to ensure the validity of the data, and the above timestamp is the generation time corresponding to the challenge value generated by the above microcontroller; pre-setting the above target device state to a waiting response state and a low power processing execution state.

[0008] Optionally, generating the above-mentioned response data packet includes the following steps: reading the above-mentioned challenge data from the above-mentioned static random access memory; verifying the validity and freshness of the above-mentioned challenge data to obtain a second verification result; in response to the above-mentioned second verification result indicating that it is correct, using a pre-stored device authentication key to generate signature information for the above-mentioned challenge data; and determining the current authentication status and the above-mentioned signature information as a response data packet.

[0009] Optionally, the near-field communication device performs at least one of the following settings during the device production stage: writing the data required for the device operation corresponding to the near-field communication device into the target non-volatile memory included in the near-field communication device, wherein the data required for the device operation includes: basic data, device identification information and device authentication key; configuring initial security parameters and access control policies.

[0010] Optionally, the near-field communication device performs at least one of the following settings during the security setting phase: performing read and write protection processing on the sensitive data area in the target non-volatile memory; locking the key data area in the target non-volatile memory; and write protection processing on the firmware in the target non-volatile memory.

[0011] Optionally, the near-field communication device performs at least one of the following settings during the functional testing phase: testing the communication function corresponding to the near-field communication device, the target bus communication function, and the read and write functions corresponding to the static random access memory; performing a challenge and response test on the near-field communication device to simulate the actual authentication process and verify the security of the device.

[0012] Optionally, the NFC device performs at least one of the following settings during the initial configuration phase: setting default parameters, default security level, and challenge update frequency for the NFC device; and initializing the data area corresponding to the static random access memory to clear data.

[0013] Optionally, the near-field communication device performs at least one of the following settings during the binding and sharing phase: sending the device authentication key to the target application in the target device for key storage; and writing near-field communication structured data for launching the target application in the target device into the static random access memory.

[0014] Optionally, when the above-mentioned near-field communication device is in a low-power state, at least one of the following processing operations is performed: pre-powering the above-mentioned near-field communication module and micro-control unit to support the target unlocking operation; cutting off at least one non-essential functional module; setting the above-mentioned near-field communication module to a passive wake-up mechanism; turning off the above-mentioned micro-control unit to periodically generate a challenge value, and setting the byte size corresponding to the challenge value; shortening the response time corresponding to the response data packet to the target time; optimizing the verification path; and the above-mentioned method also includes: sending a low-power warning message to the above-mentioned target device.

[0015] In the second aspect, some embodiments of the present disclosure provide a device processing apparatus, which is applied to a near-field communication device, including: a sending unit, configured to send challenge data stored in a static random access memory to the above-mentioned target device in response to the above-mentioned near-field communication device being activated by a target device with a near-field communication function by a built-in near-field communication module; a verification unit, configured to monitor a response data packet sent by the above-mentioned target device in response to the above-mentioned challenge data, and verify the correctness and validity of the above-mentioned response data packet using a pre-stored device authentication key to obtain a first verification result; a first execution unit, configured to execute the unlocking processing of the above-mentioned target device in response to the above-mentioned first verification result being correct and valid; and a second execution unit, configured to automatically execute the setting processing operation of the unlocking event in response to the above-mentioned target device being in an unlocked state.

[0016] Optionally, the device also includes: obtaining the challenge value currently generated by the microcontroller periodically; determining the above challenge value, random number and timestamp as adjustment data, wherein the above random number is a value generated by the above microcontroller to ensure the validity of the data, and the above timestamp is the generation time corresponding to the challenge value generated by the above microcontroller; pre-setting the above target device state to a waiting response state and a low power processing execution state.

[0017] Optionally, when the above-mentioned near-field communication device is in a low-power state, at least one of the following processing operations is performed: the above-mentioned near-field communication module and micro-control unit are powered in advance to support the target unlocking operation; at least one non-essential functional module is cut off; the above-mentioned near-field communication module is set to a passive wake-up mechanism; the above-mentioned micro-control unit is turned off to periodically generate a challenge value, and the byte size corresponding to the challenge value is set; the response time corresponding to the response data packet is shortened to the target time; and the device also includes: sending a low-power alarm message to the above-mentioned target device.

[0018] In a third aspect, some embodiments of the present disclosure provide an electronic device comprising: one or more processors; a storage device on which one or more programs are stored, and when the one or more programs are executed by one or more processors, the one or more processors implement the method described in any implementation manner in the first aspect.

[0019] In a fourth aspect, some embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method described in any implementation manner in the first aspect is implemented.

[0020] In a fifth aspect, some embodiments of the present disclosure provide a computer program product, including a computer program, which implements the method described in any implementation manner in the first aspect when executed by a processor.

[0021] The above-described embodiments of the present disclosure have the following beneficial effects: The device processing methods of some embodiments of the present disclosure achieve efficient device unlocking through near-field communication technology while ensuring authentication security. Specifically, the low unlocking efficiency of related devices is caused by inadequate security measures on the devices, making them vulnerable to malicious attacks, leading to device data leakage and illegal access to functions. Furthermore, the device-user interaction method is relatively simple and complex, which affects the user experience and results in cumbersome device usage logic and low efficiency. Based on this, the device processing methods of some embodiments of the present disclosure firstly, in response to the aforementioned near-field communication device being activated by a target device with near-field communication functionality by a built-in near-field communication module, send challenge data stored in a static random access memory to the target device. Here, the use of near-field communication technology can greatly improve the convenience of interaction between the device and the user. The challenge data stored in the static random access memory is permanently retained as long as the power remains on. The challenge data is sent to the target device as a response, thereby achieving effective and secure authentication of the target device. Then, the response data packet sent by the target device in response to the challenge data is monitored, and the correctness and validity of the response data packet are verified using the pre-stored device authentication key to obtain a first verification result. Here, by verifying the correctness and validity of the response data packet, effective security authentication of the device can be achieved on the basis of ensuring the security of the device data. Then, in response to the first verification result being characterized as correct and valid, after ensuring that the security authentication is passed, the target device unlocking process can be automatically executed to perform subsequent related device processing operations. Finally, in response to the target device being in an unlocked state, the setting processing operation of the unlocking event is automatically executed. In summary, through the technology of near-field communication function, the interaction mode between the device and the user can be diversified and convenient. Through the back-and-forth verification of challenge data and response data packets between the device and the user, security authentication in the device unlocking process can be achieved, the security protection of the device can be guaranteed, and malicious attacks can be avoided, resulting in device data leakage and illegal access to functions. BRIEF DESCRIPTION OF THE DRAWINGS

[0022] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.

[0023] Figure 1 is a flow chart of some embodiments of a device processing method according to the present disclosure;

[0024] Figure 2 is a schematic structural diagram of some embodiments of the device processing apparatus according to the present disclosure;

[0025] Figure 3 It is a structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION

[0026] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.

[0027] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure may be combined with each other.

[0028] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0029] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".

[0030] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0031] Before performing any of the collection, storage, and use of user personal information (e.g., response data packets) involved in this disclosure, relevant organizations or individuals must fulfill their obligations, including conducting personal information security impact assessments, fulfilling their obligation to inform the personal information subject, and obtaining the prior authorization and consent of the personal information subject.

[0032] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.

[0033] Continue to refer Figure 1 , shows a process 100 of some embodiments of the device processing method according to the present disclosure. The device processing method, applied to a near field communication device, includes the following steps:

[0034] Step 101: in response to the NFC module of the NFC device being activated by the target device having the NFC function, the challenge data stored in the static random access memory is sent to the target device for response processing of the challenge data.

[0035] In some embodiments, in response to the NFC module being activated by a target device with NFC functionality, the execution subject of the device processing method (e.g., the NFC device) may send challenge data stored in a static random access memory (SRAM) to the target device to process the challenge data in response. The NFC device may be a device with NFC (Near Field Communication) functionality to be unlocked. In different scenarios, the NFC device may be a device with different functions. For example, in a smart door lock security interaction scenario, the NFC device may be a smart door lock with NFC functionality. For another example, in a smart home scenario, the NFC device may be a control device corresponding to a smart home control system with NFC functionality. The target device with NFC functionality may be the object that activates the NFC device. In practice, the target device may be a handheld device that supports NFC and corresponds to the object being controlled. For example, in a smart door lock scenario, the target device may be a mobile terminal (e.g., a mobile phone, a remote control, etc.) held by the target user. Unlocking the smart door lock is achieved through the mobile terminal using NFC technology. In a smart home scenario, the target device can be a mobile terminal (e.g., a cell phone, remote control, etc.) held by the target user. Near-field communication (NFC) technology is used through the mobile terminal to unlock and control smart furniture. The NFC module can be an NFC module within the NFC device. For example, the NFC module can be an NFC wireless keyboard (keypad). It should be noted that the conditions for the NFC device to be activated by the target device can be set by the NFC device during its production. For example, the activation condition can be that the distance between the target device's corresponding NFC interface and the NFC module within the NFC device is less than a target value. Static Random Access Memory (SRAM) is a type of semiconductor memory based on a flip-flop structure that stores data using bi-stable transistor circuits. It retains information for a long time as long as power is maintained, without the need for periodic refreshes like DRAM (dynamic random access memory). Challenge data in NFC refers to dynamically generated data used to verify the identity of a device or user during the security authentication process, typically involving encryption protocols and a two-way authentication mechanism. The core function of challenge data is to ensure the authenticity and data integrity of both communicating parties through a temporarily generated random number (nonce) or encrypted instruction, preventing replay attacks and identity forgery. The target device is the entity responsible for processing the challenge data. The target device responds to the challenge data to complete the authentication process.

[0036] As an example, the execution subject may receive a challenge data acquisition request sent by the target device via an RF interface (Radio Frequency Interface), and the execution subject may send the challenge data stored at the current time to the target device according to the challenge data acquisition request.

[0037] It should be noted that if the target device is a mobile device, when the target device is locked, the NFC tag position of the device (such as a smart lock or electronic device) is clearly marked to guide the user to place the middle of the phone (usually the NFC antenna position) close to the center of the tag to reduce angle deviation. Use a high-sensitivity NFC chip (such as NXP PN532) to support a wide range of sensing distances (0-5cm), reducing the reliance on precise fit. Set a short-range strong magnetic field area on the device side. When the screen is locked, the proximity of the mobile device triggers "quick wake-up" and forcibly activates the NFC controller (the device MCU must support low-power wake-up NFC module).

[0038] In some optional implementations of some embodiments, before step 101, the method further includes:

[0039] The first step is to obtain the challenge value currently generated by the microcontroller unit (MCU) periodically. That is, the challenge value can be content generated periodically by the microcontroller unit. For example, a challenge value is generated every 10 minutes. In practice, the MCU can generate challenge values in a random period. The challenge value (Challenge) in device authentication is a core element in the security authentication protocol, which is mainly used to verify the authenticity of the device or user identity and prevent replay attacks and forgery risks. Its core function is to ensure the uniqueness and security of each authentication interaction through dynamically generated random numbers or encryption parameters. For example, for smart door lock scenarios, the MCU generates a new random challenge value every 5 minutes through I2C (Inter-Integrated Circuit). For smart home scenarios, the MCU generates a new random challenge value every 10 minutes.

[0040] The second step is to determine the challenge value, random number, and timestamp as adjustment data. The timestamp can be the timestamp of the challenge value generation or the timestamp corresponding to the challenge value acquisition. The random number is a value generated by the microcontroller to ensure data validity. The timestamp is the time when the challenge value generated by the microcontroller was generated.

[0041] The third step is to pre-set the target device state to a response waiting state and a low power consumption processing state, wherein the response waiting state may be a state of waiting for the target device to respond to the challenge data.

[0042] In some optional implementations of some embodiments, the near field communication device performs at least one of the following settings during the device production stage:

[0043] Setting 1: Write the data required for the operation of the device corresponding to the above-mentioned near-field communication device into the target non-volatile memory (EEPROM) included in the above-mentioned near-field communication device. The data required for the operation of the above-mentioned device includes: basic data, device identification information and device authentication key. The basic data can be the most basic data required for the operation of the device. For example, the basic data can include: device parameters and device status. The device identification information can represent the identity information of the device. In practice, the device identification information can include: a device identifier and a unique device ID. The device authentication key can be the key required during the device authentication process.

[0044] Setting 2: Configure initial security parameters and access control policies. The device's initial security parameters ensure basic security configuration during initial deployment or when restoring factory settings. They cover core settings at the hardware, software, and network levels. These parameters may include, but are not limited to, at least one of the following: identity authentication parameters, network and communication security parameters, firmware and software security parameters, and physical and environmental parameters. Access control policies can be a system of rules for dynamically managing access rights to device resources. These policies integrate identity, role, and environmental attributes for refined control.

[0045] In some optional implementations of some embodiments, the near field communication device performs at least one of the following settings during the security setting phase:

[0046] Setting 1: Read and write protection is applied to the sensitive data area in the target non-volatile memory. The sensitive data area can be the storage area corresponding to sensitive data. For smart door lock scenarios, the door lock's security management module can write-protect the EEPROM to prevent data tampering.

[0047] Setting 2: Lock the key data area in the target non-volatile memory. This key data area can be the storage area corresponding to the device authentication key. Set read and write protection for sensitive data areas in the EEPROM (such as the authentication key storage area) and lock the device key area to prevent unauthorized access.

[0048] Setting 3: Write-protect the firmware in the target non-volatile memory. For smart door locks, if the door lock supports firmware updates, set firmware write protection through the firmware management interface to ensure firmware security.

[0049] In some optional implementations of some embodiments, the near field communication device performs at least one of the following settings during the functional testing phase:

[0050] Setup 1: Test the communication function of the NFC device, the target bus communication function, and the read / write function of the static random access memory. The NFC device communication function can be NFC. The target bus communication function can be an I2C connection. The read / write function of the static random access memory can be SRAM. NFC RF communication can also be tested.

[0051] Setup 2: Perform a challenge and response test on the NFC device to simulate the actual authentication process and verify the device's security. Here, a complete challenge-response test is performed to simulate the actual authentication process and verify the device's security.

[0052] In some optional implementations of some embodiments, the near field communication device performs at least one of the following settings during the initial configuration phase:

[0053] Setting 1: Set the default parameters, default security level, and challenge update frequency for the aforementioned near-field communication devices. In practice, the default parameters, default security level, and challenge update frequency can be set through the device's configuration interface or app. For smart door lock scenarios, set the door lock's default parameters through the door lock's configuration interface or app, such as the NFC communication frequency to 13.56MHz and the data format to NFC Data Exchange Format. Configure the door lock's default security level to high and set the challenge update frequency to every 5 minutes. Initialize the door lock's SRAM data area and clear previous data. For smart home scenarios, set the system's default parameters, such as the NFC communication frequency and data format, through the system's configuration interface or app. Configure the system's default security level to medium and set the challenge update frequency to every 10 minutes. Initialize the system's SRAM data area.

[0054] Setting 2: Initialize the data area corresponding to the above static random access memory to clear the data.

[0055] In some optional implementations of some embodiments, the near field communication device performs at least one of the following settings during the binding and sharing phase:

[0056] Setting 1: Send the device authentication key to the target application on the target device for key storage. In practice, the key stored in the NFC tag is transferred to the app via a service server or Bluetooth, where it is stored. When sharing the device with an authorized user, the key is transferred to the user's app using the same method.

[0057] Setting 2: Write the NFC structured data used to launch the target application on the target device into the static random access memory (SRAM). In practice, write the NDEF information into the keypad NFC SRAM to ensure that the target device can correctly identify the app to be launched.

[0058] Optionally, you can enable NFC unlocking without the app open through the following settings:

[0059] First, through the deep collaboration between system-level NFC event monitoring and hardware-level security modules, the NFC unlocking function of the mobile device is realized when the screen is locked or no application is running. The specific core architecture is divided into three levels:

[0060] 1. Device side: Integrates an NFC chip (such as NXP PN7642) with a secure element (SE) to store device keys and generate dynamic challenge values.

[0061] 2. Mobile device: Receive the challenge data through the system-level NFC service (such as Android's NfcAdapter or iOS's Core NFC) and use SE or TEE (Trusted Execution Environment) to complete the encrypted response.

[0062] 3. Communication protocol: Use lightweight encryption protocols (such as HMAC-SHA256) to implement challenge-response interaction to ensure data integrity and prevent replay attacks.

[0063] Then, configure the NFC tag as follows:

[0064] 1. Set up the NDEF record as follows: embed a custom URI (such as yourapp: / / nfc-unlock) to trigger system-level operations without launching the app.

[0065] 2. Set the data format as follows: Use NFC Forum Type 5 tags (ISO 15693) to support fast data exchange and anti-collision mechanisms.

[0066] The integration process of the security module is as follows:

[0067] 1. The device authentication key (such as AES-256) is stored in the SE chip (such as NXP PN532) and protected by hardware encryption.

[0068] 2. The MCU periodically generates a random challenge value (such as a 32-byte Nonce) through the I2C interface and writes it into the SRAM area of the NFC tag.

[0069] Step 102 : monitoring a response data packet sent by the target device in response to the challenge data, and verifying the correctness and validity of the response data packet using a pre-stored device authentication key to obtain a first verification result.

[0070] In some embodiments, the response data packet sent by the target device in response to the challenge data is monitored, and the execution subject can use the pre-stored device authentication key to verify the correctness and validity of the response data packet to obtain a first verification result. Among them, the response data packet can be a data packet after responding to the challenge data. The response data packet may include: response information and response encryption information in response to the challenge data. The device authentication key may be a key for authenticating the device. Correctness verification can be to verify whether the response data packet is correct. In practice, the accuracy of the response information and the response encryption information can be checked by the device authentication key. The validity of the response data packet is checked by checking the received timestamp of the response data packet. The first verification result can be a verification result of whether the response data packet is correct or valid. Here, the near field communication device triggers data packet monitoring by the target duration to monitor whether the target device has sent a response data packet.

[0071] It should be noted that in the challenge and response mechanism, asynchronous wake-up and low-power wake-up design are supported. Asynchronous wake-up means that when the device detects that a mobile device is approaching (even if the mobile device is locked), the challenge data (including timestamp and random number) is sent via NFC. If the first read fails (such as the mobile device does not wake up the application), the device caches the challenge data in SRAM and allows repeated reading within 3 seconds (up to 3 retries) to improve fault tolerance. The low-power wake-up design means that the device's NFC module is in "low-power listening mode" when in standby mode, and wakes up the MCU only when the NFC field strength of the mobile device is detected, avoiding frequent polling and power consumption while ensuring immediate response.

[0072] In some optional implementations of some embodiments, generating the above-mentioned response data packet includes the following steps:

[0073] The first step is to read the challenge data from the static random access memory.

[0074] In the second step, the validity and freshness of the challenge data are verified to obtain a second verification result. Validity verification is to ensure that the challenge data (Challenge) complies with the expected rules in terms of logic, format and encryption results to prevent forgery or tampering attacks. For example, validity verification may include: format verification, encryption result matching and business logic verification. Freshness verification is to ensure that the challenge data is timely to prevent replay attacks (Replay Attack). Freshness verification may include: timestamp verification, random number / serial number increment, and dynamic key update. The second verification result may include: validity verification result and freshness verification result. Freshness verification may be a verification process to confirm whether the challenge information is the latest generated.

[0075] In the third step, in response to the second verification result indicating that the challenge data is correct, a signature information for the challenge data is generated using the pre-stored device authentication key, wherein the signature information may be an HMAC signature.

[0076] The fourth step is to determine the current authentication status and the above signature information as a response data packet.

[0077] Step 103 : In response to the first verification result indicating that the verification result is correct and valid, the target device unlocking process is executed.

[0078] In some embodiments, in response to the first verification result indicating that the target device is correct and valid, the execution subject may perform device unlocking processing. That is, if the first verification result is determined to be correct and valid, it indicates that the target device has passed device authentication and supports near field communication interaction.

[0079] Step 104 : In response to the target device being in an unlocked state, automatically executing a setting processing operation for an unlocking event.

[0080] In some embodiments, in response to the target device being in the device unlocked state, the execution subject may automatically execute the setting processing operation of the unlocking event. The unlocking event may be the entire event process of device authentication and device unlocking between the near-field communication device and the target device. In practice, the various processing operations may include but are not limited to at least one of the following: storage and processing of unlocking events, updating device status, and clearing sensitive data in SRAM. For example, for smart door lock scenarios, the various processing operations may include: recording unlocking events, clearing sensitive data in SRAM, and resetting the door lock status. For example, for smart home scenarios, the various processing operations may include: recording unlocking events, clearing sensitive data in SRAM, and resetting the smart home system status.

[0081] In some optional implementations of some embodiments, when the near field communication device is in a low-battery state, at least one of the following processing operations is performed:

[0082] Operation 1: Power the NFC module and microcontroller in advance to support the target number of unlocking operations. That is, when the main battery is low, the pre-stored power will be used to power the NFC module (passive mode) and the MCU minimum system (only I2C, SRAM, NFC controller) to support at least 10 unlocking operations.

[0083] Operation 2: Disconnect at least one non-essential functional module. That is, when the battery voltage is detected to be lower than a threshold (e.g., 2.8V), the power supply to non-essential modules (e.g., display, wireless communication module) is automatically disconnected, leaving only the NFC receiver, MCU low-power core unit, and SRAM maintenance circuit.

[0084] Step 3: Set the NFC module to a passive wake-up mechanism. The passive wake-up mechanism can be: 1. The NFC module operates in passive mode (Tag mode), activating only when the mobile device's NFC antenna is in close proximity (power consumption <10μA in standby mode), avoiding the high power consumption associated with active scanning. 2. When a mobile device approaches, the device wakes up through NFC field strength sensing (energy coupling in the ISO / IEC 14443 protocol), eliminating the need for continuous monitoring.

[0085] Operation 4: Disable the periodic generation of challenge values by the microcontroller, and set the corresponding byte size of the challenge value. Disabling the periodic generation of challenge values by the microcontroller means that the system will no longer periodically generate new challenges in standby mode (the original function consumes approximately 1mA per time), and will only temporarily generate a single challenge when NFC is triggered, reducing MCU computing power consumption. Setting the corresponding byte size of the challenge value means that the challenge value length can be reduced from 32 bytes to 16 bytes (e.g., only a random number, omitting the timestamp) when the battery is low, but retaining the anti-replay mechanism (recording the last 10 nonces in SRAM to prevent duplication).

[0086] Action 5: Reduce the response time corresponding to the response data packet to the target time. In practice, shorten the response timeout from 30 seconds to 10 seconds to reduce the active time of the NFC module and MCU.

[0087] It should be noted that when a device (such as a smart lock or IoT terminal) enters a low-power state (such as the battery voltage is lower than a preset threshold, usually below 3.0V), it is necessary to prevent the NFC module from continuously monitoring and causing power depletion, ensure that the user can still trigger unlocking through NFC, prevent the device from "crashing" and becoming inaccessible, and not reduce the security of the authentication mechanism (such as key protection and challenge freshness verification) when the battery is low.

[0088] Operation 6: Optimize the verification path. This optimization can include skipping non-critical checks (such as the optional step of writing the user ID) and directly verifying the HMAC response and nonce uniqueness, thus reducing computational power consumption. The verification path can be the verification path for the response data packet during the device authentication process.

[0089] And after step 104, the steps further include:

[0090] The execution entity may send low battery warning information to the target device.

[0091] Optionally, the execution entity may cut off at least one non-essential functional module, including the following steps:

[0092] The first step is to obtain the remaining power of the near field communication device at the current time.

[0093] The second step is to select the corresponding essential functional module information based on the power range corresponding to the remaining power. Each power range has corresponding essential functional module information, which can represent the essential functional modules that can be powered within the power range. In other words, different power ranges correspond to different executable essential functional modules.

[0094] In the third step, each necessary functional module and corresponding power supply identifier in the necessary functional module information is displayed on the power supply page so that the operator can adjust the power supply of each necessary functional module. The power supply page can be a page for processing power supply related events.

[0095] The fourth step is to receive the adjusted set of necessary functional modules for power supply.

[0096] In the fifth step, it is determined whether normal power supply can be achieved according to the power consumption corresponding to each essential functional module in the essential functional module set.

[0097] In step 6, in response to determining that normal power supply of the necessary power supply module set can be achieved, power supply processing is performed on the necessary functional module set, and the remaining functional module set is regarded as at least one non-essential functional module to perform power supply cancellation processing.

[0098] In the seventh step, in response to determining that normal power supply of the necessary power supply module set cannot be achieved, the necessary power supply modules with lower priorities, the identification of no power supply and the reason for no power supply are displayed on the above-mentioned power supply page according to the power supply module priority corresponding to the necessary power supply modules, so that the above-mentioned operation objects can make adaptive adjustments to obtain the target necessary functional module set.

[0099] In the eighth step, power supply processing is performed on the target essential functional module set, and the remaining functional module sets are regarded as at least one non-essential functional module to perform power supply cancellation processing.

[0100] In the ninth step, the above-mentioned necessary functional module set or target necessary functional module set is used as an optional power supply scheme for the modules corresponding to the above-mentioned power range.

[0101] In the tenth step, in response to receiving the supply confirmation information for the power interval at the next time, the optional power supply schemes for the above module are displayed for the above operation object to select.

[0102] As one of the inventive points of the present disclosure, another technical problem is solved: "How to achieve user-satisfied and customized power supply under limited power supply conditions to ensure the power supply needs of the near-field communication module and the fine-tuning unit." Based on this, the present disclosure makes a preliminary determination of the necessary functional module information through the correspondence between the power area and the necessary functional module information. On the basis of the preliminary determination, user-satisfied and customized power supply is achieved through the customized selection of the power supply module. On this basis, through the generation of module supply options, the efficient completion of the necessary functional module configuration can be achieved when the power range supply also appears at the next time.

[0103] The above-described embodiments of the present disclosure have the following beneficial effects: The device processing methods of some embodiments of the present disclosure achieve efficient device unlocking through near-field communication technology while ensuring authentication security. Specifically, the low unlocking efficiency of related devices is caused by inadequate security measures on the devices, making them vulnerable to malicious attacks, leading to device data leakage and illegal access to functions. Furthermore, the device-user interaction method is relatively simple and complex, which affects the user experience and results in cumbersome device usage logic and low efficiency. Based on this, the device processing methods of some embodiments of the present disclosure firstly, in response to the aforementioned near-field communication device being activated by a target device with near-field communication functionality by a built-in near-field communication module, send challenge data stored in a static random access memory to the target device. Here, the use of near-field communication technology can greatly improve the convenience of interaction between the device and the user. The challenge data stored in the static random access memory is permanently retained as long as the power remains on. The challenge data is sent to the target device as a response, thereby achieving effective and secure authentication of the target device. Then, the response data packet sent by the target device in response to the challenge data is monitored, and the correctness and validity of the response data packet are verified using the pre-stored device authentication key to obtain a first verification result. Here, by verifying the correctness and validity of the response data packet, effective security authentication of the device can be achieved on the basis of ensuring the security of the device data. Then, in response to the first verification result being characterized as correct and valid, after ensuring that the security authentication is passed, the target device unlocking process can be automatically executed to perform subsequent related device processing operations. Finally, in response to the target device being in an unlocked state, the setting processing operation of the unlocking event is automatically executed. In summary, through the technology of near-field communication function, the interaction mode between the device and the user can be diversified and convenient. Through the back-and-forth verification of challenge data and response data packets between the device and the user, security authentication in the device unlocking process can be achieved, the security protection of the device can be guaranteed, and malicious attacks can be avoided, resulting in device data leakage and illegal access to functions.

[0104] Further references Figure 2 As an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of a device processing apparatus. These apparatus embodiments are similar to Figure 1 Corresponding to the method embodiments shown, the device processing apparatus can be specifically applied to various electronic devices.

[0105] like Figure 2As shown, a device processing apparatus 200 includes: a sending unit 201, a verification unit 202, a first execution unit 203, and a second execution unit 204. The sending unit 201 is configured to, in response to the NFC module being activated by a target device with NFC functionality, send challenge data stored in a static random access memory to the target device; the verification unit 202 is configured to monitor a response data packet sent by the target device in response to the challenge data, and verify the correctness and validity of the response data packet using a pre-stored device authentication key to obtain a first verification result; the first execution unit 203 is configured to, in response to the first verification result indicating that the target device is correct and valid, execute unlocking processing on the target device; and the second execution unit 204 is configured to, in response to the target device being in an unlocked state, automatically execute a setting processing operation for an unlocking event.

[0106] In some optional implementations of some embodiments, the apparatus 200 further includes: an acquisition unit, a determination unit, and a setting unit (not shown in the figure). The acquisition unit may be configured to: acquire the challenge value currently generated by the microcontroller periodically. The determination unit may be configured to: determine the challenge value, random number, and timestamp as adjustment data, wherein the random number is a value generated by the microcontroller to ensure data validity, and the timestamp is the generation time corresponding to the challenge value generated by the microcontroller. The setting unit may be configured to: pre-set the target device state to a waiting for response state and a low-power processing state.

[0107] In some optional implementations of some embodiments, when the near-field communication device is in a low-battery state, at least one of the following processing operations is performed: pre-powering the near-field communication module and microcontroller unit to support a target number of unlocking operations; disconnecting at least one non-essential functional module; configuring the near-field communication module to a passive wake-up mechanism; disabling the microcontroller unit from periodically generating a challenge value and setting the byte size corresponding to the challenge value; and shortening the response time corresponding to the response data packet to a target time. Furthermore, the apparatus further includes: transmitting a low-battery warning message to the target device.

[0108] It is understood that the units described in the device processing apparatus 200 are similar to those described in the reference Figure 1 Therefore, the operations, features and beneficial effects described above for the method are also applicable to the device processing apparatus 200 and the units included therein, and will not be repeated here.

[0109] Reference below Figure 3, which shows a structural schematic diagram of an electronic device (eg, a near field communication device) 300 suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0110] like Figure 3 As shown, the electronic device 300 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory 302 or a program loaded from a storage device 308 into a random access memory 303. Various programs and data required for the operation of the electronic device 300 are also stored in the random access memory 303. The processing device 301, the read-only memory 302, and the random access memory 303 are connected to each other via a bus 304. An input / output interface 305 is also connected to the bus 304.

[0111] Typically, the following devices may be connected to the input / output interface 305: an input device 306 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 307 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 308 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 309. The communication device 309 may allow the electronic device 300 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 3 The electronic device 300 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead. Figure 3 Each block shown in the figure may represent one device, or may represent multiple devices as needed.

[0112] In particular, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from a network via the communication device 309, or installed from the storage device 308, or installed from the read-only memory 302. When the computer program is executed by the processing device 301, the above-mentioned functions defined in the method of some embodiments of the present disclosure are performed.

[0113] It should be noted that in some embodiments of the present disclosure, the computer-readable medium mentioned above may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.

[0114] In some embodiments, the client and server can communicate using any currently known or future developed network protocol, such as HTTP (HyperText Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.

[0115] The computer-readable medium may be included in the electronic device; or it may exist independently without being assembled into the electronic device. The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device: in response to the NFC device being activated by a target device with NFC function, the built-in NFC module is activated, and the challenge data stored in the static random access memory is sent to the target device; the response data packet sent by the target device in response to the challenge data is monitored, and the correctness and validity of the response data packet are verified using a pre-stored device authentication key to obtain a first verification result; in response to the first verification result indicating that the target device is correct and valid, the target device is unlocked; in response to the target device being in an unlocked state, various setting operations for the unlocking event are automatically executed.

[0116] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0117] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0118] The units described in some embodiments of the present disclosure may be implemented in software or in hardware. The units described may also be provided in a processor. For example, they may be described as follows: a processor includes a sending unit, a verification unit, a first execution unit, and a second execution unit. The names of these units do not, in some cases, constitute limitations on the units themselves. For example, the first execution unit may also be described as "a unit that executes the above-mentioned target device unlocking process in response to the above-mentioned first verification result being characterized as correct and valid."

[0119] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0120] Some embodiments of the present disclosure further provide a computer program product, including a computer program, which implements any of the above-mentioned device processing methods when executed by a processor.

[0121] The above description is only an illustration of some preferred embodiments of the present disclosure and the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but should also cover other technical solutions formed by any combination of the above-mentioned technical features or their equivalent features without departing from the above-mentioned inventive concept. For example, the above-mentioned features are replaced with (but not limited to) technical features with similar functions disclosed in the embodiments of the present disclosure.

Claims

1. A device processing method, applied to a near field communication device, comprising: In response to a target device having a near field communication function activating a built-in near field communication module of the near field communication device, sending the challenge data stored in the static random access memory to the target device; monitoring a response data packet sent by the target device in response to the challenge data, and verifying the correctness and validity of the response data packet using a pre-stored device authentication key to obtain a first verification result; In response to the first verification result indicating that the verification result is correct and valid, performing the target device unlocking process; In response to the target device being in an unlocked state, a setting processing operation of an unlocking event is automatically executed.

2. The method according to claim 1, wherein The method further comprises: Get the challenge value currently generated by the microcontroller cycle; Determining the challenge value, the random number, and the timestamp as adjustment data, wherein the random number is a value generated by the microcontroller unit to ensure data validity, and the timestamp is the generation time corresponding to the challenge value generated by the microcontroller unit; The target device state is pre-set to a response waiting state and a low power consumption processing execution state.

3. The method according to claim 1, wherein Generating the response data packet comprises the following steps: Reading the challenge data from the static random access memory; Verifying the validity and freshness of the challenge data to obtain a second verification result; In response to the second verification result indicating that the challenge data is correct, generating signature information for the challenge data using a pre-stored device authentication key; The current authentication state and the signature information are determined as a response data packet.

4. The method according to claim 1, wherein The near field communication device performs at least one of the following settings during the device production stage: Writing data required for device operation corresponding to the near field communication device into a target non-volatile memory included in the near field communication device, wherein the data required for device operation includes: basic data, device identification information and a device authentication key; Configure initial security parameters and access control policies.

5. The method according to claim 1, wherein The near field communication device performs at least one of the following settings during the security setting phase: Perform read and write protection on sensitive data areas in the target non-volatile memory; Locking the key data area in the target non-volatile memory; Perform write protection processing on the firmware in the target non-volatile memory.

6. The method according to claim 1, wherein The near field communication device performs at least one of the following settings during the functional testing phase: Testing the communication function corresponding to the near field communication device, the target bus communication function, and the read and write functions corresponding to the static random access memory; A challenge and response test is performed on the near field communication device to simulate the actual authentication process and verify the security of the device.

7. The method according to claim 1, wherein The NFC device performs at least one of the following settings during the initial configuration phase: Setting default parameters, default security level, and challenge update frequency for the near field communication device; An initialization operation is performed on the data area corresponding to the static random access memory to clear data.

8. The method according to claim 1, wherein The NFC device performs at least one of the following settings during the binding and sharing phases: Sending the device authentication key to a target application in the target device for key storage; Writing near field communication structured data for launching a target application in the target device into the static random access memory.

9. The method according to claim 1, wherein When the near field communication device is in a low-battery state, performing at least one of the following processing operations: The near field communication module and the micro control unit are powered in advance to support the target unlocking operation; Cut off at least one non-essential functional module; Setting the near field communication module to a passive wake-up mechanism; Turning off the microcontroller unit from periodically generating a challenge value, and setting a byte size corresponding to the challenge value; Shorten the response time corresponding to the response data packet to the target time; Optimize verification path; And the method further comprises: Sending a low battery warning message to the target device.

10. A device processing apparatus, applied to a near field communication device, comprising: a sending unit configured to, in response to a target device having a near field communication function activating a built-in near field communication module of the near field communication device, send the challenge data stored in the static random access memory to the target device; a verification unit configured to monitor a response data packet sent by the target device in response to the challenge data, and verify the correctness and validity of the response data packet using a pre-stored device authentication key to obtain a first verification result; a first execution unit configured to execute the target device unlocking process in response to the first verification result indicating that the first verification result is correct and valid; The second execution unit is configured to automatically execute a setting processing operation of an unlocking event in response to the target device being in an unlocked state.

11. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 9.

12. A computer-readable medium having a computer program stored thereon, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 9 is implemented.

13. A computer program product comprising a computer program, which, when executed by a processor, implements the method according to any one of claims 1 to 9.