Bluetooth key distribution module with identity display and manual confirmation mechanism and equipment rejection list function
By introducing identity visual display, dual-button confirmation mechanism and device short-term rejection list, the Bluetooth key distribution device's identity is not visible, lack of manual intervention and repeated interference risks is solved, and a secure and auditable key distribution process is achieved.
Patent Information
- Application Number
- CN202510910178.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-02
- Publication Date
- 2025-09-05
AI Technical Summary
The existing Bluetooth key distribution devices have shortcomings in terms of invisible identity, lack of manual intervention, risk of repeated interference and no short-term blocking measures, resulting in frequent misconnection and malicious attacks.
Introduce identity visual display, a two-button confirmation mechanism and a short-term rejection list of devices to ensure that users visually confirm the other party’s identity before each copy, and prevent repeated connections from the device in the short term after rejection.
Through identity visualization and a two-button confirmation mechanism, the mis-issuance of keys is eliminated, repeated interference by malicious devices is prevented, and auditable secure key distribution is achieved.
Smart Images

Figure CN120602930A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of Bluetooth encrypted communication and key distribution, and in particular relates to a Bluetooth key distribution module with identity display and manual confirmation mechanisms and a device rejection list function. Background Art
[0002] Existing Bluetooth key distribution devices typically rely on physical docking or BLE automatic pairing for offline key synchronization, but these have the following drawbacks: 1. Identity invisibility: Users cannot visually confirm the identity of the other module before pairing, which can easily lead to misconnections or man-in-the-middle attacks. 2. Lack of manual intervention: The entire process is almost entirely automated, and users cannot proactively terminate the connection upon detecting a problem. 3. Risk of repeated interference: If a third-party device repeatedly scans and attempts to connect, even if the user presses "Cancel" once, the third-party device can immediately initiate another connection, causing malicious harassment. 4. No short-term blocking measures: Even if the user rejects the connection once with "Cancel," the system will still allow the device to connect for a few seconds, failing to effectively prevent repeated malicious attempts. Therefore, a new Bluetooth key distribution method is needed that incorporates "visual identity display + two-button confirmation" and a "short-term device rejection list" mechanism. This ensures that users can clearly see the identity of the other party before each copy attempt. If the user rejects the connection, the device is temporarily placed on the "deny list" to prevent further attempts. Summary of the Invention
[0003] In order to at least solve or partially solve the above problems, a Bluetooth key distribution module with identity display and manual confirmation mechanism and device rejection list function is provided to improve the anti-middleman interference and auditability of the key copying process.
[0004] In order to achieve the above object, the present invention provides the following technical solutions: The present invention provides a Bluetooth key distribution module with identity display and manual confirmation mechanism and device rejection list function, including an MCU main control chip, a BLE Bluetooth communication module, a Flash storage chip, a display module, and a physical button module; The MCU main control chip is used to control the BLE Bluetooth communication module, monitor key input, update the display content, manage the rejection list, perform encrypted transmission and log recording; The BLE Bluetooth communication module is used to support BLE 5.0 and above protocols and is responsible for scanning, broadcasting, pairing and GATT services; The Flash storage chip is used to store the encrypted key structure, the local device_id and the temporary rejection list, and the operation log; The display screen module is used to display pairing information and user prompts in real time; The physical button module includes a confirmation button and a cancel button. The confirmation button is connected to the GPIO input terminal of the MCU and is used for the user to confirm the copy; The cancel button is connected to the GPIO input of the MCU and is used for user rejection and triggering the device's short-term rejection mechanism.
[0005] As a preferred technical solution of the present invention, the key structure includes source_id, shared_key, and CRC check code.
[0006] As a preferred technical solution of the present invention, it also includes a status light module, which is used to indicate the module status.
[0007] As a preferred technical solution of the present invention, a LOCK hardware toggle switch is further included. The LOCK hardware toggle switch is used to manually enable or disable the Flash write permission.
[0008] Compared with the prior art, the present invention has the following beneficial effects: 1. **Identity Visualization**: Bidirectionally displays the device_ID or notes for enhanced user visibility. 2. **Two-Button Manual Confirmation**: Users must press "Confirm" to copy, and "Cancel" to immediately abort, eliminating accidental transfers. 3. **Device Rejection List**: Device_IDs rejected by the user are temporarily rejected for 30 seconds to prevent repeated interference from the same malicious device. 4. **Auditability**: Logs record all pairing, rejection, and transfer results for easy traceability. 5. **Interoperability**: Key hardware can be replaced with equivalent components, regardless of model. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings: Figure 1 It is a schematic diagram of the module hardware structure of the present invention; Figure 2 It is a timing flow chart of identity visualization and rejection list of the present invention; DETAILED DESCRIPTION
[0010] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0011] Furthermore, if detailed description of known art is not necessary to illustrate the characteristics of the present invention, it will be omitted.
[0012] Example 1 like Figure 1-2As shown, the present invention provides a Bluetooth key distribution module with identity display and manual confirmation mechanisms, as well as a device rejection list function. It primarily includes the following components: 1. MCU Main Control Chip: - Functions: Control the BLE module, monitor key inputs (confirm / cancel), update the display screen, manage the rejection list, perform encrypted transmission, and log. - Requirements: Provide BLE communication capabilities, at least two GPIO inputs (for buttons), at least one GPIO output (for LEDs), one I²C or SPI interface (for driving the OLED), and a built-in timer for second-level clocking. - Optional models: including but not limited to the STM32 series, ESP32 series, and nRF52840. 2. BLE Bluetooth Communication Module: - Functions: Supports BLE 5.0 and higher protocols, responsible for scanning, advertising, pairing, and GATT services. - Requirements: Connects to the MCU via UART / SPI / I²C, etc., and supports AES-128 encryption. - Can be integrated into an MCU (such as the ESP32) or an external submodule (such as the nRF52840 module). 3. Flash Storage Chip: - Function: Stores the encrypted key structure (including source_id, shared_key, CRC checksum), the local device_id, temporary rejection list, operation logs, etc. - Requirements: Supports write protection (Flash Lock) to prevent duplicate writes. - Optional Capacity: 4MB or above is suitable. 4. Display Module: - Function: Displays pairing information and user prompts in real time. - Requirements: Low-power OLED or small e-ink screen, typically a 0.96-inch 128×64 OLED (such as an SSD1306 driver with an I²C interface). - Display content includes: - "Waiting for pairing, please insert the target module" - "Connecting from: [source_id] (or note name)" - "Copying to: [target_id] (or note name), please confirm within X seconds" - "Copying... Progress: XX%" - "Copy successful" or "Copy failed" - "Device [ID] temporarily rejected, try again in 30 seconds" 5. Physical buttons: - Confirm button (GPIO_YES): Connected to the MCU's GPIO input for user confirmation of copying; - Cancel button (GPIO_NO): Connected to the MCU's GPIO input for user rejection and triggering the device's short-term rejection mechanism; - Debounce: Software delay of 10-20ms for debounce design or a simple hardware RC circuit. 6.Status Light Module: - Tri-color LED indicates module status: - Flashing blue: Pairing / Preparing; - Steady green: Copying successful; - Steady red: Connection canceled or copying failed. 7. LOCK Hardware Toggle Switch (Optional): - Used to manually enable or disable flash write access; - When LOCK is on, the MCU denies all write operations (only reads are allowed) to prevent accidental key overwriting. **System Workflow Example (A456 → B123)**: A. Initialization: - The MCU performs a power-on self-test and reads the flash. If no key is present, it waits for the app to initialize; - The app writes source_id = A456 and shared_key, which the MCU then stores in the flash and locks; - Upon completion, the module becomes a "super module"; others remain idle as "normal modules." B. Physical connection: - Insert the A456 and B123 male connectors into the female connector, the MCU external interrupt is triggered, and `read_target_device_id()` is called to obtain B123; - Call `is_device_rejected(B123)`: - If B123 is within the 30-second rejection period, it will display "Device B123 temporarily rejected, you can try again in 30 seconds", the LED will light red, and exit; - Otherwise, enter the identity display stage. C. Identity display and confirmation: - A456 displays on the OLED: "Copying to: B123, please confirm within 10 seconds"; - B123 displays on the OLED: "Connection from: A456, please confirm within 10 seconds"; - Start a 10-second countdown and wait for a key press: - If the user presses the confirm key, enter secure transmission; - If the user presses the cancel key or the timeout expires, call `reject_device(B123)`, add B123 to the rejection list, display "Device B123 temporarily rejected, try again in 30 seconds", the LED lights red, stops broadcasting, and exits. D. Secure transmission: - A456 stops advertising and starts the BLE GATT service; - Reads `KeyStruct { source_id=A456, shared_key, CRC}` from Flash, encrypts it using AES-128, and sends it to B123 via GATT_Write; - B123 receives and decrypts it, then verifies the CRC; - After verification, writes the key to its own Flash and locks it; - The A456 / B123 LED turns green, and the OLED displays "Copy Successful." After 3 seconds, the connection is disconnected and the pairing process returns to standby. E.Logging and auditing: - Each success or failure is recorded as `LogEntry { timestamp, source_id, target_id, result, error_code}` in the Flash log area; - The log can be exported via the serial port or BLE feature for subsequent auditing. F. Reject list management function (simplified example): ```c #define MAX_REJECTED 8 #define REJECT_TIMEOUT 30 typedef struct { uint32_t device_id; uint32_texpire_ts;} RejectEntry; static RejectEntry g_reject_list[MAX_REJECTED];static uint8_t g_reject_count = 0; extern uint32_t get_current_timestamp_sec(void); void reject_device(uint32_t device_id) { uint32_t now = get_current_timestamp_sec(), expire = now + REJECT_TIMEOUT; for(int i=0; i <g_reject_count; i++) { if(g_reject_list[i].device_id == device_id) { g_reject_list[i].expire_ts = expire; return;}} if(g_reject_count < MAX_REJECTED) { g_reject_list[g_reject_count++] = (RejectEntry){device_id, expire};} else { g_reject_list[0] = (RejectEntry){device_id, expire};}} bool is_device_rejected(uint32_t device_id) { uint32_t now = get_current_timestamp_sec();for(int i=0; i<g_reject_count; i++) { if(g_reject_list[i].device_id ==device_id) { if(now < g_reject_list[i].expire_ts) return true; / / Remove if expired g_reject_list[i] = g_reject_list[--g_reject_count]; return false;}} returnfalse;} void cleanup_reject_list(void) { uint32_t now = get_current_timestamp_sec(); int i = 0; while(i < g_reject_count) { if(now >= g_reject_list[i].expire_ts) { g_reject_list[i] = g_reject_list[--g_reject_count];}else i++;}} ```Preferred, 1. **MCU selection**: STM32F103 or ESP32 are recommended, compatible with I²C peripherals, GPIO interrupts and timers. 2. **Display**: 0.96-inch 128×64 OLED (SSD1306 driver), connected to the MCU via I²C, capable of displaying real-time countdowns and reminder information. 3. **Buttons**: Two surface-mount touch buttons, connected to MCU GPIOs, with software debounce. 4. **BLE Module**: Integrated in the MCU (ESP32) or external submodule (nRF52840), supports AES-128 hardware acceleration. 5. **Flash Storage**: SPI NOR Flash with a capacity of ≥ 4MB, divided into a key area (0x0000–0x0FFF), a log area (0x1000–0x1FFF), and an optional deny list area. 6. **System Clock**: An internal timer provides a second-level clock with an accuracy of ±1s. 7. **OLED Interaction Logic**: - "Waiting for pairing, please insert the target module" - "Connection from: A456, please confirm within 10 seconds" - "Copying to: B123, please confirm within 10 seconds" - "Identity confirmation passed, copying... XX%" - "Copy successful" - "Device B123 temporarily rejected, please try again in 30 seconds." Application scenario description 1. **Key distribution for military or government offline devices**: In an offline environment, ensure that only designated targets can obtain keys after manual confirmation. 2. **Vehicle smart key or in-vehicle authorization system**: Vehicle owners use this module to authorize temporary vehicle rental users, preventing malicious devices from re-connecting. 3. **Security access control and door lock devices**: Administrators dynamically update access rights, combining identity display and deny list mechanisms to prevent the misissue of keys. 4. **Portable devices such as medical devices and law enforcement recorders**: Ensure that key distribution in on-site or remote environments is legal and compliant. 5. **Internal offline LAN key synchronization within the enterprise**: Implement secure and auditable offline key distribution in an isolated network environment to ensure the needs of confidential units.
[0013] Note: - The aforementioned MCU models, OLED drivers, BLE submodules, and Flash memory capacities are examples only and can be replaced with functionally equivalent devices without affecting the scope of this invention. - The values for the reject list duration (30 seconds), list capacity (8 entries), and countdown (10 seconds) can be adjusted based on actual needs.
[0014] To further enhance on-site verification efficiency and security, manufacturers are recommended to print a unique device ID (device_id) on the product casing. Before copying, users can compare the casing ID with the on-screen ID by following these steps: 1. After pairing is triggered, the Super Module and target module screens display each other's device_id (e.g., "A456" and "B123"). 2. The user checks the target module's casing ID plate to confirm whether it matches the target device_id displayed on the screen. Simultaneously, the target module user checks the Super Module casing ID to confirm whether it matches the on-screen ID. 3. Only if the casing ID matches the on-screen ID, the user presses the "Confirm" button to proceed with key copying. If not, the user presses the "Cancel" button to trigger the device rejection list and temporarily reject the device (30 seconds). 4. It is recommended that the casing ID be laser engraved or printed with a durable, abrasion-resistant print. A QR code or barcode can be added for easy scanning and verification. During production, ensure that the ID written in the firmware matches the casing ID plate to prevent misplacement or tampering. This added functionality allows users to more intuitively perform on-site verification, reducing the likelihood of misoperation and enhancing overall security. This invention aims to provide a Bluetooth key distribution module with the following features: - Bidirectional identity visualization: Before key duplication, the display screens of both modules display the other party's device_ID or pre-indicated device ID, allowing users to visually confirm the key. - Two-button manual confirmation: The user must press the "Confirm" button before encrypted transmission begins; pressing the "Cancel" button immediately terminates the process. - Short-term device rejection list: When the user presses the "Cancel" button or the connection times out without confirmation, the corresponding device_ID is added to the rejection list. Any subsequent connection attempts from this device within the next 30 seconds will be rejected with the message "Device [ID] temporarily rejected. Try again in 30 seconds." - Simple and easy to implement: This can be accomplished using a general-purpose MCU, an OLED display, two GPIO buttons, and a small array, eliminating the need for complex hardware resources. (Note: "Small array" here refers to the memory structure used to store a simple set of data, such as the "rejected device ID and its expiration timestamp," within the MCU. Specifically, this array typically contains two fields: device_id (32-bit integer, or defined according to the ID length you actually use, such as a 16-byte MAC or a 4-byte custom number) expire_ts (32-bit integer, indicating the expiration time when the device_id is rejected, in seconds) ).
[0015] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art will be able to modify the technical solutions described in the aforementioned embodiments or substitute equivalents for some of the technical features. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A Bluetooth key distribution module with identity display and manual confirmation mechanism and device rejection list function, characterized in that: Including MCU main control chip, BLE Bluetooth communication module, Flash storage chip, display module, and physical button module; The MCU main control chip is used to control the BLE Bluetooth communication module, monitor key input, update the display content, manage the rejection list, perform encrypted transmission and log recording; The BLE Bluetooth communication module is used to support BLE 5.0 and above protocols and is responsible for scanning, broadcasting, pairing and GATT services; The Flash storage chip is used to store the encrypted key structure, the local device_id and the temporary rejection list, and the operation log; The display screen module is used to display pairing information and user prompts in real time; The physical button module includes a confirmation button and a cancel button. The confirmation button is connected to the GPIO input terminal of the MCU and is used for the user to confirm the copy; The cancel button is connected to the GPIO input of the MCU and is used for user rejection and triggering the device's short-term rejection mechanism.
2. A Bluetooth key distribution module with identity display and manual confirmation mechanism and device rejection list function according to claim 1, characterized in that: The key structure includes source_id, shared_key, and CRC check code.
3. A Bluetooth key distribution module with identity display and manual confirmation mechanism and device rejection list function according to claim 1, characterized in that: It also includes a status light module, which is used to indicate the module status.
4. A Bluetooth key distribution module with identity display and manual confirmation mechanism and device rejection list function according to claim 1, characterized in that: A LOCK hardware toggle switch is also included. The LOCK hardware toggle switch is used to manually enable or disable Flash write permission.