Intelligent lock offline unlocking method, lock and electronic key

By introducing task constraints, fingerprint entry and SIM card detection into the smart lock system, and combining asymmetric encryption and symmetric encryption, the usage limitations of smart locks in network-free environments are solved, safe and reliable offline unlocking is achieved, and the security and applicability of the locks are improved.

CN120636022APending Publication Date: 2025-09-12SHENZHEN BRANCH OF BANK OF COMM CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510780177.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-12
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

Existing smart locks are difficult to use in an environment without a network, which limits their application in areas where network equipment cannot be installed.

Method used

An intelligent lock system based on task constraints, fingerprint pre-entry storage, and SIM card detection is adopted, combining asymmetric encryption and symmetric encryption to achieve safe and reliable unlocking in an offline environment. Through reasonable hardware design, key management and power management, the security and flexibility of unlocking in offline state are ensured.

Benefits of technology

It realizes safe and reliable unlocking of smart locks in a network-free environment, improves the safety and applicability of locks, adapts to various complex usage scenarios, and meets multiple application needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120636022A_ABST
    Figure CN120636022A_ABST
Patent Text Reader

Abstract

The invention discloses an intelligent lock offline unlocking method, a lock and an electronic key in the technical field of intelligent locks.The intelligent lock offline unlocking method comprises the steps that the electronic key obtains offline unlocking constraint conditions in a network connection state in advance and registers with the lock to generate a first secret key and a second secret key, the constraint conditions comprise a first constraint condition and a second constraint condition; after registration of the electronic key is completed, fingerprint information used for unlocking is collected and stored, the first secret key is a master secret key, and the second secret key is a working secret key. The offline unlocking scheme is set through the intelligent lock system based on task constraint, fingerprint advanced input and storage, SIM card detection and operation in the network-free state, the safety and applicability of the lock can be effectively improved, the use requirements of different scenes are met, safe and reliable unlocking of the passive lock in the network-free environment is achieved, and the safety of the passive lock is improved. The safety and the flexibility of the lock of an enterprise are obviously improved, and the lock is suitable for various complex use scenes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of smart locks, and in particular to an offline unlocking method for a smart lock, a lock, and an electronic key. Background Art

[0002] Smart keys and locks are widely used in cash boxes, vaults, safes, equipment cabinets, security doors, and other scenarios requiring high security and flexibility. However, these locks typically rely on network communication, making them difficult to use offline. This significantly limits their use in areas without a network connection and where network equipment cannot be installed. Summary of the Invention

[0003] The purpose of the present invention is to provide an offline unlocking method for smart locks, locks and electronic keys. By setting up an offline unlocking scheme for a smart lock system based on task constraints, fingerprint pre-entry storage, SIM card detection, and operation in a network-free state, the security and applicability of the lock can be effectively improved to meet the usage requirements of different scenarios. By combining asymmetric encryption and symmetric encryption, safe and reliable unlocking of passive locks in a network-free environment is achieved. Through reasonable hardware design, key management, communication mechanism and power management, the efficiency, reliability and scalability of the scheme are ensured, which can significantly improve the security and flexibility of enterprise locks, adapt to various complex usage scenarios, and meet the needs of multiple application scenarios.

[0004] To achieve the above object, the present invention provides the following technical solutions:

[0005] In a first aspect, a method for unlocking a smart lock offline is provided, comprising:

[0006] The electronic key obtains offline unlocking constraint conditions in advance in a network connected state, and registers with the lock to generate a first key and a second key, wherein the constraint conditions include the first constraint condition and the second constraint condition;

[0007] After the electronic key is registered, fingerprint information for unlocking is collected and stored, wherein the first key is a master key and the second key is a working key;

[0008] When the display screen of the electronic key displays "network disconnected", a detection module built into the electronic key collects the IMSI number of the SIM card inserted into the electronic key and performs a first check on whether the insertion status of the SIM card is normal, wherein the detection module is a card tray adapted to the SIM card;

[0009] When the first verification is successful, the electronic key performs a second verification to determine whether the first constraint condition is satisfied. When the second verification is successful, the electronic key performs a third verification to determine whether the second constraint condition is satisfied.

[0010] After the third verification is successful, the electronic key is inserted into the lock and rotated to unlock it. During this process, physical contact conducts electricity to the lock, unlocking it. This electricity is used to receive commands from the electronic key and unlock the lock. The master key is protected using asymmetric encryption technology, and the working key is encrypted and protected using the master key, ultimately ensuring the security of key transmission.

[0011] As a further solution of the present invention, the first constraint condition includes the collection and storage of fingerprint information, the correct insertion of the SIM card into the electronic key, and the absence of a network connection. The second constraint condition includes the target person information and the target unlocking time. The target unlocking time is the duration of the offline unlocking process. If the offline unlocking time exceeds the preset time range, the unlocking will fail due to a timeout.

[0012] As a further solution of the present invention, the electronic key obtains offline unlocking constraint conditions in advance in a network connected state, including:

[0013] Electronic key detection network status;

[0014] When the network is connected, the electronic key connects to the backend system and periodically retrieves offline unlocking constraints from the backend system every 20 to 30 minutes. The most recently retrieved offline unlocking constraints are used as the latest offline unlocking constraints. Upon power-on or at a scheduled interval of 20 to 30 minutes, the electronic key automatically stores unlocking time, lock, unlocker, and other information on the device. This information can also be manually updated on the key. Data transmitted is encrypted using a working key to ensure security. A timer is configured on the electronic key to periodically retrieve the backend system time for synchronization.

[0015] As a further solution of the present invention, the electronic key obtains offline unlocking constraint conditions in advance in a network connected state, including:

[0016] The electronic key collects and saves the latest offline unlocking constraint inputted from the unlocking menu on the display screen every 20 to 30 minutes, and uses the most recently acquired offline unlocking constraint as the latest offline unlocking constraint.

[0017] As a further solution of the present invention, the method of using the most recently acquired offline unlocking constraint as the latest offline unlocking constraint includes:

[0018] When the latest offline unlocking constraint obtained by the electronic key is inconsistent with the saved offline unlocking constraint, the electronic key deletes the saved offline unlocking constraint and saves the latest offline unlocking constraint as the current offline unlocking constraint.

[0019] As a further solution of the present invention: the collecting and storing of fingerprint information for unlocking includes:

[0020] The electronic key receives the personnel number data and fingerprint information, and sends the received personnel number data and fingerprint information to the background system;

[0021] When the electronic key receives the fingerprint information again, the electronic key sends a verification request to the background system to check whether the personnel number and the fingerprint information match;

[0022] When the electronic key receives the verification pass information, the electronic key encrypts and stores the verified person number and fingerprint information.

[0023] As a further solution of the present invention, the electronic key performs a second verification to determine whether the first constraint condition is satisfied. When the second verification is successful, the electronic key performs a third verification to determine whether the second constraint condition is satisfied, including:

[0024] When the electronic key receives information indicating that the offline unlocking time does not exceed the offline unlocking time preset in the first constraint, complete fingerprint information, the SIM card is correctly inserted into the electronic key, and there is no network status, it is determined that the first constraint is met and the second verification is successful;

[0025] When the electronic key collects the target unlocking person information and the target unlocking time, it is determined that the second constraint condition is met and the third verification is successful.

[0026] As a further solution of the present invention, the electronic key obtains offline unlocking constraint conditions in advance in a network-connected state, and registers with the lock to generate a first key and a second key, including:

[0027] (1) Use the private key to sign the public key of the digital key and store the signature in the electronic key, which generates a random number;

[0028] (2) The electronic key sends the signature and random number to the backend system, which verifies the signature using the public key.

[0029] (3) After the signature verification is passed, the public key is used to encrypt the first key generated by the background system to obtain an encrypted value. The background uses a random number to splice the encrypted value, and then uses the private key of the background system to sign it to obtain a signature value. The background system is used to save the first key verification value;

[0030] (4) The backend system returns the random number, the first key ciphertext, the signature value, the Bank of Communications public key, and the signature of the private key on the public key;

[0031] (5) The key verifies whether the random number returned in step (4) is consistent with the random number saved in step (1). If they are consistent, the public key is used to verify the signature of the public key;

[0032] (6) After the signature is verified, the public key is used to verify the random number and the first key ciphertext signature value;

[0033] (7) When the signature verification is successful, the first key ciphertext is decrypted using the private key of the electronic key to obtain the plaintext, which is then stored in the electronic key;

[0034] (8) The electronic key returns the check value calculated by the first key to the background system. The background system compares the check value calculated by the obtained first key with the check value of the first key saved in step (3) to see if they are consistent. If they are consistent, the download of the first key is completed and the first key is obtained;

[0035] (9) Using the backend system to encrypt the second key using the first key and transmit it to the key terminal, temporarily saving the second key check value;

[0036] (10) The electronic key uses the first key to decrypt the second key plaintext, uses the second key to calculate the check value, and returns it to the background system;

[0037] (11) The backend system compares the obtained verification value with the temporarily saved second key verification value to see if they are consistent. If they are consistent, the download of the second key is completed.

[0038] In a second aspect, an electronic key is provided, comprising a constraint condition acquisition module, a fingerprint information acquisition module, an IMSI number acquisition module, a constraint condition judgment module, and a power conduction module;

[0039] The constraint condition acquisition module is configured to acquire the constraint conditions for offline unlocking in a network connected state, and register with the lock to generate a first key and a second key, wherein the constraint conditions include the first constraint condition and the second constraint condition;

[0040] The fingerprint information collection module is configured to collect and store fingerprint information for unlocking after the electronic key is registered, wherein the first key is a master key and the second key is a working key;

[0041] The IMSI number acquisition module is configured to, when the display screen of the electronic key displays "network disconnected," cause the detection module built into the electronic key to acquire the IMSI number of the SIM card inserted into the electronic key and perform a first check on whether the insertion status of the SIM card is normal, wherein the detection module is a card tray adapted to the SIM card;

[0042] The constraint condition judgment module is configured to, when the first verification is successful, perform a second verification on the electronic key to determine whether the first constraint condition is satisfied, and when the second verification is successful, perform a third verification on the electronic key to determine whether the second constraint condition is satisfied;

[0043] The power conduction module is configured such that when the third verification succeeds, the electronic key is inserted into the lock and rotated to unlock it. During the process of rotating to unlock, the power conduction module provides power to the lock through physical contact conduction to open the lock, wherein the power is used to receive instructions from the electronic key and unlock the lock.

[0044] In a third aspect, a lock is provided, comprising the electronic key as described in the above solution, and the lock is a passive lock.

[0045] Compared with the prior art, the present invention has the following beneficial effects:

[0046] 1. In the present invention, by satisfying the conditions of designated unlocking person, unlocking time, completion of fingerprint entry and storage, normal insertion of SIM card, and no network status in offline state without network, the updated constraint conditions can be automatically obtained every half hour when there is network, or the offline unlocking task can be manually updated through the menu of the electronic key, thereby improving the convenience and flexibility of use.

[0047] 2. In the present invention, by pre-recording the unlocking person's fingerprint information in the presence of a network and storing it on the key end for a long time, and by satisfying the insertion state of the SIM card and the absence of a network, the offline unlocking operation can be performed by turning the electronic key, which not only improves the convenience of offline unlocking of the smart lock, but also ensures the safety of unlocking.

[0048] 3. In the present invention, an offline unlocking scheme is set up by the smart lock system based on task constraints, fingerprint pre-entry storage, SIM card detection, and operation in a network-free state, which can effectively improve the security and applicability of the lock and meet the usage requirements of different scenarios. By combining asymmetric encryption and symmetric encryption, safe and reliable unlocking of passive locks in a network-free environment is achieved. Through reasonable hardware design, key management, communication mechanism and power management, the efficiency, reliability and scalability of the scheme are ensured, which can significantly improve the security and flexibility of enterprise locks, adapt to various complex usage scenarios, and meet the needs of multiple application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 A diagram showing the steps of the method of the present invention;

[0050] Figure 2 FIG. 4 is a module structure diagram of the electronic key of the present invention.

[0051] In the figure: 1. Constraint acquisition module; 2. Fingerprint information collection module; 3. IMSI number collection module; 4. Constraint judgment module; 5. Power conduction module. DETAILED DESCRIPTION

[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0053] Example:

[0054] See also Figure 1 In an embodiment of the present invention, a method for unlocking a smart lock offline is provided, comprising the following steps:

[0055] S1: The electronic key obtains offline unlocking constraint conditions in advance while connected to the network, and registers with the lock to generate a first key and a second key, wherein the constraint conditions include the first constraint condition and the second constraint condition;

[0056] S2: After the electronic key is registered, fingerprint information for unlocking is collected and stored, where the first key is the master key and the second key is the working key;

[0057] S3: When the display screen of the electronic key indicates that the network is disconnected, a detection module built into the electronic key collects the IMSI number of the SIM card inserted into the electronic key and performs a first check on whether the SIM card is properly inserted. The detection module is a card tray adapted for the SIM card.

[0058] S4: When the first verification is successful, the electronic key performs a second verification to determine whether the first constraint condition is satisfied. When the second verification is successful, the electronic key performs a third verification to determine whether the second constraint condition is satisfied.

[0059] S5: After the third verification is successful, the electronic key is inserted into the lock and turned to unlock it. During this process, power is supplied to the lock through physical contact, allowing it to open. This power is used to receive the electronic key's instructions and unlock the lock. The master key is protected using asymmetric encryption technology, and the working key is encrypted and protected using the master key, ultimately ensuring the security of key transmission.

[0060] Preferably, after the unlocking is successful in step S5, the communication between the electronic key and the lock is disconnected, and the electronic key returns to the offline state. At this time, the storage module of the electronic key records the time, place and imsi number of the SIM card of the unlocking to form an unlocking record for subsequent query and audit. If the electronic key attempts to unlock in the offline state but fails to pass any verification, the electronic key will be locked for a period of time and will be prohibited from trying to unlock again to prevent malicious cracking and enhance security. After the electronic key is reconnected to the network, the electronic key will automatically upload the unlocking record to the cloud server. The cloud server analyzes the unlocking record to determine whether there is abnormal unlocking behavior. If so, a security warning will be sent to the user to remind the user to pay attention to the security of the lock. In addition, the user can remotely view the unlocking record of the electronic key through the mobile phone APP to understand the usage of the lock. At the same time, the user can also remotely update the firmware of the electronic key through the APP to repair possible security vulnerabilities and improve the security of the lock.

[0061] Example 1:

[0062] Preferably, the first constraint condition includes the collection and storage of fingerprint information, the correct insertion of the SIM card into the electronic key, and an offline state. The second constraint condition includes target person information and a target unlocking timeout. The target unlocking timeout is the duration of the offline unlocking process. If the offline unlocking timeout exceeds a preset timeout range, the unlocking will fail due to a timeout. During the offline unlocking process, the smart lock first checks whether the first constraint condition is met: whether the fingerprint information is correctly collected and stored, whether the SIM card is correctly inserted into the electronic key, and whether the electronic key is offline. Only when all these conditions are met will the smart lock proceed to check the second constraint condition. The second constraint condition includes target person information and a target unlocking timeout. The target person information is used to verify whether the unlocking request is from a legitimate user, while the target unlocking timeout is used to limit the duration of the offline unlocking process. If the offline unlocking timeout exceeds the preset timeout range, the smart lock will automatically determine that the timeout has expired and the unlocking will fail. This ensures the security and reliability of the offline unlocking process and prevents unauthorized users from exploiting the offline state to maliciously unlock the lock.

[0063] Preferably, the electronic key obtains offline unlocking constraint conditions in advance when connected to the network, including:

[0064] Electronic key detection network status;

[0065] When the network is connected, the electronic key connects to the backend system and periodically retrieves offline unlocking constraints from the backend system every 20 to 30 minutes. The most recently retrieved offline unlocking constraints are used as the latest offline unlocking constraints. When the electronic key is powered on or every 20 to 30 minutes, it automatically stores unlocking time, lock, unlocker, and other information on the device. During transmission, the data is encrypted using the working key to ensure security. A timer is configured on the electronic key to synchronize the time with the backend system.

[0066] Preferably, if the network status is disconnected, the electronic key will maintain the offline unlocking constraints obtained last time until the network connection is re-established and new offline unlocking constraints are successfully obtained. In addition, the electronic key also has a power-off protection mechanism. When the electronic key is low on battery or the power is accidentally cut off, the stored offline unlocking constraints and related information will not be lost, ensuring that it can continue to be used the next time it is turned on. When the smart lock receives an offline unlocking request sent by the electronic key, it will first verify the legitimacy of the electronic key, including verifying the electronic key's identity information and whether it has offline unlocking permission. Only if the verification is successful will the smart lock further perform the unlocking operation according to the offline unlocking constraints provided by the electronic key.

[0067] Preferably, the most recently acquired offline unlocking constraint is used as the latest offline unlocking constraint, including:

[0068] If the latest offline unlocking constraints obtained by the electronic key are inconsistent with the saved offline unlocking constraints, the electronic key deletes the saved offline unlocking constraints and saves the latest offline unlocking constraints as the current offline unlocking constraints. The electronic key also records the timestamp of this update operation for easier management. If the electronic key attempts to unlock the door offline multiple times but fails after a certain number of attempts, it will automatically lock, prohibiting further offline unlocking attempts until the door is reconnected and unlocked by an administrator. This ensures the flexibility of offline unlocking while enhancing system security and preventing unauthorized unlocking.

[0069] Preferably, collecting and storing fingerprint information for unlocking includes:

[0070] The electronic key receives the personnel number data and fingerprint information, and sends the received personnel number data and fingerprint information to the background system;

[0071] When the electronic key receives the fingerprint information again, it sends a verification request to the backend system to check whether the personnel number and the fingerprint information match;

[0072] When the electronic key receives verification information, it encrypts and stores the verified person's ID and fingerprint information. If it receives verification failure information, it refuses to store the fingerprint information and prompts the user to re-enter it. In addition, the electronic key has a self-updating function for fingerprint information. If the recognition rate of the stored fingerprint information decreases due to wear and tear, the electronic key automatically prompts the user to re-enter the fingerprint information, ensuring high accuracy during offline unlocking. During the fingerprint storage process, the electronic key uses advanced encryption algorithms to ensure the security of fingerprint information and prevent illegal access or tampering, further enhancing system security.

[0073] Preferably, the electronic key performs a second verification to determine whether the first constraint condition is satisfied. When the second verification is successful, the electronic key performs a third verification to determine whether the second constraint condition is satisfied, including:

[0074] When the electronic key receives information indicating that the offline unlocking time does not exceed the offline unlocking time preset in the first constraint, complete fingerprint information, the SIM card is correctly inserted into the electronic key, and there is no network status, it is determined that the first constraint is met and the second verification is successful;

[0075] When the electronic key collects the target unlocking person's information and target unlocking duration, it determines that the second constraint is satisfied and the third verification is successful. The target unlocking person's information includes the person's ID and fingerprint information. If the second or third verification fails, the electronic key refuses to perform the offline unlocking operation and prompts the user to review the relevant information or try again. This dual verification mechanism ensures the security and accuracy of offline unlocking operations and effectively prevents unauthorized unlocking attempts. The electronic key also records detailed information about each offline unlocking operation, including unlocking time and unlocking person information, for backend system traceability and auditing, further enhancing system security and traceability.

[0076] Preferably, the electronic key obtains offline unlocking constraint conditions in advance in a network connected state, and registers with the lock to generate a first key and a second key, including:

[0077] (1) Use the private key SK_Vnd to sign the digital key public key Sig(SK_Vnd)[PK_Key] and store the signature in the electronic key. The electronic key generates a random number R_Key;

[0078] (2) The electronic key sends the signature and random number to the back-end system of the Bank of Communications. The back-end system of the Bank of Communications uses the manufacturer's public key PK_Vnd to verify the signature Sig(SK_Vnd)[PK_Key];

[0079] (3) After the signature verification is passed, the public key PK_Key is used to encrypt the first key MK generated by the Bank of Communications backend system, and the encryption value Crypt(PK_Key)[MK] is obtained. The backend uses the random number R_Key to splice the encrypted value, and then uses the private key SK_Bank of the Bank of Communications backend system to sign it to obtain the signature value Sig(SK_Bank)[R_Key+Crypt(PK_Key)[MK]], and the backend system is used to save the first key check value checkValue1;

[0080] (4) The backend system returns the random number R_Key, the first key ciphertext Crypt(PK_Key)[MK], the signature value Sig(SK_Bank)[R_Key+Crypt(PK_Key)[MK]], the Bank of Communications public key PK_Bank, and the signature of the manufacturer's private key on the Bank of Communications public key Sig(SK_Vnd)[PK_Bank];

[0081] (5) Key verification: Check whether the random number R_Key returned in step (4) is consistent with the random number R_Key saved in step (1). If they are consistent, use the manufacturer's public key PK_Vnd to verify the signature Sig(SK_Vnd)[PK_Bank] of the bank's public key;

[0082] (6) After the signature is verified, the random number and the first key ciphertext signature value Sig(SK_Bank)[R_Key+Crypt(PK_Key)[MK]] are verified using the Bank of Communications public key PK_Bank;

[0083] (7) When the signature verification is successful, the first key ciphertext Crypt(PK_Key)[MK] is decrypted using the electronic key's private key SK_Key to obtain the plaintext, which is then stored in the electronic key.

[0084] (8) The electronic key returns the check value checkValue2 calculated by the first key to the background system. The background system compares the check value checkValue2 calculated by the obtained first key with the check value checkValue1 of the first key saved in step (3) to see if they are consistent. If they are consistent, the download of the first key is completed and the first key is obtained;

[0085] (9) Using the Bank of Communications backend system to encrypt the second key with the first key and transmit it to the key terminal, temporarily saving the second key check value checkValue1;

[0086] (10) The electronic key uses the first key to decrypt the second key plaintext, uses the second key to calculate the check value checkValue2, and returns it to the Bank of Communications backend system;

[0087] (11) The Bank of Communications backend system compares the obtained check value checkValue2 with the temporarily saved second key check value checkValue1 to see if they are consistent. If they are consistent, the download of the second key is completed.

[0088] Example 2:

[0089] Preferably, the first constraint condition includes the collection and storage of fingerprint information, the correct insertion of the SIM card into the electronic key, and the absence of a network connection. The second constraint condition includes the target person information and the target unlocking time. The target unlocking time is the duration of the offline unlocking process. If the offline unlocking time exceeds the preset time range, the unlocking will fail due to a timeout.

[0090] Preferably, the electronic key obtains offline unlocking constraint conditions in advance when connected to the network, including:

[0091] The electronic key collects and saves the latest offline unlocking constraints entered in the unlocking menu on the display screen every 20 to 30 minutes, and uses the most recently acquired offline unlocking constraints as the latest offline unlocking constraints.

[0092] Preferably, the most recently acquired offline unlocking constraint is used as the latest offline unlocking constraint, including:

[0093] When the latest offline unlocking constraint obtained by the electronic key is inconsistent with the saved offline unlocking constraint, the electronic key deletes the saved offline unlocking constraint and saves the latest offline unlocking constraint as the current offline unlocking constraint.

[0094] Preferably, collecting and storing fingerprint information for unlocking includes:

[0095] The electronic key receives the personnel number data and fingerprint information, and sends the received personnel number data and fingerprint information to the background system;

[0096] When the electronic key receives the fingerprint information again, it sends a verification request to the backend system to check whether the personnel number and the fingerprint information match;

[0097] When the electronic key receives the verification information, it encrypts and stores the verified person number and fingerprint information.

[0098] Preferably, the electronic key performs a second verification to determine whether the first constraint condition is satisfied. When the second verification is successful, the electronic key performs a third verification to determine whether the second constraint condition is satisfied, including:

[0099] When the electronic key receives information indicating that the offline unlocking time does not exceed the offline unlocking time preset in the first constraint, complete fingerprint information, the SIM card is correctly inserted into the electronic key, and there is no network status, it is determined that the first constraint is met and the second verification is successful;

[0100] When the electronic key collects the target unlocking person information and the target unlocking time, it is determined that the second constraint condition is met and the third verification is successful.

[0101] Preferably, the electronic key obtains offline unlocking constraint conditions in advance in a network connected state, and registers with the lock to generate a first key and a second key, including:

[0102] (1) Use the private key SK_Vnd to sign the digital key public key Sig(SK_Vnd)[PK_Key] and store the signature in the electronic key. The electronic key generates a random number R_Key;

[0103] (2) The electronic key sends the signature and random number to the back-end system of the Bank of Communications. The back-end system of the Bank of Communications uses the manufacturer's public key PK_Vnd to verify the signature Sig(SK_Vnd)[PK_Key];

[0104] (3) After the signature verification is passed, the public key PK_Key is used to encrypt the first key MK generated by the Bank of Communications backend system, and the encryption value Crypt(PK_Key)[MK] is obtained. The backend uses the random number R_Key to splice the encrypted value, and then uses the private key SK_Bank of the Bank of Communications backend system to sign it to obtain the signature value Sig(SK_Bank)[R_Key+Crypt(PK_Key)[MK]], and the backend system is used to save the first key check value checkValue1;

[0105] (4) The backend system returns the random number R_Key, the first key ciphertext Crypt(PK_Key)[MK], the signature value Sig(SK_Bank)[R_Key+Crypt(PK_Key)[MK]], the Bank of Communications public key PK_Bank, and the signature of the manufacturer's private key on the Bank of Communications public key Sig(SK_Vnd)[PK_Bank];

[0106] (5) Key verification: Check whether the random number R_Key returned in step (4) is consistent with the random number R_Key saved in step (1). If they are consistent, use the manufacturer's public key PK_Vnd to verify the signature Sig(SK_Vnd)[PK_Bank] of the bank's public key;

[0107] (6) After the signature is verified, the random number and the first key ciphertext signature value Sig(SK_Bank)[R_Key+Crypt(PK_Key)[MK]] are verified using the Bank of Communications public key PK_Bank;

[0108] (7) When the signature verification is successful, the first key ciphertext Crypt(PK_Key)[MK] is decrypted using the electronic key's private key SK_Key to obtain the plaintext, which is then stored in the electronic key.

[0109] (8) The electronic key returns the check value checkValue2 calculated by the first key to the background system. The background system compares the check value checkValue2 calculated by the obtained first key with the check value checkValue1 of the first key saved in step (3) to see if they are consistent. If they are consistent, the download of the first key is completed and the first key is obtained;

[0110] (9) Using the Bank of Communications backend system to encrypt the working key using the first key and transmit it to the key terminal, temporarily saving the working key check value checkValue1;

[0111] (10) The electronic key uses the first key to decrypt the working key plaintext, uses the working key to calculate the check value checkValue2, and returns it to the Bank of Communications backend system;

[0112] (11) The Bank of Communications backend system compares the obtained check value checkValue2 with the temporarily saved working key check value checkValue1 to see if they are consistent. If they are consistent, the download of the working key is completed.

[0113] like Figure 2 As shown, this embodiment also provides an electronic key, which includes a constraint condition acquisition module 1, a fingerprint information acquisition module 2, an IMSI number acquisition module 3, a constraint condition judgment module 4 and a power conduction module 5;

[0114] The constraint condition acquisition module 1 is configured to obtain the constraint conditions for offline unlocking in a network connected state, and register with the lock to generate a first key and a second key, wherein the constraint conditions include the first constraint condition and the second constraint condition;

[0115] The fingerprint information collection module 2 is configured to collect and store fingerprint information for unlocking after the electronic key is registered, wherein the first key is a master key and the second key is a working key;

[0116] The IMSI number acquisition module 3 is configured to, when the display screen of the electronic key displays "network disconnected", cause the detection module built into the electronic key to acquire the IMSI number of the SIM card inserted into the electronic key and perform a first check on whether the insertion status of the SIM card is normal, wherein the detection module is a card tray adapted to the SIM card;

[0117] The constraint condition determination module 4 is configured to, when the first verification is successful, perform a second verification on the electronic key to determine whether the first constraint condition is satisfied, and when the second verification is successful, perform a third verification on the electronic key to determine whether the second constraint condition is satisfied;

[0118] The power conduction module 5 is configured to provide power to the lock through physical contact conduction during the process of turning to unlock the lock when the electronic key is inserted into the lock and turned to unlock after the third verification is successful, wherein the power is used to receive instructions from the electronic key and unlock the lock.

[0119] This embodiment also provides a lockset, comprising an electronic key as described above. The lockset is a passive lock, which is a lockset without its own power source. The lockset also includes a lock cylinder, a lock tongue, a transmission mechanism, and a lock housing. The lock cylinder is compatible with the electronic key, the lock tongue is connected to the transmission mechanism, and the transmission mechanism is used to drive the lock tongue in response to rotation of the electronic key. The lock housing is used to house the lock cylinder, lock tongue, and transmission mechanism. Once the electronic key successfully passes all verifications and meets the constraints, the electronic key can be inserted into the lock cylinder and rotated, which in turn drives the lock tongue through the transmission mechanism, thereby unlocking the lockset. Because the lockset is passive (i.e., it lacks its own power source), the electronic key needs to provide power to the lockset through physical contact during the unlocking process to ensure that the lockset can properly receive the electronic key's instructions and complete the unlocking action. This intelligent offline unlocking method not only improves the security and convenience of unlocking but also avoids the problems of unlocking failures caused by power supply issues in traditional locks.

[0120] The above description is only a preferred specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field, within the technical scope disclosed by the present invention, who makes equivalent replacements or changes based on the technical solution and inventive concept of the present invention, should be covered by the scope of protection of the present invention.

Claims

1. A method for unlocking a smart lock offline, comprising: The electronic key obtains offline unlocking constraint conditions in advance in a network connected state, and registers with the lock to generate a first key and a second key, wherein the constraint conditions include the first constraint condition and the second constraint condition; After the electronic key is registered, fingerprint information for unlocking is collected and stored, wherein the first key is a master key and the second key is a working key; When the display screen of the electronic key displays "network disconnected", a detection module built into the electronic key collects the IMSI number of the SIM card inserted into the electronic key and performs a first check on whether the insertion status of the SIM card is normal, wherein the detection module is a card tray adapted to the SIM card; When the first verification is successful, the electronic key performs a second verification to determine whether the first constraint condition is satisfied. When the second verification is successful, the electronic key performs a third verification to determine whether the second constraint condition is satisfied. When the third verification is successful, the electronic key is inserted into the lock and turned to unlock it. During the process of turning to unlock, power is provided to the lock through physical contact conduction to open the lock, wherein the power is used to receive instructions from the electronic key and unlock the lock.

2. The offline unlocking method for smart locks according to claim 1, characterized in that: The first constraint condition includes collecting and saving fingerprint information, correctly inserting the SIM card into the electronic key, and no network status, and the second constraint condition includes target person information and target unlocking time.

3. The offline unlocking method for smart locks according to claim 2, characterized in that: The electronic key obtains offline unlocking constraint conditions in advance in a network connected state, including: Electronic key detection network status; When the network status is connected, the electronic key accesses the background system and periodically obtains offline unlocking constraints from the background system every 20 to 30 minutes, and uses the most recently obtained offline unlocking constraints as the latest offline unlocking constraints.

4. The offline unlocking method for smart locks according to claim 2, characterized in that: The electronic key obtains offline unlocking constraint conditions in advance in a network connected state, including: The electronic key collects and saves the latest offline unlocking constraint inputted from the unlocking menu on the display screen every 20 to 30 minutes, and uses the most recently acquired offline unlocking constraint as the latest offline unlocking constraint.

5. The offline unlocking method for smart locks according to claim 4 or 5, characterized in that: The most recently acquired offline unlocking constraint is used as the latest offline unlocking constraint, including: When the latest offline unlocking constraint obtained by the electronic key is inconsistent with the saved offline unlocking constraint, the electronic key deletes the saved offline unlocking constraint and saves the latest offline unlocking constraint as the current offline unlocking constraint.

6. The offline unlocking method for smart locks according to claim 5, characterized in that: The collecting and storing of fingerprint information for unlocking includes: The electronic key receives the personnel number data and fingerprint information, and sends the received personnel number data and fingerprint information to the background system; When the electronic key receives the fingerprint information again, the electronic key sends a verification request to the background system to check whether the personnel number and the fingerprint information match; When the electronic key receives the verification pass information, the electronic key encrypts and stores the verified person number and fingerprint information.

7. The offline unlocking method for smart locks according to claim 6, characterized in that: The electronic key performs a second verification to determine whether the first constraint condition is satisfied. When the second verification is successful, the electronic key performs a third verification to determine whether the second constraint condition is satisfied, including: When the electronic key receives information indicating that the offline unlocking time does not exceed the offline unlocking time preset in the first constraint, complete fingerprint information, the SIM card is correctly inserted into the electronic key, and there is no network status, it is determined that the first constraint is met and the second verification is successful; When the electronic key collects the target unlocking person information and the target unlocking time, it is determined that the second constraint condition is met and the third verification is successful.

8. The offline unlocking method for smart locks according to claim 7, characterized in that: The electronic key obtains offline unlocking constraint conditions in advance in a network connected state, and registers with the lock to generate a first key and a second key, including: (1) Use the private key to sign the public key of the digital key and store the signature in the electronic key, which generates a random number; (2) The electronic key sends the signature and random number to the backend system, which verifies the signature using the public key. (3) After the signature verification is passed, the first key generated by the backend system is encrypted using the public key to obtain an encrypted value. The backend uses a random number to concatenate the encrypted value, and then uses the private key of the backend system to sign it to obtain a signature value. The backend system is used to save the first key verification value; (4) The backend system returns the random number, the first key ciphertext, the signature value, the Bank of Communications public key, and the signature of the private key on the public key; (5) The key verifies whether the random number returned in step (4) is consistent with the random number saved in step (1). If they are consistent, the public key is used to verify the signature of the public key; (6) After the signature is verified, the public key is used to verify the random number and the first key ciphertext signature value; (7) When the signature verification is successful, the first key ciphertext is decrypted using the private key of the electronic key to obtain the plaintext, which is then stored in the electronic key; (8) The electronic key returns the check value calculated by the first key to the background system. The background system compares the check value calculated by the obtained first key with the check value of the first key saved in step (3) to see if they are consistent. If they are consistent, the download of the first key is completed and the first key is obtained; (9) Using the backend system to encrypt the second key using the first key and transmit it to the key terminal, temporarily saving the second key check value; (10) The electronic key uses the first key to decrypt the second key plaintext, uses the second key to calculate the check value, and returns it to the background system; (11) The backend system compares the obtained verification value with the temporarily saved second key verification value to see if they are consistent. If they are consistent, the download of the second key is completed.

9. An electronic key, characterized in that: The electronic key comprises: A constraint condition acquisition module (1), wherein the constraint condition acquisition module (1) is configured to acquire the constraint condition for offline unlocking in a network connected state, and register with the lock to generate a first key and a second key, wherein the constraint condition includes the first constraint condition and the second constraint condition; A fingerprint information collection module (2), wherein the fingerprint information collection module (2) is configured to collect and store fingerprint information for unlocking after the electronic key is registered, wherein the first key is a master key and the second key is a working key; an IMSI number acquisition module (3), wherein the IMSI number acquisition module (3) is configured to, when the display screen of the electronic key displays "network disconnected", cause a detection module built into the electronic key to acquire the IMSI number of a SIM card inserted into the electronic key and perform a first check on whether the insertion state of the SIM card is normal, wherein the detection module is a card tray adapted to the SIM card; A constraint condition judgment module (4), wherein the constraint condition judgment module (4) is configured to, when the first verification is successful, perform a second verification on the electronic key to determine whether the first constraint condition is satisfied, and when the second verification is successful, perform a third verification on the electronic key to determine whether the second constraint condition is satisfied; The power conduction module (5) is configured such that when the third verification succeeds, the electronic key is inserted into the lock and rotated to unlock it, and during the process of rotating to unlock it, power is provided to the lock through the effect of physical contact conduction to unlock the lock, wherein the power is used to receive instructions from the electronic key and unlock the lock.

10. A lock, characterized in that: The lock comprises the electronic key according to claim 9, and the lock is a passive lock.

Citation Information

Patent Citations

  • Vehicle-mounted terminal offline processing method, equipment, storage medium and device

    CN110995823A

  • Initial key downloading method, computer equipment and storage medium

    CN112446782A

  • Passive lock and unlocking / locking method

    CN113436368A

  • Key device and associated method, computer program and computer program product

    US20160379431A1