Device access control methods, apparatus, electronic devices and storage media
By employing a dual verification mechanism of dynamic key generation and key mapping sequence, the security and stability issues of after-sales data access for energy storage systems are resolved, enabling secure and reliable access control even under limited on-site conditions and unstable networks.
Patent Information
- Application Number
- CN202511163958.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-20
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2045-08-20
AI Technical Summary
Existing energy storage systems suffer from problems such as low security, reliance on specialized tools, and unstable network environments when accessing after-sales data, leading to inconvenience and system instability.
It adopts a dual authentication mechanism of dynamic key generation strategy and key mapping sequence. It generates dynamic password through device unique identifier and real-time clock, and combines physical key combination for secure access. It introduces hierarchical and incremental locking mechanism and non-volatile storage to record access logs.
It improves the security and reliability of after-sales data access for energy storage systems, avoids password leaks and network dependence, and ensures the stability of access and the security of equipment.
Smart Images

Figure CN120675816B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of device access technology, specifically relating to a device access control method, apparatus, electronic device, and storage medium. Background Technology
[0002] Energy storage systems play a vital role in renewable energy utilization and power regulation. Their after-sales data spans the entire equipment lifecycle and is of significant value for fault analysis, health assessment, operational optimization, and product improvement. However, current technologies often restrict access to after-sales data due to security, confidentiality, and technical limitations, relying primarily on fixed passwords, specialized debugging tools, software upgrades, or remote diagnostic platforms.
[0003] In the process of developing this application, the inventors discovered that the prior art has at least the following problems: unified passwords are easily leaked, and the management of different passwords is costly; reliance on professional tools is limited by on-site conditions and personnel skills; software upgrade methods are prone to system instability; remote diagnosis depends on network quality and is easily affected in remote areas. Summary of the Invention
[0004] To address the aforementioned issues, this application proposes a device access control method to improve the security and reliability of after-sales data access for energy storage systems, and to enable effective authorization and management of professional maintenance personnel.
[0005] To address the aforementioned technical problems, one technical solution adopted in this application is: providing a device access control method, the method comprising: responding to a received activation signal, generating a target verification key through a preset dynamic key generation strategy; converting the target verification key into a key mapping sequence based on a preset key conversion rule, and entering a key input listening state; in the key input listening state, receiving an input key sequence signal and an input confirmation key signal to verify whether the input key sequence signal matches the key mapping sequence and the mapping relationship table, and whether the input confirmation key signal matches the mapping relationship table; if the input key sequence signal matches the key mapping sequence and the mapping relationship table, and the input confirmation key signal matches the mapping relationship table, then accessing the hidden interface.
[0006] In some embodiments, generating a target verification key through a preset dynamic key generation strategy includes: obtaining device identification information; obtaining first clock data and performing a time window calculation on the first clock data to obtain key time validity information; wherein the key time validity information includes first standard timestamp information and week calendar information; selecting a corresponding password generation rule according to the number of physical buttons; and generating a target verification key based on the password generation rule, device identification information, first standard timestamp information, and week calendar information.
[0007] In some embodiments, based on a preset key conversion rule, the target verification key is converted into a key mapping sequence and a key input listening state is entered, including: based on the key conversion rule, performing password and key conversion operations on each number in the target verification key to obtain a key mapping sequence corresponding to the target verification key, and entering a key input listening state.
[0008] In some embodiments, the key validity information further includes permission expiration time stamp information. The method further includes: when in a key input listening state, acquiring second clock data and performing timestamp conversion on the second clock data to obtain second standard timestamp information; comparing the second standard timestamp information with the permission expiration time stamp information; if the second standard timestamp information is not greater than the permission expiration time stamp information, then determining that the target verification key is within the validity period; if the second standard timestamp information is greater than the permission expiration time stamp information, then determining that the target verification key has expired.
[0009] In some embodiments, receiving input key sequence signals and input confirmation key signals to verify whether the input key sequence signals match the key mapping sequence and mapping table, and whether the input confirmation key signals match the mapping table, includes: obtaining an input interval time; comparing the input interval time with a preset timeout threshold; if the input interval time is less than the preset timeout threshold and no input confirmation key signal is received, then continuing to receive input key sequence signals; if the input interval time is less than the preset timeout threshold and the input confirmation key signal has been received, then verifying whether the input key sequence signals match the key mapping sequence and mapping table, and whether the input confirmation key signals match the mapping table; if the input interval time is not less than the preset timeout threshold, executing a backtracking process.
[0010] In some embodiments, the method further includes: calculating the total number of input key sequence combinations and the total number of confirmation key combinations based on the number of physical keys; and generating a mapping table based on the week calendar information, the total number of input key sequence combinations, and the total number of confirmation key combinations.
[0011] In some embodiments, a mapping table is generated based on the week calendar information, the total number of input key sequence combinations, and the total number of confirmation key combinations. This includes: enumerating the total number of input key sequence combinations to obtain key sequence combinations; enumerating the total number of confirmation key combinations to obtain confirmation key combinations; and mapping the week calendar information to the key sequence combinations and confirmation key combinations respectively to generate a mapping table.
[0012] To address the aforementioned technical problems, another technical solution adopted in this application is: providing a device access control apparatus, comprising: a key generation module, used to generate a target verification key in response to a received activation signal through a preset dynamic key generation strategy; a key conversion module, used to convert the target verification key into a key mapping sequence based on preset key conversion rules, and enter a key input listening state; a key verification module, used to receive an input key sequence signal and an input confirmation key signal in the key input listening state, to verify whether the input key sequence signal matches the key mapping sequence and mapping table, and whether the input confirmation key signal matches the mapping table; and an interface access module, used to access a hidden interface if the input key sequence signal matches the key mapping sequence and mapping table, and the input confirmation key signal matches the mapping table.
[0013] To solve the above-mentioned technical problems, another technical solution adopted in the embodiments of this application is: to provide an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the above-mentioned method.
[0014] To solve the above-mentioned technical problems, another technical solution adopted in the embodiments of this application is: to provide a non-volatile computer-readable storage medium that stores computer-executable instructions, which, when executed by an electronic device, cause the electronic device to perform the above-mentioned method.
[0015] Unlike related technologies, this application provides a device access control method, apparatus, electronic device, and storage medium. By introducing a dynamic key generation strategy and a key-to-key sequence mapping mechanism, it effectively overcomes the limitations and risks of existing technologies, such as the ease of leakage of unified passwords, the high cost of managing different passwords, and reliance on professional tools and software upgrades. Specifically, the dynamic key generation strategy ensures that the key required for each access verification is different. Even if the key is intercepted during transmission or use, it cannot be reused in subsequent accesses, fundamentally improving access security. The key is converted into a key mapping sequence and combined with a mapping table for double matching verification, which not only avoids the risk of directly exposing the key but also increases the difficulty of cracking. The confirmation key signal verification in the key input listening state can prevent access to the hidden interface through brute-force attempts or accidental operations, thereby further improving the reliability of access. This method does not rely on a network environment or complex professional debugging tools, and can securely complete after-sales data access authorization under limited on-site conditions and unstable networks. It facilitates controlled access for professional maintenance personnel and ensures the stability of energy storage system operation and data confidentiality, effectively solving the problems of password security, tool dependence, and network constraints existing in the prior art. Attached Figure Description
[0016] One or more embodiments are illustrated by way of example with reference to the accompanying drawings. These illustrations do not constitute a limitation on the embodiments. Elements having the same reference numerals in the drawings are denoted as similar elements. Unless otherwise stated, the figures in the drawings are not to be limited by scale.
[0017] Figure 1 This is a flowchart of a device access control method provided in an embodiment of this application;
[0018] Figure 2 This is a schematic diagram of the structure of a device access control device provided in an embodiment of this application;
[0019] Figure 3 This is a schematic diagram of the hardware structure of an electronic device that performs a device access control method according to an embodiment of this application. Detailed Implementation
[0020] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and thoroughly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0021] It should be noted that, unless otherwise specified, the various features in the embodiments of this application can be combined with each other, all of which are within the protection scope of this application. Furthermore, although functional modules are divided in the device schematic diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device schematic diagram or the order in the flowchart.
[0022] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and are not used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and are not limited in number; for example, a first object can be one or more.
[0023] Unless otherwise defined, all technical and scientific terms used in this specification have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used in this specification is for the purpose of describing particular embodiments only and is not intended to limit the scope of this application.
[0024] As a crucial component of new energy sources and smart grids, energy storage systems directly impact the stability of the power system and the safety of user energy consumption. Energy storage devices generate a wealth of after-sales data throughout their lifecycle, including real-time operating parameters, fault logs, and historical operating records. This after-sales data not only forms the technical foundation for ensuring equipment reliability but also serves as a vital basis for manufacturers to optimize product performance and improve services. By analyzing this data, maintenance personnel can accurately pinpoint the root cause of faults, dynamically monitor the equipment's health status, and dynamically adjust operating parameters for different application scenarios, thereby improving the safety and operational efficiency of the energy storage system. Furthermore, manufacturers can leverage after-sales data to continuously optimize control algorithms and iterate software versions, enhancing the equipment's adaptability and stability.
[0025] In existing technologies, after-sales data acquisition for energy storage systems mainly relies on the following methods: first, accessing the device's hidden interface by entering a fixed password; second, using professional debugging tools to connect to the device via a communication interface to read data; third, enabling access to the hidden interface through software upgrade packages; and fourth, authorizing access to relevant data through the manufacturer's remote diagnostic platform. These methods meet data access needs to a certain extent, but they also have certain shortcomings.
[0026] First, fixed passwords pose a risk of data leakage and are complex to manage, making it difficult to guarantee access security. Second, professional debugging tools have a high learning curve, and the loss or damage of these tools can affect repair progress. Third, software upgrades may cause equipment malfunctions due to power outages or abnormal upgrade packages, increasing the difficulty of repair. Furthermore, remote access depends on the network environment; unstable networks or insufficient coverage make it difficult to guarantee the continuity and reliability of access. More importantly, after-sales data contains core equipment parameters and proprietary algorithms; disclosing this data to ordinary users could lead to misoperation or the leakage of core technologies.
[0027] To address the aforementioned issues, this application proposes a device access control method based on a unique device identifier and a real-time clock. By combining complex operation sequences of physical buttons, secure access to hidden device functions is achieved. Specifically, the unique device serial number and a real-time generated timestamp are used for encrypted calculation to dynamically generate an access password, ensuring the uniqueness and timeliness of the access credentials. A dual physical interaction verification mechanism is formed by mapping multiple button combinations to weekday-specific button sequences and a confirmation button, enhancing access security. A hierarchical, incremental locking mechanism is introduced, significantly increasing the difficulty of brute-force attacks. Simultaneously, non-volatile storage is used to record access logs, enabling tamper-proof auditing of access behavior. This solution fully utilizes existing device hardware resources, requiring no additional hardware investment, and achieves secure, efficient, and reliable hidden interface access control.
[0028] In addition, the hardware and data foundation of the device access control method provided in this application includes, but is not limited to: 1) SN code storage: The unique SN code is burned into the MCU's non-volatile storage (such as Flash) when the device leaves the factory, containing information such as device type, production batch, and unique identification code. 2) RTC module: It has an RTC module, providing time data at the year, month, day, hour, minute, and second level, and supports power-off retention (powered by a backup battery). 3) Button input: The device has two or more physical buttons: such as the system POWER button, AC output button, and DC output button typically found in energy storage systems. Or reliable touch buttons / touch screens in specific areas: The display screen is equipped with directional keys (up / down / left / right), function keys (menu / confirm / return), and numeric keys (0-9). The MCU scans the button status in real time.
[0029] The device access control method provided in this application will be described in detail below with reference to specific embodiments.
[0030] Please see Figure 1 , Figure 1 This is a flowchart of a device access control method provided in an embodiment of this application. Figure 1 As shown, the method includes steps S11-S14:
[0031] S11: In response to the received activation signal, generate the target verification key through a preset dynamic key generation strategy.
[0032] The process of generating a target verification key using a preset dynamic key generation strategy includes: obtaining device identification information; obtaining first clock data and performing a time window calculation on the first clock data to obtain key time validity information; wherein the key time validity information includes first standard timestamp information and week calendar information; selecting the corresponding password generation rule according to the number of physical buttons; and generating the target verification key based on the password generation rule, device identification information, first standard timestamp information, and week calendar information.
[0033] Before generating the target verification key, the system needs to receive an activation signal to trigger the hidden interface access activation mechanism. The specific process is as follows:
[0034] (1) Interface Status Judgment: The system continuously monitors the current interface status of the device and only allows access to the hidden access process when the device is on a preset baseline interface. The preset baseline interface is usually the device information display interface (such as the software version information interface) to avoid accidental touches on other interfaces. This judgment is implemented through the software interface management module, which updates the interface status indicator in real time.
[0035] (2) Predefined physical key combination detection: The system monitors whether specific key combinations are pressed simultaneously through a hardware key scanning module. Predefined combinations include, for example, "AC key and DC key pressed simultaneously". "Pressed simultaneously" means that the keys in the combination have overlapping activation states in time, not individual keys. This detection is performed periodically to ensure continuous and reliable acquisition of key states.
[0036] (3) Activation Status Validity Judgment: To prevent accidental brute-force attacks, the system further judges the validity of the activation status, including: Continuous Key Pressing Time Detection: The above key combination must be continuously pressed for a period of no less than a preset threshold T1, typically 10 seconds, with a tolerance of ±5%. Locked Status Judgment: The device must be in an unlocked state, i.e., it must not be triggered by multiple incorrect inputs to ensure secure access. If the device is in a locked state, or the key press duration does not reach the threshold, the access process will not be triggered. The duration is determined by a timer, which starts counting from the first time the key combination meets the activation conditions.
[0037] (4) Triggering condition comprehensive judgment: The system will determine that the activation signal has been successfully received and trigger the hidden interface access process only when all of the following conditions are met: the device is currently in the preset baseline interface; a predefined combination of physical buttons is pressed at the same time; the duration of continuous button press reaches the threshold. The device is not locked.
[0038] If the above conditions are met, the system outputs an activation signal and proceeds to the subsequent dynamic key generation process. Otherwise, it continues to monitor and waits for the conditions to be met.
[0039] Upon receiving the activation signal, the system executes the following steps according to the preset dynamic key generation strategy:
[0040] (1) Acquisition of device identification information: The system reads the unique serial number (SN code) from the device's non-volatile memory and records the read SN code as... For example, a 14-digit numeric string burned at the factory. This information is unique and unchangeable, serving as the basis for identity binding in dynamic key generation.
[0041] (2) First clock data acquisition and time window calculation: The system reads the current real-time clock data (i.e., the first clock data) through the real-time clock module (RTC module) and formats it into the first standard timestamp information. , format as " "or" For example: June 11, 2025 at 09:30 corresponds to .
[0042] At the same time, extract the corresponding weekly calendar information. This indicates the day of the week (1 represents Monday, 7 represents Sunday). For example, Wednesday is recorded as... .
[0043] Based on the preset password validity period (Unit: minutes), calculate password expiration time (i.e., permission expiration timestamp information). This ensures that the generated key is valid only within a specified time window, preventing security risks arising from prolonged key validity. For example, and At that time, The corresponding password is valid from 09:30 to 09:35 on June 11, 2025. After data collection and calculation are completed, , , Store it in a temporary register, and then execute the subsequent steps.
[0044] (3) Password generation rule selection: The system selects the corresponding password generation rule based on the number of physical buttons N of the current device. The password length and value range are adjusted according to the number of buttons. For example: when N=2, a 2-digit numeric password is generated (modulo 100); when N=3, a 3-digit numeric password is generated (modulo 1000); and so on. The rule ensures that the password complexity matches the number of buttons.
[0045] (4) Execution of dynamic password generation algorithm: This embodiment adopts a hybrid hash calculation method: the device identification information Compared with the first standard timestamp information Concatenate the strings into a string; use the CRC32 algorithm to calculate the cyclic redundancy check value of the string, and obtain the hash value. ;Will Multiply by the week calendar information To enhance dynamism, a modulo operation is performed on the product result, with the modulus determined by the number of physical keys N, to obtain the final dynamic password. Let be the target verification key. It is understandable that when N=2, Take the last two decimal digits of the calculation result; when N=3, Take the last three decimal digits of the calculation result, and so on.
[0046] For example, suppose , , If N=2, then the result is obtained through calculation. If N=3, then the result is obtained through calculation. .
[0047] (5) Target verification key output: the calculated key. Output for subsequent key mapping and verification.
[0048] This step, by responding to the received activation signal, achieves strict trigger detection for access to the hidden interface and secure generation of dynamic keys, significantly improving the security and reliability of device access control. Specifically, the system only activates the hidden access process when the device is on a preset baseline interface, a predefined combination of physical buttons is pressed continuously for a preset time threshold, and the device is not locked, effectively preventing accidental triggering of malicious brute-force attacks. Subsequently, based on the device's unique identification information and real-time collected clock data, combined with a time-limited window, a target verification key is dynamically generated, ensuring the key's timeliness and uniqueness, further enhancing the dynamic management capabilities of access permissions. This dynamic key generation strategy not only effectively improves the system's security level but also takes into account ease of use, avoiding the vulnerability of traditional static passwords, and providing a solid guarantee for secure access to the device's hidden interface.
[0049] S12: Based on the preset key conversion rules, convert the target verification key into a key mapping sequence and enter the key input listening state.
[0050] Specifically, based on preset key conversion rules, the target verification key is converted into a key mapping sequence, and a key input listening state is entered. This includes: based on the key conversion rules, performing password and key conversion operations on each number in the target verification key to obtain a key mapping sequence corresponding to the target verification key, and entering a key input listening state.
[0051] The system receives the target verification key generated in step S11. This key is typically a dynamic password composed of numbers, such as "487". This password represents the verification basis for access control, but directly using a numerical password may pose security risks. Therefore, it is necessary to convert the numerical password into a corresponding physical key sequence to achieve higher-security operation verification. The specific implementation is as follows:
[0052] The system processes the target verification key bit by bit according to a preset key conversion rule. This rule defines the mapping relationship between numbers, physical keys, and the number of times keys are pressed. For example, on a device with three physical keys (key A, key B, and key C), the conversion rule can stipulate that the first digit of the target verification key corresponds to the number of times key A is pressed; the second digit corresponds to the number of times key B is pressed; and the third digit corresponds to the number of times key C is pressed. Taking the dynamic password "487" as an example, the system sequentially maps the number "4" to key A being pressed 4 times, "8" to key B being pressed 8 times, and "7" to key C being pressed 7 times, thus forming a complete key mapping sequence K: "key A pressed 4 times → key B pressed 8 times → key C pressed 7 times".
[0053] During the conversion process, the system matches the length of the target verification key with the number of physical buttons on the device to ensure that the conversion rules are adapted to the current device configuration. If the number of buttons or the password length changes, the system can dynamically adjust the conversion rules to ensure the accuracy and usability of the button sequence conversion.
[0054] After the mapping conversion is completed, the system enters the key input monitoring state. In this state, the system monitors and records the key input sequence signals input by the user in real time, waiting for the user to input according to the key mapping sequence. The monitoring module captures each key event, including the key type and the number of times it is pressed, and compares the user input sequence with the mapping sequence as the basis for subsequent verification.
[0055] This step converts the target verification key into a key mapping sequence based on a preset key conversion rule and then enters a key input monitoring state. This achieves an effective mapping from digital passwords to physical key sequences, significantly improving the security and ease of operation of system access verification. This conversion process avoids the direct exposure of digital passwords, reducing the risk of password theft or cracking. Simultaneously, the diverse combinations of physical keys on the device increase the complexity and unpredictability of the password, enhancing its resistance to attacks. Once in key input monitoring mode, the system can capture and verify the user's physical key input sequence in real time, ensuring that only correct key inputs can pass verification and access the hidden interface, effectively preventing unauthorized access. Furthermore, this step is highly flexible and adaptable, dynamically adjusting the conversion rules according to the number and characteristics of physical keys on different devices, adapting to various hardware environments.
[0056] In some embodiments, before entering the key input listening state, the method further includes a timed visual display of the target verification key. After the system completes the calculation of the target verification key, the secure display and automatic destruction of the password are achieved through the following steps: Interface rendering: A black background prompt box is generated in the central area of the device's main display screen, and the prompt box displays "The key input password is {" in bold white font. The prompt message is "}". For example: when When the key input is complete, the system displays "Key input password is 487". Timing control: A countdown timer starts, and the prompt message is continuously displayed for a preset time t seconds (t is configurable, typically 10 seconds), during which the screen backlight automatically adjusts to maximum brightness. Automatic destruction: After the timer ends, the prompt box automatically disappears, the system clears the temporary password variable from memory, and restores the screen backlight to its initial brightness. Understandably, the password prompt box is no longer displayed at this time, and the stored password value is cleared. After the display is complete, the system enters key input listening mode.
[0057] This embodiment achieves a balance between user needs for password visibility and system security protection by displaying dynamic passwords in a limited-time visual format. Specifically, the system prominently displays the current dynamic password in the center of the device's main display screen, allowing users to quickly and accurately retrieve the required keypad password, improving operational convenience and accuracy. A countdown timer ensures the password is only visible for a preset period, avoiding security risks associated with prolonged password exposure. After the countdown ends, the password hint is automatically destroyed and the password variable in memory is cleared, further preventing unauthorized access or screenshotting of the password. Simultaneously, the screen backlight brightness adjustment enhances the readability and security of the password display, improving the user experience.
[0058] In some embodiments, the key validity information further includes permission expiration time stamp information. The method further includes: when in a key input listening state, acquiring second clock data and performing timestamp conversion on the second clock data to obtain second standard timestamp information; comparing the second standard timestamp information with the permission expiration time stamp information; if the second standard timestamp information is not greater than the permission expiration time stamp information, then determining that the target verification key is within the validity period; if the second standard timestamp information is greater than the permission expiration time stamp information, then determining that the target verification key has expired.
[0059] During the password input phase, the system continuously monitors the relationship between the current time and the password expiration time to ensure that only input within the password's validity period is accepted. If the password expires, the process is forcibly terminated to ensure access security. The specific process is as follows:
[0060] (1) Clock synchronization upon startup of key input monitoring: When the system enters key input monitoring mode, it immediately obtains the current system time through the RTC (Real-Time Clock) module to obtain the second clock data. This clock data typically contains year, month, day, hour, minute, and second information. The system converts this clock data into a unified format timestamp, called the second standard timestamp information, which is generally in the format of " "or" ”, recorded as This format is the same as the permission expiration timestamp information generated in the previous step S11. Consistent formatting facilitates subsequent numerical comparisons.
[0061] (2) Comparison of the validity period of the dynamic password: The system will use the current timestamp Compared with the preset permission expiration time stamp Perform a numerical comparison. This comparison process generally uses integer comparison logic:
[0062] like This indicates that the password validity period has not expired, and the password remains valid. The system continues to allow the user to input the password. The system remains in input listening mode, waiting for the user to complete the password input.
[0063] like If the password has expired, the system immediately stops listening for input. If the user has already entered some keystrokes, the system clears the sequence to prevent the incorrect password from being misused. Simultaneously, the system automatically returns to the initial trigger detection step S11, waiting for the next access to the hidden interface.
[0064] Understandably, if a password timeout causes a process reset, the system not only clears the input cache but also triggers log entries or error counting to prevent brute-force attempts. This timeout reset mechanism ensures the validity and security of passwords, avoiding the risk of prolonged password leaks and enhancing the security of system access control. Furthermore, the time verification in this embodiment is not a one-time check but a periodic (e.g., every second) real-time check, ensuring an immediate response to password expiration events at any moment during user input. This continuous monitoring effectively prevents users from continuing to enter passwords after the expiration date, ensuring system access is limited to authorized time periods.
[0065] For example, suppose the permission expiration timestamp The password is "202506110935", meaning it's valid until 09:35 on June 11, 2025. When the system detects the current time... The time is "202506110933" (i.e., 09:33), which satisfies the condition. The system continues to allow input. If the current time... Reaching "202506110936", exceeding If the input is cleared, the system will immediately terminate the verification process and return to the initial state.
[0066] In this embodiment, by monitoring the relationship between the current time and the password permission expiration time in real time, it ensures that users are allowed to enter and verify passwords only within the validity period of the dynamic password, effectively preventing expired passwords from being used and improving the security and reliability of system access control; at the same time, the input data is automatically cleared and the process is reset upon timeout, avoiding accidental operation and potential security risks, and ensuring secure access to the hidden interface of the device.
[0067] S13: In key input monitoring state, receive input key sequence signal and input confirmation key signal to verify whether the input key sequence signal matches the key mapping sequence and mapping table, and whether the input confirmation key signal matches the mapping table.
[0068] S14: If the input key sequence signal matches the key mapping sequence and mapping table, and the input confirmation key signal matches the mapping table, then access the hidden interface.
[0069] The process of receiving input key sequence signals and input confirmation key signals to verify whether the input key sequence signals match the key mapping sequence and mapping table, and whether the input confirmation key signals match the mapping table, includes: obtaining the input interval time; comparing the input interval time with a preset timeout threshold; if the input interval time is less than the preset timeout threshold and no input confirmation key signal is received, then continuing to receive input key sequence signals; if the input interval time is less than the preset timeout threshold and the input confirmation key signal has been received, then verifying whether the input key sequence signals match the key mapping sequence and mapping table, and whether the input confirmation key signals match the mapping table; if the input interval time is not less than the preset timeout threshold, executing a backtracking process.
[0070] Once the system enters key input monitoring mode, it monitors all relevant physical key events in real time. Specifically, the system captures every key press and release operation by the user through hardware interrupts or polling, and records the detected key events in chronological order to form an input key sequence signal. In addition to ordinary key sequences, the system also specifically monitors input confirmation key signals. Confirmation keys are typically triggered by a specific combination of physical keys (e.g., pressing two keys simultaneously), and their function is to indicate the end of the current input sequence, prompting the system to verify. The system determines in real time whether the confirmation key has been detected during the monitoring process.
[0071] When the target verification key is valid, the system continuously listens for input key sequence signals and input confirmation key signals to complete password verification. The specific implementation process is as follows:
[0072] (1) Input Interval Timing: The system starts a high-precision timer when it first detects a key press, records this moment as the "first key press time", and begins recording the input key sequence (format: key ID + number of presses) and the input confirmation key. Subsequently, each time a new key input is detected, the system calculates the difference between the current key input time and the first key press time, i.e., the current input interval time. This timer ensures that it accurately reflects the time elapsed from when the user begins typing to the current moment.
[0073] (2) Comparison of input interval time with timeout threshold: The system presets a timeout threshold. (For example, 5000 milliseconds), used to limit the continuity requirements of key input:
[0074] like Since no confirmation key was detected, it means the user is still entering a password. The system continues to listen for keystrokes but does not perform any verification operation, waiting for more input.
[0075] like Upon detecting that the user has completed entering the confirmation key, it indicates that the user has finished entering the password, and the system is ready to execute the verification process.
[0076] like This indicates an input timeout, which may be due to the user pausing for too long or entering incorrect information, prompting the system to execute a backtracking process.
[0077] If the input interval exceeds a threshold, the system considers the current input invalid and executes a backtracking process: clearing the currently recorded input key sequence signal and input confirmation key signal, releasing relevant memory resources; resetting the timer and listening state to prepare for receiving new key input; and triggering corresponding user prompts or log recordings to track input anomalies.
[0078] For example, suppose a dynamic password is converted to a key sequence of "key A × 4 times, key B × 8 times, key C × 7 times", and the confirmation key is "key D double-click". A timer starts after the user begins pressing keys: if the user continuously inputs "key A × 4, key B × 8, key C × 7" within 4000 milliseconds, and triggers the confirmation key "key D double-click" at 4500 milliseconds, the system immediately verifies the input. Upon successful verification, access to the hidden interface is granted. If the user pauses for 7000 milliseconds after inputting "key B × 4" (exceeding the preset timeout threshold), the system determines that the input has timed out, clears all entered data, and returns to the waiting state for the first key press, requiring the user to re-enter the password.
[0079] By rigorously verifying and matching the input key sequence signals and the confirmation key signal, the system ensures that the user's input password sequence is completed continuously and accurately within a specified time window, effectively preventing unauthorized access due to input timeout, incorrect key sequence, or invalid confirmation key. A high-precision timer monitors the input interval in real time, dynamically determining whether the input has timed out, and a mapping table is used to comprehensively verify the key sequence and confirmation key, thus improving the security and reliability of password verification.
[0080] In some embodiments, the method further includes: calculating the total number of input key sequence combinations and the total number of confirmation key combinations based on the number of physical keys; and generating a mapping table based on the week calendar information, the total number of input key sequence combinations, and the total number of confirmation key combinations.
[0081] In some embodiments, a mapping table is generated based on the week calendar information, the total number of input key sequence combinations, and the total number of confirmation key combinations. This includes: enumerating the total number of input key sequence combinations to obtain key sequence combinations; enumerating the total number of confirmation key combinations to obtain confirmation key combinations; and mapping the week calendar information to the key sequence combinations and confirmation key combinations respectively to generate a mapping table.
[0082] When the system detects that the input interval is less than a preset timeout threshold and the confirmation key signal is input, it triggers the verification process for the input key sequence signal and the input confirmation key signal. To enhance the security and uniqueness of the verification, the total number of input key sequence combinations and the total number of confirmation key combinations are calculated based on the number of physical keys N on the device, thereby constructing a dynamic and time-period-related mapping table. The specific process is as follows:
[0083] (1) Calculation of the number of physical key combinations: The system reads the number of physical keys N of the device and calculates the total number of key sequence combinations. This covers all non-empty key combinations (including single-key, double-key, triple-key, and multi-key combinations). It also calculates and confirms the total number of key combinations. , represents the combination of pressing and holding all two buttons simultaneously.
[0084] (2) Key combination enumeration: Based on the value of N, the system generates all key sequence combinations and confirmation key combinations through enumeration. Key sequence combinations are enumerated in binary increment for all non-empty subsets, as shown in Table 1. Taking N=3 as an example, combination number 001 corresponds to single key A, 010 corresponds to single key B, 011 corresponds to double key A+B, etc. It should be noted that when the number of physical buttons N on the device equals 3, the number of non-empty button combinations is exactly 7, which perfectly corresponds to the mapping relationship of 7 days a week, achieving one-to-one correspondence and strong combination diversity. However, when N is greater than 3, the total number of combinations will increase significantly, far exceeding 7. At this time, any 7 combinations can be flexibly selected or preset according to specific needs to form different mapping table groups to support longer periods (such as using one mapping for the first 15 days of a month and another mapping for the last 15 days), thereby enhancing the security and adaptability of the system. Conversely, when the number of buttons is small (such as only 2 buttons), the number of non-empty combinations is small (only 3). At this time, these 3 combinations need to be reused cyclically for the 7-day mapping relationship to ensure the integrity of the mapping table and the continuity of function.
[0085] Table 1 - Key Sequence Combinations
[0086]
[0087] As shown in Table 2, the confirmation key combination enumerates all the combinations of simultaneous long press of two keys by using the combination formula. For example, when N=3, there are three combinations: A+B, A+C, and B+C.
[0088] Table 2 - Confirm Key Combinations
[0089]
[0090] (3) Generation of mapping relationship table: The system obtains the current week calendar information, that is, the information obtained in step S11. (1-7, corresponding to Monday to Sunday respectively). The weekday values are periodically mapped to key sequence combinations and confirmation key combinations, creating a dynamic mapping table of "weekday - key sequence combination - confirmation key combination". Key sequence combinations are assigned one-to-one according to the weekday order, ensuring that each day corresponds to a unique key sequence combination. Since the number of confirmation key combinations is usually less than 7, a cyclical reuse method is used to map them to the weekday, ensuring the continuity and cyclicality of the mapping. The enumerated key sequence combinations and confirmation key combinations are combined with the weekday information to generate a mapping table, as shown in Table 3, which explicitly specifies the key sequence combination and corresponding confirmation key combination for each day, ensuring that the input operation on that day strictly matches the preset mapping.
[0091] Table 3 - Mapping Relationship Table
[0092]
[0093] (4) Input verification mechanism: During the verification phase, the system performs multi-dimensional verification of the input key sequence and confirmation key based on the mapping table: Verifying whether the number of times each key in the input key sequence is pressed matches the number generated by the dynamic password. Verifying whether the input key combination completely matches the key sequence combination mapped for the day. Verifying whether the double-press combination of the confirmation key matches the confirmation key combination mapped for the day.
[0094] (5) Verification result processing: If all the above verifications pass, the input is deemed valid, the permission verification is successful, and access to the hidden interface is granted. If any verification fails (including incorrect key presses, mismatched key combinations, or input timeout), the system immediately triggers a security lock mechanism to prevent unauthorized access.
[0095] For example, taking the target verification key as 487 and the day as Wednesday, the key mapping sequence is {press key A 4 times → press key B 8 times → press key C 7 times}. After inputting the key sequence and the confirmation key, the mapping table is consulted. The key sequence for Wednesday is: short press keys A and B, no need to press key C. Therefore, short press key A 4 times, then short press key B 8 times. Then, the mapping table is consulted again. The confirmation key for Wednesday is: long press key B and key C simultaneously. Therefore, long press key B and key C simultaneously. All the above checks pass, the input is deemed valid, the permission verification is successful, and access to the hidden interface is granted.
[0096] This embodiment calculates and enumerates all possible key sequence combinations and confirmation key combinations based on the number of physical keys on the device. It then dynamically generates a mapping table of "day of the week - key sequence combination - confirmation key combination" using weekday information. This achieves the time periodicity and diversity of key input verification, effectively improving the uniqueness and security of password input. This mechanism not only significantly expands the space of input combinations, increasing the difficulty of brute-force attacks, but also ensures the accuracy and real-time nature of input operations through strict combination matching and timing verification. It prevents unauthorized or timed-out operations from intruding into the system, enhancing the reliability and protection capabilities of device access control, thereby improving the overall security level of the system and the credibility of user operations.
[0097] In some embodiments, if all the above checks pass, the input is deemed valid, the permission verification is successful, and the hidden interface activation and exit detection process is executed; if any check fails (including incorrect key presses, mismatched combinations, or input timeout), the system immediately triggers the security lock mechanism and executes the security lock process.
[0098] The hidden interface activation and exit detection process is as follows: The system loads the hidden interface and enables the page turning function (preset page turning keys, such as short press of A / B keys to turn pages), and monitors the exit key in real time (preset exit key, such as A+B long press for 2 seconds): If an exit operation is detected, the normal interface display process is executed; if no exit is detected and there is no operation, the access duration timer control process is executed to enter the timeout mechanism.
[0099] The access duration timing control process is as follows: Start the cumulative timer. ,like (Preset value, such as 2 minutes), return to the hidden interface to activate and exit the detection process; otherwise, execute the storage process.
[0100] The security lockout process includes: error counter. Increment by 1 to calculate the lock duration. (Unit: hours) The lock duration uses a tiered, incremental approach rather than a fixed value (e.g., 30 minutes the first time, 60 minutes the second time, and 120 minutes the third time) to increase the cost of brute-force attacks. Access to the hidden interface is prohibited during this period. An error counter is included. Stored in non-volatile memory, it will be cleared after 24 hours.
[0101] The storage process is as follows: the timestamp and operation record of this access are stored in non-volatile memory to form a traceability log. The format is: access timestamp + access result (success / failure). After storage is completed, the regular interface display process is executed.
[0102] The standard interface display process is as follows: display the standard interface.
[0103] This embodiment effectively ensures the security of device access and the accuracy of operations through a multi-factor authentication mechanism. When the input is valid and the authorization is successfully verified, the system automatically activates the hidden interface and supports page turning. Simultaneously, it monitors the exit button in real time to ensure users can safely exit at any time, guaranteeing operational flexibility and convenience. Access duration timer control further prevents the hidden interface from being inactive for extended periods, automatically triggering timeout processing and improving system resource management efficiency. If any authentication failure is detected, including incorrect keystrokes, incorrect key combinations, or input timeout, the system immediately triggers a security lock mechanism. This mechanism employs a tiered, progressively increasing lock duration strategy, significantly increasing the difficulty of brute-force attacks and effectively preventing unauthorized access. Access to the hidden interface is prohibited during the security lock period, ensuring system security and reliability. All access behaviors are recorded in non-volatile memory to form a detailed traceability log, facilitating subsequent auditing and security management. Finally, the system automatically switches back to the regular interface based on the access results, ensuring a consistent user experience and system stability.
[0104] It should be noted that relevant operators can obtain the following information from the maintenance manual or training: the triggering conditions for accessing the hidden interface; the key conversion rules for dynamic passwords and key sequences; the mapping table of "weekday - key sequence combination - confirmation key combination"; which physical key each key A, B, ..., N represents; the page turning button actions in the hidden interface; the button actions for exiting the hidden interface; and the timeout period for the hidden interface.
[0105] This application provides a device access control method that, without adding any extra hardware, utilizes only the device's existing display screen, physical buttons, RTC clock, and stored serial number (SN) code to achieve a highly secure, reliable, and accident-proof hidden interface access mechanism. Its core advantages are: First, the target verification key is dynamically generated based on the current time and the device's unique SN code, changing each time access is made, completely eliminating the risk of static passwords being spied on, recorded, or replayed, and ensuring that the target verification key of one device cannot be used on another. Second, access requires physical button operation, blocking the possibility of purely remote attacks. Simultaneously, the target verification key is only briefly displayed on the screen, making it extremely difficult to completely spied on or recorded; even if dynamic data and input sequences are recorded once, their dynamic nature prevents them from being used in subsequent attempts. Furthermore, a tiered locking duration strategy that increases with the number of errors significantly increases the difficulty of brute-force attacks, making them virtually impossible within the specified time window. This mechanism also strictly restricts access; only those who know the access method, possess physical access permissions to the device, and can correctly interpret dynamic information and input sequences can successfully enter, effectively preventing unauthorized operations. More importantly, the complex access process not only improves security but also significantly reduces the possibility of ordinary users accidentally accessing professional or sensitive backend interfaces, ensuring the stability of system operation and the consistency of user experience.
[0106] Based on the device access control method provided in the above embodiments, this application further provides a device access control apparatus. Please refer to... Figure 2 , Figure 2 This is a schematic diagram of the access control device for this equipment. (For example...) Figure 2 As shown, the device 200 includes: a key generation module 210, a key conversion module 220, a key verification module 230, and an interface access module 240.
[0107] The key generation module 210 generates a target verification key in response to a received activation signal using a preset dynamic key generation strategy. The key conversion module 220 converts the target verification key into a key mapping sequence based on preset key conversion rules and enters a key input listening state. The key verification module 230 receives an input key sequence signal and an input confirmation key signal in the key input listening state to verify whether the input key sequence signal matches the key mapping sequence and mapping table, and whether the input confirmation key signal matches the mapping table. The interface access module 240 accesses the hidden interface if the input key sequence signal matches the key mapping sequence and mapping table, and the input confirmation key signal matches the mapping table.
[0108] It should be noted that the above-described device access control device can execute the device access control method provided in the embodiments of this application, and has the corresponding functional modules and beneficial effects of executing the method. Technical details not described in detail in the device access control device embodiments can be found in the device access control method provided in the embodiments of this application.
[0109] This application also provides an electronic device 300, please refer to... Figure 3 This diagram illustrates the hardware structure of an electronic device 300 capable of performing the methods described in the above embodiments. The electronic device 300 includes: at least one processor 310; and a memory 320 communicatively connected to the at least one processor 310. Figure 3 Taking a processor 310 as an example, the memory 320 stores instructions executable by the at least one processor 310. These instructions, when executed by the at least one processor 310, enable the at least one processor 310 to perform the device access control method described in the above embodiment. The processor 310 and the memory 320 can be connected via a bus or other means. Figure 3 Taking the example of a connection between China and Israel via a bus.
[0110] The memory 320, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules, such as the program instructions / modules corresponding to the device access control method in the embodiments of this application. The processor 310 executes various functional applications and data processing of the server by running the non-volatile software programs, instructions, and modules stored in the memory 320, thereby implementing the device access control method described in the above embodiments.
[0111] The memory 320 may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created based on the use of the computing device. Furthermore, the memory 320 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some embodiments, the memory 320 may optionally include memory remotely located relative to the processor 310, and these remote memories may be connected to the computing device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.
[0112] The one or more modules are stored in the memory 320, and when executed by the one or more processors 310, the device access control method described in the above embodiments is executed.
[0113] It should be noted that the electronic device in this embodiment can be a control and human-machine interaction device in an energy storage system, including but not limited to: the main control unit of the energy storage system, the energy management system (EMS) controller, and a local human-machine interaction terminal with display and input functions (such as a control panel with physical buttons and a display screen, an LCD touch panel, etc.). Furthermore, it can also be other electronic devices with a processor, memory, real-time clock (RTC), unique serial number storage module, and button input module, such as industrial controllers, electromechanical equipment control panels, power distribution equipment intelligent terminals, robot control consoles, etc., thereby realizing a wide range of equipment safety verification and operation control functions.
[0114] The above-described product can execute the method provided in the embodiments of this application, and has the corresponding functional modules and beneficial effects for executing the method. Technical details not described in detail in this embodiment can be found in the device access control method described in the embodiments of this application.
[0115] This application provides a non-volatile computer-readable storage medium storing computer-executable instructions. These instructions are executed by one or more processors to enable the at least one processor to perform the device access control method described in the above embodiments. For example, the non-volatile computer-readable storage medium may be a read-only memory (ROM), a random access memory (RAM), a compact disc read-only memory (CDROM), magnetic tape, floppy disk, or optical data storage device, etc.
[0116] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0117] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.
[0118] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and not to limit them; under the concept of this application, the technical features of the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations of different aspects of this application as described above, which are not provided in detail for the sake of brevity; although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or make equivalent substitutions for some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.
Claims
1. A device access control method, characterized in that, The method includes: In response to the received activation signal, a target verification key is generated using a preset dynamic key generation strategy; Based on the preset key conversion rules, the target verification key is converted into a key mapping sequence, and the key input listening state is entered. In the key input monitoring state, input key sequence signals and input confirmation key signals are received to verify whether the input key sequence signals match the key mapping sequence and mapping table, and whether the input confirmation key signals match the mapping table. If the input key sequence signal matches the key mapping sequence and the mapping table, and the input confirmation key signal matches the mapping table, then the hidden interface is accessed.
2. The device access control method according to claim 1, characterized in that, The generation of the target verification key through a preset dynamic key generation strategy includes: Obtain device identification information; First clock data is acquired, and a time window is calculated on the first clock data to obtain key time validity information; wherein, the key time validity information includes first standard timestamp information and week calendar information; Select the corresponding password generation rule based on the number of physical keys; The target verification key is generated based on the password generation rules, the device identification information, the first standard timestamp information, and the week calendar information.
3. The device access control method according to claim 1, characterized in that, The process of converting the target verification key into a key mapping sequence based on a preset key conversion rule and entering a key input listening state includes: Based on the key conversion rules, each number in the target verification key is converted into a password and keystroke, resulting in the keystroke mapping sequence corresponding to the target verification key, and then the keystroke input listening state is entered.
4. The device access control method according to claim 2, characterized in that, The key expiration information also includes permission expiration timestamp information, and the method further includes: When in the key input listening state, the second clock data is acquired, and the second clock data is converted into a timestamp to obtain the second standard timestamp information; Compare the second standard timestamp information with the permission expiration timestamp information; If the second standard timestamp information is not greater than the permission expiration timestamp information, then the target verification key is determined to be within the validity period; If the second standard timestamp information is greater than the permission expiration timestamp information, then the target verification key is determined to be invalid.
5. The device access control method according to claim 1, characterized in that, The step of receiving input key sequence signals and input confirmation key signals to verify whether the input key sequence signals match the key mapping sequence and mapping table, and whether the input confirmation key signals match the mapping table, includes: Get the input interval time; The input interval time is compared with a preset timeout threshold; If the input interval is less than the preset timeout threshold and no input confirmation key signal is received, then the input key sequence signal continues to be received. If the input interval time is less than the preset timeout threshold, and the input confirmation key signal has been received, then verify whether the input key sequence signal matches the key mapping sequence and the mapping table, and whether the input confirmation key signal matches the mapping table. If the input interval is not less than the preset timeout threshold, a backtracking process is executed.
6. The device access control method according to claim 2, characterized in that, The method further includes: Based on the number of physical buttons, calculate the total number of input button sequence combinations and the total number of confirmation button combinations; The mapping table is generated based on the weekly calendar information, the total number of input key sequence combinations, and the total number of confirmation key combinations.
7. The device access control method according to claim 6, characterized in that, The step of generating the mapping table based on the week calendar information, the total number of input key sequence combinations, and the total number of confirmation key combinations includes: The total number of input key sequence combinations is enumerated to obtain the key sequence combinations; The total number of confirmation key combinations is enumerated to obtain the confirmation key combinations; The weekly calendar information is mapped to the key sequence combination and the confirmation key combination respectively, generating the mapping table.
8. A device access control device, characterized in that, The device includes: A key generation module, which is used to generate a target verification key in response to a received activation signal by means of a preset dynamic key generation strategy; A key conversion module is used to convert the target verification key into a key mapping sequence based on a preset key conversion rule, and then enter a key input listening state. A key verification module is used to receive an input key sequence signal and an input confirmation key signal in the key input listening state, so as to verify whether the input key sequence signal matches the key mapping sequence and the mapping relationship table and whether the input confirmation key signal matches the mapping relationship table. An interface access module is configured to access a hidden interface if the input key sequence signal matches the key mapping sequence and the mapping table, and the input confirmation key signal matches the mapping table.
9. An electronic device, characterized in that, include: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1-7.
10. A non-volatile computer-readable storage medium, characterized in that, The non-volatile computer-readable storage medium stores computer-executable instructions that, when executed by an electronic device, cause the electronic device to perform the method described in any one of claims 1-7.
Citation Information
Patent Citations
Public cloud storage access method and device, equipment and storage medium
CN117240617A
Access control method and system for terminal key area
CN120263439A