Method for activating emotional robot in residence scene

By accessing the management system in smart housing scenarios to obtain rental status and user authorization information, and combining spatial feature identification for triple verification, the system dynamically generates activation boundaries and encrypts and stores data, thus solving the privacy protection problem of user emotional interaction in smart housing and realizing safe and personalized emotional services.

CN121389098APending Publication Date: 2026-01-23GUANGDONG JINMA ROBOT TECHNOLOGY DEVELOPMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511408380.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-29
Publication Date
2026-01-23

AI Technical Summary

Technical Problem

Existing technologies in smart home scenarios lack dynamic binding of user emotional interaction and privacy protection, resulting in rigid access control, easy impersonation of single verification methods, and lack of spatial privacy management of sensitive data, leading to a high risk of user privacy leakage.

Method used

By accessing the residence management system to obtain rental status and user encrypted authorization information, and combining spatial feature identifiers to dynamically generate activation boundaries, the system performs triple verification of user identity, residence ownership, and location validity, activates the emotional interaction function, clears data in dormant mode, and uses hardware encryption to store privacy data.

Benefits of technology

This system ensures that the emotional robot is activated only within the legal tenant's residence, preventing unauthorized use, ensuring user privacy and security, providing personalized emotional services, reducing the risk of data leakage, and meeting users' needs for emotional companionship and privacy protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121389098A_ABST
    Figure CN121389098A_ABST
Patent Text Reader

Abstract

The invention provides an emotional robot activation method for a residence scene, and relates to the technical field of robots, and the method comprises the steps: obtaining a leasing state based on a management system, combining with a residence space feature identifier to dynamically generate an activation boundary, and guaranteeing that a robot can activate a core function only in a residence legally used by a current tenant; through a triple verification mechanism fusing user identity, residence ownership and positioning effectiveness, illegal use or remote cracking by unauthorized personnel is effectively prevented, and the safety and compliance of equipment use are remarkably improved; in the service level, an emotion interaction function and local privacy data storage are only opened when verification is passed and the verification is in an activation boundary, and once the robot leaves a residence or a lease term is over, the robot automatically enters a sleep mode and clears sensitive data, so that a strong privacy protection effect is technically realized, the demand of a user for personalized emotion accompanying is met, and the user experience is improved. And the data leakage risk is fundamentally reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of robots, in particular to a method for activating an emotional robot in a dwelling scenario. BACKGROUND

[0002] In the context of intelligent service robots increasingly integrating into smart dwelling scenarios, the existing technology mainly focuses on general functional services such as cleaning and delivery, and its technical implementation relies on pre-set electronic fence to limit the activity range, lacking deep design for user emotional interaction and privacy protection. Such technology generally has some defects. Firstly, the permission control mechanism is rigid, using static geographic fence, which cannot be dynamically bound with dwelling rental status and user identity; secondly, the activation of the robot relies on single verification methods such as code scanning or Bluetooth, which has the risk of being misused by non-tenants or illegally opened; thirdly, the emotional interaction function involving sensitive data such as voice and emotion recognition lacks spatial privacy control, resulting in prominent user privacy leakage risks. SUMMARY

[0003] The purpose of the present application is to provide a method for activating an emotional robot in a dwelling scenario to solve one or more technical problems in the prior art and at least provide a beneficial choice or create conditions.

[0004] The solution to the technical problem of the present application is: the present application provides a method for activating an emotional robot in a dwelling scenario, which is executed by an emotional robot deployed in a dwelling, comprising: accessing a management system of the dwelling to obtain rental status information of the current dwelling and encrypted authorization information of the user; based on the rental status information, combining the spatial feature identifier of the dwelling, dynamically generating an activation boundary in units of physical space of the dwelling, and obtaining real-time positioning information of the emotional robot; based on the rental status information, the encrypted authorization information, the activation boundary and the positioning information, performing three-way verification of user identity, dwelling ownership and positioning validity; after passing the three-way verification, activating and opening the emotional interaction function and local privacy data storage function of the emotional robot; when a trigger signal of the sleep mode is detected, the emotional robot automatically enters the sleep mode, closes the sensor and clears the local privacy data.

[0005] Further, the process of accessing the dwelling management system comprises: establishing an encrypted communication connection with the dwelling management system through the HTTPS protocol, sending a registration request including the unique device code of the emotional robot; after the management system verifies the legality of the device, the current rental status information of the dwelling and the encrypted authorization information of the user are pushed in real time through the WebSocket protocol; The lease status information includes a lease start time and a lease end time. The encryption authorization information includes a unique identification code of the residence, a hash value of a user's ID card, and a dynamic authorization token, wherein the validity period of the dynamic authorization token is bound to the lease period of the residence.

[0006] Further, the spatial feature identifier is selected from at least one of a residence door magnet state signal, an indoor Wi-Fi hotspot fingerprint, and a UWB positioning anchor point, wherein: The indoor Wi-Fi hotspot fingerprint is a signal strength distribution feature of a unique MAC address access point deployed in the residence, and a fingerprint library is constructed after denoising by a Kalman filtering algorithm, with a signal sampling interval not exceeding a preset interval threshold and a positioning resolution not exceeding a preset resolution threshold. The UWB positioning anchor point is a super wideband positioning base station installed at the four corners of the residence, supporting a TDoA ranging mode, with a positioning error not exceeding a preset error threshold, and the coordinates of the UWB positioning anchor point are mapped to a local coordinate system of the residence after coordinate conversion.

[0007] Further, based on the lease status information, the spatial feature identifier of the residence is combined to dynamically generate an active boundary in units of the physical space of the residence, including: Based on the lease status information, receiving the residence floor plan data issued by the management system; Based on the spatial feature identifier of the residence and the residence floor plan data, generating a polygon boundary in units of the physical space of the residence by a boundary fitting algorithm; According to the polygon boundary, extracting laser radar point cloud feature points of the residence wall corner, fitting a wall plane equation, and determining the coordinates of the four corner vertices as physical feature points; Combining the signal mutation threshold of the Wi-Fi hotspot fingerprint and the distance intersection of the UWB anchor point, supplementing virtual feature points of non-physical boundaries; Performing polygon fitting on the physical feature points and virtual feature points by a least squares method to generate a boundary coordinate set as the active boundary, the active boundary is associated with the unique identification code of the residence and the management system code, and is stored in the local encryption chip of the robot.

[0008] Further, the real-time acquisition of the positioning information of the emotional robot includes: Scanning the indoor environment at a preset frequency using a laser radar, outputting point cloud data and extracting plane features as laser radar data; Collecting RGB-D images using a vision sensor, and generating visual odometry data as vision sensor data by an ORB feature point matching algorithm; Receiving anchor point signals using a UWB positioning module, and outputting three-dimensional coordinate raw values as UWB positioning data; The laser radar data, the visual sensor data and the UWB positioning data are fused by using an extended Kalman filtering algorithm to output the positioning information of the emotional robot.

[0009] Further, the fusion of the laser radar data, the visual sensor data and the UWB positioning data by using the extended Kalman filtering algorithm to output the positioning information of the emotional robot comprises the following steps: Based on the UWB positioning data, a first position coordinate of the emotional robot is predicted by combining a robot motion model; Based on the laser radar data and the visual sensor data, a residual equation is constructed to correct the first position coordinate and iteratively optimize to obtain a second position coordinate of the emotional robot; The second position coordinate is continuously monitored, and if the coordinate drift does not exceed a preset drift threshold and the matching degree of the laser radar data and the visual sensor data is not less than a preset matching degree threshold, the second position coordinate is confirmed to be valid and is taken as the positioning information of the emotional robot; Otherwise, a sensor failure alarm is triggered and a UWB single-mode positioning is enabled, and the three-dimensional coordinate original value is taken as the positioning information of the emotional robot.

[0010] Further, the specific process of the triple verification comprises: User identity verification: based on the user's login request, the real-time facial features or identity card chip information of the user are collected, and the collected information is compared with the user biological feature template pre-stored in the management system. When the similarity exceeds a preset similarity threshold and the living body detection is passed, an identity verification pass signal is output; Residence ownership verification: the communication module of the emotional robot is called to interact with the electronic door lock of the residence through near-field data, and the communication distance does not exceed a preset distance threshold and the continuous communication time length is not less than a preset time length threshold. The residence physical code returned by the electronic door lock is received and compared with the residence unique identification code in the encrypted authorization information. When the comparison is passed, an ownership verification pass signal is output; Positioning validity verification: the real-time acquired positioning information is compared with the activation boundary. When the emotional robot continuously stays within the activation boundary for more than a preset activation time threshold, a positioning validity verification pass signal is output; The judgment condition for passing the triple verification is that the identity verification pass signal, the residence ownership verification pass signal and the positioning validity verification pass signal are valid at the same time, and the current time is within the lease time range in the lease state information.

[0011] Further, the emotional interaction function comprises a voice chat module and an emotion recognition engine, wherein: The voice chat module supports real-time interaction in multiple languages, integrates a natural language processing model, supports context semantic understanding and personalized dialogue style configuration; The emotion recognition engine collects facial expression features through a camera and voice tone features through a microphone, uses a deep learning model to recognize the emotional state of the user, and dynamically adjusts the interaction strategy according to the emotional state.

[0012] Further, the local private data storage function uses a hardware encryption mechanism: The private data generated during the emotional interaction is collected by the sensor, encrypted in real time by the encryption chip built into the emotional robot, and stored in an independent encryption partition; the access to the encryption partition needs to verify the user session number and the validity period of the temporary permission package at the same time, the data retention time does not exceed the lease period of the residence, and only local reading is supported, external data export is prohibited.

[0013] Further, the trigger conditions for automatically entering the sleep mode include: The first trigger condition: detecting that the positioning information of the emotional robot exceeds the activation boundary, and the duration exceeds the preset leaving duration threshold, determining that it is "outside the activation boundary"; The second trigger condition: the residence lease state information pushed by the management system changes to termination; The third trigger condition: receiving the "end use" instruction of the user; When any trigger condition is met, the trigger signal of the sleep mode is detected, the emotional robot immediately cuts off the hardware power supply of the microphone, camera and positioning sensor, closes the emotional interaction function interface, and performs three overwrites on the encryption partition through the physical erasure algorithm, and generates a data destruction log after the cleaning is completed and uploads it to the management system.

[0014] The beneficial effects of the present application are: the present application provides an emotional robot activation method for a residence scene, which generates an activation boundary based on the lease state obtained by the management system and combined with the residence space feature, ensures that the robot can only activate the core function in the residence legally used by the current tenant; through the triple verification mechanism of user identity, residence ownership and positioning validity, unauthorized personnel are effectively prevented from using or remotely cracking, significantly improving the security and compliance of device use; in terms of service, the emotional interaction function and the local private data storage are only opened when the verification is passed and within the activation boundary, and once the robot leaves the residence or the lease period ends, it automatically enters the sleep mode and clears the sensitive data, achieving strong privacy protection effect from a technical point of view, meeting the needs of users for personalized emotional companionship, and fundamentally reducing the risk of data leakage.

[0015] Other features and advantages of the present application will be set forth in the description that follows, and in part will be apparent from the description, or can be learned by practice of the application. The purposes and other advantages of the present application will be realized and attained by the structure particularly pointed out in the written description and claims hereof as well as the appended drawings. BRIEF DESCRIPTION OF DRAWINGS

[0016] The accompanying drawings are included to provide a further understanding of the technical solutions of the present application, and constitute a part of the specification, and are used to explain the technical solutions of the present application together with the embodiments of the present application, and do not constitute a limitation on the technical solutions of the present application.

[0017] Figure 1 is a flowchart of an emotional robot activation method of a residence scene provided by the present application. DETAILED DESCRIPTION

[0018] In order to make the purposes, technical solutions and advantages of the present application more clearly understood, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application.

[0019] The present application will be further described below with reference to the accompanying drawings and specific embodiments. The described embodiments should not be considered as limiting the present application, and all other embodiments obtained by those of ordinary skill in the art without making creative efforts fall within the scope of protection of the present application.

[0020] In the following description, "some embodiments" are related to a subset of all possible embodiments, but it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments, and can be combined with each other without conflict.

[0021] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.

[0022] With the rapid development of artificial intelligence and Internet of Things technology, service robots have gradually entered the residence industry and are widely used in residence cleaning, article delivery and other basic function scenes. At the same time, AI emotional interaction technology has made great progress, and functions such as voice recognition, emotion perception and natural language dialogue are becoming mature, laying a foundation for providing more personalized interaction experience for users. However, the integration of these technologies in the residence scene is still in its infancy, and most products focus on functional services, and have not yet explored the application potential of robots in the fields of emotional companionship, psychological counseling and personalized interaction.

[0023] Currently, service robots in residential settings primarily rely on static environmental perception and preset rules for operational control. Typical technical methods include building electronic fences using indoor positioning systems based on Wi-Fi fingerprints or Bluetooth beacons, and using SLAM (Simultaneous Localization and Mapping) technology to create floor plans of the residence and set restricted areas, thereby limiting the robot's range of movement. Furthermore, in the field of shared devices, such as power banks and shared bicycles, QR code scanning or Bluetooth near-field communication are commonly used for user authentication and device unlocking. While these methods achieve basic functional control and access authorization, their logic is relatively simple, typically relying on a single factor (such as the scanning action) to trigger the opening mechanism, lacking deep perception of the usage environment context and multi-dimensional security verification.

[0024] While the aforementioned technologies have met basic housing service needs to some extent, they have revealed significant shortcomings in new application scenarios oriented towards the "emotional privacy + rental model." First, existing systems generally lack the ability to dynamically bind robot function activation to user rental behavior and physical space ownership, failing to achieve the personalized service logic of "activating emotional interaction functions only within the rented residence," potentially leading to the collection or leakage of privacy data in unauthorized spaces. Second, traditional electronic fences are mostly defined by fixed coordinates and lack the ability to dynamically adjust based on real-time data from the housing management system, making it difficult to adapt to the reality of frequent tenant changes. Third, the identity verification mechanism is weak; relying solely on scanning codes or app logins cannot ensure that the operator is the legitimate occupant, posing a risk of impersonation and theft. Finally, when the robot leaves the designated residence or the rental ends, there is a lack of closed-loop management mechanisms such as automatically shutting down sensors and clearing locally stored privacy interaction records, failing to guarantee the security of user data throughout its entire lifecycle and violating basic privacy protection principles. Therefore, a new activation method that can deeply integrate the housing rental process, user identity authentication, and physical space constraints is urgently needed to build a truly safe, private, and reliable emotional service robot application system.

[0025] To solve the above problems, the application provides an emotional robot activation method for a residence scenario, the core of which is to realize deep coupling of robot functions and residence rental status through a technical architecture of "dynamic activation boundary + multi-factor fusion verification + private data closed-loop management". Specifically, the system accesses a residence management system to obtain residence rental status and user encrypted authorization information in real time, combines spatial feature identifiers such as door magnetic signals, Wi-Fi fingerprints or UWB positioning, dynamically generates an activation boundary in units of physical residences to replace a traditional static electronic fence, and in the activation process, the robot needs to complete user identity verification, residence ownership verification and positioning validity verification, and after passing the three verifications, the emotional interaction and local private data storage functions can be started. When a trigger condition of the sleep mode is detected, the emotional robot automatically enters the sleep mode, closes the sensor and clears the local private data, thereby constructing a full life cycle safety closed loop from activation to termination, and ensuring the privacy of user emotional interaction and the exclusivity of service authorization.

[0026] First, the emotional robot activation method for a residence scenario provided by the embodiments of the application will be described in detail below with reference to the accompanying drawings.

[0027] With reference to Figure 1 The emotional robot activation method for a residence scenario provided by the embodiments of the application is executed by an emotional robot deployed in a residence, and the implementation process of the method includes but is not limited to the following steps.

[0028] In step S110, the management system of the residence is accessed to obtain the rental status information of the current residence and the encrypted authorization information of the user.

[0029] In step S110, a trusted data channel between the emotional robot and the residence operation management system is established. Through the interface with the management system, the robot can obtain real-time dynamic business data related to the current residence, including rental status information such as rental period start and end time, cleaning status, check-in / check-out label, and encrypted authorization information including residence unique identification code, user identity certificate hash value and dynamic authorization token. This process not only ensures that the start of the robot service strictly depends on the legal rental relationship, but also realizes the pre-binding of user identity and device permission, providing a trusted data source and identity basis for all subsequent security control logic.

[0030] In step S120, based on the rental status information, the spatial feature identifiers of the residence are combined to dynamically generate an activation boundary in units of physical spaces of the residence, and the positioning information of the emotional robot is obtained in real time.

[0031] In step S120, the system no longer relies on preset map coordinates or fixed no-entry zones, but automatically generates an "activation boundary" that completely matches the physical room based on the actual rental status and spatial feature identification of the current residence. This positioning-boundary linkage mechanism ensures that the robot must be stably located inside the rented residence before it can be activated, fundamentally eliminating the risk of cross-room use or external misuse.

[0032] In step S130, based on the rental status information, encrypted authorization information, activation boundary, and positioning information, a three-way verification of user identity, residence ownership, and positioning validity is performed.

[0033] In step S130, a multi-level, strongly correlated security verification system is constructed to achieve the "person-room-machine" trinity identity authentication. First, in the user identity verification link, it is ensured that the operator is the legally registered occupant. Second, in the residence ownership verification link, it is confirmed that the user indeed has the right to use the current room. Finally, in the positioning validity verification link, the system judges whether the robot has been continuously located within the activation boundary generated in step S120 for more than a preset time (e.g., 10 seconds), excluding temporary misentry or interference during movement. All three verifications must pass and be within the effective rental period before proceeding to the next step, greatly improving the system's anti-counterfeiting ability and security, effectively preventing potential threats such as remote control, account theft, and unauthorized access.

[0034] In step S140, after the three-way verification, the emotional interaction function and local private data storage function of the emotional robot are activated and opened.

[0035] In step S140, once the three-way verification is successful, the robot will remove the function restrictions, enable the voice chat module and emotion recognition engine, and achieve intelligent emotional interaction. More importantly, all sensitive data generated during the interaction process (such as conversation records and emotion analysis results) are encrypted in real time by the built-in encryption chip and stored in an independent hardware encryption partition. Access requires double credentials (session number + temporary permission package), and any form of external export is prohibited. This "function-on-demand and data-in-place storage" design not only meets the user's demand for emotional services, but also maximizes the protection of personal privacy from being leaked or misused.

[0036] In step S150, when the trigger signal of the sleep mode is detected, the emotional robot automatically enters the sleep mode, closes the sensors, and clears the local private data.

[0037] In step S150, the closed-loop management of the service life cycle is completed, which is the last line of defense to protect user privacy and security, realizes the privacy protection principle of "use and start, use and destroy", eliminates the possibility of data residue, secondary use or being explored by subsequent guests, truly realizes "data without trace", and significantly enhances the user's trust and security in intelligent services.

[0038] In some embodiments of the present application, in step S110, the process of accessing the residence management system includes the following steps: establishing an encrypted communication connection with the residence management system through the HTTPS protocol, sending a registration request including the unique device code of the emotional robot; after the management system verifies the legality of the device, the current residence rental status information and the user's encrypted authorization information are pushed in real time through the WebSocket protocol. Among them, the rental status information includes the start time and end time of the rental period; the encrypted authorization information is encrypted by RSA-2048 algorithm, and the encrypted authorization information includes the unique identification code of the residence, the user's identity card hash value and the dynamic authorization token, wherein the validity period of the dynamic authorization token is bound with the residence rental period, and the generation frequency threshold of the dynamic authorization token is determined according to the security level requirements of the residence rental business.

[0039] Specifically, an encrypted communication connection is established with the residence management system through the HTTPS protocol, and a registration request containing the unique device code of the emotional robot is sent, which is the first line of defense for secure and reliable access to the system. The HTTPS protocol is based on the TLS / SSL encryption transmission mechanism, which can effectively prevent data from being eavesdropped, tampered with or forged during transmission, and ensure that the communication link between the robot and the management system has confidentiality, integrity and identity authentication capability. This design avoids the risk of man-in-the-middle attacks caused by traditional HTTP clear text transmission, which is particularly important in public network or cross-system integration scenarios. At the same time, the "unique device code of the emotional robot" carried in the registration request as a hardware-level identity identifier is used for the management system to verify the legality of the terminal device. Only devices that have been pre-registered and authorized can complete registration, thereby eliminating the possibility of illegal terminals impersonating access, forging services or stealing user data. This mechanism builds the foundation of "device trust" and provides security for all subsequent data interactions.

[0040] After verifying the legality of the device, the management system pushes the current residence rental status information and the user's encrypted authorization information in real time through the WebSocket protocol, realizing the upgrade from "passive query" to "active push", greatly improving the response efficiency and data timeliness of the system. Compared with the traditional polling method, WebSocket supports full-duplex long connection communication, which can immediately push updated information to the robot at the moment of residence state change (such as check-in, check-out, renewal, and cleaning completion), ensuring that its functional state is synchronized with the actual business process. The "rental period start time" and "rental period end time" in the rental status information provide a clear service time window for the robot, making it only have activation conditions within the legal rental period; the accurate acquisition of these dynamic business data makes the robot's behavior logic highly coordinated with the residence operation rhythm, improving the automation and intelligence level of service.

[0041] Further, the "residence unique identification code, user ID card hash value, and dynamic authorization token" contained in the encrypted authorization information constitute a multi-level, strongly associated identity and permission certificate system. Among them, the "residence unique identification code" is used to accurately match the physical space, ensuring that the robot can only respond to instructions from a specific room; the "user ID card hash value" realizes the unique identification of the user's identity by one-way encryption processing (such as SHA-256) on the original ID number, balancing the identification needs and privacy protection; while the most critical "dynamic authorization token" is generated using standard protocols such as OAuth 2.0 or JWT (JSON Web Token), with a clear issuance time, validity period, and digital signature, its life cycle is strictly bound to the residence rental period - that is, the token is generated at check-in and automatically invalidated at check-out. This design not only realizes the time effectiveness control of permissions, but also supports the revocation and refresh mechanism of tokens, which can immediately terminate authorization once abnormal behavior is found. The three together constitute a set of secure credentials that are not forgeable, not replayable, and time-effective, providing a solid data foundation for subsequent identity verification and permission control.

[0042] In summary, the access process builds a high-security, low-latency, and strongly associated system-level data channel through the combination of "HTTPS encrypted communication + WebSocket real-time push + multi-dimensional encrypted authorization information". It not only solves the problems of device island, information lag, and permission confusion in traditional smart home systems, but also deeply embeds the robot service into the core business process of the residence, realizing the fine management logic of "renting determines rights, housing determines boundaries, and people control". This mechanism provides a reliable data source and permission basis for subsequent key links such as dynamic boundary generation, triple verification, and privacy data closed loop, and is the prerequisite and cornerstone for the safe and reliable operation of the entire emotional robot activation method. At the same time, the design has good scalability and can adapt to different brands and architectures of management systems, with strong industrial landing value.

[0043] In some embodiments of the present application, the spatial feature identifier of the residence is selected from at least one of a residence door magnet state signal, an indoor Wi-Fi hotspot fingerprint, and a UWB positioning anchor point.

[0044] Traditional service robots rely on global SLAM maps and fixed coordinate points for region division, which is difficult to adapt to the characteristics of frequent tenant replacement and dynamic environmental changes in residences. The present scheme realizes independent identification and accurate positioning of each residence by introducing multiple physical signals with spatial uniqueness and stability as "spatial fingerprints". This multi-modal signal fusion design not only improves the robustness of the system (when a signal source fails, other signals can be used to compensate), but also enhances the anti-counterfeiting capability - it is difficult for attackers to replicate or simulate multiple heterogeneous signal characteristics in a short time. More importantly, these signals are strongly bound to the physical space and cannot be remotely counterfeited, ensuring that the robot can only be activated in the real rented residence, fundamentally guaranteeing the specificity of the service and the security of the privacy.

[0045] Specifically, the indoor Wi-Fi hotspot fingerprint is the signal strength distribution characteristic of the unique MAC address access point deployed in the residence, and the fingerprint library is constructed after denoising by Kalman filtering algorithm; the signal sampling interval is not more than a preset interval threshold, for example, ≤1 second, the interval threshold is determined according to the stability requirement of indoor Wi-Fi signal strength; the positioning resolution is not more than a preset resolution threshold, for example, ≤0.5 meters, the resolution threshold is determined according to the spatial division accuracy requirement of the residence activation boundary.

[0046] Each residence is deployed with a Wi-Fi access point (AP) with a unique MAC address, forming a natural spatial identifier, avoiding the identity confusion problem caused by multiple rooms sharing the same SSID. On this basis, the system collects the RSSI (Received Signal Strength Indication) of multiple sampling points in the residence before check-in or in the initialization phase, forming a "signal strength distribution map" unique to the room, i.e. the fingerprint library. Due to the unique pattern of the attenuation and reflection of wireless signals by obstacles such as walls and furniture, the Wi-Fi fingerprints of different residences show high difference and good discrimination. Further, the original signal data is denoised using Kalman filtering algorithm, effectively suppressing the signal fluctuations caused by human movement, electrical interference, etc., and improving the positioning stability. By setting "the signal sampling interval does not exceed the preset threshold" and "the positioning resolution does not exceed the preset threshold", the density and accuracy of data collection are ensured to meet the needs of subsequent boundary generation, providing reliable low-level data support for dynamic activation.

[0047] The UWB positioning anchor is a UWB positioning base station installed at the four corners of the residence, supporting TDoA ranging mode, with a positioning error not exceeding a preset error threshold, which is determined according to the size of the physical space of the residence and the positioning accuracy requirement. The coordinates of the UWB positioning anchor are mapped to the local coordinate system of the residence after coordinate conversion.

[0048] Specifically, the UWB (Ultra-Wideband) positioning anchor is installed at the four corners of the residence and supports TDoA (Time Difference of Arrival) ranging mode, aiming to provide sub-meter or even centimeter-level high-precision positioning capability to meet the stringent requirements of emotional robots for spatial perception. UWB technology has the advantages of wide bandwidth, strong anti-multipath interference capability, and high time resolution, making it particularly suitable for precise positioning in complex indoor environments. By arranging four UWB base stations at the four corners of the residence, a local positioning network is formed, and the UWB tag carried by the robot can receive signals from multiple base stations simultaneously, and the precise coordinates of itself in three-dimensional space are calculated using the TDoA algorithm. Compared with traditional ToA (Time of Arrival) or RSSI positioning, this method has higher anti-clock synchronization error capability, and the positioning result is more stable and reliable. By limiting the "positioning error not exceeding the preset error threshold" (such as ≤0.3 meters), it ensures that the robot can accurately determine whether it is within the boundary of the residence, preventing false activation or false dormancy caused by positioning drift. In addition, "the coordinates of the UWB anchor are mapped to the local coordinate system of the residence after coordinate conversion" means that the system converts the global positioning data into a relative coordinate system based on the room, facilitating subsequent data fusion and boundary fitting with other modules such as laser radar and vision sensor, improving the operability and computational efficiency of the algorithm.

[0049] In some embodiments of the present application, in step S120, based on the lease status information, a dynamic activation boundary in the unit of the physical space of the residence is generated in combination with the spatial feature identifier of the residence, including the following steps.

[0050] In step S210, based on the lease status information, the residence layout data issued by the management system is received.

[0051] In step S210, the emotional robot is provided with macro spatial structure information about the current residence. Through deep integration with the residence management system, the robot can receive digital layout data corresponding to the residence while obtaining the lease status, including geometric information such as wall direction, door and window position, and room size. This design avoids the time-consuming, error accumulation and environment-dependent problems caused by the robot relying entirely on autonomous mapping. More importantly, the layout data is updated in real time with the lease status, ensuring that the robot can generate a dedicated activation boundary based on the latest room layout every time a new tenant moves in, realizing the fine management of “one room one map, one guest one boundary”. In addition, this layout serves as prior knowledge, which can significantly improve the convergence speed and accuracy of the subsequent boundary fitting algorithm, especially in complex room types or severe signal obstruction scenarios, effectively guiding the feature point extraction and polygon construction process, and providing a reliable structured reference for the entire dynamic boundary generation process.

[0052] In step S220, based on the spatial feature identifier of the residence and the residence layout data, a polygon boundary in the unit of the physical space of the residence is generated through a boundary fitting algorithm.

[0053] In step S220, the system no longer relies on a pre-set fixed electronic fence, but instead integrates the layout provided by the management system (macro structure) and the spatial feature identifier collected in real time (micro signal) to automatically generate a polygon boundary that perfectly matches the current rental residence through a boundary fitting algorithm. This process realizes the accurate mapping of physical space and digital permissions: only when the robot is located within the polygon area does it have the qualification to activate the emotional function. This method breaks through the limitations of the traditional service robot “global map + forbidden area” mode, making each residence an independent “service authorization unit”, greatly enhancing the privacy and security of the service. At the same time, the boundary is dynamically reconstructed with the replacement of tenants, avoiding the risk of residual permissions of previous tenants or cross-room misactivation, and truly realizing the intelligent permission control logic of “on-demand generation and change with rental”.

[0054] In step S230, according to the polygon boundary, the laser radar point cloud feature points of the corner of the residence wall are extracted, the wall plane equation is fitted, and the coordinates of the four corner vertices are determined as physical feature points.

[0055] In step S230, the high-precision ranging capability of the laser radar is used to extract real physical boundary features from the actual environment, which is a field verification and fine correction of the layout data of the management system. After the robot is started, indoor point cloud data is obtained by 360-degree laser scanning, and dense point clusters at wall corner points are identified, and a clustering and edge detection algorithm is used to extract key corner point features. Subsequently, based on these point cloud data, the plane equation of the wall surface is fitted, and the accurate three-dimensional coordinates of the four corners of the room are calculated as "physical feature points". These points are directly derived from the real environment and are not affected by drawing errors, decoration changes or furniture obstructions, and have very high spatial accuracy. Using these measured feature points as the basis for boundary fitting can effectively correct possible deviations in the layout (such as size errors and wall shifts), ensuring that the generated active boundary is highly consistent with the actual physical space, and providing a reliable geometric reference for subsequent positioning validity verification.

[0056] In step S240, the intersection of the signal mutation threshold of the Wi-Fi hotspot fingerprint and the distance of the UWB anchor points is combined to supplement the virtual feature points of the non-physical boundary.

[0057] In step S240, information from the non-physical signal dimension is introduced to identify "logical boundaries" or "signal boundaries" that cannot be directly detected by the laser radar, thereby enhancing the integrity and anti-interference capability of the active boundary. For example, near the door frame or partition wall, the Wi-Fi signal strength often shows a significant mutation, and the system identifies these change points by setting a "signal mutation threshold" and includes them as virtual feature points in the boundary calculation; similarly, the distance intersection between UWB anchor points (i.e. the overlapping area of multiple base station signal coverage ranges) can be used to calculate the relative position constraints of the robot in three-dimensional space, further defining the boundary range. These "virtual feature points" do not correspond to physical walls, but reflect the propagation characteristics of wireless signals in space, and can effectively identify the communication boundaries and perception boundaries of the room. Especially in complex environments (such as curved walls, glass partitions, and furniture obstructions), the laser radar may not be able to capture all the corner points completely, and the virtual feature points can play a supplementary and correction role, improving the robustness and adaptability of boundary fitting.

[0058] In step S250, the physical feature points and virtual feature points are polygonally fitted by the least squares method to generate a boundary coordinate set as the active boundary, and the active boundary is associated with a unique identification code of the residence and a management system code, and is stored in the local encryption chip of the robot.

[0059] In step S250, the system fuses the physical feature points with the virtual feature points, performs polygon fitting using the least squares method, and solves a closed polygon boundary coordinate set that best represents the distribution trend of all feature points. This method has mathematical optimality and can generate a smooth and stable boundary contour even in the presence of measurement noise and point position deviation. The generated active boundary not only accurately reflects the physical and signal characteristics of the current residence, but also achieves bidirectional binding with the residence management system through "association of residence unique identification code and management system code", ensuring that the boundary is only effective for the room. Finally, the boundary coordinate set is stored in an encrypted chip locally to the robot to prevent external tampering or illegal reading, ensuring the security of the authority data. This design makes the active boundary a "dynamically generated, locally stored, and room-specific" secure asset, providing an unforgeable spatial verification basis for subsequent emotional function activation.

[0060] In some embodiments of the present application, in step S120, the positioning information of the emotional robot is acquired in real time, including the following steps.

[0061] In step S310, a laser radar is used to scan the indoor environment at a preset frequency, output point cloud data, and extract plane features as laser radar data.

[0062] In step S310, the indoor environment is periodically scanned by a laser radar to obtain high-precision environmental geometric information, which is the basis for realizing autonomous positioning and spatial perception of the robot. The laser radar emits laser beams at a preset frequency (such as 10 times per second) and receives reflected signals to generate point cloud data containing tens of thousands of three-dimensional coordinate points, which can accurately depict the contours and distances of static obstacles such as walls, furniture, and door frames in the room. By filtering, segmenting, and clustering the point cloud data, large-scale plane features such as walls and floors are further extracted, which have high stability and repeatability and can be used as reliable references for robot positioning. Compared with other sensors, the laser radar is not affected by changes in light, and can work stably even in night or low-light environments, with a ranging accuracy of centimeters. This step provides a high-fidelity environmental model for subsequent boundary recognition, path planning, and positioning fusion, and is a key data source for constructing "active boundaries" and verifying the effectiveness of the robot's position.

[0063] In step S320, an RGB-D image is collected using a vision sensor, and vision odometry data is generated as vision sensor data through an ORB feature point matching algorithm.

[0064] In step S320, visual perception capability is introduced to make up for the deficiencies of laser radar in texture information and dynamic environment understanding. The visual sensor (such as a depth camera) synchronously collects the RGB color image and D depth information of the environment to form an RGB-D data stream. Through the ORB (Oriented FAST and Rotated BRIEF) feature point extraction and matching algorithm, the system can identify the same corner, edge and other significant features between consecutive frames, and calculate the relative pose change of the robot during movement, that is, the visual odometry (VO) data. The ORB algorithm has the advantages of high computational efficiency, rotation invariance and robustness to light changes, and is suitable for real-time operation in small and medium-sized structured environments such as homes. The visual sensor not only provides rich semantic information (such as identifying objects such as beds, tables and doors), but also captures transparent objects (such as glass windows) or soft obstacles (such as curtains) that are difficult to detect by laser radar. The generated visual odometry data provides high-frequency pose estimation for positioning fusion, especially when the robot moves or rotates for a short distance, showing excellent dynamic response capability, and enhancing the continuity and delicacy of the overall positioning system.

[0065] In step S330, the UWB positioning module receives anchor point signals and outputs three-dimensional coordinate raw values as UWB positioning data.

[0066] In step S330, high-precision and low-delay absolute position measurement is achieved through ultra-wideband (UWB) technology, providing a global reference for multi-source positioning fusion. The UWB positioning module receives wireless pulse signals from UWB anchors deployed at the corners of the residence, calculates the distance between the robot and each anchor point using TDoA (Time Difference of Arrival) or ToF (Time of Flight) algorithms, and then solves the absolute coordinates of the robot in three-dimensional space through triangulation or multilateration. UWB technology has nanosecond-level time resolution, strong anti-multipath interference capability and centimeter-level positioning accuracy (usually error ≤ 30 cm), and can maintain stable output even in complex indoor environments. Unlike laser and visual methods that rely on environmental features, UWB provides "true value" coordinates independent of environmental structure, unaffected by furniture movement, light changes or temporary obstructions. The UWB positioning data output in this step serves as an "anchor point" in the fusion framework, effectively correcting the cumulative drift that may occur in laser and visual systems over a long period of time, ensuring that the robot maintains high-precision positioning capability throughout the rental period.

[0067] In step S340, an extended Kalman filter algorithm is used to perform spatio-temporal registration and fusion of laser radar data, visual sensor data and UWB positioning data, and output the positioning information of the emotional robot.

[0068] In step S340, the optimal fusion of multi-sensor data is realized by an Extended Kalman Filter (EKF) algorithm, and a high-precision and high-robustness comprehensive positioning result is output. EKF is a classic nonlinear state estimation algorithm, which can process data from different sensors with different frequencies and noise characteristics, fully exerting the advantages of each sensor: UWB provides global stability, laser radar ensures geometric accuracy, and visual sensor enhances dynamic response. The final output positioning information not only has high precision (≤0.3 meters) and low delay, but also has strong anti-interference capability - even if a sensor temporarily fails (such as visual failure in darkness, UWB signal blocked), the system can still rely on other sensors to maintain reliable positioning, providing a solid technical guarantee for function control within the "activated boundary".

[0069] In some embodiments of the present application, in step S340, an Extended Kalman Filter algorithm is used to perform spatio-temporal registration and fusion of laser radar data, visual sensor data and UWB positioning data, and to output the positioning information of the emotional robot, including the following steps.

[0070] In step S410, based on the UWB positioning data, the first position coordinate of the emotional robot is predicted by combining the robot motion model.

[0071] In step S410, the high-precision absolute position information provided by UWB and the kinematic model of the robot itself are used to preliminarily estimate the position at the current time. UWB positioning data has centimeter-level precision and low delay characteristics, and can provide real-time three-dimensional coordinates of the robot in the global coordinate system as a reliable initial value for state estimation. On this basis, the system combines the motion model of the robot's wheeled drive (such as differential model or omni-directional movement model), and predicts the ideal position change at the current time according to the pose, linear velocity and angular velocity, etc. control input at the last time. This prediction process not only utilizes external observation data (UWB), but also integrates internal motion information to form a "priori estimation" of the robot's pose, i.e. the "first position coordinate". This coordinate serves as the starting point for subsequent correction steps, effectively reducing the risk of cumulative error caused by relying solely on the motion model, while providing a stable and reliable initial state for multi-sensor fusion, ensuring that the filtering algorithm can still converge quickly in complex environments.

[0072] In step S420, based on the laser radar data and the visual sensor data, a residual equation is constructed to correct the first position coordinate and perform iterative optimization to obtain the second position coordinate of the emotional robot.

[0073] In step S420, the predicted value in step S410 is refined by using the environmental feature information provided by the laser radar and the visual sensor to obtain a higher-precision final positioning result. The system matches the currently collected laser radar point cloud data with the known residence map (or the locally constructed map in real time) to calculate the deviation between the wall surface, corner and other features actually observed by the robot and the predicted position; at the same time, the relative pose change of the robot is obtained by analyzing the continuous RGB-D image frames through the ORB feature point matching algorithm to generate visual odometry data. These observation data are used to construct a residual equation (i.e. the difference between the observation value and the predicted value) as a feedback signal input into the EKF framework. The filter dynamically adjusts the weight according to the size of the residual and the covariance matrix, and the "first position coordinates" are weighted and corrected, and the real pose is continuously approached through iterative optimization, and finally the "second position coordinates" are output. This process significantly improves the positioning accuracy and stability, especially when the robot turns, accelerates or temporarily blocks the UWB signal, it can still rely on environmental features to maintain high-precision positioning, avoiding the limitations of a single sensor.

[0074] In step S430, the second position coordinates are continuously monitored. If the coordinate drift does not exceed the preset drift threshold, and the matching degree of the laser radar data and the visual sensor data is not less than the preset matching degree threshold, it is confirmed that the second position coordinates are valid, and they are taken as the positioning information of the emotional robot; otherwise, a sensor failure alarm is triggered and the UWB single-mode positioning is enabled, and the three-dimensional coordinate original value is taken as the positioning information of the emotional robot.

[0075] In step S430, the system continuously monitors the dynamic performance of the "second position coordinates", and focuses on checking two indicators: one is the coordinate drift (i.e. the mutation amplitude of the position in a short time), which exceeds the preset threshold, indicating that the laser or visual system is disturbed abnormally (such as strong light directly shining on the camera, furniture suddenly moving to cause feature mismatch); the second is the matching degree between the laser radar and the visual sensor data (such as the consistency of the point cloud and the image features, the re-projection error, etc.), which is below the threshold, indicating that there is a conflict between the multi-source data, and the fusion result is unreliable. When both indicators meet the conditions, the system determines that the fusion positioning result is valid, and outputs the coordinates as the final positioning information. Otherwise, once an abnormality is detected, a sensor failure alarm is triggered to prevent false activation or false hibernation caused by false positioning, and the system automatically switches to the UWB single-mode positioning mode, and directly uses the three-dimensional coordinate original value output by the UWB module as a replacement scheme. This "main fusion + backup single mode" redundant design ensures that the robot can still maintain basic positioning ability in extreme environments, guarantees service continuity and safety, and reflects the deep consideration of the system in reliability and fault tolerance.

[0076] In some embodiments of the present application, the specific process of the triple verification in step S130 includes the following steps.

[0077] (1) User identity verification: Based on the user's login request, the real-time facial features or ID card chip information of the user are collected, compared with the user's biological feature template pre-stored in the management system, and when the similarity exceeds the preset similarity threshold and the living body detection is passed, the identity verification pass signal is output.

[0078] Specifically, in the user identity verification step, the operator's biological identity is accurately identified and anti-fake detected, which is the first security barrier to ensure that the emotional robot only provides services to the legal occupant. When the user initiates a login request, the system collects the real-time face image through the camera mounted on the robot, or reads the encrypted information (such as the photo of the certificate holder, name, etc.) in the ID card chip through the NFC module, and extracts the corresponding biological feature vector. Then, the feature is compared with the user's biological feature template pre-registered and encrypted stored in the residence management system. Only when the similarity exceeds the preset threshold (such as more than 95%) is it considered to be a successful match. More importantly, the system simultaneously performs a living body detection mechanism, which effectively prevents photo, video, mask and other non-living body deception methods by analyzing micro-expression changes, infrared thermal imaging, 3D depth map or blinking actions. This double verification (feature comparison + living body detection) not only improves the accuracy of identity recognition, but also significantly enhances the anti-attack ability of the system, ensuring that only the real and legal occupant can pass the identity verification link, laying a credible foundation for subsequent permission control.

[0079] (2) Residence ownership verification: The communication module of the emotional robot is called to interact with the electronic door lock of the residence in the near field, and when the communication distance does not exceed the preset distance threshold and the continuous communication time length is not less than the preset time threshold, the residence physical code returned by the electronic door lock is received, and consistency check is performed with the unique identification code of the residence in the encrypted authorization information. When the check is passed, the ownership verification pass signal is output.

[0080] Specifically, in the residence ownership verification step, the system calls the communication module (e.g., Bluetooth module) built in the robot to actively establish a short-range wireless connection with the electronic door lock installed on the door of the residence. The communication process is strictly limited within a preset distance threshold, and the duration of continuous communication is required to be no less than a preset threshold (e.g., 3 seconds) to exclude the possibility of signal reflection, relay attack, or long-distance eavesdropping. The electronic door lock returns its built-in "residence physical code" after confirming the legality of the connection, which corresponds one-to-one with the "residence unique identification code" in the "encrypted authorization information" issued by the management system. The system performs consistency verification, and only when the two are completely matched, is the user determined to have the ownership of the room. This "human-robot-lock" three-party near-field interaction mechanism simulates the logic of the unlocking behavior in the real check-in scene, ensuring that the robot is only allowed to activate when the user actually enters and holds the key (electronic identity) of the residence, greatly improving the physical credibility of the permission verification.

[0081] (3) Positioning validity verification: compare the real-time positioning information obtained with the activation boundary. When the emotional robot continuously stays within the activation boundary for more than a preset activation duration threshold, output a positioning validity verification pass signal.

[0082] Specifically, the system continuously compares the real-time positioning information output by step S340 with the activation boundary generated in step S250 to determine whether the robot is located within the legal range of the current rented residence. Unlike instantaneous judgment, this step introduces the design of "staying within the activation boundary for more than a preset activation duration threshold" (e.g., 10 seconds), effectively filtering out accidental situations such as the robot passing through the doorway temporarily, being temporarily moved out of the room, or positioning jumping, and avoiding false positives. Only when the robot stays in the residence for a long enough time, the system determines that its position state is valid. This mechanism ensures that the emotional interaction function is strictly dependent on the physical coexistence relationship between the robot and the user, embodying the core concept of "service with space". At the same time, this verification complements the identity and ownership verification, forming a three-layer spatial trust chain of "person in the room, clear ownership, and robot in place".

[0083] (4) The judgment condition for passing the three-layer verification is that the identity verification pass signal, the residence ownership verification pass signal, and the positioning validity verification pass signal are all valid, and the current time is within the rental period time range in the rental status information.

[0084] Specifically, by setting the judgment condition of triple verification, the final decision logic of function activation is defined, which is the integration and closed loop of the entire security verification system. The system requires that the "identity verification signal, residence ownership verification signal and positioning validity verification signal" must be effective at the same time, and the current time must be within the "rent period start and end time" range provided by the management system, and the four conditions are indispensable. This design eliminates the possibility of bypassing or forging a single verification link, achieving multi-factor strong binding security control. For example, even if someone can impersonate the identity information, if he is not in the residence or does not have the door lock permission, he still cannot pass the verification; conversely, even if the robot is mistakenly placed in other rented residences, if the user identity does not match, it cannot be activated. In addition, the check of the rent period time range further increases the constraint of the time dimension, ensuring that the service is only available within the legal rental period and automatically disabled after termination. This comprehensive decision mechanism deeply integrates user identity, physical space, device status and time window, building a high-security and high-specificity access control model, which fundamentally guarantees the privacy and compliance of the emotional robot service.

[0085] In some embodiments of the present application, in step S140, the emotional interaction function includes a voice chat module and an emotion recognition engine, wherein the voice chat module supports real-time interaction in multiple languages, integrates a natural language processing model, supports context semantic understanding and personalized dialogue style configuration; the emotion recognition engine collects user facial expression features through a camera and voice tone features through a microphone, uses a deep learning model to recognize user emotional state, and dynamically adjusts the interaction strategy according to the emotional state.

[0086] Specifically, the voice chat module and the emotion recognition engine together constitute the core capability of the emotional robot to realize deep humanized interaction. The voice chat module supports real-time interaction in multiple languages, integrates an advanced natural language processing model, can not only accurately understand the literal semantics of the user, but also can combine the context to perform intent recognition and logical reasoning, and realize coherent and natural multi-round dialogue. At the same time, the module supports personalized dialogue style configuration, which can adjust different modes such as warm companionship, humorous and interesting or professional advice according to user preferences, so that the interaction has more emotional temperature and customized features, truly surpassing the mechanical response of traditional voice assistants and moving towards intelligent emotional companionship.

[0087] The emotion recognition engine collects facial expression features through the camera and captures voice tone changes through the microphone, and uses a deep learning model to recognize the emotional state of the user in multiple dimensions. The system can not only analyze micro-expressions such as eye contact and mouth corners, but also perceive emotional fluctuations from speech rate, pitch, and pauses, and achieve all-weather and all-scene emotional understanding. Based on the recognition results, the robot can dynamically adjust the interaction strategy, such as actively comforting the user when they are anxious or sharing interesting content when they are happy, to achieve intelligent response according to the situation. This multi-modal emotion perception and adaptive feedback mechanism that combines vision and hearing enables the robot to have active care and empathy, significantly improving the emotional value of the service and the user experience.

[0088] In some embodiments of the present application, in step S140, the local privacy data storage function adopts a hardware encryption mechanism. Specifically, the privacy data generated during the emotional interaction is collected by the sensor, encrypted in real time by the encryption chip built-in the emotional robot, and stored in an independent encryption partition. The access to the encryption partition needs to verify the user session number and the validity period of the temporary permission package at the same time, the data retention time does not exceed the rental period of the residence, and only local reading is supported, external data export is prohibited.

[0089] The local privacy data storage function in the present application fully guarantees the security and privacy of user emotional interaction data through a multi-level hardware and software cooperative mechanism. First, at the data generation source, all sensitive information such as voice, expression, and emotion analysis collected by cameras, microphones, and other sensors is processed in real time by the special encryption chip built-in the robot. The encryption chip uses high-strength algorithms (such as AES-256) to ensure that the original data is converted into ciphertext at the moment of collection, and even if the storage medium is physically stolen, it cannot be restored. The encrypted data is stored in an independent encryption partition, which is isolated from other system areas in terms of physics or logic, has the characteristics of tamper resistance and unauthorized access prevention, effectively prevents data leakage caused by malicious programs or system vulnerabilities, and builds an end-to-end security closed loop from collection to storage.

[0090] Secondly, the system employs strict access control and lifecycle management mechanisms to ensure that the use of privacy data remains under control and compliant. Access to encrypted partitions requires verification of both the "user session number" and the "temporary permission package validity period," implementing two-factor dynamic authorization to ensure that only the currently renting, legitimate user can decrypt and use their exclusive data during the rental period, preventing unauthorized access across users or time periods. More importantly, the retention period for all privacy data is strictly limited to the rental period of the residence; it is automatically deleted upon the end of the rental period and will not be retained long-term or used for other purposes. Simultaneously, the system prohibits any form of external data export, including USB, Bluetooth, Wi-Fi, or cloud synchronization, ensuring that data can only be read locally and never leaves the device. This "local storage, time-limited availability, and use-and-destroy" full lifecycle management strategy fully adheres to the principles of data minimization and privacy protection, fundamentally eliminating the risks of data misuse, secondary use, and remote monitoring, providing users with a truly safe and trustworthy environment for emotional companionship services.

[0091] In some embodiments of this application, the triggering conditions for automatically entering sleep mode in step S150 include the following.

[0092] (1) First triggering condition: If the location information of the emotional robot is detected to exceed the activation boundary and the duration exceeds the preset departure time threshold, it is determined to be "outside the activation boundary".

[0093] The first trigger condition continuously monitors whether the robot's location information exceeds the activation boundary. Combined with a design that limits the duration of departure to a preset threshold, this achieves an intelligent identification and anti-false alarm mechanism for physical separation from the space. This mechanism ensures that the robot is only considered "outside the activation boundary" after it has been truly moved out of the residence and stably remained in the external area for a period of time (e.g., more than 30 seconds). This effectively filters out false triggers caused by momentary interference such as brief signal drift, location jumps, or the robot briefly stopping at the doorway. Once a boundary breach is confirmed, the system immediately initiates a hibernation process to prevent the emotional interaction function from being used in unauthorized spaces (such as corridors, other residences, or outside the residence), eliminating the risk of privacy data being collected or leaked in non-private environments. This condition embodies the core security logic of "service terminates with space," ensuring the exclusivity of the emotional service and the consistency of the physical boundary.

[0094] (2) Second triggering condition: The residence rental status information pushed by the management system is changed to termination.

[0095] The second trigger condition relies on the residence rental status change information pushed by the management system. When the system detects that the status is updated to termination, the hibernation mode is automatically triggered, which is a key mechanism to synchronize the service life cycle with the residence business process. This design ensures that the termination of the robot function does not depend on user-initiated operation or device state judgment, but is uniformly controlled by the residence background management system, which has high authority and reliability. Even if the user does not manually turn off the robot or the device is still in the room, as long as the rental relationship is formally ended, the system will be forced to enter the hibernation state. This not only prevents the risk of privacy leakage caused by the residual data of the previous tenant to the subsequent cleaning, inspection and other links, but also avoids the possibility of the new tenant accidentally touching the previous interaction record. At the same time, the deep integration of this condition with the management system makes the robot an organic part of the digital operation system of the residence, improving the overall management efficiency and service automation level.

[0096] (3) The third trigger condition: receiving the "end use" instruction of the user.

[0097] The third trigger condition allows the user to actively send the "end use" instruction to trigger the hibernation mode, giving the user complete control over personal privacy and embodying the user-centered design philosophy. The user can issue the instruction through voice commands, mobile phone APP or robot body buttons, and the system will execute the hibernation process immediately after verifying the legality of the instruction. This mechanism meets the user's needs for temporary or early termination of services during the rental period, such as when absolute silence is needed, private conversations are conducted, or rest is prepared, all sensing and interaction functions can be actively turned off to gain a sense of psychological security and control. This condition is not only a technical function switch, but also an important interaction design to improve user experience and enhance trust, allowing users to always have control over smart devices and avoiding resistance caused by the feeling of being monitored.

[0098] When any of the trigger conditions is met, the system detects the trigger signal of the hibernation mode and immediately performs a series of hard safety operations: first, the hardware power supply of the microphone, camera and positioning sensor is cut off, not just software closed, to ensure that the sensor is completely disabled and to eliminate security risks such as background recording and hidden shooting; second, the emotional interaction function interface is closed to prevent any external calls or remote access. Most importantly, the system calls the physical erasure algorithm to perform three overwrites (such as writing 0 first, then 1, and finally a random number) on the encrypted partition storing private data, which is an irreversible data destruction method in line with national information security standards, effectively preventing the recovery of original data through professional tools. After cleaning, a data destruction log containing the timestamp, operation type, device number and destruction result is generated and uploaded to the management system for record, forming an auditable privacy processing record. This complete "power off - destruction - trace" closed-loop mechanism ensures that user data is truly "digitally forgotten" after the service is terminated, providing comprehensive protection for the last line of defense of privacy security.

[0099] In summary, the emotion robot activation method for the residence scene provided by the embodiments of the present application has the following technical effects.

[0100] The method realizes intelligent management of the emotion robot service by deeply fusing a residence management system, physical space feature recognition, and a multi-factor security verification mechanism. The system no longer relies on traditional static electronic fences or single identity authentication, but dynamically generates an activation boundary in units of physical rooms based on residence door magnetic signals, Wi-Fi fingerprints, UWB positioning, and the like, and combines user identity verification, residence ownership verification, and positioning effectiveness verification for triple verification, so that only a legal occupant can activate emotion interaction functions in the residence rented by the occupant, thereby fundamentally eliminating security risks such as cross-room use, remote control, and identity impersonation.

[0101] In the service process, the voice chat module and the emotion recognition engine work cooperatively to support multilingual interaction, context understanding, and emotion adaptive response, and provide personalized and temperature-sensitive emotional companionship experience. At the same time, all private data are encrypted in real time by an embedded encryption chip, stored in an independent encryption partition, and accessed by double-certificate verification, and the retention time is strictly limited to no more than the rental period, so as to realize minimum data collection and safe control. When the robot is detected to leave the residence, the rental period ends, or the user actively terminates the service, the system immediately cuts off the power supply of the sensor hardware, performs physical-level overwrite erasure on the local storage, generates an auditable data destruction log and uploads it to the management system, and forms a full life cycle privacy protection closed loop from activation to termination. The method not only significantly improves the security, privacy, and user experience of the service, but also builds a dynamic binding logic among the robot, the residence, and the user, and provides a replicable and verifiable technical paradigm for the large-scale landing of AI emotion robots in high-privacy scenes such as residences, which has outstanding innovation and industrial application value.

[0102] It should be noted that the applicable scenarios of the emotion robot activation method for the residence scene provided by the embodiments of the present application include but are not limited to hotel room scenarios, hotel public scenarios, and personal home scenarios.

[0103] Specifically, when the method is applied to a hotel room scenario, the main role is dynamic authorization based on a room rental period and privacy closed loop management, which ensures that emotion interaction functions are only opened to authorized occupants during the rental period, and realizes privacy security and room-specific services in the whole process of "check-in, use, and check-out" through room physical space boundary control and automatic data clearing after check-out.

[0104] When the method is applied to a hotel public scene, the lease state information is by default without a lease state, and the main role is dynamic management based on temporary authorization and the space range of a public area. Through temporary authorization tokens of a user and positioning verification of a virtual boundary of a public area (such as a lobby or a restaurant), temporary emotional interaction permission of a non-resident is realized, and sensitive functions are automatically closed after leaving the public area, thereby balancing service openness and data security in a public scene.

[0105] When the method is applied to a personal home scene, the lease state information is by default without a lease state, and the main role is personalized activation management based on long-term authorization of a family user and a special boundary of a home space. Through biological feature verification (such as a face or a fingerprint) of a family member and a fixed activation boundary generated by a home floor plan, long-term permission of a family member is realized, and access of a non-family member is limited, and an intelligent home system is linked to realize automatic privacy protection of “activation when a person is at home and hibernation when a person leaves home”.

[0106] It should be noted that in each specific embodiment of the present application, when relevant processing needs to be performed according to user information, user behavior data, user historical data, and user location information, and other data related to the identity or characteristics of the user, the user's permission or consent will be obtained first, and the collection, use, and processing of these data will comply with relevant laws, regulations, and standards of the country and region. In addition, when the embodiments of the present application need to obtain sensitive personal information of the user, the user's separate permission or separate consent will be obtained through a pop-up window or a jump to a confirmation page, and after obtaining the separate permission or separate consent of the user, the necessary user-related data for enabling the embodiments of the present application to normally operate will be obtained.

[0107] In some alternative embodiments, the functions / operations mentioned in the block diagram can not occur in the order mentioned in the operation schematic diagram. For example, depending on the functions / operations involved, two blocks that are shown continuously can actually be executed substantially simultaneously or the blocks can sometimes be executed in reverse order. In addition, the embodiments presented and described in the flowcharts of the present application are provided by way of example, and the purpose is to provide a more comprehensive understanding of the technology. The disclosed method is not limited to the operations and logical flows presented herein. Alternative embodiments are contemplated in which the order of various operations is changed and in which sub-operations described as part of larger operations are independently executed.

[0108] Furthermore, although the present application is described in the context of functional modules, it is understood that one or more of the functions and / or features can be integrated in a single physical device and / or software module, or one or more functions and / or features can be implemented in separate physical devices or software modules. It is also understood that a detailed discussion of the actual implementation of each module is unnecessary to an understanding of the present application. Rather, the properties, functions and internal relationships of the various functional modules disclosed in the devices shown herein are deemed to be illustrative of the principles of the present application. Accordingly, the present application is not limited to the specific embodiments described herein, but rather only by the claims that follow. It is also understood that the specific concepts disclosed herein are merely illustrative of the principles of the present application and are not intended to limit the scope of the application, which is defined solely by the claims that follow.

[0109] If the functions are implemented in software, the functions can be stored in or implemented as one or more computer program products, which can be incorporated into a computer-readable medium for use by or in connection with an apparatus, method, or system as described herein. The computer-readable medium can be a computer- only medium, a partially software and partially hardware medium, or a medium that contains both software and hardware. The computer-readable medium can be any medium that can contain, store, or transport the program for use by or in connection with the computer. The computer-readable medium can be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, or a propagation medium. The computer-readable medium can be a computer program product that can be traded from one owner / manufacturer to another, can be bought and sold, and / or can be leased, rented, loaned, etc.

[0110] The logic and / or steps represented in the flow diagrams and / or described herein, for example, can be considered as a sequence of executable instructions stored in a computer readable medium, which can be executed by a program executing system, apparatus, or device, such as a computer-based system, a processor-based system, or other system that can fetch the instructions from the instruction executing system, apparatus, or device and execute the instructions. For purposes of this specification, a "computer readable medium" can be any apparatus that can contain, store, communicate, propagate, or transport the program for use by or in connection with the program executing system, apparatus, or device.

[0111] More specific examples (a non-exhaustive list) of the computer-readable medium include the following: an electrical connection (electronic) having one or more wires, a portable computer diskette (magnetic), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can also be paper or another suitable medium upon which the program is printed, as the program can be electronically captured, for example, via optical scanning of the paper or other medium, then compiled, interpreted, or otherwise processed in a suitable manner, if necessary, and stored in a computer memory.

[0112] It should be understood that aspects of the application can be implemented in hardware, software, firmware or combinations thereof. In the above described embodiments, various steps or methods can be implemented in software or firmware that is stored in memory and executed by a suitable

[0113] In the above description of the present application, reference has been made to descriptive terms such as "one embodiment / scheme", "another embodiment / scheme" or "some embodiments / schemes" etc. which can mean that a particular feature, structure, material or characteristic described in connection with the embodiment or example is included in at least one embodiment or example of the application. The illustrative examples described above do not necessarily all refer to the same embodiment or example of the application. Furthermore, the particular features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0114] While the embodiments of the present application have been shown and described, it is to be understood that various modifications, substitutions, combinations, and alterations can be made to the embodiments without departing from the spirit and scope of the present application, which is defined by the appended claims and their equivalents.

[0115] The above is a specific description of the preferred embodiments of the present application, but the present application is not limited to the embodiments, and those skilled in the art can make various equivalent modifications or replacements without departing from the spirit of the present application, and these equivalent modifications or replacements are included in the scope defined by the claims of the present application.

Claims

1. An emotional robot activation method for a dwelling scene, characterized by, The method is executed by an emotional robot deployed in a residence, comprising: Accessing the management system of the residence, obtaining the rental status information of the current residence and the encrypted authorization information of the user; Based on the rental status information, combined with the space feature identification of the residence, the activation boundary is dynamically generated in the unit of the physical space of the residence, and the positioning information of the emotional robot is obtained in real time; Based on the rental status information, the encrypted authorization information, the activation boundary and the positioning information, the three verifications of user identity, residence ownership and positioning validity are carried out; After the three verifications, the emotional interaction function and the local privacy data storage function of the emotional robot are activated and opened; When the trigger signal of the hibernation mode is detected, the emotional robot automatically enters the hibernation mode, closes the sensor and clears the local privacy data. 2.The emotional robot activation method of a shelter scene according to claim 1, wherein, The process of accessing the management system of the residence includes: Through the HTTPS protocol, an encrypted communication connection is established with the management system, and a registration request including the unique device code of the emotional robot is sent; after the management system verifies the legality of the device, the rental status information of the current residence and the encrypted authorization information of the user are pushed in real time through the WebSocket protocol; The rental status information includes the start time and end time of the rental period; The encrypted authorization information includes the unique identification code of the residence, the hash value of the user's identity card and the dynamic authorization token, wherein the validity period of the dynamic authorization token is bound with the rental period of the residence. 3.The emotional robot activation method of a shelter scene according to claim 1, wherein, The space feature identification is selected from at least one of the door magnetic state signal of the residence, the indoor Wi-Fi hotspot fingerprint and the UWB positioning anchor point, wherein: The indoor Wi-Fi hotspot fingerprint is the signal strength distribution characteristics of the unique MAC address access point deployed in the residence, which is denoised by Kalman filtering algorithm to construct the fingerprint library, the signal sampling interval is not more than the preset interval threshold, and the positioning resolution is not more than the preset resolution threshold; The UWB positioning anchor point is a super wide band positioning base station installed at the four corners of the residence, which supports TDoA ranging mode, and the positioning error is not more than the preset error threshold, and the coordinates of the UWB positioning anchor point are mapped to the local coordinate system of the residence after coordinate conversion. 4.The emotional robot activation method of a dwelling scene according to claim 3, wherein, Based on the rental status information, combined with the space feature identification of the residence, the activation boundary is dynamically generated in the unit of the physical space of the residence, comprising: Based on the rental status information, the residence floor plan data issued by the management system is received; Based on the space feature identification of the residence and the residence floor plan data, the polygon boundary in the unit of the physical space of the residence is generated by the boundary fitting algorithm; According to the polygon boundary, the laser radar point cloud feature points of the residence wall corner are extracted, the wall plane equation is fitted, and the four corner vertex coordinates are determined as physical feature points; Combined with the signal mutation threshold of the Wi-Fi hotspot fingerprint and the distance intersection of the UWB anchor point, virtual feature points of non-physical boundary are supplemented; The physical feature points and virtual feature points are fitted by the least square method to generate the boundary coordinate set as the activation boundary, and the activation boundary is associated with the unique identification code of the residence and the management system code, and is stored in the local encryption chip of the robot. 5.The emotional robot activation method for a shelter scene according to claim 1, wherein, The real-time acquisition of the positioning information of the emotional robot comprises: scanning an indoor environment at a preset frequency by using a laser radar, outputting point cloud data and extracting a plane feature as laser radar data; collecting an RGB-D image by using a visual sensor, and generating visual odometry data as visual sensor data by using an ORB feature point matching algorithm; receiving an anchor point signal by using a UWB positioning module, and outputting a three-dimensional coordinate original value as UWB positioning data; adopting an extended Kalman filtering algorithm to perform spatio-temporal registration fusion on the laser radar data, the visual sensor data and the UWB positioning data, and outputting the positioning information of the emotional robot. 6.The emotional robot activation method of a shelter scene according to claim 5, wherein, The spatio-temporal registration fusion on the laser radar data, the visual sensor data and the UWB positioning data by using the extended Kalman filtering algorithm to output the positioning information of the emotional robot comprises the following steps: based on the UWB positioning data, a first position coordinate of the emotional robot is predicted by combining a robot motion model; a residual equation is constructed based on the laser radar data and the visual sensor data, the first position coordinate is corrected, and iterative optimization is performed to obtain a second position coordinate of the emotional robot; the second position coordinate is continuously monitored, if the coordinate drift amount does not exceed a preset drift amount threshold, and the matching degree of the laser radar data and the visual sensor data is not less than a preset matching degree threshold, it is confirmed that the second position coordinate is valid, and it is taken as the positioning information of the emotional robot; otherwise, a sensor fault alarm is triggered and a UWB single-mode positioning is enabled, and the three-dimensional coordinate original value is taken as the positioning information of the emotional robot. 7.The emotional robot activation method of a shelter scene according to claim 1, wherein, The specific process of the triple verification comprises: user identity verification: based on a login request of a user, real-time face features or identity card chip information of the user are collected, and are compared with a user biological feature template pre-stored in a management system, when a comparison similarity exceeds a preset similarity threshold and a living body detection is passed, an identity verification pass signal is output; residence ownership verification: a communication module of the emotional robot is called, near-field data interaction is performed with an electronic door lock of a residence, a communication distance does not exceed a preset distance threshold and a continuous communication time length is not less than a preset time length threshold, a residence physical code returned by the electronic door lock is received, and a consistency check is performed on the residence physical code and a residence unique identification code in the encrypted authorization information, when the check is passed, an ownership verification pass signal is output; positioning validity verification: the real-time acquired positioning information is compared with the activation boundary, when the emotional robot continuously stays in the activation boundary for more than a preset activation time threshold, a positioning validity verification pass signal is output; the judgment condition for the triple verification passing is that the identity verification pass signal, the residence ownership verification pass signal and the positioning validity verification pass signal are simultaneously valid, and a current time is within a lease time range in lease state information. 8.The emotional robot activation method of a shelter scene according to claim 1, wherein, The emotional interaction function comprises a voice chat module and an emotion recognition engine, wherein: The voice chat module supports real-time interaction in multiple languages, integrates a natural language processing model, supports context semantic understanding, and supports personalized dialogue style configuration; The emotion recognition engine collects facial expression features through a camera and voice tone features through a microphone, uses a deep learning model to recognize the user's emotional state, and dynamically adjusts the interaction strategy according to the emotional state. 9.The emotional robot activation method of a shelter scene according to claim 1, wherein, The local privacy data storage function uses a hardware encryption mechanism: The privacy data generated during emotional interaction is collected by sensors, encrypted in real time by the encryption chip built into the emotional robot, and stored in an independent encrypted partition; Access to the encrypted partition requires simultaneous verification of the user session number and the validity period of the temporary permission package, the data retention period does not exceed the lease period of the residence, and only local reading is supported, external data export is prohibited. 10.The emotional robot activation method of a shelter scene according to claim 1, wherein, The trigger conditions for automatically entering the sleep mode include: First trigger condition: Detecting that the positioning information of the emotional robot exceeds the activation boundary and the duration exceeds the preset leave duration threshold, determining that it is "outside the activation boundary"; Second trigger condition: The residence lease status information pushed by the management system changes to termination; Third trigger condition: Receiving the "end use" instruction of the user; When any trigger condition is met, the sleep mode trigger signal is detected, the emotional robot immediately cuts off the hardware power supply of the microphone, camera, and positioning sensor, closes the emotional interaction function interface, and performs three overwrites on the encrypted partition through a physical erasure algorithm, generates a data destruction log after the cleaning is completed, and uploads it to the management system.