A power bank security data transmission method based on NFC communication
Patent Information
- Application Number
- CN202511924958.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-19
- Publication Date
- 2026-08-18
- Estimated Expiration
- 2045-12-19
AI Technical Summary
传统充电宝缺乏全生命周期数据存储与管理机制,仅能通过简单指示灯或设备端显示基础剩余电量,无法记录电芯电压、工作温度、电路稳定性等关键状态参数;一旦出现过热、鼓包、易燃易爆等异常故障,难以追溯故障发生前的运行轨迹,给安全责任界定与产品优化带来阻碍,同时用户也无法实时获取充电宝核心检测信息以判断使用安全性
本发明所提出的基于NFC通讯的充电宝安全数据传输方法,与现有技术相比,本申请的有益效果在于通过在充电宝关键部件部署多维度传感器,突破传统仅采集充放电电流、剩余电量等基础数据的局限,全面捕捉电芯电压、充放电电流、工作温度、电路稳定性及接口连接状态等核心安全参数,实现从生产出厂到报废回收全流程的持续数据记录,这些全周期安全状态数据完整留存了充电宝正常运行、异常波动、老化衰减等各阶段的状态轨迹,包括电芯性能变化、电路故障前兆、极端工况下的参数异常等关键信息,为后续安全分析、故障溯源提供了完整的数据支撑,该步骤确保了数据的连续性与全面性,避免因信息不全导致的故障原因判断困难,从源头满足了全生命周期安全数据管理的核心需求,为后续标准化处理与安全存储奠定了坚实基础。其次,通过对全周期安全状态数据进行字段规整、格式统一的规范化处理,消除不同传感器数据的格式差异与冗余信息,确保数据具备一致性与可读性;结合NFC安全传输协议完成加密封装,有效抵御数据传输过程中的窃取、篡改风险,弥补了传统方案数据无加密保护的安全漏洞;转换为NDEF兼容格式后,数据可适配各类支持NFC功能的终端设备,打破传统蓝牙传输的距离限制、配对繁琐及兼容性局限。标准化NDEF安全传输数据无需额外格式转换即可直接用于无线传输,既提升了数据读取的便捷性与效率,又避免了传统数据传输中因格式不兼容导致的数据失真或读取失败,该步骤让全周期安全数据具备了统一标准与安全保障,为后续离线存储、多场景读取提供了可靠的格式与安全基础,有效减少数据丢失、泄露或无法识别的风险。然后,通过将标准化NDEF安全传输数据写入双接口非易失性加密存储芯片,非易失性特性确保数据在断电、设备闲置或报废后仍能长期留存,加密芯片则从硬件层面阻断非法数据篡改与窃取,彻底改变传统方案无长期存储机制、数据随设备运行临时存在的弊端。同时,通过分区隔离将不同类型、不同敏感等级的数据分类存储,避免数据交叉泄露;加密索引提升数据检索效率的同时保障索引安全;多重备份机制避免单一存储区域损坏导致的数据丢失,三者协同构建防篡改离线安全数据仓库,该步骤实现了全周期安全数据的稳定存储、安全防护与可靠备份,即使在充电宝长期闲置或部分部件故障的情况下,数据仍能完整、安全保留,满足了全生命周期数据管理与故障溯源对数据安全性、完整性的核心需求。最后,集成NFC射频模块激活被动通信模式,建立加密短距离无线通信链路,确保数据读取过程的安全性;支持触碰唤起HTTP网页与小程序,无需下载APP即可实现快速、便捷的数据交互,降低了用户操作门槛,提升了数据查询的灵活性与实用性,相比传统蓝牙传输需配对、依赖网络的模式,适配更多使用场景。针对短路、过热、鼓包等异常故障导致无法正常通信的场景,采用无损分离方式提取双接口非易失性加密存储芯片,通过加密芯片读取设备获取数据,彻底解决了传统方案故障状态下数据无法读取的核心痛点,这样既满足了用户实时查询数据的需求,又保障了故障溯源时的数据可及性,实现了安全数据留存管理的完整性与可靠性。
Smart Images

Figure CN121692120B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of NFC management technology, and in particular to a secure data transmission method for power banks based on NFC communication. Background Technology
[0002] In recent years, with the popularization of mobile smart devices and the increase in outdoor travel scenarios, the usage frequency of power banks as portable energy storage devices has continued to rise, placing higher demands on their operational status traceability, data storage security, and fault tracing convenience. Traditional power banks lack a full lifecycle data storage and management mechanism, and can only display basic remaining power through simple indicator lights or the device itself, unable to record key status parameters such as cell voltage, operating temperature, and circuit stability. Once abnormal faults such as overheating, bulging, or flammability and explosion occur, it is difficult to trace the operational trajectory before the fault occurred, hindering the determination of safety responsibility and product optimization. At the same time, users cannot obtain the core detection information of the power bank in real time to judge the safety of use.
[0003] Currently, some solutions for power bank status monitoring have been proposed. These solutions mostly collect basic data such as charging and discharging current and remaining power through simple built-in sensors. They are only displayed temporarily during device operation or transmitted briefly via Bluetooth. They do not establish a long-term storage mechanism and lack standardized data encapsulation and secure backup design. However, existing solutions do not adequately consider the needs of full lifecycle data management and fault tracing. They are susceptible to the lack of multi-dimensional sensors and standardized data processing procedures, and cannot comprehensively collect the status parameters of the power bank from production to disposal. Furthermore, the data is not standardized and stored offline, resulting in data loss or unreadable issues. Summary of the Invention
[0004] Therefore, it is necessary for the present invention to provide a secure data transmission method for power banks based on NFC communication in order to solve at least one of the above-mentioned technical problems.
[0005] To achieve the above objectives, a secure data transmission method for power banks based on NFC communication includes the following steps: Step S1: By deploying multi-dimensional sensors on key components of the power bank, the various status parameters of the power bank throughout its entire life cycle, from production to disposal and recycling, are continuously collected to obtain full-cycle safety status data of the power bank, covering cell voltage, charging and discharging current, operating temperature, circuit stability and interface connection status. Step S2: Standardize the power bank's full-cycle security status data by regularizing fields and unifying formats, and complete the encryption encapsulation and NDEF-compatible format conversion in accordance with the requirements of the NFC secure transmission protocol to obtain standardized NDEF secure transmission data. Step S3: Write the standardized NDEF secure transmission data into a dual-interface non-volatile encrypted storage chip according to the secure storage strategy, and build an anti-tampering offline secure data warehouse through partition isolation, encrypted indexing and multiple backup mechanisms; Step S4: Activate the passive communication mode by integrating the NFC radio frequency module inside the power bank to establish an encrypted short-range wireless communication link between the terminal device and the dual-interface non-volatile encrypted storage chip; support the use of NFC to wake up HTTP web pages, enabling rapid data interaction between the power bank and the HTTP web page; support the use of NFC to wake up mini-programs, allowing users to achieve secure data interaction with the power bank without downloading an app; when the power bank experiences short circuits, overheating, or bulging, resulting in communication failure, the dual-interface non-volatile encrypted storage chip is non-destructively separated, and the standardized NDEF secure transmission data stored in the tamper-proof offline secure data warehouse is extracted through the encrypted chip reading device, completing fault tracing and secure data retention management.
[0006] The beneficial effects of this invention are: The NFC-based secure data transmission method for power banks proposed in this invention offers several advantages over existing technologies. Firstly, by deploying multi-dimensional sensors on key components of the power bank, it overcomes the limitations of traditional methods that only collect basic data such as charging / discharging current and remaining power. Secondly, it comprehensively captures core safety parameters such as cell voltage, charging / discharging current, operating temperature, circuit stability, and interface connection status. This enables continuous data recording throughout the entire process, from production to end-of-life recycling. This full-cycle safety status data completely preserves the power bank's status trajectory at each stage, including normal operation, abnormal fluctuations, and aging degradation. It includes key information such as changes in cell performance, precursors to circuit failures, and parameter anomalies under extreme conditions. This provides complete data support for subsequent safety analysis and fault tracing. This step ensures data continuity and comprehensiveness, avoiding difficulties in determining the cause of failure due to incomplete information. It meets the core requirements of full-lifecycle safety data management from the source, laying a solid foundation for subsequent standardized processing and secure storage. Secondly, by standardizing and unifying the fields and formats of the full-cycle security status data, format differences and redundant information from different sensors are eliminated, ensuring data consistency and readability. Encryption and encapsulation using the NFC secure transmission protocol effectively resist the risk of theft and tampering during data transmission, compensating for the security vulnerabilities of traditional solutions lacking encryption protection. After conversion to an NDEF-compatible format, the data is compatible with various NFC-enabled terminal devices, breaking the distance limitations, cumbersome pairing, and compatibility limitations of traditional Bluetooth transmission. Standardized NDEF secure transmission data can be directly used for wireless transmission without additional format conversion, improving the convenience and efficiency of data reading while avoiding data distortion or reading failures caused by format incompatibility in traditional data transmission. This step provides a unified standard and security guarantee for the full-cycle security data, offering a reliable format and security foundation for subsequent offline storage and multi-scenario reading, effectively reducing the risk of data loss, leakage, or unidentifiable data. Then, by writing standardized NDEF secure transmission data into a dual-interface non-volatile encrypted storage chip, the non-volatile nature ensures that the data can be retained long-term even after power failure, device idleness, or scrapping. The encrypted chip blocks illegal data tampering and theft at the hardware level, completely changing the shortcomings of traditional solutions that lack long-term storage mechanisms and data that exists only temporarily during device operation. Simultaneously, different types and sensitivity levels of data are classified and stored through partitioning and isolation to avoid cross-data leakage; encrypted indexes improve data retrieval efficiency while ensuring index security; and multiple backup mechanisms prevent data loss due to damage to a single storage area. These three elements work together to build a tamper-proof offline secure data warehouse. This step achieves stable storage, security protection, and reliable backup of secure data throughout the entire lifecycle. Even if the power bank is idle for a long time or some components fail, the data can still be retained completely and securely, meeting the core requirements of data security and integrity for full lifecycle data management and fault tracing.Finally, an integrated NFC radio frequency module activates the passive communication mode, establishing an encrypted short-range wireless communication link to ensure the security of the data reading process. It supports touch-to-launch HTTP web pages and mini-programs, enabling fast and convenient data interaction without downloading an app. This lowers the user's operational threshold and enhances the flexibility and practicality of data queries. Compared to traditional Bluetooth transmission, which requires pairing and relies on a network, it adapts to more usage scenarios. For scenarios where communication is impossible due to abnormal faults such as short circuits, overheating, or bulging, a lossless separation method is used to extract a dual-interface non-volatile encrypted storage chip. Data is obtained by reading the device through the encrypted chip, completely solving the core pain point of traditional solutions where data cannot be read under fault conditions. This satisfies users' needs for real-time data queries while ensuring data accessibility during fault tracing, achieving the integrity and reliability of secure data retention and management. Attached Figure Description
[0007] Other features, objects, and advantages of the invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings: Figure 1 This is a flowchart illustrating the steps of the secure data transmission method for power banks based on NFC communication according to the present invention. Figure 2 for Figure 1 A detailed flowchart of step S1. Detailed Implementation
[0008] The technical method of the present invention will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without inventive effort are within the scope of protection of the present invention.
[0009] To achieve the above objectives, please refer to Figures 1 to 2 This invention provides a secure data transmission method for power banks based on NFC communication. Please refer to the embodiments of this invention. Figure 1 The diagram shown is a flowchart illustrating the steps of the secure data transmission method for power banks based on NFC communication according to the present invention. In this example, the secure data transmission method for power banks based on NFC communication includes the following steps: Step S1: By deploying multi-dimensional sensors on key components of the power bank, the various status parameters of the power bank throughout its entire life cycle, from production to disposal and recycling, are continuously collected to obtain full-cycle safety status data of the power bank, covering cell voltage, charging and discharging current, operating temperature, circuit stability and interface connection status. In this embodiment of the invention, multi-dimensional sensors are deployed on the positive and negative pins of the power bank's battery cells, the surface of the core chip of the power management unit, the solder joints of the input / output interface circuits, the four corners of the outer casing under stress, and the key connection points of the internal circuit board. The sensor acquisition frequency is set to once every 5 minutes, initiating a continuous acquisition mode from production to disposal. The acquired data includes cell voltage (real-time voltage value of each cell), charging and discharging current (loop current during charging and discharging), operating temperature (surface temperature of core components and internal ambient temperature), circuit stability (circuit resistance and signal transmission attenuation), and interface connection status (number of interface insertions and removals, contact resistance, and connection duration). During the acquisition process, the sensors convert physical quantities into electrical signals, which are transmitted to the power bank's main control unit through internal wiring. The main control unit performs analog-to-digital conversion on the electrical signals and organizes them according to a fixed format of "acquisition timestamp-component identifier-parameter type-value-status marker," forming a continuous data sequence covering the entire lifecycle of the power bank, from production and testing, transportation and storage, daily use, fault repair to disposal and recycling. Ultimately, a unified and complete full-cycle safety status data of the power bank is obtained.
[0010] Step S2: Standardize the power bank's full-cycle security status data by regularizing fields and unifying formats, and complete the encryption encapsulation and NDEF-compatible format conversion in accordance with the requirements of the NFC secure transmission protocol to obtain standardized NDEF secure transmission data. In this embodiment of the invention, the full-cycle security status data of the power bank is standardized. First, duplicate records, invalid null values, and redundant information unrelated to the security status are removed according to the meaning of the fields. Five core fields are retained: collection timestamp, component identifier, parameter type, value, and status marker. The byte length and data format of each field are specified (timestamp is a 14-bit numeric string, component identifier is a 3-bit letter code, parameter type is a 2-bit letter code, value is a 6-bit character, and status marker is a 1-bit number). Considering the data encryption and format compatibility requirements of the NFC secure transmission protocol, the AES-128 encryption algorithm is used to encrypt the value and status marker fields. The encryption key is stored in the power bank's built-in security chip. Subsequently, according to the NDEF protocol specification, the encrypted core fields are concatenated with the plaintext field identifiers to convert them into a binary data format that conforms to the protocol requirements. The data frame structure is set as "field identifier - encrypted data - check bit". The check bit uses a 32-bit cyclic redundancy check code to ensure the integrity and verifiability of the data transmission process. Finally, standardized NDEF secure transmission data that can be directly transmitted via NFC is obtained.
[0011] Step S3: Write the standardized NDEF secure transmission data into a dual-interface non-volatile encrypted storage chip according to the secure storage strategy, and build an anti-tampering offline secure data warehouse through partition isolation, encrypted indexing and multiple backup mechanisms; In this embodiment of the invention, standardized NDEF secure transmission data is written into a dual-interface non-volatile encrypted storage chip according to a secure storage strategy. The total storage capacity of the chip is divided into three independent partitions: a real-time security zone, a historical security zone, and a redundant security zone, with a capacity allocation ratio of 3:4:1. The real-time security zone stores frequently updated data from the past 7 days, the historical security zone stores 180 days of archived data, and the redundant security zone stores encrypted backups of core data. The writing process is executed through the chip's encrypted data interface, employing a strategy of "prioritizing the writing of high-security-level data and storing it in segments according to time order." The amount of data written at one time is limited to 1KB, and the writing interval is set to once every 10 minutes based on the data update frequency. During the writing process, the chip's hardware encryption mechanism is activated to perform secondary encryption on the data. To achieve fast retrieval, an encrypted data index table is built for each partition, recording the data storage address, length, and association relationship. The index table is stored using an independent encryption method. At the same time, an encrypted association mapping table is established between partitions, associating real-time data with historical data and backup data through unique data identifiers, forming multiple backup protections. The chip is configured with partition access control, allowing only the real-time secure zone to have read and write permissions, while other partitions only support reading, and reading requires key verification, ultimately building a tamper-proof, traceable, and highly reliable offline secure data warehouse.
[0012] Step S4: Activate the passive communication mode by integrating the NFC radio frequency module inside the power bank to establish an encrypted short-range wireless communication link between the terminal device and the dual-interface non-volatile encrypted storage chip; support the use of NFC to wake up HTTP web pages, enabling rapid data interaction between the power bank and the HTTP web page; support the use of NFC to wake up mini-programs, allowing users to achieve secure data interaction with the power bank without downloading an app; when the power bank experiences short circuits, overheating, or bulging, resulting in communication failure, the dual-interface non-volatile encrypted storage chip is non-destructively separated, and the standardized NDEF secure transmission data stored in the tamper-proof offline secure data warehouse is extracted through the encrypted chip reading device, completing fault tracing and secure data retention management.
[0013] In this embodiment of the invention, when the power bank is powered on, the built-in NFC radio frequency module automatically detects the power supply voltage and antenna impedance. After confirming that the hardware is ready, it initiates passive communication mode, pre-configuring a fixed HTTP webpage wake-up link and a 16-bit binary format mini-program wake-up identifier. When the terminal device enters the effective NFC communication range (0-5cm), the radio frequency module sends an encrypted detection signal, receives information such as communication capabilities, compatible protocols, and security public keys from the terminal, negotiates and determines the transmission rate and encryption method, and establishes an encrypted short-range wireless communication link. When the terminal device touches the NFC sensing area of the power bank, if the terminal supports webpage wake-up, the link automatically associates and encapsulates the standardized NDEF secure transmission data with the webpage wake-up link, transmits it to the terminal through the link, decrypts the data after receiving it, and automatically wakes up the browser to load the corresponding webpage. The data is displayed on the webpage interface in a preset format, supporting user viewing and export. If the terminal supports mini-program wake-up, the data is associated and encapsulated with the mini-program wake-up identifier. After receiving it, the terminal directly wakes up the corresponding mini-program, allowing users to view security data, fault warning information, and historical records on the mini-program interface without downloading an app. When a power bank experiences a short circuit, overheating, bulging, or other abnormal malfunctions that interrupt NFC communication, a dedicated anti-leakage disassembly tool is used in a dust-free and anti-static safe environment. The disassembly is performed in the following order: "outer shell - fixed structure - non-core circuitry - core circuit board". The encrypted storage chip area is avoided. The chip is separated non-destructively using a low-temperature hot air gun and anti-static tweezers. The chip is then connected to a dedicated reading device. After entering the decryption key, standardized NDEF secure transmission data is extracted from the offline secure data warehouse. After data extraction, encrypted backup and traceability marking are performed to complete fault tracing and secure data retention management.
[0014] Furthermore, as an embodiment of the present invention, reference is made to... Figure 2 As shown, Figure 1 A detailed flowchart of step S1 is shown below. In this embodiment, step S1 includes the following steps: S11: According to the internal structure layout of the power bank, a multi-dimensional sensor array consisting of voltage sensors, current sensors, temperature sensors, humidity sensors and circuit detection sensors is deployed at key positions of the positive and negative terminals of the battery pack, the core chip of the power management unit, the input and output interface circuit and the outer shell. It starts the uninterrupted all-time acquisition mode to capture various operating status information in real time and obtain the original safety status data stream containing multi-source heterogeneous data. In this embodiment of the invention, based on the structural layout of the power bank's internal battery cells arranged in a matrix, the power management unit located in the center of the circuit board on one side of the battery cells, the input / output interface circuits distributed on the edge of the circuit board, and the four corners of the outer shell as areas of concentrated stress, voltage sensors and current sensors are deployed at the positive and negative pins of each battery cell in the battery cell group, circuit detection sensors are deployed at the power supply pins and signal pins of the core chip of the power management unit, temperature sensors and humidity sensors are deployed near the interface contacts of the input / output interface circuits, and temperature sensors and circuit detection sensors are deployed at the four corners of the outer shell and the connection points between the battery cells and the circuit board, forming a multi-dimensional sensor array covering the core components and key locations. The sensors are connected to the power bank's built-in power supply line, and the sensor acquisition frequency is set to once per millisecond, starting an uninterrupted all-time acquisition mode. The sensors directly capture operating status information such as battery cell voltage, charging and discharging current, core chip operating circuit parameters, interface area temperature and humidity, outer shell and connection point temperature, and circuit connectivity status, continuously aggregating to form a multi-source heterogeneous original safety status data stream containing voltage data, current data, temperature data, humidity data, and circuit parameter data.
[0015] S12: The time synchronization protocol is used to perform time axis calibration and synchronization alignment on the heterogeneous data collected by different sensors in the original safety status data stream, eliminating the time deviation caused by the response delay of different sensors and generating time-series aligned data with consistent time dimension. In this embodiment of the invention, by employing the hardware clock synchronization method in the network time synchronization mechanism, the high-precision clock of the main control chip built into the power bank is used as the reference clock. The timestamps corresponding to the data collected by each sensor in the original safety status data stream are extracted. The main control chip sends a clock calibration signal to each sensor to correct the deviation between the internal clock of each sensor and the reference clock. The heterogeneous data collected by different sensors are reordered according to the time axis of the reference clock. The heterogeneous data such as voltage data, current data, and temperature data generated at the same time are marked as associated data of the same time node. The time deviation caused by the response delay of the voltage sensor and the current sensor, and the time difference of the temperature and humidity sensor and the circuit detection sensor is eliminated. Finally, time-aligned data with completely consistent time dimension and containing multiple types of data at each time node is generated.
[0016] S13: Based on the sensor's factory calibration parameters and real-time environmental interference factors, a drift compensation model is established to correct the sensor drift error in the time-series aligned data, eliminate the acquisition deviation caused by environmental interference and equipment aging, and obtain the optimized calibrated time-series data. In this embodiment of the invention, standard calibration parameters of each sensor at the time of manufacture are obtained in advance, including the measurement error range of the voltage sensor, the sensitivity coefficient of the current sensor, and the calibration curve of the temperature sensor. Combined with real-time environmental interference factors such as temperature interference, humidity interference, and electromagnetic interference commonly encountered in the actual use environment of power banks, a deviation compensation model based on the factory calibration parameters is established. The timing alignment data is input into the model, and the model corrects the measurement deviation in the voltage data caused by temperature changes, eliminates the fluctuation deviation in the current data caused by electromagnetic interference, adjusts the error in the temperature data caused by the influence of environmental humidity, and calibrates the drift deviation in the circuit parameter data caused by equipment aging. The model comprehensively eliminates the acquisition deviation caused by environmental interference and equipment aging, and outputs optimized and calibrated timing data with precise correction and significantly improved data accuracy.
[0017] S14: Use feature engineering methods to extract multi-dimensional features from the calibrated time series data, and mine voltage fluctuation features, current change trends, temperature distribution patterns and circuit signal stability information. Focus on identifying short circuit warning features, overheating risk features and abnormal interface connection features to obtain safety feature data that can reflect the safe operating status of the power bank. In this embodiment of the invention, by employing statistical feature extraction and trend feature mining methods in feature engineering, sliding window analysis is performed on voltage data in calibrated time-series data to calculate the maximum, minimum, and fluctuation amplitude of voltage within each window, and to mine voltage fluctuation features such as voltage mutations, sustained high voltage, and sustained low voltage. Linear trend fitting is performed on current data to analyze the current rise rate, fall rate, and stable duration during the charging and discharging stages, and to extract current change trends such as sudden current increases, sudden current decreases, and sustained abnormal current. Regional comparative analysis is performed on temperature data to statistically analyze the temperature distribution range, temperature difference, and heating rate at different locations, and to summarize temperature distribution patterns such as local high temperature accumulation and continuous overall temperature rise. Signal stability analysis is performed on circuit parameter data to detect the duration of circuit conduction and the smoothness of signal transmission, focusing on identifying short-circuit warning features such as voltage mutations accompanied by sudden current increases, overheating risk features such as rapid local temperature rise exceeding a set threshold, and abnormal interface connection features such as frequent fluctuations in circuit parameters and unstable connectivity in the interface area. Finally, safety feature data that comprehensively reflects the short-circuit risk, overheating hazard, interface failure, and normal operation status of the power bank is obtained.
[0018] S15: Classify and systematically archive the safety feature data according to the data collection time, parameter type and component affiliation, establish an encrypted data association index, and generate full-cycle safety status data of the power bank.
[0019] In this embodiment of the invention, by dividing the data into daily time periods according to the chronological order of data collection time, the safety feature data is divided into real-time data for the current day and historical time period data; according to parameter type, the data is divided into voltage fluctuation feature data, current change trend data, temperature distribution pattern data, circuit signal stability data, short circuit warning feature data, overheat risk feature data, and interface abnormal connection feature data; according to component affiliation, the data is divided into cell group related feature data, power management unit related feature data, input / output interface related feature data, and shell related feature data. The classified safety feature data is systematically organized, and a hierarchical archiving method is used to store different categories of data in corresponding partitions of the power bank's built-in storage module. A triple-encrypted data association index based on collection time, parameter type, and component affiliation is established. Through the index, different types of data at the same collection time, different component data of the same parameter type, and different time periods of the same component are associated and mapped to generate full-cycle safety status data covering the entire process of the power bank from startup to shutdown.
[0020] Furthermore, step S2 includes the following steps: We conduct in-depth analysis of the field structure, data type, and relationships of the full-cycle safety status data of power banks. In conjunction with the requirements of the NFC secure transmission protocol, we establish a unified data dictionary mapping relationship, clarify the meaning, format standard, and encrypted transmission rules of each field, and obtain field mapping data. In this embodiment of the invention, a data structure parsing tool is used to perform in-depth analysis of the power bank's full-cycle safety status data. The field structure is defined to include seven core fields: collection timestamp, component identifier, parameter type, feature name, value, status identifier, and association index. Each field is arranged in a fixed order: "collection timestamp - component identifier - parameter type - feature name - value - status identifier - association index". The data types are determined to cover numerical (voltage, current, temperature, fluctuation amplitude, etc.), character (component name, feature name, status description, etc.), and Boolean (interface on / off, fault warning trigger status, etc.). The relationships are defined as: collection timestamp corresponds to association index, component identifier is bound to parameter type, and feature name matches value. Based on the requirements of the NFC secure transmission protocol regarding data format, transmission rate, and encryption standards, a unified data dictionary mapping relationship is established: Field meanings are clearly defined as follows: Acquisition timestamp records the data capture time; component identifier distinguishes components such as battery packs / power management units; parameter type indicates data categories such as voltage / current; feature name describes specific characteristics such as fluctuations / sudden increases; numerical value records measured or extracted results; status identifier reflects normal / abnormal states; and association index associates data from multiple components at the same time. The format standard specifies that the acquisition timestamp is a 14-digit numeric string (year, month, day, hour, minute, second), and the component identifier is a 3-digit letter code (battery pack DXZ, power management unit DYGL, interface J...). K, shell WK), parameter type is 2-letter code (voltage DY, current DL, temperature WD, etc.), feature name is 4-letter code (fluctuation BD, sudden increase ZZ, etc.), value is 6 characters (4 integers + 2 decimals), status identifier is 1 digit (0 normal, 1 abnormal), and associated index is 8-digit code; the encrypted transmission rule setting adopts a symmetric encryption algorithm to encrypt the value and status identifier fields, and the collection timestamp, component identifier, parameter type, feature name, and associated index fields are transmitted in plaintext. The encryption key is stored in the built-in security chip of the power bank, and finally the field mapping data with completely clear field meaning, format standard, and encryption rules are obtained.
[0021] Furthermore, based on field mapping data, duplicate records, invalid fields, and redundant information in the collected data are identified and removed, core security data is retained, data volume is simplified, and optimized streamlined security data is obtained. In this embodiment of the invention, redundant data is removed from the collected data using a data cleaning tool based on field mapping data. By comparing the collection timestamp with the associated index, duplicate records are identified as multiple entries with the same collection timestamp, the same value, and the same status identifier corresponding to the same associated index. Only the earliest such duplicate record is retained, and the rest are deleted. Through field validity verification, invalid fields are identified as fields with empty values, component identifiers not registered in the data dictionary, or feature names that do not match parameter types. The entire data entry containing invalid fields is directly removed. Through information correlation analysis, redundant information is identified as auxiliary description fields unrelated to security status, duplicated component attribute information, and historical redundant indexes that exceed NFC transmission requirements. According to the "core security data retention standard," information corresponding to the six core fields of collection timestamp, component identifier, parameter type, feature name, value, and status identifier is selected and retained, while all auxiliary descriptions, duplicate attributes, and redundant index information are deleted. During the simplification process, the integrity and relevance of each piece of data were verified based on the field mapping data to ensure that the retained data could directly reflect the safe operation status of the power bank. The final result was a 60% reduction in data volume compared to the original data, with no omission of core information.
[0022] Furthermore, according to the preset data type conversion rules, the numerical, character, and boolean data of different formats in the simplified security data are uniformly converted into standard data types that conform to the NDEF protocol requirements, eliminating data format differences and obtaining standard format security data; In this embodiment of the invention, by pre-setting strict data type conversion rules, numeric data is converted into a UTF-8 encoded character string. The integer part retains the actual number of significant digits, and the decimal part is fixed to 2 digits. If the number of digits is insufficient, it is padded with 0s. If the number of digits exceeds the limit, it is truncated by rounding. Character data is directly encoded in UTF-8 to retain the original characters. The length is uniformly defined according to the standard specified by the field mapping data (3 digits for component identifier, 2 digits for parameter type, etc.). If the number of digits is insufficient, it is padded with spaces at the end. If the number of digits exceeds the limit, the specified length of characters is truncated. Boolean data is converted into a 1-digit numeric string (true is converted to 1, false is converted to 0). The simplified security data is uniformly converted according to this rule: numerical voltage data (e.g., 5.12V) is converted to the string "000512", current data (e.g., 2.3A) is converted to the string "000230", temperature data (e.g., 42.5℃) is converted to the string "004250", and fluctuation amplitude (e.g., 0.85) is converted to the string "000085"; character-type component identifiers "DXZ" and "DYGL" retain 3 digits, parameter types "DY" and "DL" retain 2 digits, and feature names "BD" and "ZZ" retain 4 digits; Boolean interface conduction status "true" is converted to "1", and fault warning not triggered "false" is converted to "0". The conversion process strictly follows the NDEF protocol's requirements for data encoding, length, and format to ensure that all converted data conforms to the protocol compatibility standard, eliminating format differences between different data types, and ultimately obtaining standardized security data that can be directly used for NFC transmission.
[0023] Furthermore, the standard format security data is encrypted using the AES-128 encryption algorithm to generate encrypted ciphertext data, while embedding the device's unique identifier as the basis for decryption tracing, thus obtaining encrypted security data; In this embodiment of the invention, standard format secure data is encrypted using the AES-128 encryption algorithm. The encryption process relies on the built-in security chip in the power bank, which has a built-in encryption operation module. The key is stored in an independent encrypted partition and cannot be read externally. Before encryption, the complete content of the standard format secure data is extracted and concatenated into a continuous data string according to the field order of "collection timestamp-component identifier-parameter type-feature name-value-status identifier". The data string is split into 16-byte fixed blocks, with zeros padded to the end of any blocks less than 16 bytes. The encryption operation module calls the AES-128 algorithm and encrypts each data block using the 128-bit fixed key pre-stored in the security chip. Encrypted blocks are generated through a process of byte substitution, row shifting, column mixing, and round key addition. All encrypted blocks are then concatenated in their original order to form complete encrypted ciphertext data. At the same time, the 16-bit unique device identifier (generated by combining the production serial number and hardware code) fixed when the power bank leaves the factory is extracted, converted into a 32-bit hexadecimal string, and embedded at the beginning of the encrypted ciphertext data as the basis for decryption and traceability. The unique device identifier and the encrypted ciphertext data are clearly distinguished by a delimiter, and finally encrypted security data containing decryption and traceability information is obtained to ensure that the data is not illegally stolen or tampered with during the data transmission process.
[0024] Furthermore, strictly following the structural specifications of the NDEF protocol regarding the record header, payload, and record tail, the encrypted secure data is recorded in a structured manner, with reasonable record type identifiers, length indicators, and data offset parameters set, and cyclic redundancy check bits are embedded to generate transmission error detection codes. In this embodiment of the invention, the encrypted secure data is arranged in a record structure strictly following the record structure specifications of the NDEF protocol. A 3-byte record header is set. The first byte is a status flag (bit 7 is set to 1 to indicate the last record, bit 6 is set to 0 to indicate short record format, and the remaining bits are fixed to 0), the second byte is a type length indicator (indicating the number of bytes of the subsequent record type identifier), and the third byte is a payload length indicator (indicating the number of bytes of the encrypted secure data). The record type identifier is set to 10 bytes, using ASCII encoded text type identifier, clearly indicating the purpose of data transmission. The payload is arranged in the order of "device unique identifier - encrypted ciphertext data", completely containing the core content of decryption traceability and secure data. A 1-byte end flag bit (fixed to 0x00) is set at the end of the record. During the arrangement process, the cyclic redundancy check value of the entire NDEF record is calculated, generating a 2-byte cyclic redundancy check bit, which is embedded after the record end as a transmission error detection code for the terminal to verify the integrity when receiving data. At the same time, the data offset parameter is set to 0x00 to ensure that the terminal reads the data accurately from the beginning position of the record, ultimately forming a complete NDEF format data with an error detection mechanism.
[0025] Furthermore, compatibility adjustments are made for the NFC module characteristics of different brands and models of terminal devices. At the same time, the NDEF record types corresponding to the web page wake-up identifier and the mini-program wake-up identifier are configured to ensure that encrypted data can be normally recognized by various terminals and pass decryption verification, generating standardized NDEF secure transmission data with encryption protection, fault tolerance and wake-up interaction capabilities.
[0026] In this embodiment of the invention, by collecting NFC module characteristic data from mainstream brand and model terminal devices, including supported transmission rates, compatible NDEF record types, and data parsing format requirements, compatibility adaptation adjustments are made for different characteristics: for NFC modules supporting high-speed transmission, the data transmission rate is set to 424kbps; for modules supporting only low-speed transmission, the rate is adjusted to 106kbps to ensure that the rate matching does not cause transmission interruptions. Two types of NDEF record types are configured: the record type corresponding to the webpage wake-up identifier adopts the URI type, and the data field contains the complete address of the secure data query webpage; the record type corresponding to the mini-program wake-up identifier adopts the external type, and a dedicated type identifier string is set to match the corresponding mini-program preset identifier. During the adaptation process, the data recognition success rate is verified by simulating the NFC reading process of different terminal devices, and the status flag bits and type length indicator parameters of the record header are adjusted to ensure that all types of terminals can correctly recognize the record structure. When the terminal reads data, it first determines the wake-up method by the record type identifier, triggers the launch of the webpage or mini-program, then decrypts the encrypted secure data by the device's unique identifier, verifies the data integrity by cyclic redundancy check bits, and finally generates standardized NDEF secure transmission data with encryption protection, fault tolerance and wake-up interaction capabilities, realizing secure data transmission compatible across terminals.
[0027] Furthermore, step S3 includes the following steps: Combining the hardware encryption features of dual-interface non-volatile encrypted storage chips with the storage requirements of standardized NDEF secure transmission data, a secure partitioning plan is designed for the chip storage architecture. This plan divides the chip into a real-time secure zone for storing real-time updated secure data, a historical secure zone for storing historically accumulated secure data, and a redundant secure zone for encrypted backup. Partition access permission controls are set, and the functional positioning and secure storage scope of each partition are clarified to obtain partition security planning data. In this embodiment of the invention, by combining the hardware encryption features of the dual-interface non-volatile encrypted storage chip (supporting AES-128 hardware-accelerated encryption, independent key management area, and interface access permission isolation) with the storage requirements of standardized NDEF secure transmission data, a secure partitioning plan is implemented for the chip's storage architecture. The total storage capacity of the chip is divided into three functional partitions in a 1:2:1 ratio: the real-time security zone is set to 2MB, specifically for storing real-time updated security data for the past 7 days to meet high-frequency read requirements; the historical security zone is set to 4MB, storing historical cumulative security data for the past 180 days to support long-term traceability and querying; and the redundant security zone is set to 2MB, providing encrypted backups of the core data in the real-time and historical security zones to address the risk of data corruption. Partition access permission controls are set: the real-time security zone only allows read and write permissions, the historical security zone only allows read permissions, and the redundant security zone only allows write and restore reads of backups that have passed encryption verification. Permission verification is implemented through the chip's built-in access control module, requiring a matching preset permission key to execute the corresponding operation. This clarifies the functional positioning and secure storage scope of each partition, forming partition security planning data.
[0028] Furthermore, based on the functional positioning of each partition in the partition security planning data, the storage priority of the standardized NDEF secure transmission data is determined according to the update frequency, security level and access priority. Encryption identifiers are added to high-security-level data to obtain data security priority labels. In this embodiment of the invention, standardized NDEF secure transmission data is prioritized for storage based on functional positioning of partitioned security planning data. By update frequency: short-circuit warning data, overheat risk data, and interface anomaly data updated every 10 minutes are classified as high-frequency update data, with the highest priority; voltage fluctuation statistics and current change trend data updated hourly are classified as medium-frequency update data, with a medium priority; and full-cycle security summary data updated daily are classified as low-frequency update data, with the lowest priority. By security level: security data containing fault status identifiers and abnormal values are classified as high-security-level; and regular data containing normal operation parameters are classified as ordinary-security-level. A unique encrypted identifier (1-byte fixed code 0x01) is added to all high-security-level data to distinguish it from ordinary-security-level data. A three-dimensional data security priority label containing update frequency priority, security level, and encrypted identifier is generated to ensure that data storage and access are performed in an orderly manner according to priority.
[0029] Furthermore, based on data security priority labels, differentiated encryption writing strategies are formulated to determine the writing order, encryption level, and data overwrite rules of high-security-level data and ordinary-security data in each partition, clarify the single-write data volume and write interval parameters, and set up a write log auditing mechanism to obtain encrypted write control data. In this embodiment of the invention, a differentiated encryption write strategy is formulated based on data security priority labels. The write order is defined as follows: high-priority data is written to the real-time security zone first; medium-priority data is written to the real-time security zone and then to the historical security zone sequentially; and low-priority data is written to the historical security zone and then to the redundant security zone. High-security-level data uses chip hardware encryption (AES-128), while ordinary-security-level data uses software-assisted encryption (consistent with the transmission encryption algorithm). Data overwrite rules are set as follows: the real-time security zone uses first-in, first-out overwrite; when storage reaches its limit, the oldest real-time data is deleted. The historical security zone uses time-segmented storage, without active overwriting; only when capacity is saturated is the oldest historical data deleted. The redundant security zone uses differential backup, updating only the changed core data and not storing complete copies repeatedly. The single write data volume is limited to 1KB / batch, and the write interval is set as follows: high-priority data is written every 10 minutes, medium-priority data is written every hour, and low-priority data is written at a fixed time each day. A write log audit mechanism is set up to record the timestamp, data priority, write partition, data length, and encryption status of each write. The log is stored in a separate audit area on the chip and is tamper-proof, forming encrypted write control data.
[0030] Furthermore, in accordance with the requirements for encrypted write control data, the standardized NDEF secure transmission data is written to the corresponding secure storage partition in batches and at different times through the chip's encrypted data interface, and the writing progress, encryption status and error information of each batch of data are fed back in real time to obtain encrypted write status feedback data. In this embodiment of the invention, standardized NDEF secure transmission data is written to the corresponding secure storage partition in batches and time periods according to the requirements of encrypted write control data, through the chip's SPI encrypted data interface (supporting hardware stream encrypted transmission). High-priority data is split into 1KB batches, and the write process is initiated every 10 minutes. It is transmitted to the real-time secure area through a hardware encrypted channel. Before writing, the chip's encryption module verifies the data encryption identifier; if it matches, the write is executed. Medium-priority data is split hourly and written to the real-time secure area (latest data) and the historical secure area (archived data) respectively. Low-priority data is split into batches daily and written synchronously to the historical secure area and the redundant secure area. The chip's built-in write status monitoring module provides real-time feedback on the write progress (0%-100%), encryption status (encryption successful / failed), and error information (interface abnormality / permission verification failure / insufficient capacity) of each batch of data. The feedback data is transmitted to the power bank's main control unit through an interrupt signal, forming encrypted write status feedback data to ensure that the write process is monitorable and traceable.
[0031] Furthermore, based on the encrypted write status feedback data, the integrity and encryption effectiveness of the data written to each partition are verified. An encrypted data index table is built for each secure storage partition to record the encrypted data storage address, data length and associated data location information. At the same time, an encrypted association mapping table between partitions is established to realize fast retrieval and association query of secure data, forming a tamper-proof offline secure data warehouse.
[0032] In this embodiment of the invention, the integrity of data writing in each partition is verified by comparing the length of the written data with the length of the stored data in the feedback based on the encrypted write status feedback data, and the encryption validity is verified by the data encryption verification module through the chip encryption verification module. If incomplete or encrypted data is found, the backup and recovery mechanism of the redundant security zone is triggered. An encrypted data index table is constructed for each secure storage partition. The index table is sorted by the data write timestamp and records the storage start address, data length, security priority label, and associated index code of each encrypted data. The index table is stored at the beginning of each partition and occupies a fixed storage space (128KB / partition). An encrypted association mapping table is established between partitions. The high-frequency data in the real-time security zone is associated with the archived data in the historical security zone and the backup data in the redundant security zone through the data association index code. The mapping table is stored encrypted (different from the data encryption key) and is only decrypted and accessed during data retrieval. Through the index table and the association mapping table, the terminal device can quickly locate the target data by timestamp, security level, and component identifier, realize cross-partition association query, and finally form a tamper-proof, traceable, and highly available offline secure data warehouse.
[0033] Furthermore, obtaining the zoning planning data includes the following steps: The chip physical security attribute parameters corresponding to the storage medium type, storage cell distribution, maximum read / write rate, erase / write life limit, hardware encryption algorithm support type, and data retention time of the dual-interface non-volatile encrypted storage chip are obtained through chip reading tools, forming chip physical security attribute data; In this embodiment of the invention, a dedicated chip reading tool is used to connect to the debugging interface of a dual-interface non-volatile encrypted storage chip to initiate a physical security attribute detection process. The storage medium type is identified as flash memory, confirming that it achieves non-volatile data retention based on the charge storage principle. The storage unit distribution is determined to be page-based, with each page having a fixed capacity of 256 bytes. Storage units are divided into blocks, with each block containing 64 pages. The maximum read / write speeds are 10MB / s for reading and 5MB / s for writing, which directly determine data transmission and storage efficiency. The erase / write lifespan is confirmed to be 100,000 cycles per block; exceeding this limit will lead to a decrease in storage reliability. The hardware encryption algorithm supports both AES-128 and AES-256 symmetric encryption algorithms, integrated into the chip's hardware encryption engine. The data retention time is confirmed to be 10 years, meaning that under specified environmental conditions, data can be stably stored for 10 years without loss. All the parameters obtained from the detection are organized in the format of "attribute name-parameter value-unit-security impact description" to form chip physical security attribute data containing six core categories of information: storage medium, cell distribution, read and write performance, lifespan limit, encryption support, and data retention.
[0034] Furthermore, a systematic analysis was conducted on the update frequency variation of standardized NDEF secure transmission data, the distribution characteristics of secure access frequency of terminal devices, and the minimum security period requirements for data retention, clarifying the lifecycle characteristics of different types of secure data and obtaining data security lifecycle characteristics. In this embodiment of the invention, a systematic analysis of standardized NDEF secure transmission data clarifies the characteristics of the data security lifecycle. The analysis examines the update frequency variation: short-circuit warning data, overheat risk data, and interface anomaly data require real-time monitoring, and their update frequency dynamically changes with the device's operating status. Under high load, they are updated every 5 minutes; under low load, they are updated every 15 minutes, with an average update frequency of once every 10 minutes. Voltage fluctuation statistics and current trend data are updated at fixed intervals, generating statistical results hourly. The full-cycle security summary data is updated daily at midnight, integrating all security data for the day. The analysis also examines the distribution characteristics of terminal device security access frequency: real-time security data (last 7 days) has an average daily access frequency of 20 times, historical security data (7-180 days) has an average daily access frequency of 3 times, and archived data older than 180 days has an extremely low access frequency. Finally, the minimum security retention period requirements are defined: high-security-level fault data must be retained for 180 days for fault tracing; normal operating security data must be retained for 30 days to meet routine inspection needs; and summary data must be retained for 90 days for trend analysis. By combining update frequency, access frequency, and retention period, a clearly categorized data security lifecycle characteristic is obtained.
[0035] Furthermore, a multi-dimensional matching analysis is conducted between the storage capacity, read / write performance, encryption capability, and lifetime limitation parameters in the chip's physical security attribute data and the update frequency, security access requirements, and retention period in the data security lifecycle characteristics to evaluate the degree of compatibility between the chip's hardware security features and data security storage requirements, thereby obtaining security compatibility assessment data. In this embodiment of the invention, chip physical security attribute data and data security lifecycle characteristics are matched and analyzed from multiple dimensions. Storage capacity matching: The chip's total storage capacity is 8MB. Fault-related data, calculated based on the average daily generation, requires 3MB of storage for 180 days; normal operation data requires 2MB for 30 days; summary data requires 1MB for 90 days; the remaining 2MB can be used as redundant backup. The chip capacity meets the requirements. Read / write performance matching: High-frequency updated data has a single write volume of 1KB. Calculated at a write frequency of 10 minutes, the required write rate is far lower than the chip's maximum write rate, ensuring a perfect read / write performance match. Encryption capability matching: Data transmission and storage use AES-128 encryption. The chip hardware supports this algorithm and has acceleration capabilities, ensuring a perfect encryption capability match. Lifespan limit matching: High-frequency write data is concentrated in specific blocks. Calculated based on the average daily write count, the block erase / write cycles are approximately 3650 times per year. A 100,000 erase / write cycle lifespan can meet the needs of 27 years of use, far exceeding the expected lifespan of the device. By quantifying the degree of matching in each dimension, the assessment concluded that the chip hardware security features and data security storage requirements are fully compatible, requiring only minor adjustments to the partition capacity allocation. This results in security compatibility assessment data that includes matching dimensions, assessment results, and optimization suggestions.
[0036] Furthermore, based on the matching results of chip performance and data requirements in the security adaptability assessment data, and combined with the security level of each type of data, the capacity allocation ratio of real-time security zone, historical security zone and redundant security zone is reasonably determined to ensure that each partition can meet the storage requirements and encryption requirements of the corresponding security data, and thus obtain security capacity allocation data. In this embodiment of the invention, based on the complete compatibility conclusions of security adaptability assessment data and combined with the security levels of various data types, the partition capacity allocation ratio is determined. High-security-level fault data (short-circuit warnings, overheating risks, interface anomaly data) requires priority in ensuring storage reliability and access efficiency, and is allocated to the real-time security zone and historical security zone; normal-operation data and summary data of ordinary security levels are allocated to the historical security zone, while redundant space is reserved. Considering both data storage requirements and chip capacity, the capacity allocation ratio of the real-time security zone, historical security zone, and redundant security zone is determined to be 3:4:1: the real-time security zone capacity is set at 3MB to meet the high-security-level data storage requirements of frequent updates over the past 10 days; the historical security zone capacity is set at 4MB to store 180 days of fault data, 30 days of normal-operation data, and 90 days of summary data; the redundant security zone capacity is set at 1MB, specifically for encrypted backup of core fault data in the real-time security zone. This allocation ratio satisfies the storage requirements of data with different security levels, fully utilizes chip storage resources, and adapts to the chip storage unit block partitioning rules, resulting in accurate security capacity allocation data.
[0037] Furthermore, based on the security capacity allocation data, the starting address, ending address, and address range of each partition are determined. Partition address encryption mapping rules are designed to achieve secure conversion between logical addresses and physical addresses. At the same time, the encryption migration trigger conditions, migration paths, and security cleanup strategies for redundant data after migration are formulated between partitions, generating partition security planning data.
[0038] In this embodiment of the invention, the address range of each partition is defined according to the security capacity allocation data. The chip storage address is encoded in hexadecimal, with a starting address of 0x000000, a real-time security zone address range of 0x000000-0x02FFFF (3MB), a historical security zone address range of 0x030000-0x06FFFF (4MB), and a redundant security zone address range of 0x070000-0x07FFFF (1MB). A partition address encryption mapping rule is designed, using linear mapping combined with XOR operations to achieve secure conversion between logical and physical addresses. The logical address is the virtual address used by the user, and the physical address is the actual address of the chip storage unit. The conversion process is automatically completed by the chip address mapping module, and the mapping key is stored in the chip's independent key area. Establish data encryption migration trigger conditions: Real-time security zone data stored for more than 10 days is automatically migrated to the historical security zone; historical security zone faulty data stored for more than 180 days, normal operation data stored for more than 30 days, and summary data stored for more than 90 days are automatically migrated to the redundant security zone for backup; the migration path is set as real-time security zone → historical security zone → redundant security zone, and the migration process is transmitted through the chip's internal encrypted channel, using AES-128 encryption throughout. Establish a redundant data security cleanup strategy: When redundant security zone data stored for more than one year, and the historical security zone data is verified to be complete, redundant data is completely cleared using chip erase commands. The cleanup process is recorded in the audit log, ultimately generating partition security planning data with clearly defined partition addresses, secure mappings, and orderly migration.
[0039] Furthermore, the process of generating the data security lifecycle characteristics includes the following steps: Standardized NDEF secure transmission data is classified into different types based on the real-time nature of data generation and the differences in security applications. These types are clearly distinguished into real-time monitoring security data that reflects the current security operation status and historical statistical security data that records historical security operation status, thus obtaining data security classification results. In this embodiment of the invention, standardized NDEF secure transmission data is categorized into two core data types based on the real-time nature of data generation and its security purpose. Real-time monitoring security data is defined as data that captures and reflects the current safe operating status of the power bank in real time. This includes real-time voltage data of the battery pack, real-time charging and discharging current data, real-time temperature data of core components, circuit continuity status data, short-circuit warning trigger status data, overheat risk real-time monitoring data, and interface connection stability data. This type of data must be stored immediately after generation and supported for rapid access, used for real-time safety status judgment and risk warning. Historical statistical security data is defined as data recording historical safe operating conditions based on real-time data aggregation and analysis. This includes hourly voltage fluctuation statistics, daily current change trend curve data, weekly safety status summary reports, fault occurrence time and handling results records, and monthly safety operation score data. This type of data is used for historical status tracing, fault pattern analysis, and safety performance evaluation. The classification results are organized according to the format of "data type - included sub-items - security purpose - generation method" to obtain data security classification results with clear boundaries and specific uses.
[0040] Furthermore, the update interval statistics of the real-time monitoring security data in the data security classification results are performed in the time dimension. The time node of each data update is recorded, the time difference between two adjacent updates is calculated, and an update interval dataset is formed to obtain real-time update frequency data that can reflect the update pattern of real-time security data. In this embodiment of the invention, the update interval of real-time monitoring safety data in the data security classification results is statistically analyzed in terms of time dimension. The time recording module of the power bank's main control unit extracts the time node (accurate to the second) at which each piece of real-time monitoring safety data is generated, and establishes a time node sequence for each data sub-item. Taking short-circuit warning data as an example, the generation time nodes of 100 consecutive data points are extracted, and the time difference (unit: seconds) between two adjacent time nodes is calculated, resulting in an update interval dataset composed of 99 time differences. Similarly, update interval datasets for other real-time data such as real-time voltage, real-time current, and real-time temperature are calculated. Statistical analysis is performed on each dataset to calculate the average update interval, maximum update interval, minimum update interval, and standard deviation of the update interval. The average update interval for short-circuit warning data is 600 seconds (10 minutes), the maximum update interval is 1800 seconds (30 minutes), and the minimum update interval is 300 seconds (5 minutes). The average update interval for real-time voltage data is 300 seconds (5 minutes). The statistical results of the update intervals of all real-time data are integrated to obtain real-time update frequency data that comprehensively reflects the update patterns of various types of real-time safety data.
[0041] Furthermore, by retrieving the security interaction logs between the terminal device and the NFC module, a comprehensive analysis is conducted on the access time, number of accesses, access terminal type, and security verification results of historical security data. The access frequency of historical security data for different time periods and different types is statistically analyzed to obtain the data security access frequency distribution. In this embodiment of the invention, a comprehensive analysis of access behavior for historical statistical security data is performed by retrieving the security interaction logs between the terminal device and the NFC module (the logs are stored in the log partition of the power bank's built-in storage). The logs include the access time (accurate to the minute), number of accesses (multiple accesses from the same terminal within the same time period are counted as a single valid access), terminal type (categorized by brand and model), and security verification result (verification passed / failed) for each access record. The access frequency of various types of historical security data is statistically analyzed by time period (0-6 AM, 6-12 AM, 12-6 PM, 6-12 PM); and by data type (hourly statistics, daily trend data, weekly summary data, fault record data), the total number of accesses and the average daily number of accesses for each type of data are also statistically analyzed. The analysis results show that the access frequency is highest between 2-4 PM, with an average of 4 accesses per day; the access frequency for fault record data is highest, with an average of 3 accesses per day; the access frequency for hourly statistics is lowest, with an average of 1 access per day; smartphone terminals account for 80% of accesses, and tablet terminals account for 20%; the security verification pass rate is 95%. These statistical results are organized into a structure of "time period - data type - access frequency - terminal type percentage - verification pass rate" to obtain the data security access frequency distribution.
[0042] Furthermore, based on the actual security uses of different types of data in the data security classification results and the industry security standard requirements, combined with the warranty period, fault traceability period and data security retention regulations of power bank products, the minimum retention period requirements for each type of data are determined, and the security retention period threshold data are obtained. In this embodiment of the invention, based on the actual security uses of different types of data in the data security classification results, combined with industry security standards, the warranty period of power bank products, the fault tracing period, and data security retention regulations, the security retention period thresholds for various types of data are determined. Real-time monitoring security data is used for real-time early warning; industry standards require retention until the next data update. Considering the fault tracing needs within the warranty period, the retention period threshold is determined to be 7 days; real-time data exceeding 7 days is automatically converted to historical statistical data. Hourly statistical data and daily trend data are used for short-term operational status analysis; the warranty period is 2 years, and the fault tracing period is 180 days, so the retention period threshold is determined to be 90 days. Weekly summary data and monthly score data are used for long-term performance evaluation; retention is required until 1 year after product obsolescence. Given the expected lifespan of the power bank is 5 years, the retention period threshold is determined to be 2 years. Fault record data is used for fault tracing and liability determination; regulations explicitly require retention for at least 3 years. Considering the 2-year warranty period, the retention period threshold is determined to be 3 years. The retention period thresholds for various types of data are organized in the format of "Data Type - Security Use - Reference Factor - Retention Period Threshold - Unit" to obtain the security retention period threshold data.
[0043] Furthermore, the real-time update frequency data, data security access frequency distribution, and security retention period threshold data are structurally integrated to establish a data security lifecycle characteristic model, comprehensively presenting the core characteristics of various types of data in terms of updates, secure access, and secure retention, and generating data security lifecycle characteristics.
[0044] In this embodiment of the invention, a data security lifecycle characteristic model is established by structurally integrating real-time update frequency data, data security access frequency distribution, and security retention period threshold data. The model comprises three core dimensions: the update dimension integrates the average update interval, maximum and minimum update interval, and update triggering conditions (timed / event-driven) for various types of data; the access dimension integrates the average daily access frequency, time-period access distribution, terminal type distribution, and verification pass rate for various types of data; and the retention dimension integrates the retention period threshold, retention format requirements (raw data / statistical results), and destruction conditions (automatic destruction upon timeout / manual review and destruction) for various types of data. The model presents the core characteristics of various types of data in the three dimensions in tabular form: real-time monitoring security data updates every 5-30 minutes, with an average of 20 accesses per day and a retention period of 7 days; fault record data updates when a fault occurs, with an average of 3 accesses per day and a retention period of 3 years; and weekly summary data updates every 7 days, with an average of 2 accesses per day and a retention period of 2 years. This model comprehensively presents the core characteristics of various types of data throughout their entire lifecycle, from generation and update, secure access to retention and destruction, ultimately generating structured and quantifiable data security lifecycle characteristics.
[0045] Furthermore, the statistical analysis of the time-dimensional update interval of the real-time monitoring security data in the data security classification results includes the following steps: The encrypted timestamp information corresponding to each data record is extracted from the real-time monitoring security data in the data security classification results using a timestamp extraction algorithm. The data records are sorted in chronological order to construct an encrypted time series dataset containing a complete time series. In this embodiment of the invention, a timestamp extraction algorithm is used to process the real-time monitoring security data in the data security classification results. This algorithm is specifically designed for the field structure of standardized NDEF secure transmission data, accurately locating the start and end positions of the "collection timestamp" field in each data record (the field has a fixed length of 14 digits). All real-time monitoring security data (including 7 sub-items such as real-time voltage of battery cells, real-time charging and discharging current, and real-time temperature of core components) are traversed, and the encrypted timestamp information corresponding to each data record is extracted one by one (timestamp format is year, month, day, hour, minute, second, such as 20241215103000). The extracted timestamps are converted to Unix timestamp format (integers in seconds), and all data records are sorted in ascending order of timestamp value to ensure that the data records form a continuous sequence according to their generation time. Independent encrypted time series datasets are constructed for different sub-items of data. Each dataset contains the sorted timestamps of 1000 consecutive data records for that sub-item, forming a complete time series set covering all real-time monitoring data sub-items.
[0046] Furthermore, a time interval calculation method is used to perform a difference operation on the timestamps of two adjacent data records in the encrypted time series dataset to obtain the time interval value between each two adjacent data points, forming a continuous interval duration sequence. In this embodiment of the invention, a point-by-point difference calculation method is used to calculate the timestamps in each encrypted time series dataset. Taking the real-time voltage data time series dataset as an example, the timestamp of the second data point in the sorted timestamp sequence is subtracted from the timestamp of the first data point to obtain the first time interval value; then the timestamp of the third data point is subtracted from the timestamp of the second data point to obtain the second time interval value, and so on, until the difference calculation of all adjacent timestamps in the dataset is completed, generating an interval duration sequence containing 999 time interval values. Similarly, the same operation is performed on the time series datasets of six other types of real-time monitoring data, such as real-time current, real-time temperature, and short-circuit warning. Each dataset generates a corresponding interval duration sequence, and the unit of the time interval values in all sequences is unified to seconds, forming a continuous and quantifiable set of interval duration sequences, which intuitively reflects the time interval distribution of data updates.
[0047] Furthermore, an outlier identification model is established based on statistical methods, a reasonable interval threshold range is set, and the data in the interval duration sequence are detected one by one to identify and remove abnormal interval data that exceed the threshold range, so as to obtain the effective interval sequence after removing interference. In this embodiment of the invention, an outlier identification model is established based on the 3σ principle in statistics. This model uses the mean and standard deviation of the interval duration sequence as the core to calculate the threshold range. First, a preliminary statistical analysis is performed on a single interval duration sequence (such as the interval sequence of short-circuit warning data), calculating the mean and standard deviation of the sequence. The threshold range is set from the mean minus three times the standard deviation to the mean plus three times the standard deviation. Values exceeding this range are judged as abnormal interval data. Each data point in the interval duration sequence is checked one by one. If a certain time interval value is less than the lower threshold limit (such as an extremely short interval of 1 second caused by sensor mis-triggered activation) or greater than the upper threshold limit (such as an excessively long interval of 3600 seconds caused by equipment sleep mode), it is marked as abnormal data and removed from the sequence. This process is repeated to process the interval duration sequences of all real-time monitoring data sub-items, removing interference data caused by factors such as sensor failure, equipment sleep mode, and transmission interruption, to obtain the effective interval sequence after interference removal for each sub-item, ensuring the accuracy of subsequent statistical analysis.
[0048] Furthermore, a comprehensive analysis of the effective interval sequence is performed. The arithmetic mean of all interval data in the sequence is calculated to obtain the average interval. The interval data with the smallest value is selected by traversing and comparing to obtain the shortest interval. The interval data with the largest value is selected by traversing and comparing again to obtain the longest interval. At the same time, the variance and standard deviation parameters of the interval data are calculated to obtain the interval statistics. In this embodiment of the invention, a comprehensive statistical analysis is performed on each effective interval sequence. Taking the effective interval sequence of real-time temperature data as an example, firstly, the summation of all interval data in the sequence is performed, and then divided by the total number of interval data to obtain the arithmetic mean (average interval) of the sequence. By traversing all data in the sequence and comparing the numerical values one by one, the interval data with the smallest value (shortest interval) and the interval data with the largest value (longest interval) are selected. At the same time, the variance (reflecting the dispersion of the interval data) and standard deviation (reflecting the fluctuation range of the interval data) of the sequence are calculated. For example, the effective interval sequence of short-circuit warning data is calculated to have an average interval of 600 seconds, a shortest interval of 300 seconds, and a longest interval of 1800 seconds. The variance and standard deviation quantify the specific degree of interval fluctuation. The same method is used to complete the statistical analysis of the effective interval sequences of all real-time monitoring data sub-items. The average interval, shortest interval, longest interval, variance, and standard deviation parameters of each sub-item are compiled and summarized to form structured interval statistical data.
[0049] Furthermore, based on the various parameters in the interval statistical data, a real-time update frequency model that can reflect the update pattern of real-time monitoring security data is constructed. The model quantifies the density and fluctuation characteristics of data updates to generate real-time update frequency data.
[0050] In this embodiment of the invention, a multi-dimensional real-time update frequency model is constructed based on various parameters in the interval statistical data. The model includes a core parameter layer and a characteristic description layer: the core parameter layer directly incorporates quantitative indicators such as average interval, shortest interval, longest interval, variance, and standard deviation; the characteristic description layer quantifies the density (smaller average interval indicates more frequent updates) and fluctuation characteristics (smaller standard deviation indicates more stable updates) of data updates through parameter combinations. For example, the model parameters for real-time voltage data are an average interval of 300 seconds, a shortest interval of 150 seconds, a longest interval of 600 seconds, and a relatively small standard deviation, indicating that its updates are frequent and stable; the model parameters for short-circuit warning data are an average interval of 600 seconds, a shortest interval of 300 seconds, a longest interval of 1800 seconds, and a relatively large standard deviation, indicating that its update frequency fluctuates with the equipment status. By integrating the models of all real-time monitoring data sub-items, a comprehensive model covering various data update patterns is formed. This model comprehensively quantifies the temporal characteristics of data updates, ultimately generating real-time update frequency data that accurately reflects the update patterns of real-time monitoring safety data.
[0051] Furthermore, the comprehensive analysis of the effective interval sequence includes the following steps: The data entries in the effective interval sequence are counted one by one to determine the total number of interval data participating in the statistical calculation. At the same time, the start index and end index of the sequence are recorded to obtain the data volume statistics results. In this embodiment of the invention, the processed valid interval sequence is counted item by item, and the counting process is performed using a sequence index management mechanism. Each valid interval sequence is assigned a consecutive integer index according to the generation order, with the starting index fixed at 0, and subsequent items are assigned values in natural ascending order (e.g., 0, 1, 2...n-1, where n is the total number of sequence items). Taking the valid interval sequence of real-time voltage data as an example, starting from the first interval data corresponding to index 0, each interval value corresponding to each index is checked sequentially to see if it is valid data (not a null value after being removed) by traversing line by line. Each time a valid data is confirmed, the count is incremented by 1 until the index position corresponding to the last data in the sequence is reached. After the traversal is completed, the final accumulated count result is recorded as the total number of interval data, and the starting index (fixed at 0) and ending index (count result decremented by 1) of the sequence are extracted. For example, if the count result of the valid interval sequence of real-time voltage data is 980, the ending index is 979. Following the same process, count and index the effective interval sequences of all seven types of real-time monitoring data sub-items, including real-time current, real-time temperature, and short-circuit warning. Organize the total number of interval data, start index, and end index of each sub-item into the format of "data sub-item - total number - start index - end index" to obtain accurate data volume statistics results.
[0052] Furthermore, based on the statistical results of the data volume, the range of the datasets participating in the accumulation operation is determined. The accumulation calculation method is used to continuously accumulate all the interval data in the effective interval sequence, and the intermediate results in the accumulation process are recorded. Finally, the sum of all the interval data is obtained, that is, the total interval duration data. In this embodiment of the invention, the range of the dataset participating in the accumulation operation is clearly defined based on the statistical results of the data volume, namely, all interval data corresponding to the sequence start index (0) to the end index (total number - 1), ensuring that there is no data omission or invalid operation exceeding the range. A successive accumulation calculation method is used to continuously accumulate the interval data in the valid interval sequence. The accumulation operation is performed by the built-in data processing module of the power bank, ensuring the speed and accuracy of the operation. Taking the valid interval sequence of real-time temperature data of the core component as an example, the statistical result of this sequence data volume is 950 records, with a start index of 0 and an end index of 949. First, the interval data corresponding to index 0 is extracted as the initial accumulation value. Then, the interval data corresponding to index 1 is extracted and added to the initial accumulation value to obtain the first intermediate accumulation result. Next, the first intermediate accumulation result is added to the interval data corresponding to index 2 to obtain the second intermediate accumulation result, and so on, until the addition operation of the interval data corresponding to index 949 and the previous intermediate accumulation result is completed. During the accumulation process, an intermediate result is recorded every 100 data entries for verification of the calculation process, avoiding accumulation errors. After all the data has been accumulated, the final accumulated result is the sum of all interval data in the valid interval sequence, with the unit uniformly set to seconds, forming the total interval duration data. At the same time, all intermediate results in the accumulation process are associated with and stored with the final sum for easy traceability and verification later.
[0053] Furthermore, the total interval duration data is divided by the total number of interval data in the data volume statistics, and a reasonable number of decimal places are retained in strict accordance with the numerical calculation rules to obtain the average interval duration that can reflect the average level of the interval. In this embodiment of the invention, the total interval duration data is divided by the total number of interval data. The calculation process strictly follows numerical calculation rules to ensure that the accuracy of the result meets the data application requirements. Before the calculation, the numerical calculation rules are clearly defined: the division operation retains two decimal places, and the third decimal place is rounded according to the rounding rules. If the third decimal place is less than 5, it is discarded; if it is greater than or equal to 5, it is rounded up to the second decimal place. Taking the effective interval sequence of short-circuit warning data as an example, its total interval duration data is 58,800 seconds, and the total number of interval data is 98. Dividing 58,800 by 98 yields a preliminary calculation result; retaining two decimal places according to the preset rules, the final average interval duration is obtained. Similarly, the same division operation is performed on all real-time monitoring data sub-items: the total interval duration of real-time voltage data is 39,200 seconds, and the total number of data is 980, resulting in the average interval duration; the total interval duration of real-time current data is 49,000 seconds, and the total number of data is 980, resulting in the average interval duration. The average interval of all sub-items is rounded to two decimal places and is expressed in seconds. This result directly reflects the average level of the corresponding real-time monitoring data update interval, providing a precise quantitative basis for subsequent data storage partitioning planning and update frequency adaptation.
[0054] Furthermore, the shortest interval cache variable is initialized, and the first data entry in the effective interval sequence is assigned to the cache variable as the initial reference value to obtain the initial cache data. Starting from the second data entry in the effective interval sequence, each data entry is extracted in turn as the current data to be compared, and the current data to be compared is compared with the initial cache data to obtain the comparison result. In this embodiment of the invention, the initialization and comparison operations for the shortest interval filtering are performed on the effective interval sequence. These operations are executed by the built-in data processing module of the power bank according to a fixed procedure. Taking the effective interval sequence of real-time charging and discharging current data as an example (this sequence contains 980 data entries, indexed from 0 to 979), firstly, the shortest interval cache variable is initialized. The first data entry corresponding to index 0 in the sequence is directly assigned to this variable as the initial reference value for subsequent comparisons, forming the initial cache data. Starting from the second data entry corresponding to index 1, each data entry is extracted sequentially in ascending order of index as the current data to be compared. The extraction process strictly follows the index order and does not skip any valid data. After each extraction, the current data to be compared is immediately compared with the initial cache data. The comparison uses a bit-by-bit comparison method, checking from the highest bit to the lowest bit to clarify the numerical relationship between the two, obtaining a clear comparison result of "the current data is smaller," "the current data is larger," or "the two are equal," ensuring that the comparison is unambiguous.
[0055] Furthermore, if the comparison result shows that the current data to be compared is less than the initial cached data, the shortest interval cache variable is updated to the current data to be compared, and the updated cached data is obtained. If the comparison result shows that the current data to be compared is greater than or equal to the initial cached data, the initial cached data is kept unchanged. The data extraction, numerical comparison and cache update steps are repeated until all data entries in the valid interval sequence are traversed. The final cached data is the shortest interval duration. Using the same logic as filtering the shortest interval duration, the longest interval cache variable is initialized and the valid interval sequence is traversed to filter out the interval data with the largest value, and the longest interval duration is obtained. In this embodiment of the invention, cache variable updates or hold operations are performed based on the comparison results. If the comparison result shows that the current data to be compared is less than the initial cache data, the value of the shortest interval cache variable is immediately updated to the current data to be compared, generating updated cache data, which is then used as the reference value for the next round of comparison. If the comparison result shows that the current data to be compared is greater than or equal to the initial cache data, the value of the shortest interval cache variable remains unchanged, and the original initial cache data is still used as the reference value for the next round of comparison. The loop process of "extracting current data - numerical comparison - cache update" is repeated until the last data entry corresponding to index 979 in the effective interval sequence is traversed. At this point, the value stored in the shortest interval cache variable is the shortest interval duration of the sequence. The same logic is used to filter the longest interval duration: the longest interval cache variable is initialized, the first data entry of the sequence is used as the initial reference value, and comparisons are extracted sequentially starting from the second data entry. If the current data to be compared is greater than the cache variable value, it is updated; otherwise, it remains unchanged. After traversal, the value stored in the cache variable is the longest interval duration. For example, the effective interval sequence of real-time voltage data is filtered, with the shortest interval being 150 seconds and the longest interval being 600 seconds; the shortest interval sequence of short-circuit warning data is 300 seconds and the longest interval is 1800 seconds.
[0056] Furthermore, the calculated average interval duration, shortest interval duration, and longest interval duration are integrated with the previously calculated variance and standard deviation parameters to generate interval statistics.
[0057] In this embodiment of the invention, the calculated average interval duration, the shortest interval duration, and the longest interval duration are systematically integrated with the variance and standard deviation parameters calculated using statistical methods. The integration process follows a fixed structure of "data sub-item - core statistical parameter - parameter value - unit," with each real-time monitoring data sub-item forming an independent statistical entry: the real-time voltage data entry includes five parameters—average interval duration, shortest interval duration, longest interval duration, variance, and standard deviation—along with their corresponding values; the other six data sub-items, such as real-time current, real-time temperature, and short-circuit warning, are organized in the same format. All parameter values are retained to two decimal places, with the unit uniformly set to seconds. The variance and standard deviation are presented as quantified results according to previously set calculation rules, ensuring consistent data format. The statistical entries of all data sub-items are categorized and summarized according to data type to form structured interval statistics. This data comprehensively covers the central tendency (mean interval), extreme values (shortest / longest interval), and dispersion (variance / standard deviation) of the effective interval sequence, fully reflecting the core statistical characteristics of the real-time monitoring security data update interval, and providing a comprehensive and accurate quantitative basis for the subsequent construction of the real-time update frequency model.
[0058] Furthermore, the secure data interaction with the power bank described in step S4 includes the following steps: The system detects the current power supply status of the power bank and the hardware readiness of the NFC radio frequency module, obtaining the module activation prerequisite data. Based on the module activation prerequisite data, it initiates the passive communication mode initialization process of the NFC radio frequency module, pre-configures the HTTP web page wake-up link and the mini-program wake-up identifier, and obtains the mode initialization configuration data. It sends an encrypted wireless communication detection signal through the NFC radio frequency module to scan the NFC modules of terminal devices within the surrounding effective range, obtaining the communication capability identifier, compatibility protocol information, security verification public key, and application wake-up support type of the terminal device, and obtains the terminal detection response data. Based on the terminal detection response data and the mode initialization configuration data, it negotiates communication parameters and obtains the link negotiation result data. In this embodiment of the invention, the output voltage, output current, and remaining battery percentage are collected in real time using the built-in power supply status detection circuit of the power bank. The module's power supply voltage, RF antenna impedance, and chip operating temperature are read through the hardware readiness detection pin of the NFC RF module. These two types of data together constitute the module activation prerequisite data. The power supply voltage must be stable within the range of 3.3V ± 0.1V, and the RF antenna impedance matching error must not exceed 5%. The NFC RF module's passive communication mode initialization is initiated. The HTTP webpage wake-up link is configured to be a static Uniform Resource Locator in encrypted format through the module's internal registers, and the mini-program wake-up identifier is set to a 16-bit binary fixed code, forming the mode initialization configuration data. The NFC RF module transmits an encrypted wireless communication detection signal conforming to the ISO14443A standard through its built-in RF transmitting circuit. The signal transmission power is controlled at 10mW, and the effective detection range is limited to 0-5cm. The system receives response signals from the NFC modules of surrounding terminal devices. Through signal demodulation circuitry, it parses the terminal device's communication capability identifier (fixed encoding supporting a 106kbps transmission rate), the compatibility protocol information (NDEF protocol standard encoding defined by the NFC Forum), the security verification public key (2048-bit RSA asymmetric encryption public key), and the application wake-up support type (binary identifier for web pages or mini-programs). These are integrated to obtain the terminal detection response data. Based on the wake-up parameters in the mode initialization configuration data, the system compares and matches them with the compatibility protocol and application support type in the terminal detection response data. It then negotiates and determines the data transmission rate, encryption algorithm, and wake-up method, forming the link negotiation result data.
[0059] Furthermore, based on the link negotiation result data, an encrypted short-range wireless communication link is established between the terminal device and the dual-interface non-volatile encrypted storage chip, and link establishment confirmation data is obtained through the session key; based on the link establishment confirmation data, the encrypted data read request sent by the terminal device is received and the legitimate access rights of the requesting terminal are parsed and verified to obtain read request parsing data; based on the read request parsing data, the corresponding standardized NDEF secure transmission data is retrieved from the tamper-proof offline secure data warehouse, and encrypted data fragmentation and transmission order arrangement are performed. If the target invocation method is an HTTP webpage, the data is associated and encapsulated with the webpage invocation link; if the target invocation method is a mini-program, the data is associated and encapsulated with the mini-program invocation identifier to obtain an encrypted data queue to be transmitted. In this embodiment of the invention, an encrypted short-range wireless communication link conforming to the ISO15693 standard is established between the NFC radio frequency module and the NFC module of the terminal device based on the communication parameters in the link negotiation result data. During the link establishment process, a 128-bit AES symmetric session key is generated using a pre-shared key. The session key is used to encrypt and transmit the link establishment confirmation command. After receiving the decryption confirmation signal from the terminal, link establishment confirmation data is formed. The encrypted data read request sent by the terminal device is received via the link. After the request data is decrypted using AES, the device identifier and access permission code in the request are extracted and compared with the pre-stored legal device whitelist and permission code library in the dual-interface non-volatile encrypted storage chip. The whitelist storage capacity is no less than 100 records, and the permission code uses 32-bit binary verification. After successful verification, read request parsing data is formed. Based on the data index in the read request parsing data, the corresponding standardized NDEF secure transmission data is retrieved from the tamper-proof offline secure data warehouse. The data warehouse is stored using a hardware encryption chip, and the retrieval process is transmitted through the chip's built-in encrypted channel. The retrieved data is fragmented into 1024-byte segments and arranged for transmission according to the segment index. If the target invocation method in the link negotiation result data is an HTTP webpage, each data segment is associated and encapsulated with the webpage invocation link in the mode initialization configuration data through binary concatenation. The encapsulated data frame contains a segment identifier, a link field, a data field, and a verification field. If the target invocation method is a mini-program, the data segment is associated and encapsulated with the mini-program invocation identifier through fixed byte insertion. The structure of the encapsulated data frame is consistent with that of the webpage invocation encapsulation. Finally, all encapsulated segmented data are integrated to form an encrypted data queue to be transmitted.
[0060] Furthermore, the encrypted data queue is sent piece by piece to the terminal device through the established encrypted short-range wireless communication link, providing real-time feedback on data transmission progress and reception confirmation information. The integrity of data transmission is verified based on the check bit, and an encrypted retransmission mechanism is triggered if any transmission is missing. After the terminal device receives the complete encrypted data and completes the decryption verification, it automatically executes the corresponding operation according to the associated wake-up identifier. It can wake up an HTTP webpage via NFC touch and synchronize the decrypted power bank data to the webpage interface for quick interaction; or it can wake up a mini-program via NFC touch, allowing users to interact with the power bank's secure data through the mini-program interface without downloading an app, achieving offline encrypted real-time interaction of standardized NDEF secure data transmission. In this embodiment of the invention, through an established encrypted short-range wireless communication link, encrypted data queues are sent to the terminal device piece by piece in an ordered transmission sequence. After each data piece is sent, there is a 50-millisecond pause to receive a 16-bit binary reception confirmation signal from the terminal device. This signal contains the fragment reception status and verification result. The number of transmitted fragments and the total number of fragments are recorded in real time to form transmission progress data. A 32-bit cyclic redundancy check (CRC) code is appended to the end of each data fragment. After receiving the data, the terminal device verifies its integrity using the same verification algorithm. If the verification result indicates missing or incorrect data, the terminal sends a retransmission request. The NFC radio frequency module immediately triggers the encrypted retransmission mechanism to retransmit the corresponding data fragment. The number of retransmissions does not exceed three. After receiving all data fragments, the terminal device decrypts them using the session key and reassembles them in the ordered sequence. After completing the decryption verification, it reads the wake-up flag from the data encapsulation. If the trigger is a webpage, the terminal device's NFC module triggers the system's built-in browser call command. The browser is activated via a touch sensor signal, and the associated HTTP webpage is loaded. The decrypted power bank security data is then filled into the corresponding display area of the webpage according to a preset data field format, enabling real-time data display and interaction. If the trigger is a mini-program, the terminal device's NFC module triggers the system's mini-program call interface. The corresponding mini-program is directly invoked via a touch sensor signal. The decrypted power bank security data is synchronized to the interface controls via the mini-program's built-in data receiving interface. Users can view and operate the relevant security data on the mini-program interface without additional operation, achieving encrypted real-time interaction even without a network connection.
[0061] Furthermore, step S4, which involves completing fault tracing and security data retention management, includes the following steps: When a power bank malfunctions and loses communication, a fault status detection process is performed to identify the fault type, the scope of its impact, and the physical security status of the encrypted storage chip, yielding fault detection and assessment data. Based on this data, a suitable anti-leakage disassembly tool is selected, and a targeted safe disassembly process is developed, specifying the disassembly sequence, operational force, and chip protection measures to prevent data leakage, resulting in disassembly plan data. Following the disassembly plan data, the power bank's outer shell, internal fixing structure, and connecting lines are gradually disassembled in a dust-free and safe environment, avoiding critical components in the area where the encrypted storage chip is located to minimize physical damage during disassembly, resulting in disassembly process status data. In this embodiment of the invention, when the power bank interrupts NFC communication due to an abnormal fault, the voltage of the power supply circuit is measured with a multimeter, the waveform of the communication signal is detected with an oscilloscope, and short circuits and open circuits are checked with a dedicated circuit testing device. At the same time, it is observed whether the encrypted storage chip package is damaged and whether the pins are oxidized or bent. By comparing the parameters of the normal chip with the actual test results, it is determined that the fault type is that the power supply module is burned out, the fault affects the NFC communication module and the power supply line of the encrypted storage chip, and the physical safety status of the encrypted storage chip is that the package is intact but the pins are not powered. Fault detection assessment data is formed, which includes fault characteristics, distribution map of the affected area, and chip appearance inspection record. Based on the assessment data, a special anti-leakage disassembly tool set consisting of anti-static ceramic disassembly tweezers, a mini low-temperature hot air gun, and an insulated disassembly pry bar is selected. The procedure is to first disconnect the external power supply of the power bank, then use the hot air gun to uniformly heat the outer shell seam at a low temperature of 45°C, use the insulated pry bar to slowly pry open the outer shell along the seam, remove the internal fixing screws one by one and mark the screw positions, avoid the central circuit board area where the encrypted storage chip is located, and prioritize the separation of non-critical power supply lines for safe disassembly. The process clearly defines the disassembly sequence as: outer casing - fixed structure - non-core circuitry - core circuit board peripheral components. The force applied during operation is controlled to only loosen connecting components. Chip protection measures include covering the chip surface with an anti-static protective film and grounding the disassembly tools throughout the process to prevent data loss due to static electricity or physical contact. A disassembly plan data is generated, including a tool list, detailed operating steps, force control standards, and protective measures instructions. In a dust-free, safe environment equipped with an anti-static floor and humidity controlled at 40%-60%, following the disassembly plan data, the outer casing edge is first continuously heated with a miniature low-temperature hot air gun for 3 minutes. Then, an insulated pry bar is inserted gradually from one corner of the casing and slowly pried open. After the casing is fully opened, anti-static tweezers are used to remove the fixing screws and place them in the corresponding marked storage box. The internal battery and circuit board connection cables are then disconnected, and redundant circuitry in the non-encrypted chip area is cut with scissors. Throughout the disassembly process, a magnifying glass is used to observe the peripheral components of the encrypted storage chip, avoiding contact with the chip package and pins. The component status, operation time, and any abnormalities during the disassembly process are recorded in real time, generating disassembly process status data.
[0062] Furthermore, based on the disassembly process status data, the installation position and fixing method of the dual-interface non-volatile encrypted memory chip are located. A precise disassembly operation is used to separate the chip from the surrounding circuitry, ensuring the integrity of the chip pins, storage medium, and package structure, resulting in a non-destructive separation of the target encrypted memory chip. The target encrypted memory chip is then subjected to visual cleaning and pin inspection to remove surface stains and residual solder, yielding chip pre-processing inspection data. The pre-processed target encrypted memory chip is then adapted and connected to a dedicated encrypted chip reading device. The communication interface, power supply parameters, and encrypted data parsing protocol of the reading device are configured, and the device decryption key is input to obtain chip connection configuration data. In this embodiment of the invention, based on the central circuit board layout and component connection relationships recorded in the disassembly process status data, and by observing the circuit board solder joint distribution using a high-definition microscope, the installation position and soldering method of the dual-interface non-volatile encrypted memory chip located in the central area of the circuit board and connected to the surrounding circuits through eight solder joints are determined. A miniature low-temperature hot air gun is used to heat the chip pin solder joints at a low temperature of 50°C, while simultaneously using anti-static ceramic tweezers to gently support the bottom of the chip. After the solder at the solder joints melts, the chip is slowly lifted upwards to separate the chip from the surrounding circuits. Throughout the process, the tweezers are kept perpendicular to the chip to avoid bending the pins, ensuring that the chip pins are not deformed, the storage medium is not squeezed, and the package structure remains intact, thus obtaining the target encrypted memory chip after non-destructive separation. Subsequently, the chip surface is gently wiped with a lint-free cotton swab moistened with anhydrous ethanol to remove dust, residual solder residue, and other contaminants. Then, a metal probe is used to contact each pin of the chip in sequence, in conjunction with... The multimeter's continuity setting is used to test the continuity between the pins and the chip's internal circuitry. Observing the multimeter's pointer changes determines whether there are any broken or loose connections on the pins, verifying the continuity and integrity of the chip pins. This generates pre-processed chip testing data, including cleaning operation records, pin test point diagrams, and continuity status records. The pre-processed target encrypted storage chip is placed on an anti-static test socket, ensuring precise alignment between the chip pins and the socket contacts. A physical connection is established between the dedicated encryption chip reader's NFC interface and the test socket. The reader's power supply interface is adjusted to 3.3V DC output mode, and the device's built-in NFC data transmission protocol is enabled. A preset hardware decryption key is entered through the device's operation panel. The key is entered via the device's built-in encrypted keyboard and transmitted in real-time to the device's internal decryption module, generating chip connection configuration data that includes interface connection method, power supply mode settings, protocol enable type, and key entry records.
[0063] Furthermore, based on the chip connection configuration data, the chip reading device is activated, and an encrypted data reading command is sent to read the encrypted partition index and data storage address of the offline secure data warehouse in the target encrypted storage chip, thereby obtaining the warehouse structure mapping data. The storage location of the standardized NDEF secure transmission data is located according to the warehouse structure mapping data, and the encrypted data content is extracted partition by partition. Data integrity verification and error correction are performed, and the original data is recovered using a decryption algorithm, resulting in the extracted original data. The extracted original data undergoes format restoration and data integration to restore the complete structure and relationships of the standardized NDEF secure transmission data, resulting in the restored target data. The restored target data is then encrypted, backed up, and marked for traceability. The data extraction time, disassembly process information, fault correlation characteristics, and data access logs are recorded to complete fault tracing and secure data retention management.
[0064] In this embodiment of the invention, based on chip connection configuration data, pressing the start button of the dedicated encrypted chip reading device automatically sends an encrypted data reading command. The command is transmitted to the target encrypted storage chip via the NFC interface, activating the chip's internal offline secure data warehouse read permission. The device reads the index table of the encrypted partitions within the warehouse and the physical address of each partition's data storage. The index table contains information such as partition name, data start position, and partition size. The storage address is recorded in hexadecimal form in the device's storage unit, forming a warehouse structure mapping data containing index information and an address mapping table. Based on the partition index and storage address corresponding to the standardized NDEF secure transmission data in the warehouse structure mapping data, the reading device's partition data extraction function sends data extraction commands to the target partitions one by one, transmitting the encrypted data within the partitions to the reading device's buffer in the form of a data stream. The device's built-in cyclic redundancy check mechanism compares the characteristic values before and after data transmission. For erroneous data segments that occur during transmission, the device corrects them by repeatedly extracting the segment and splicing it with adjacent data segments. After error correction is completed, the encrypted data is decoded using the symmetric decryption algorithm integrated into the device to recover the unencrypted original data content, resulting in extracted original data containing complete data fragments, verification records, and error correction logs. By reading the device's format restoration function, the scattered fields in the extracted original data are recombined according to the field order, delimiter rules, and association logic of standardized NDEF data to restore the complete data structure, establish the association relationship between different data fragments, and supplement missing field identifiers, resulting in structurally complete and logically coherent restored target data. The restored target data is sent to a dedicated storage server through the device's encrypted transmission channel. The server uses the AES encryption algorithm to encrypt the data and adds a unique traceability identifier to the data. The identifier includes the data extraction timestamp, the device number recorded during disassembly, the fault association feature description, and the data access operation record. Through the server's log management function, the time, operation behavior, and accessed device information of each data access are automatically recorded to achieve fault traceability and secure data retention management.
[0065] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features of the invention herein.
Claims
1. A secure data transmission method for power banks based on NFC communication, characterized in that, Includes the following steps: Step S1: By deploying multi-dimensional sensors on key components of the power bank, the various status parameters of the power bank throughout its entire life cycle, from production to disposal and recycling, are continuously collected to obtain full-cycle safety status data of the power bank, covering cell voltage, charging and discharging current, operating temperature, circuit stability and interface connection status. Step S2: Standardize the power bank's full-cycle security status data by regularizing fields and unifying formats, and complete the encryption encapsulation and NDEF-compatible format conversion in accordance with the requirements of the NFC secure transmission protocol to obtain standardized NDEF secure transmission data. Step S3: Write the standardized NDEF secure transmission data into a dual-interface non-volatile encrypted storage chip according to the secure storage strategy, and build an anti-tampering offline secure data warehouse through partition isolation, encrypted indexing and multiple backup mechanisms; Step S4: Activate the passive communication mode by integrating the NFC radio frequency module inside the power bank to establish an encrypted short-range wireless communication link between the terminal device and the dual-interface non-volatile encrypted storage chip; support the use of NFC to wake up HTTP web pages, enabling fast data interaction between the power bank and the HTTP web page; support the use of NFC to wake up mini-programs, allowing users to achieve secure data interaction with the power bank without downloading an APP; When a power bank experiences a short circuit, overheating, or bulging, resulting in communication failure, the dual-interface non-volatile encrypted storage chip is non-destructively separated. The encrypted chip is then used to read the device and extract the standardized NDEF secure transmission data stored in the tamper-proof offline secure data warehouse, thus completing fault tracing and secure data retention management.
2. The secure data transmission method for power banks based on NFC communication according to claim 1, characterized in that, Step S1 includes the following steps: According to the internal structure layout of the power bank, a multi-dimensional sensor array consisting of voltage sensors, current sensors, temperature sensors, humidity sensors and circuit detection sensors is deployed at key locations such as the positive and negative terminals of the battery pack, the core chip of the power management unit, the input and output interface circuit and the outer shell. This enables a continuous, all-time acquisition mode to capture various operating status information in real time and obtain the original safety status data stream containing multi-source heterogeneous data. A time synchronization protocol is used to perform time axis calibration and synchronization alignment on heterogeneous data collected by different sensors in the original safety status data stream, eliminating the time deviation caused by the response delay of different sensors and generating time-series aligned data with consistent time dimension. Based on the sensor's factory calibration parameters and real-time environmental interference factors, a drift compensation model is established to correct the sensor drift error in the time-series aligned data, eliminating the acquisition deviation caused by environmental interference and equipment aging, and obtaining optimized calibrated time-series data. Feature engineering methods are used to extract multi-dimensional features from the calibrated time series data, mining voltage fluctuation characteristics, current change trends, temperature distribution patterns and circuit signal stability information. The key features identified are short circuit warning characteristics, overheating risk characteristics and abnormal interface connection characteristics, to obtain safety feature data that can reflect the safe operating status of the power bank. The safety feature data is classified, organized, and systematically archived according to the data collection time, parameter type, and component affiliation. An encrypted data association index is established to generate full-cycle safety status data for the power bank.
3. The secure data transmission method for power banks based on NFC communication according to claim 1, characterized in that, Step S2 includes the following steps: We conduct in-depth analysis of the field structure, data type, and relationships of the full-cycle safety status data of power banks. In conjunction with the requirements of the NFC secure transmission protocol, we establish a unified data dictionary mapping relationship, clarify the meaning, format standard, and encrypted transmission rules of each field, and obtain field mapping data. Based on field mapping data, duplicate records, invalid fields and redundant information in the collected data are identified and removed, core security data is retained, data volume is simplified, and optimized and streamlined security data is obtained. According to the preset data type conversion rules, the numerical, character, and boolean data of different formats in the simplified security data are uniformly converted into standard data types that conform to the NDEF protocol requirements, eliminating data format differences and obtaining standard format security data; The standard format security data is encrypted using the AES-128 encryption algorithm to generate encrypted ciphertext data. At the same time, the unique device identifier is embedded as the basis for decryption and traceability to obtain encrypted security data. Strictly follow the structural specifications of the NDEF protocol regarding the record header, payload, and record tail, arrange the record structure of encrypted secure data, set reasonable record type identifiers, length indicators, and data offset parameters, and embed cyclic redundancy check bits to generate transmission error detection codes; Compatibility adjustments are made to the NFC module characteristics of different brands and models of terminal devices. At the same time, the NDEF record types corresponding to the web page wake-up identifier and the mini program wake-up identifier are configured to ensure that encrypted data can be normally recognized by various terminals and pass decryption verification, generating standardized NDEF secure transmission data with encryption protection, fault tolerance and wake-up interaction capabilities.
4. The secure data transmission method for power banks based on NFC communication according to claim 1, characterized in that, Step S3 includes the following steps: Combining the hardware encryption features of dual-interface non-volatile encrypted storage chips with the storage requirements of standardized NDEF secure transmission data, a secure partitioning plan is designed for the chip storage architecture. This plan divides the chip into a real-time secure zone for storing real-time updated secure data, a historical secure zone for storing historically accumulated secure data, and a redundant secure zone for encrypted backup. Partition access permission controls are set, and the functional positioning and secure storage scope of each partition are clarified to obtain partition security planning data. Based on the functional positioning of each partition in the partition security planning data, the storage priority of standardized NDEF secure transmission data is determined according to update frequency, security level and access priority. Encryption identifiers are added to high-security-level data to obtain data security priority labels. Based on data security priority labels, differentiated encryption writing strategies are formulated to determine the writing order, encryption level, and data overwrite rules of high-security-level data and ordinary-security data in each partition, clarify the single-write data volume and write interval parameters, set up a write log auditing mechanism, and obtain encrypted write control data. According to the requirements of encrypted write control data, the standardized NDEF secure transmission data is written to the corresponding secure storage partition in batches and time periods through the chip's encrypted data interface, and the writing progress, encryption status and error information of each batch of data are fed back in real time to obtain encrypted write status feedback data. Based on the encrypted write status feedback data, the integrity and encryption effectiveness of the data written to each partition are verified. An encrypted data index table is built for each secure storage partition to record the encrypted data storage address, data length and associated data location information. At the same time, an encrypted association mapping table is established between each partition to realize fast retrieval and association query of secure data, forming a tamper-proof offline secure data warehouse.
5. The secure data transmission method for power banks based on NFC communication according to claim 4, characterized in that, The process of obtaining the partition security planning data includes the following steps: The chip physical security attribute parameters corresponding to the storage medium type, storage cell distribution, maximum read / write rate, erase / write life limit, hardware encryption algorithm support type, and data retention time of the dual-interface non-volatile encrypted storage chip are obtained through chip reading tools, forming chip physical security attribute data; A systematic analysis was conducted on the update frequency variation pattern of standardized NDEF secure transmission data, the distribution characteristics of secure access frequency of terminal devices, and the minimum security period requirements for data retention. The life cycle characteristics of different types of secure data were clarified, and the data security life cycle characteristics were obtained. By performing multi-dimensional matching analysis between the storage capacity, read / write performance, encryption capability, and lifetime limitation parameters in the chip's physical security attribute data and the update frequency, security access requirements, and retention period in the data security lifecycle characteristics, the degree of compatibility between the chip's hardware security features and data security storage requirements is evaluated, and security compatibility assessment data is obtained. Based on the matching results of chip performance and data requirements in the security adaptability assessment data, and combined with the security level of each type of data, the capacity allocation ratio of real-time security zone, historical security zone and redundant security zone is reasonably determined to ensure that each partition can meet the storage requirements and encryption requirements of the corresponding security data, and thus obtain security capacity allocation data. Based on the security capacity allocation data, the starting address, ending address, and address range of each partition are determined. Partition address encryption mapping rules are designed to achieve secure conversion between logical addresses and physical addresses. At the same time, the encryption migration trigger conditions, migration paths, and security cleanup strategies for redundant data after migration are formulated between partitions, generating partition security planning data.
6. The secure data transmission method for power banks based on NFC communication according to claim 5, characterized in that, The process of generating the data security lifecycle characteristics includes the following steps: Standardized NDEF secure transmission data is classified into different types based on the real-time nature of data generation and the differences in security applications. These types are clearly distinguished into real-time monitoring security data that reflects the current security operation status and historical statistical security data that records historical security operation status, thus obtaining data security classification results. The update interval statistics of real-time monitoring security data in the data security classification results are performed in the time dimension. The time node of each data update is recorded, the time difference between two adjacent updates is calculated, and an update interval dataset is formed to obtain real-time update frequency data that can reflect the update pattern of real-time security data. By retrieving the security interaction logs between the terminal device and the NFC module, a comprehensive analysis is conducted on the access time, number of accesses, access terminal type, and security verification results of historical security data. The access frequency of historical security data in different time periods and of different types is statistically analyzed to obtain the data security access frequency distribution. Based on the actual security uses of different types of data in the data security classification results and the industry security standard requirements, combined with the warranty period, fault traceability period and data security retention regulations of power bank products, the minimum retention period requirements for each type of data are determined, and the security retention period threshold data are obtained. By structurally integrating real-time update frequency data, data security access frequency distribution, and security retention period threshold data, a data security lifecycle characteristic model is established to comprehensively present the core characteristics of various types of data in terms of updates, secure access, and secure retention, and to generate data security lifecycle characteristics.
7. The secure data transmission method for power banks based on NFC communication according to claim 6, characterized in that, The statistical analysis of the time-dimensional update interval of the real-time monitoring security data in the data security classification results includes the following steps: The encrypted timestamp information corresponding to each data record is extracted from the real-time monitoring security data in the data security classification results using a timestamp extraction algorithm. The data records are sorted in chronological order to construct an encrypted time series dataset containing a complete time series. The time interval calculation method is used to perform difference calculation on the timestamps of two adjacent data records in the encrypted time series dataset to obtain the time interval value between each two adjacent data points, forming a continuous interval duration sequence; An outlier identification model is established based on statistical methods. A reasonable interval threshold range is set, and the data in the interval duration sequence are detected one by one. Abnormal interval data that exceed the threshold range are identified and removed to obtain the effective interval sequence after removing interference. A comprehensive analysis of the effective interval sequence is performed. The arithmetic mean of all interval data in the sequence is calculated to obtain the average interval. The interval data with the smallest value is selected by traversing and comparing to obtain the shortest interval. The interval data with the largest value is selected by traversing and comparing again to obtain the longest interval. At the same time, the variance and standard deviation parameters of the interval data are calculated to obtain the interval statistics. Based on the parameters in the interval statistical data, a real-time update frequency model is constructed that can reflect the update pattern of real-time monitoring security data. The model quantifies the density and fluctuation characteristics of data updates and generates real-time update frequency data.
8. The secure data transmission method for power banks based on NFC communication according to claim 7, characterized in that, The comprehensive analysis of the effective interval sequence includes the following steps: The data entries in the effective interval sequence are counted one by one to determine the total number of interval data participating in the statistical calculation. At the same time, the start index and end index of the sequence are recorded to obtain the data volume statistics results. Based on the statistical results of the data volume, the range of the dataset to be included in the accumulation operation is determined. The accumulation calculation method is used to continuously accumulate all the interval data in the effective interval sequence, and the intermediate results in the accumulation process are recorded. Finally, the sum of all the interval data is obtained, that is, the total interval duration data. The total interval duration data is divided by the total number of interval data in the data volume statistics, and a reasonable number of decimal places are retained in strict accordance with the numerical calculation rules to obtain the average interval duration that can reflect the average level of the interval. Initialize the shortest interval cache variable by assigning the first data entry in the effective interval sequence to the cache variable as the initial reference value to obtain the initial cache data; starting from the second data entry in the effective interval sequence, extract each data entry in turn as the current data to be compared, and compare the current data to be compared with the initial cache data to obtain the comparison result. If the comparison result shows that the current data to be compared is less than the initial cached data, then the shortest interval cache variable is updated to the current data to be compared, and the updated cached data is obtained. If the comparison result shows that the current data to be compared is greater than or equal to the initial cached data, then the initial cached data remains unchanged. The data extraction, numerical comparison and cache update steps are repeated until all data entries in the valid interval sequence have been traversed. The final cached data is the shortest interval duration. Using the same logic as filtering the shortest interval duration, the longest interval cache variable is initialized and the valid interval sequence is traversed to filter out the interval data with the largest value, and the longest interval duration is obtained. The calculated average interval duration, shortest interval duration, and longest interval duration are integrated with the previously calculated variance and standard deviation parameters to generate interval statistics.
9. The secure data transmission method for power banks based on NFC communication according to claim 1, characterized in that, The secure data interaction between the power bank and the user described in step S4 includes the following steps: The system detects the current power supply status of the power bank and the hardware readiness of the NFC radio frequency module, obtaining the module activation prerequisite data. Based on the module activation prerequisite data, it initiates the passive communication mode initialization process of the NFC radio frequency module, pre-configures the HTTP web page wake-up link and the mini-program wake-up identifier, and obtains the mode initialization configuration data. It sends an encrypted wireless communication detection signal through the NFC radio frequency module to scan the NFC modules of terminal devices within the surrounding effective range, obtaining the communication capability identifier, compatibility protocol information, security verification public key, and application wake-up support type of the terminal device, and obtains the terminal detection response data. Based on the terminal detection response data and the mode initialization configuration data, it negotiates communication parameters and obtains the link negotiation result data. Based on the link negotiation results, an encrypted short-range wireless communication link is established between the terminal device and the dual-interface non-volatile encrypted storage chip, and link establishment confirmation data is obtained through the session key. Based on the link establishment confirmation data, the encrypted data read request sent by the terminal device is received and the legitimate access rights of the requesting terminal are parsed to obtain read request parsing data. Based on the read request parsing data, the corresponding standardized NDEF secure transmission data is retrieved from the tamper-proof offline secure data warehouse, and encrypted data fragmentation and transmission order arrangement are performed. If the target invocation method is an HTTP webpage, the data is associated and encapsulated with the webpage invocation link; if the target invocation method is a mini-program, the data is associated and encapsulated with the mini-program invocation identifier to obtain an encrypted data queue to be transmitted. The encrypted data queue is sent piece by piece to the terminal device via an established encrypted short-range wireless communication link. The data transmission progress and reception confirmation information are fed back in real time. The integrity of the data transmission is verified based on the check bit. If there is any transmission loss, the encrypted retransmission mechanism is triggered. After the terminal device receives the complete encrypted data and completes the decryption verification, it automatically performs the corresponding operation according to the associated wake-up identifier. It can wake up an HTTP webpage by NFC touch and synchronize the decrypted power bank data to the webpage interface to achieve quick interaction; or it can wake up a mini-program by NFC touch. Users can interact with the secure data of the power bank through the mini-program interface without downloading an APP, realizing offline encrypted real-time interaction of standardized NDEF secure data transmission.
10. The secure data transmission method for power banks based on NFC communication according to claim 1, characterized in that, Step S4, which describes completing fault tracing and security data retention management, includes the following steps: When a power bank malfunctions and loses communication, a fault status detection process is performed to identify the fault type, the scope of its impact, and the physical security status of the encrypted storage chip, yielding fault detection and assessment data. Based on this data, a suitable anti-leakage disassembly tool is selected, and a targeted safe disassembly process is developed, specifying the disassembly sequence, operational force, and chip protection measures to prevent data leakage, resulting in disassembly plan data. Following the disassembly plan data, the power bank's outer shell, internal fixing structure, and connecting lines are gradually disassembled in a dust-free and safe environment, avoiding critical components in the area where the encrypted storage chip is located to minimize physical damage during disassembly, resulting in disassembly process status data. Based on the disassembly process status data, the installation position and fixing method of the dual-interface non-volatile encrypted memory chip are located. A precise disassembly operation is used to separate the chip from the surrounding circuits, ensuring the integrity of the chip pins, storage medium, and package structure, resulting in a non-destructive separation of the target encrypted memory chip. The target encrypted memory chip is then subjected to external cleaning and pin inspection to remove surface stains and residual solder, yielding chip pre-processing inspection data. The pre-processed target encrypted memory chip is then adapted and connected to a dedicated encrypted chip reading device. The communication interface, power supply parameters, and encrypted data parsing protocol of the reading device are configured, and the device decryption key is input to obtain chip connection configuration data. The chip reading device is started based on the chip connection configuration data. An encrypted data reading command is sent to read the encrypted partition index and data storage address of the offline secure data warehouse in the target encrypted storage chip, thus obtaining the warehouse structure mapping data. The storage location of the standardized NDEF secure transmission data is located according to the warehouse structure mapping data. The encrypted data content is extracted partition by partition, and data integrity verification and error correction are performed. The original data is recovered through decryption algorithms to obtain the extracted original data. The extracted original data is then formatted and integrated to restore the complete structure and relationships of the standardized NDEF secure transmission data, thus obtaining the restored target data. The restored target data is then encrypted, backed up, and marked for traceability. The data extraction time, disassembly process information, fault correlation characteristics, and data access logs are recorded to complete fault tracing and secure data retention management.
Citation Information
Patent Citations
NFC label
CN106845599A
Full-life-cycle aviation material management method and system based on radio frequency tag
CN114118326A