Intelligent door lock remote password sharing door opening method and system based on quantum key

By using quantum key technology to generate and manage initial keys for door locks and terminals, the problems of key leakage and platform management pressure in remote door opening of smart door locks are solved, achieving high security and lightweight key management, and ensuring the security and reliability of door opening operations.

CN121811531APending Publication Date: 2026-04-07E-SURFING DIGITAL LIFE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-13
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing smart door lock remote unlocking technologies suffer from risks of key leakage, heavy platform operation and management pressure, and insufficient security of temporary passwords, especially in terms of key uniqueness and true randomness.

Method used

By employing quantum key technology, a quantum cryptography service platform generates truly random numbers to generate initial keys for door locks and terminals. Symmetric encryption algorithms are used to ensure the secure transmission and synchronization of session keys. Combined with hardware secure storage and dynamically generated quantum session keys, the uniqueness and unpredictability of the keys are achieved.

Benefits of technology

It improves the security of smart door lock systems, avoids the risks of key duplication and leakage, reduces the difficulty and cost of platform operation and management, and ensures the security and reliability of door opening operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121811531A_ABST
    Figure CN121811531A_ABST
Patent Text Reader

Abstract

The invention provides an intelligent door lock remote password sharing door opening method and system based on a quantum key. The method comprises the following steps: generating initial keys of a door lock and two terminals through a quantum cryptography service platform; the door lock access management platform activates the door lock according to the sharing request; the door lock requests a quantum session key from the quantum cryptography service platform, and the quantum session key is decrypted and acquired by using the door lock initial key; the platform sends the quantum session key identifier to the first terminal and the second terminal, the two terminals respectively use respective initial keys to obtain and decrypt the session key, and synchronous distribution of the quantum session key among the three parties is realized; the first terminal encrypts the temporary door opening password by using the quantum session key to generate password ciphertexts, and the password ciphertexts are respectively issued to the second terminal and the door lock through the platform; the second terminal and the door lock respectively decrypt to obtain the temporary door opening password, and the door lock executes unlocking after verifying that the input password is matched with the temporary password. According to the invention, high-security remote password sharing and verification are realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of terminal security management, and particularly relates to a quantum key-based intelligent door lock remote password sharing opening method and system. BACKGROUND

[0002] As an important part of smart home, the intelligent door lock provides users with a variety of convenient unlocking methods. With the development of Internet of Things technology, the intelligent door lock gradually has the function of remote communication unlocking through the mobile phone client connecting the service platform, and plays an important role in remote authorization opening, temporary visitor management, emergency rescue and other application scenarios. In these scenarios, the door lock needs to be connected to the network and ensure the security of remote opening through encrypted communication, and at the same time needs to realize the secure sharing and synchronization of temporary passwords between different terminals.

[0003] However, the existing intelligent door lock remote opening technical scheme has many security risks. The current mainstream encryption scheme usually adopts the way of prewriting fixed encryption key when the door lock is factory-finished, or preinstalling asymmetric private key in the door lock to generate session key through key agreement algorithm. These schemes have the following technical problems: the door lock firmware is easy to be decompiled and cracked, resulting in the leakage of the encryption key prewritten in the firmware; the door lock access management platform needs to store and manage a large number of door lock key lists, increasing the operation and management pressure of the platform and the risk of key leakage; the public and private key pairs generated by the door lock manufacturer during production cannot guarantee uniqueness, and multiple door locks may use the same key; the security of the temporary password directly pushed by the short message or APP is insufficient, and the generated temporary password is a pseudo-random number, which has the risk of being predicted and cracked.

[0004] Therefore, how to realize the secure synchronization and distribution of temporary opening passwords between the door lock and multiple authorized terminals while guaranteeing the uniqueness and true randomness of the key, and at the same time reduce the key management pressure of the door lock access management platform, has become a technical problem to be solved. SUMMARY

[0005] In view of the above deficiencies of the prior art, the purpose of the application is to provide a quantum key-based intelligent door lock remote password sharing opening method and system.

[0006] The application provides a quantum key-based intelligent door lock remote password sharing opening method, comprising: S1: generating a true random number generated by a quantum random number generator through a quantum password service platform to obtain a door lock initial key, a first terminal initial key and a second terminal initial key; S2: send the sharing request information to the door lock access management platform, the sharing request information carries a door lock unique identifier, a first terminal account and a second terminal account, and the door lock access management platform sends an activation instruction to the door lock according to the door lock unique identifier; S3: the door lock initiates a session key request to the quantum cryptography service platform carrying a door lock initial key identifier in response to the activation instruction, the quantum cryptography service platform encrypts the quantum session key through a symmetric encryption algorithm to obtain a first encrypted ciphertext, and returns the first encrypted ciphertext and the quantum session key identifier to the door lock, and the door lock decrypts the first encrypted ciphertext using the door lock initial key to obtain the quantum session key; S4: the door lock access management platform sends the quantum session key identifier to the first terminal and the second terminal, the first terminal uses the first terminal initial key and the second terminal uses the second terminal initial key to respectively obtain the encrypted quantum session key from the quantum cryptography service platform, and after decryption processing, the quantum session key is synchronously distributed between the first terminal, the second terminal and the door lock; S5: the first terminal encrypts the temporary door opening password to be shared using the quantum session key to obtain a password ciphertext, and sends the password ciphertext to the second terminal and the door lock through the door lock access management platform; S6: the second terminal and the door lock respectively use the quantum session key held by each to decrypt the password ciphertext to obtain the temporary door opening password, and the door lock matches and verifies the received password input with the decrypted temporary door opening password, and performs an unlocking operation after verification.

[0007] According to the intelligent door lock remote sharing password opening method based on quantum key provided by the application, step S1 further comprises: S11: based on the quantum cryptography service platform, a true random number is generated based on at least one of the physical unpredictability of photon counting, photon arrival time or photon arrival position through a quantum random number generator; S12: the true random number is used as an entropy source to respectively generate a door lock initial key, a first terminal initial key and a second terminal initial key, and a unique key identifier is allocated to each initial key to obtain a door lock initial key identifier, a first terminal initial key identifier and a second terminal initial key identifier; S13: the door lock initial key is pre-written into the security chip built in the door lock, and the first terminal initial key and the second terminal initial key are respectively written into the SIM cards of the first terminal and the second terminal; S14: the quantum cryptography service platform establishes and stores a correspondence table of keys and key identifiers.

[0008] According to the present invention, a method for remotely sharing a password to open a smart door lock based on quantum key distribution, the method further includes the following steps before step S2: S21: When the door lock is activated, the first terminal binds itself to the door lock and sends the binding relationship between the first terminal account and the unique identifier of the door lock to the door lock access management platform; S22: The door lock access management platform establishes and stores the correspondence between the first terminal account and the unique identifier of the door lock; S23: The door lock establishes a heartbeat connection with the door lock access management platform. All other components except the heartbeat connection component enter a dormant state, waiting for the activation command to wake them up.

[0009] According to the present invention, a method for remotely sharing a password to open a smart door lock based on quantum key distribution, in step S3, the process of the quantum cryptography service platform encrypting the quantum session key using a symmetric encryption algorithm to obtain the first encrypted ciphertext further includes: S31: The quantum cryptography service platform receives the initial key identifier of the door lock sent by the door lock, and obtains the initial key of the door lock by querying the corresponding relationship table according to the initial key identifier of the door lock; S32: The quantum cryptography service platform uses a quantum random number generator to generate quantum session keys and assigns quantum session key identifiers to the quantum session keys; S33: Using the initial key of the door lock as the encryption key, the quantum session key is encrypted using the SM4 symmetric encryption algorithm to obtain the first encrypted ciphertext.

[0010] According to the present invention, a method for remotely sharing a password to open a smart door lock based on quantum key distribution, after step S3, further includes: S34: The door lock sends the quantum session key identifier to the door lock access management platform; S35: The door lock access management platform stores the correspondence between the unique door lock identifier and the quantum session key identifier in the cache; S36: The door lock access management platform receives the second terminal account, finds the corresponding second terminal through the door lock's unique identifier, and sends the door lock's unique identifier to the second terminal.

[0011] According to the present invention, a method for remotely sharing a password to open a smart door lock based on quantum key distribution, in step S4, the process of the first terminal using its initial key to obtain an encrypted quantum session key from a quantum cryptography service platform specifically includes: S411: The door lock access management platform responds to the sharing request from the first terminal and returns the quantum session key identifier to the first terminal; S412: The first terminal, carrying the first terminal initial key identifier and the quantum session key identifier, initiates an acquisition request to the quantum cryptography service platform; S413: The quantum cryptography service platform obtains the quantum session key by querying the quantum session key identifier and obtains the first terminal initial key by querying the first terminal initial key identifier; S414: Using the initial key of the first terminal as the encryption key, the quantum session key is encrypted using the SM4 symmetric encryption algorithm to obtain the second encrypted ciphertext, and the second encrypted ciphertext is returned to the first terminal; S415: The first terminal uses the first terminal initial key stored in the SIM card to decrypt the second encrypted ciphertext and obtain the quantum session key.

[0012] According to the present invention, a method for remotely sharing a password to open a smart door lock based on quantum key distribution, in step S4, the process of the second terminal using its initial key to obtain an encrypted quantum session key from a quantum cryptography service platform specifically includes: S421: The second terminal, carrying the unique identifier of the second door lock and the second terminal account, initiates a request to the door lock access management platform; S422: The door lock access management platform verifies the authorization status of the second terminal based on the second terminal account and the unique identifier of the second door lock. After successful verification, it extracts the quantum session key identifier from the temporarily stored correspondence and sends the quantum session key identifier to the second terminal. S423: The second terminal reads the second terminal initial key and the second terminal initial key identifier from the SIM card, combines the second terminal initial key identifier and the quantum session key identifier, and sends them to the quantum cryptography service platform; S424: The quantum cryptography service platform obtains the initial key of the second terminal by querying the initial key identifier of the second terminal, and obtains the quantum session key by querying the quantum session key identifier; S425: Using the initial key of the second terminal as the encryption key, the quantum session key is encrypted using the SM4 symmetric encryption algorithm to obtain the third encrypted ciphertext, and the third encrypted ciphertext is returned to the second terminal; S426: The second terminal uses the initial key of the second terminal stored in the SIM card to decrypt the third encrypted ciphertext and obtain the quantum session key.

[0013] According to the present invention, a method for remotely sharing a password to unlock a smart door lock based on quantum key distribution, step S5 further includes: S51: The first terminal receives the temporary door opening password and validity period information entered by the user; S52: The first terminal uses the quantum session key as the encryption key to encrypt the temporary door opening password and obtain the password ciphertext; S53: The first terminal sends the password ciphertext, validity period information and unique door lock identifier to the door lock access management platform; S54: The door lock access management platform sends the encrypted password to the second terminal, and at the same time finds the corresponding door lock based on the unique identifier of the door lock, and sends the encrypted password and validity time information to the door lock.

[0014] According to the present invention, a method for remotely sharing a password to unlock a smart door lock based on quantum key distribution is provided. In step S6, the door lock performs a matching verification based on the received password input and the decrypted temporary unlocking password. After successful verification, the unlocking operation is performed. The specific steps include: S61: The door lock uses the quantum session key to decrypt the received ciphertext and obtain the temporary unlocking password plaintext; S62: The door lock receives the password information entered by the user through the keypad; S63: Match the input password information with the decrypted temporary door opening password plaintext, and verify the validity period by combining the valid time information; S64: When the password matches and is within the valid time range, the door lock performs the unlocking operation.

[0015] This invention also provides a smart door lock remote password sharing unlocking system based on quantum key distribution, comprising: The quantum cryptography service platform is used to generate keys from truly random numbers using a quantum random number generator to obtain initial keys for a door lock, a first terminal, and a second terminal, and to establish a mapping relationship between multiple initial keys and their corresponding key identifiers. The quantum cryptography service platform is also used to generate quantum session keys after receiving the initial key identifier of the door lock, and to encrypt the quantum session keys using a symmetric encryption algorithm before sending them to the door lock, the first terminal, and the second terminal respectively. The door lock access management platform is used to receive sharing request information carrying a unique door lock identifier, a first terminal account, and a second terminal account, and to send an activation command to the door lock according to the unique door lock identifier; the door lock access management platform is also used to store the binding relationship between the first terminal account and the unique door lock identifier, temporarily store the correspondence between the unique door lock identifier and the quantum session key identifier, and verify the authorization status of the second terminal. A key storage module is installed in the security chip inside the door lock to store the door lock initial key and the door lock initial key identifier; the key storage module is also installed in the SIM cards of the first terminal and the second terminal to store the first terminal initial key and the first terminal initial key identifier, and the second terminal initial key and the second terminal initial key identifier, respectively. The key synchronization module is used to initiate a session key request to the quantum cryptography service platform after the door lock responds to the activation command, carrying the door lock's initial key identifier. It receives the first encrypted ciphertext and quantum session key identifier returned by the quantum cryptography service platform, and decrypts the first encrypted ciphertext using the door lock's initial key to obtain the quantum session key. The key synchronization module is also used for the first terminal and the second terminal to obtain the encrypted quantum session key from the quantum cryptography service platform using their respective initial keys and decrypt it, thereby realizing the synchronous distribution of the quantum session key among the first terminal, the second terminal, and the door lock. The password encryption module is used by the first terminal to encrypt the temporary door opening password to be shared using a quantum session key to obtain the password ciphertext, and then distributes the password ciphertext to the second terminal and the door lock respectively through the door lock access management platform. The verification and unlocking module is used by the second terminal and the door lock to decrypt the ciphertext using their respective quantum session keys to obtain a temporary unlocking password. The verification and unlocking module is also used by the door lock to match and verify the received password input with the decrypted temporary unlocking password, and to verify the timeliness by combining the valid time information. After the verification is successful, the unlocking operation is performed.

[0016] This invention provides a method and system for remotely sharing passwords to unlock smart locks based on quantum key distribution. By utilizing a quantum cryptography service platform and a quantum random number generator to generate truly random numbers as an entropy source based on the physical unpredictability of photon counting, photon arrival time, or photon arrival location, it fundamentally solves the key predictability problem caused by traditional pseudo-random number generation methods. This effectively avoids the risk of key duplication between different locks due to the use of the same factor to generate random numbers, ensuring that the initial key for each lock and each terminal, as well as the session key for each communication, are unique and unpredictable, significantly improving the overall security of the system. Furthermore, this invention employs a hardware-level secure storage method, storing the initial key separately in the lock's security chip and the terminal's SIM card. Even if the lock firmware is decompiled or cracked, or firmware information is leaked during production, attackers cannot directly obtain the encryption key. Moreover, since the quantum session key used for each communication is dynamically generated by the quantum cryptography service platform, attackers cannot predict or forge the session key using historical key information, thus preventing the sending of false unlocking commands and effectively preventing illegal unlocking. Furthermore, the door lock access management platform of the present invention only needs to manage the binding relationship between users and door locks. The session key identifier only needs to be temporarily stored during the operation and can be deleted after the operation is completed. There is no need to store and manage a large number of door lock key lists for a long time, which significantly reduces the difficulty of platform operation and management and the risk of key leakage, reduces the platform's storage pressure and security maintenance costs, and makes large-scale door lock access management more lightweight and secure. Attached Figure Description

[0017] The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Throughout the drawings, the same reference numerals denote the same parts. It is obvious that the drawings described below are merely some embodiments of the present invention, and those skilled in the art can obtain other drawings based on these drawings.

[0018] Figure 1 This is a schematic diagram of a method for remotely sharing a password to open a smart door lock based on quantum key distribution, provided in an embodiment of the present invention. Figure 2 This is a schematic diagram of a remote password sharing system for smart locks based on quantum key distribution, provided as an embodiment of the present invention. Detailed Implementation

[0019] To enable those skilled in the art to better understand the technical solutions in the embodiments of the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, not all embodiments. It should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0020] Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts disclosed in this invention.

[0021] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicating orientation or positional relationships based on the orientation or positional relationships shown in the accompanying drawings, are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance. The terms "installed," "connected," and "linked" should be interpreted broadly; for example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal communication of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0022] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numerals in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. Rather, they are merely examples of methods and systems consistent with some aspects of the invention as detailed in the appended claims.

[0023] The embodiments of the present invention are described below with reference to the figures.

[0024] like Figure 1 As shown, this invention provides a method for remotely sharing passwords to open smart locks based on quantum key distribution, comprising: S1: Generate keys from the true random numbers generated by the quantum random number generator through the quantum cryptography service platform to obtain the initial key of the door lock, the initial key of the first terminal, and the initial key of the second terminal.

[0025] Step S1 further includes: S11: Based on the quantum cryptography service platform, a quantum random number generator generates true random numbers based on at least one of the physical unpredictability methods of photon counting, photon arrival time, or photon arrival location.

[0026] Furthermore, quantum random number generators utilize the intrinsic randomness of quantum mechanics to generate truly random numbers, unlike traditional algorithm-based pseudo-random number generators. Specifically, the photon counting method detects the number of photons arriving at the detector per unit time; since the photon emission and arrival process follows the quantum uncertainty principle, its counting result is truly random. The photon arrival time method measures the precise time interval between photons arriving at the detector; this time interval is unpredictable due to quantum fluctuations. The photon arrival position method records the impact positions of photons on the detector array; this position distribution conforms to a quantum probability distribution.

[0027] In step S11 of this invention, a quantum random number generator is started through a quantum cryptography service platform. At least one physical method is selected, and the detector continuously collects the raw data stream generated by quantum events. The physical signal is converted into a digital bit sequence by an analog-to-digital converter. Then, the raw bit sequence is post-processed to eliminate device bias, and finally, a true random number sequence that meets the requirements of statistical uniformity and independence is output.

[0028] S12: Using the true random number as the entropy source, generate the door lock initial key, the first terminal initial key and the second terminal initial key respectively, and assign a unique key identifier to each initial key to obtain the door lock initial key identifier, the first terminal initial key identifier and the second terminal initial key identifier.

[0029] Furthermore, since the entropy source provides the randomness, this invention uses a true random number sequence as a high-quality entropy source input to the key generation module. Subsequently, the quantum cryptography service platform extracts a bit string of a specified length from the true random number sequence directly as the initial key K1 for the door lock; it then extracts a non-overlapping bit string of the same length from the sequence as the initial key K2 for the first terminal; and finally extracts the next segment as the initial key K2' for the second terminal. Subsequently, the quantum cryptography service platform assigns a unique identifier to each generated key, using UUID format or an auto-incrementing number, generating an initial key identifier ID1 for the door lock corresponding to K1, an initial key identifier ID2 for the first terminal corresponding to K2, and an initial key identifier ID2' for the second terminal corresponding to K2', establishing a one-to-one mapping relationship between the key and the identifier.

[0030] S13: Pre-write the initial key of the door lock into the security chip built into the door lock, and write the initial key of the first terminal and the initial key of the second terminal into the SIM cards of the first terminal and the second terminal respectively.

[0031] Furthermore, the security chip is a hardware module with anti-tampering and encrypted storage functions. Before leaving the factory, the door lock establishes a secure connection with the quantum cryptography service platform through a dedicated writing device. In step S13, the initial key K1 and its identifier ID1 of the door lock are transmitted to the writing device through an encrypted channel via the quantum cryptography service platform. The writing device burns K1 and ID1 into the unreadable storage area of ​​the security chip built into the door lock. The SIM card serves as the security chip for the terminal. During the card production or activation stage, the SIM cards of the first and second terminals are connected to the quantum cryptography service platform via OTA technology. The quantum cryptography service platform writes the initial key K2 and identifier ID2 of the first terminal into the SIM card of the first terminal, and writes the initial key K2' and identifier ID2' of the second terminal into the SIM card of the second terminal. The key data is stored in the secure file system of the SIM card and can only be accessed by authorized applications.

[0032] S14: A table of correspondences between keys and key identifiers is established and stored by the quantum cryptography service platform.

[0033] In step S14, the quantum cryptography service platform of the present invention creates a key relationship table in the database. The table structure includes a key identifier field, a key value field, a device type field, and a generation timestamp field. Specifically, the platform writes the correspondence between the initial key identifier ID1 of the door lock and the key K1 into the first record of the table, and marks the device type as door lock; writes the correspondence between the initial key identifier ID2 of the first terminal and the key K2 into the second record, and marks the device type as first terminal; writes the correspondence between the initial key identifier ID2' of the second terminal and the key K2' into the third record, and marks the device type as second terminal. The resulting correspondence table is indexed with the key identifier as the primary key. When a key identifier query request is received, the platform quickly retrieves and returns the corresponding key value through the index.

[0034] The steps preceding step S2 include: S21: When the door lock is activated, the first terminal binds itself to the door lock and sends the binding relationship between the first terminal account and the unique identifier of the door lock to the door lock access management platform.

[0035] Furthermore, the unique identifier of the door lock refers to the serial number or device code assigned to the door lock at the factory. The first terminal, the mobile phone of the door lock owner, establishes a connection with the door lock via Bluetooth or NFC near-field communication upon initial activation, and the door lock transmits its unique identifier to the first terminal. Additionally, the first terminal account is the mobile phone number or user ID registered by the user on the door lock access management platform. The first terminal's APP reads the currently logged-in account information, combines the first terminal account with the door lock's unique identifier into a binding data packet, and sends this data packet to the binding interface of the door lock access management platform via an internet connection.

[0036] S22: The door lock access management platform establishes and stores the correspondence between the first terminal account and the unique identifier of the door lock.

[0037] Furthermore, after receiving the binding data packet, the door lock access management platform parses and extracts the first terminal account and the door lock's unique identifier. It then creates a new record in the binding relationship database, storing the first terminal account as the user field and the door lock's unique identifier as the device field, establishing a mapping relationship between the account and the device. The platform also creates a reverse index, allowing users to query the bound first terminal account using the door lock's unique identifier as the key, and to query all door lock devices bound to that account using the first terminal account as the key.

[0038] S23: The door lock establishes a heartbeat connection with the door lock access management platform. All other components except the heartbeat connection component enter a dormant state, waiting for the activation command to wake them up.

[0039] In step S23, the heartbeat connection refers to a long-term connection during which the door lock sends a liveness signal to the door lock access management platform. The door lock establishes a TCP long connection with the platform via a WiFi or 4G module. The door lock sends heartbeat data packets to the platform at fixed time intervals (e.g., 30 seconds). After receiving the heartbeat packets, the platform returns an acknowledgment response to maintain the connection. The door lock's heartbeat connection component continuously runs, listening for messages sent by the platform. Other functional components of the door lock, such as the password verification module, display module, and motor control module, enter a low-power sleep state. When the heartbeat connection component receives an activation command from the platform, it triggers an interrupt signal to wake up the sleep component.

[0040] S2: Send the sharing request information to the door lock access management platform. The sharing request information carries the door lock's unique identifier, the first terminal account, and the second terminal account. The door lock access management platform sends an activation command to the door lock based on the door lock's unique identifier.

[0041] S3: In response to the activation command, the door lock sends a session key request to the quantum cryptography service platform, carrying the door lock initial key identifier. The quantum cryptography service platform encrypts the quantum session key using a symmetric encryption algorithm to obtain a first encrypted ciphertext, and returns the first encrypted ciphertext and the quantum session key identifier to the door lock. The door lock uses the door lock initial key to decrypt the first encrypted ciphertext to obtain the quantum session key.

[0042] In step S3, the process of the quantum cryptography service platform encrypting the quantum session key using a symmetric encryption algorithm to obtain the first encrypted ciphertext further includes: S31: The quantum cryptography service platform receives the initial key identifier of the door lock sent by the door lock, and obtains the initial key of the door lock by querying the corresponding relationship table according to the initial key identifier of the door lock.

[0043] In step S31, after the door lock is activated, the initial key identifier ID1 of the door lock stored in the security chip is first read, and ID1 is encapsulated into a query request message and sent to the quantum cryptography service platform. The interface service of the quantum cryptography service platform receives the request message, parses and extracts the ID1 field value, uses ID1 as a query condition to perform a SELECT query operation in the key relationship table established in step S14, matches the record whose key identifier field is equal to ID1, and returns the key value field of the record, thus obtaining the initial key K1 of the door lock.

[0044] S32: The quantum cryptography service platform uses a quantum random number generator to generate quantum session keys and assigns quantum session key identifiers to the quantum session keys.

[0045] In step S32, the quantum cryptography service platform restarts the quantum random number generator, generating a new true random number sequence as in step S11. 128 bits or 256 bits are extracted from this sequence as the quantum session key Ks for this session. The platform then generates a new unique identifier as the quantum session key identifier IDs, which is generated using a combination of timestamp and random number to ensure global uniqueness. Finally, the platform inserts a new record into the key relationship table, storing the correspondence between IDs and Ks, and marking the device type as the session key.

[0046] S33: Using the initial key of the door lock as the encryption key, the quantum session key is encrypted using the SM4 symmetric encryption algorithm to obtain the first encrypted ciphertext.

[0047] Further, in step S33, the present invention uses the initial door lock key K1 obtained in step S31 as the encryption key input for the SM4 algorithm, and the quantum session key Ks generated in step S32 as the plaintext input. After receiving the data, the SM4 algorithm performs 32 rounds of iterative operations. Each round includes nonlinear transformation, linear transformation, and round key addition. Specifically, Ks is grouped into 128-bit blocks. If the length of Ks is 256 bits, it is divided into two groups. Each group is input into the SM4 encryption function, and 32 rounds of encryption iteration are performed using the round key derived from K1. In each round, nonlinear transformation is achieved through byte substitution using an S-box, and linear transformation is achieved through cyclic shift and XOR operations. Finally, a 128-bit ciphertext block is output. Finally, all ciphertext blocks are concatenated to obtain the first encrypted ciphertext EK1(Ks).

[0048] After step S3, the following is also included: S34: The door lock sends the quantum session key identifier to the door lock access management platform.

[0049] In step S34, after receiving the first encrypted ciphertext EK1(Ks) and quantum session key identifier IDs returned by the quantum cryptography service platform, the door lock reads the initial key K1 from the security chip and uses K1 as the SM4 decryption key to decrypt EK1(Ks). The SM4 decryption process performs 32 rounds of iterations in reverse order of encryption, using the same round key in reverse order to finally output the plaintext quantum session key Ks. After decryption, the door lock stores Ks in the volatile storage area of ​​the security chip. Subsequently, the door lock constructs a reporting message, the message body of which contains the unique identifier of the door lock and the quantum session key identifier IDs, and sends the message to the door lock access management platform through the heartbeat connection channel.

[0050] S35: The door lock access management platform stores the correspondence between the unique door lock identifier and the quantum session key identifier in a cache.

[0051] Furthermore, in step S35, the door lock access management platform receives the reporting message from step S34, parses and extracts the unique identifier of the door lock and the quantum session key identifier IDs, uses the unique identifier of the door lock as the key and IDs as the value, executes the SET command to write the key-value pair into the cache, and sets the expiration time to 10 minutes or 30 minutes. After the time expires, the cache will automatically delete the record to avoid occupying storage space for a long time.

[0052] S36: The door lock access management platform receives the second terminal account, finds the corresponding second terminal through the door lock's unique identifier, and sends the door lock's unique identifier to the second terminal.

[0053] Furthermore, the door lock access management platform receives a sharing request information containing a second terminal account in step S2. Based on this account, the platform queries the user device table for the device push address or online connection identifier bound to that account to obtain the second terminal's communication address. Subsequently, the platform extracts the door lock's unique identifier from the sharing request information, constructs a notification message, and the message body contains the door lock's unique identifier and a sharing operation type marker. This notification message is sent to the second terminal's app via push service or a long connection channel. The second terminal receives and parses the message, learns that door lock sharing is authorized, and records the door lock's unique identifier.

[0054] S4: The door lock access management platform sends the quantum session key identifier to the first terminal and the second terminal. The first terminal uses the initial key of the first terminal and the second terminal uses the initial key of the second terminal to obtain the encrypted quantum session key from the quantum cryptography service platform respectively. After decryption, the quantum session key is synchronously distributed among the first terminal, the second terminal and the door lock.

[0055] In step S4, the process of the first terminal using its initial key to obtain the encrypted quantum session key from the quantum cryptography service platform specifically includes: S411: The door lock access management platform responds to the sharing request from the first terminal and returns the quantum session key identifier to the first terminal.

[0056] In step S411, after the door lock access management platform receives the sharing request information sent by the first terminal in step S2, the request information already carries the unique identifier of the door lock, the account of the first terminal, and the account of the second terminal. After storing the correspondence between the unique identifier of the door lock and the quantum session key identifier IDs in the cache in step S35, the platform constructs a response message for the sharing request of the first terminal. Subsequently, the platform uses the unique identifier of the door lock as the key to execute a GET command to read the corresponding value from the cache and obtain the quantum session key identifier IDs. Then, the platform encapsulates the IDs into the data field of the response message and returns the response message to the first terminal through the connection channel established between the first terminal and the platform. The APP of the first terminal receives the response message, parses and extracts the quantum session key identifier IDs and caches them in local memory.

[0057] S412: The first terminal, carrying the first terminal initial key identifier and the quantum session key identifier, sends an acquisition request to the quantum cryptography service platform.

[0058] Furthermore, the first terminal reads the pre-stored first terminal initial key identifier ID2 from the secure file system of the SIM card, and combines the quantum session key identifier IDs obtained in step S411 with ID2 to construct a request data packet. This data packet includes a request type field marked as session key acquisition, a first terminal initial key identifier field filled with ID2, and a quantum session key identifier field filled with IDs. Subsequently, the first terminal connects to the key distribution interface of the quantum cryptography service platform via a mobile network or WiFi, and sends the request data packet to the quantum cryptography service platform using HTTPS encrypted transmission.

[0059] S413: The quantum cryptography service platform obtains the quantum session key by querying the quantum session key identifier and obtains the first terminal initial key by querying the first terminal initial key identifier.

[0060] The quantum cryptography service platform's interface receives the request data packet sent by the first terminal, parses it, and extracts the quantum session key identifier IDs and the first terminal's initial key identifier ID2. Subsequently, the platform performs a SELECT query operation in the key relationship table using IDs as the query condition, matching records where the key identifier field equals IDs, and reads the quantum session key Ks from the key value field of that record. Simultaneously, the platform performs another SELECT query operation in the same key relationship table using ID2 as the query condition, matching records where the key identifier field equals ID2, and finally reads the first terminal's initial key K2 from the key value field of that record.

[0061] S414: Using the initial key of the first terminal as the encryption key, the quantum session key is encrypted using the SM4 symmetric encryption algorithm to obtain the second encrypted ciphertext, and the second encrypted ciphertext is returned to the first terminal.

[0062] Furthermore, this invention uses the initial terminal key K2 obtained in step S413 as the input key for the SM4 algorithm, and the quantum session key Ks as the plaintext to be encrypted. Then, the SM4 algorithm is executed, processing Ks into 128-bit blocks. Each block undergoes 32 rounds of encryption iteration. In each round, a round key derived from K2 is XORed with the data block. After S-box byte substitution and linear transformation, ciphertext blocks are output after 32 iterations. All ciphertext blocks are then concatenated to form the second encrypted ciphertext EK2(Ks). Finally, the quantum cryptography service platform constructs a response data packet, fills the data field with EK2(Ks), and returns the response data packet to the first terminal via an HTTPS encrypted channel.

[0063] S415: The first terminal uses the first terminal initial key stored in the SIM card to decrypt the second encrypted ciphertext and obtain the quantum session key.

[0064] In step S415, the first terminal receives the response data packet returned by the quantum cryptography service platform and parses it to extract the second encrypted ciphertext EK2(Ks). Subsequently, the first terminal sends a key read command to the SIM card, which reads the initial key K2 from the secure file system and returns it to the terminal application. Then, this invention uses K2 as the SM4 decryption key to perform decryption on EK2(Ks). The SM4 decryption process performs 32 rounds of inverse iterative transformation using the same round key in the reverse order of encryption, sequentially performing inverse linear transformation and inverse S-box replacement on the ciphertext blocks. After all rounds are completed, the plaintext blocks are output. Finally, the decrypted plaintext blocks are concatenated to restore the complete quantum session key Ks, which the first terminal stores in a secure area of ​​memory for subsequent encryption operations.

[0065] In step S4, the process of the second terminal using its initial key to obtain the encrypted quantum session key from the quantum cryptography service platform specifically includes: S421: The second terminal sends a request to the door lock access management platform, carrying the unique identifier of the second door lock and the second terminal account.

[0066] In step S421, after receiving the door lock unique identifier notification message sent by the door lock access management platform in step S36, the second terminal extracts the door lock unique identifier from the message. Then, the second terminal reads the currently logged-in second terminal account information, combines the door lock unique identifier with the second terminal account to construct a key to obtain a request data packet. The data packet includes a request type field marked as session key application, a door lock identifier field filled with the door lock unique identifier, and a user account field filled with the second terminal account. Finally, the second terminal sends the request data packet to the authorization verification interface of the door lock access management platform via the Internet connection.

[0067] S422: The door lock access management platform verifies the authorization status of the second terminal based on the second terminal account and the unique identifier of the second door lock. After successful verification, it extracts the quantum session key identifier from the temporarily stored correspondence and sends the quantum session key identifier to the second terminal.

[0068] Furthermore, the door lock access management platform receives the request data packet from the second terminal, parses and extracts the second terminal account and the unique identifier of the door lock. Subsequently, the platform compares the extracted second terminal account with the second terminal account carried in the sharing request information in step S2, and at the same time compares the unique identifier of the door lock with the unique identifier of the door lock in the sharing request. If both comparisons are consistent, the verification is successful and the second terminal is confirmed to have an authorized status.

[0069] After successful verification, the platform executes a GET command from the cache stored in step S35 using the unique identifier of the door lock as the key, reads the corresponding quantum session key identifier IDs, and simultaneously constructs an authorization response message, filling the IDs into the key identifier field of the message, and sends the response message to the second terminal via network connection.

[0070] S423: The second terminal reads the second terminal initial key and the second terminal initial key identifier from the SIM card, combines the second terminal initial key identifier and the quantum session key identifier, and sends them to the quantum cryptography service platform.

[0071] In step S423, the second terminal receives the authorization response message from the door lock access management platform, parses and extracts the quantum session key identifier IDs, and then sends a read command to the SIM card. The SIM card reads the pre-stored second terminal initial key K2' and second terminal initial key identifier ID2' from the secure file system and returns K2' and ID2' to the terminal application. After returning, the second terminal combines ID2' and IDs to construct a request data packet. The data packet includes a request type field, a second terminal initial key identifier field filled with ID2', and a quantum session key identifier field filled with IDs. Finally, the second terminal sends the request data packet to the key distribution interface of the quantum cryptography service platform via a network connection.

[0072] S424: The quantum cryptography service platform obtains the initial key of the second terminal by querying the initial key identifier of the second terminal, and obtains the quantum session key by querying the quantum session key identifier.

[0073] In step S424, the quantum cryptography service platform first receives the request data packet from the second terminal, parses and extracts the initial key identifier ID2' and the quantum session key identifier IDs of the second terminal. Then, the platform performs a SELECT query operation in the key relationship table using ID2' as the query condition, matches the record where the key identifier field is equal to ID2', and reads the initial key K2' of the second terminal from the key value field of the record. At the same time, the platform performs a SELECT query operation in the key relationship table using IDs as the query condition, matches the record where the key identifier field is equal to IDs, and finally reads the quantum session key Ks from the key value field of the record.

[0074] S425: Using the initial key of the second terminal as the encryption key, the quantum session key is encrypted using the SM4 symmetric encryption algorithm to obtain the third encrypted ciphertext, and the third encrypted ciphertext is returned to the second terminal.

[0075] In step S425, the present invention uses the initial key K2' of the second terminal obtained in step S424 as the input key of the SM4 algorithm, and the quantum session key Ks as the plaintext to be encrypted. Subsequently, the SM4 algorithm is executed, dividing Ks into 128-bit groups, performing 32 rounds of encryption iterations for each group. In each round, the round key derived from K2' is XORed with the data group, followed by S-box substitution and linear transformation. After 32 rounds, ciphertext groups are output, and then the ciphertext groups are concatenated to form the third encrypted ciphertext EK2'(Ks). Subsequently, the quantum cryptography service platform constructs a response data packet, fills EK2'(Ks) into the data field, and returns the response data packet to the second terminal through a network encryption channel.

[0076] S426: The second terminal uses the initial key of the second terminal stored in the SIM card to decrypt the third encrypted ciphertext and obtain the quantum session key.

[0077] In step S426, the second terminal receives the response data packet returned by the quantum cryptography service platform and parses it to extract the third encrypted ciphertext EK2'(Ks). Then, the second terminal calls the initial key K2' stored in the SIM card and uses K2' as the SM4 decryption key to perform decryption on EK2'(Ks). Subsequent SM4 decryption is performed, using the same round key in reverse order of encryption for 32 rounds of reverse iteration, sequentially performing inverse linear transformation and inverse S-box replacement on the ciphertext blocks. After completion, the plaintext blocks are output. Finally, the decrypted plaintext blocks are concatenated to restore the quantum session key Ks, which the second terminal stores in a secure memory area for subsequent decryption of the temporary access password.

[0078] S5: The first terminal encrypts the temporary door opening password to be shared using a quantum session key to obtain the password ciphertext, and then sends the password ciphertext to the second terminal and the door lock respectively through the door lock access management platform.

[0079] Step S5 further includes: S51: The first terminal receives the temporary door opening password and validity period information entered by the user.

[0080] Furthermore, the first terminal's APP interface displays a password sharing function module. Users can enter a temporary door opening password to be shared in the password input box via the touchscreen. This password is a combination of 4 to 8 digits. At the same time, the interface displays an expiration time selection control, allowing users to select the validity period of the password, including the valid start time and valid end time, or select preset options such as 1 hour, 24 hours, or 7 days.

[0081] In step S51, the APP of the first terminal reads the password string and time selection parameter entered by the user, converts the password into a byte array, and converts the time information into a timestamp format, storing them in temporary variables respectively.

[0082] S52: The first terminal uses the quantum session key as the encryption key to encrypt the temporary door opening password and obtain the ciphertext.

[0083] In step S52, the first terminal reads the quantum session key Ks obtained in step S415 from the secure memory area and uses Ks as the encryption key input for the SM4 algorithm. Then, the present invention uses the byte array of the temporary unlock cipher as plaintext input. If the cipher byte length is less than 128 bits, it is padded to the block length. Subsequently, the SM4 algorithm is executed, dividing the padded plaintext into 128-bit blocks. Each block undergoes 32 rounds of encryption iteration, using the round key derived from Ks for XOR, S-box substitution, and linear transformation. After 32 rounds, the ciphertext blocks are output. Finally, the ciphertext blocks are concatenated to form the ciphertext EKs (unlock cipher), which the first terminal stores in a memory variable.

[0084] S53: The first terminal sends the encrypted password, validity period information, and unique lock identifier to the lock access management platform.

[0085] In step S53, the first terminal reads the unique identifier of the door lock associated with the current operation from its local cache. This identifier was recorded when the sharing request was initiated in step S2. This invention constructs a password distribution request data packet, which includes an operation type field marked as password issuance, a password ciphertext field filled with the EKs generated in step S52, an validity time field filled with the timestamp obtained in step S51, and a door lock identifier field filled with the unique identifier of the door lock. After constructing the data packet, the first terminal sends the request data packet to the password distribution interface of the door lock access management platform via an internet connection.

[0086] S54: The door lock access management platform sends the encrypted password to the second terminal, and at the same time finds the corresponding door lock based on the unique identifier of the door lock, and sends the encrypted password and validity time information to the door lock.

[0087] Furthermore, the door lock access management platform receives the password distribution request data packet from the first terminal, parses and extracts the password ciphertext EKs, validity time information, and the unique identifier of the door lock. Then, based on the sharing relationship recorded in step S2, the platform queries the second terminal's account, searches for the second terminal's connection identifier in the online device table using the account, constructs a password notification message, encapsulates the EKs, and sends it to the second terminal via push service. Simultaneously, the platform uses the unique identifier of the door lock as a query condition to search for the door lock's heartbeat connection session in the device connection table, constructs a password delivery command message, the message body containing the EKs and validity time information, and finally sends this command message to the door lock through the heartbeat connection channel.

[0088] S6: The second terminal and the door lock use their respective quantum session keys to decrypt the ciphertext and obtain a temporary unlocking password. The door lock matches and verifies the received password input with the decrypted temporary unlocking password. If the verification is successful, the door lock will perform the unlocking operation.

[0089] In step S6, the door lock performs a matching verification between the received password input and the decrypted temporary unlocking password. The process of unlocking the door after successful verification includes: S61: The door lock uses the quantum session key to decrypt the received ciphertext and obtain the temporary unlocking password plaintext.

[0090] Furthermore, in step S61, the door lock receives a password issuance instruction message from the door lock access management platform via a heartbeat connection, and extracts the password ciphertext EKs and validity time information from the message body. Simultaneously, the door lock reads the quantum session key Ks stored in step S34 from the volatile storage area of ​​the security chip, and uses Ks as the decryption key for the SM4 algorithm.

[0091] Subsequently, this invention uses Ks to perform SM4 decryption on EKs, performing 32 rounds of reverse iteration by ciphertext grouping. In each round, the same round key is used for inverse linear transformation and inverse S-box replacement. After decryption, a plaintext byte array is output. The door lock removes padding from the plaintext byte array, converts the remaining bytes into a numeric string format, and obtains the temporary unlocking password plaintext. This plaintext, along with the valid time information, is stored in the door lock's temporary password storage area.

[0092] S62: The door lock receives the password information entered by the user through the keypad.

[0093] The door lock's keypad includes numeric keys 0 through 9 and a confirmation key. The user enters the password by pressing the numeric keys sequentially. The lock's key scanning module monitors the key press status in real time, generating an interrupt signal each time a key is pressed. The interrupt service routine reads the key code and appends the corresponding numeric character to the input buffer. When the user presses the confirmation key, the lock reads the complete string from the input buffer, stores it as the password to be verified in the verification buffer, and simultaneously records the current system timestamp as the input time.

[0094] S63: Match the input password information with the decrypted temporary door opening password plaintext, and verify the validity period by combining the valid time information.

[0095] In step S63, the door lock reads the user-inputted password string from the verification buffer and the temporary unlocking password plaintext string decrypted in step S61 from the temporary password storage area. It then compares the two strings character by character to determine if the number of characters and the value of each character are completely identical. After the password matching is complete, the door lock reads the input timestamp recorded in step S62 and the valid time information from the temporary password storage area to determine if the input timestamp falls within the valid start and end time range. Finally, the invention performs a logical AND operation between the password matching result and the timeliness verification result. The verification result is considered successful only if both verifications are true.

[0096] S64: When the password matches and is within the valid time range, the door lock performs the unlocking operation.

[0097] Furthermore, based on the verification result of step S63, if the verification result is successful, the door lock control module sends an unlocking control signal to the motor drive circuit. After receiving the control signal, the motor drive circuit supplies power to the door lock motor, and the motor rotates to drive the bolt mechanical structure to retract from the keyhole, completing the unlocking action.

[0098] Simultaneously, the door lock records an unlocking event log, which includes an unlocking timestamp, the password type used (marked as temporary), verification result, and other information. This log is stored in the door lock's non-volatile memory. After unlocking, the door lock reports a successful unlocking message to the door lock access management platform. The platform records this operation event and can selectively push an unlocking notification to the first terminal.

[0099] like Figure 2 As shown, the present invention also provides a smart door lock remote password sharing unlocking system based on quantum key distribution, comprising: The quantum cryptography service platform is used to generate keys from truly random numbers using a quantum random number generator to obtain initial keys for a door lock, a first terminal, and a second terminal, and to establish a mapping relationship between multiple initial keys and their corresponding key identifiers. The quantum cryptography service platform is also used to generate quantum session keys after receiving the initial key identifier of the door lock, and to encrypt the quantum session keys using a symmetric encryption algorithm before sending them to the door lock, the first terminal, and the second terminal respectively. The door lock access management platform is used to receive sharing request information carrying a unique door lock identifier, a first terminal account, and a second terminal account, and to send an activation command to the door lock according to the unique door lock identifier; the door lock access management platform is also used to store the binding relationship between the first terminal account and the unique door lock identifier, temporarily store the correspondence between the unique door lock identifier and the quantum session key identifier, and verify the authorization status of the second terminal. A key storage module is installed in the security chip inside the door lock to store the door lock initial key and the door lock initial key identifier; the key storage module is also installed in the SIM cards of the first terminal and the second terminal to store the first terminal initial key and the first terminal initial key identifier, and the second terminal initial key and the second terminal initial key identifier, respectively. The key synchronization module is used to initiate a session key request to the quantum cryptography service platform after the door lock responds to the activation command, carrying the door lock's initial key identifier. It receives the first encrypted ciphertext and quantum session key identifier returned by the quantum cryptography service platform, and decrypts the first encrypted ciphertext using the door lock's initial key to obtain the quantum session key. The key synchronization module is also used for the first terminal and the second terminal to obtain the encrypted quantum session key from the quantum cryptography service platform using their respective initial keys and decrypt it, thereby realizing the synchronous distribution of the quantum session key among the first terminal, the second terminal, and the door lock. The password encryption module is used by the first terminal to encrypt the temporary door opening password to be shared using a quantum session key to obtain the password ciphertext, and then distributes the password ciphertext to the second terminal and the door lock respectively through the door lock access management platform. The verification and unlocking module is used by the second terminal and the door lock to decrypt the ciphertext using their respective quantum session keys to obtain a temporary unlocking password. The verification and unlocking module is also used by the door lock to match and verify the received password input with the decrypted temporary unlocking password, and to verify the timeliness by combining the valid time information. After the verification is successful, the unlocking operation is performed.

[0100] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the embodiments of the present invention, and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the protection scope of the present invention.

Claims

1. A method for remotely sharing passwords to unlock smart locks based on quantum key distribution, characterized in that, include: S1: Generate keys by using the true random numbers generated by the quantum random number generator through the quantum cryptography service platform to obtain the initial key of the door lock, the initial key of the first terminal, and the initial key of the second terminal; S2: Send the sharing request information to the door lock access management platform. The sharing request information carries the door lock's unique identifier, the first terminal account, and the second terminal account. The door lock access management platform sends an activation command to the door lock based on the door lock's unique identifier. S3: In response to the activation command, the door lock sends a session key request to the quantum cryptography service platform, carrying the door lock initial key identifier. The quantum cryptography service platform encrypts the quantum session key using a symmetric encryption algorithm to obtain a first encrypted ciphertext, and returns the first encrypted ciphertext and the quantum session key identifier to the door lock. The door lock uses the door lock initial key to decrypt the first encrypted ciphertext to obtain the quantum session key. S4: The door lock access management platform sends the quantum session key identifier to the first terminal and the second terminal. The first terminal uses the first terminal's initial key and the second terminal uses the second terminal's initial key to obtain the encrypted quantum session key from the quantum cryptography service platform. After decryption, the quantum session key is synchronously distributed among the first terminal, the second terminal, and the door lock. S5: The first terminal uses a quantum session key to encrypt the temporary door opening password to be shared, obtains the password ciphertext, and sends the password ciphertext to the second terminal and the door lock respectively through the door lock access management platform; S6: The second terminal and the door lock use their respective quantum session keys to decrypt the ciphertext and obtain a temporary unlocking password. The door lock matches and verifies the received password input with the decrypted temporary unlocking password. If the verification is successful, the door lock will perform the unlocking operation.

2. The method for remotely sharing passwords to open a smart door lock based on quantum key distribution, as described in claim 1, is characterized in that... Step S1 further includes: S11: Based on the quantum cryptography service platform, a quantum random number generator generates true random numbers based on at least one of the physical unpredictability methods of photon counting, photon arrival time, or photon arrival location. S12: Using the true random number as an entropy source, generate the door lock initial key, the first terminal initial key and the second terminal initial key respectively, and assign a unique key identifier to each initial key to obtain the door lock initial key identifier, the first terminal initial key identifier and the second terminal initial key identifier; S13: Pre-write the initial key of the door lock into the security chip built into the door lock, and write the initial key of the first terminal and the initial key of the second terminal into the SIM cards of the first terminal and the second terminal respectively. S14: A table of correspondences between keys and key identifiers is established and stored by the quantum cryptography service platform.

3. The method for remotely sharing passwords to open a smart door lock based on quantum key distribution according to claim 1, characterized in that, Step S2 includes the following: S21: When the door lock is activated, the first terminal binds itself to the door lock and sends the binding relationship between the first terminal account and the unique identifier of the door lock to the door lock access management platform; S22: The door lock access management platform establishes and stores the correspondence between the first terminal account and the unique identifier of the door lock; S23: The door lock establishes a heartbeat connection with the door lock access management platform. All other components except the heartbeat connection component enter a dormant state, waiting for the activation command to wake them up.

4. The method for remotely sharing passwords to open a smart door lock based on quantum key distribution according to claim 1, characterized in that, In step S3, the process of the quantum cryptography service platform encrypting the quantum session key using a symmetric encryption algorithm to obtain the first encrypted ciphertext further includes: S31: The quantum cryptography service platform receives the initial key identifier of the door lock sent by the door lock, and obtains the initial key of the door lock by querying the corresponding relationship table according to the initial key identifier of the door lock; S32: The quantum cryptography service platform uses a quantum random number generator to generate quantum session keys and assigns quantum session key identifiers to the quantum session keys; S33: Using the initial key of the door lock as the encryption key, the quantum session key is encrypted using the SM4 symmetric encryption algorithm to obtain the first encrypted ciphertext.

5. The method for remotely sharing passwords to open a smart door lock based on quantum key distribution according to claim 1, characterized in that, After step S3, the following is also included: S34: The door lock sends the quantum session key identifier to the door lock access management platform; S35: The door lock access management platform stores the correspondence between the unique door lock identifier and the quantum session key identifier in the cache; S36: The door lock access management platform receives the second terminal account, finds the corresponding second terminal through the door lock's unique identifier, and sends the door lock's unique identifier to the second terminal.

6. The method for remotely sharing passwords to open a smart door lock based on quantum key distribution according to claim 1, characterized in that, In step S4, the process of the first terminal using its initial key to obtain the encrypted quantum session key from the quantum cryptography service platform specifically includes: S411: The door lock access management platform responds to the sharing request from the first terminal and returns the quantum session key identifier to the first terminal; S412: The first terminal, carrying the first terminal initial key identifier and the quantum session key identifier, initiates an acquisition request to the quantum cryptography service platform; S413: The quantum cryptography service platform obtains the quantum session key by querying the quantum session key identifier and obtains the first terminal initial key by querying the first terminal initial key identifier; S414: Using the initial key of the first terminal as the encryption key, the quantum session key is encrypted using the SM4 symmetric encryption algorithm to obtain the second encrypted ciphertext, and the second encrypted ciphertext is returned to the first terminal; S415: The first terminal uses the first terminal initial key stored in the SIM card to decrypt the second encrypted ciphertext and obtain the quantum session key.

7. The method for remotely sharing passwords to open a smart door lock based on quantum key distribution according to claim 1, characterized in that, In step S4, the process of the second terminal using its initial key to obtain the encrypted quantum session key from the quantum cryptography service platform specifically includes: S421: The second terminal, carrying the unique identifier of the second door lock and the second terminal account, initiates a request to the door lock access management platform; S422: The door lock access management platform verifies the authorization status of the second terminal based on the second terminal account and the unique identifier of the second door lock. After successful verification, it extracts the quantum session key identifier from the temporarily stored correspondence and sends the quantum session key identifier to the second terminal. S423: The second terminal reads the second terminal initial key and the second terminal initial key identifier from the SIM card, combines the second terminal initial key identifier and the quantum session key identifier, and sends them to the quantum cryptography service platform; S424: The quantum cryptography service platform obtains the initial key of the second terminal by querying the initial key identifier of the second terminal, and obtains the quantum session key by querying the quantum session key identifier; S425: Using the initial key of the second terminal as the encryption key, the quantum session key is encrypted using the SM4 symmetric encryption algorithm to obtain the third encrypted ciphertext, and the third encrypted ciphertext is returned to the second terminal; S426: The second terminal uses the initial key of the second terminal stored in the SIM card to decrypt the third encrypted ciphertext and obtain the quantum session key.

8. The method for remotely sharing passwords to open a smart door lock based on quantum key distribution according to claim 1, characterized in that, Step S5 further includes: S51: The first terminal receives the temporary door opening password and validity period information entered by the user; S52: The first terminal uses the quantum session key as the encryption key to encrypt the temporary door opening password and obtain the password ciphertext; S53: The first terminal sends the password ciphertext, validity period information and unique door lock identifier to the door lock access management platform; S54: The door lock access management platform sends the encrypted password to the second terminal, and at the same time finds the corresponding door lock based on the unique identifier of the door lock, and sends the encrypted password and validity time information to the door lock.

9. A method for remotely sharing passwords to open a smart door lock based on quantum key distribution, as described in claim 1, is characterized in that... In step S6, the door lock verifies the received password input against the decrypted temporary unlocking password. The process of unlocking the door after successful verification includes: S61: The door lock uses the quantum session key to decrypt the received ciphertext and obtain the temporary unlocking password plaintext; S62: The door lock receives the password information entered by the user through the keypad; S63: Match the input password information with the decrypted temporary door opening password plaintext, and verify the validity period by combining the valid time information; S64: When the password matches and is within the valid time range, the door lock performs the unlocking operation.

10. A quantum key-based smart lock remote password sharing unlocking system, used to execute the quantum key-based smart lock remote password sharing unlocking method as described in any one of claims 1 to 9, characterized in that, include: The quantum cryptography service platform is used to generate keys from truly random numbers using a quantum random number generator to obtain initial keys for a door lock, a first terminal, and a second terminal, and to establish a mapping relationship between multiple initial keys and their corresponding key identifiers. The quantum cryptography service platform is also used to generate quantum session keys after receiving the initial key identifier of the door lock, and to encrypt the quantum session keys using a symmetric encryption algorithm before sending them to the door lock, the first terminal, and the second terminal respectively. The door lock access management platform is used to receive sharing request information carrying a unique door lock identifier, a first terminal account, and a second terminal account, and to send an activation command to the door lock according to the unique door lock identifier; the door lock access management platform is also used to store the binding relationship between the first terminal account and the unique door lock identifier, temporarily store the correspondence between the unique door lock identifier and the quantum session key identifier, and verify the authorization status of the second terminal. A key storage module is installed in the security chip inside the door lock to store the door lock initial key and the door lock initial key identifier; the key storage module is also installed in the SIM cards of the first terminal and the second terminal to store the first terminal initial key and the first terminal initial key identifier, and the second terminal initial key and the second terminal initial key identifier, respectively. The key synchronization module is used to initiate a session key request to the quantum cryptography service platform after the door lock responds to the activation command, carrying the door lock's initial key identifier. It receives the first encrypted ciphertext and quantum session key identifier returned by the quantum cryptography service platform, and decrypts the first encrypted ciphertext using the door lock's initial key to obtain the quantum session key. The key synchronization module is also used for the first terminal and the second terminal to obtain the encrypted quantum session key from the quantum cryptography service platform using their respective initial keys and decrypt it, thereby realizing the synchronous distribution of the quantum session key among the first terminal, the second terminal, and the door lock. The password encryption module is used by the first terminal to encrypt the temporary door opening password to be shared using a quantum session key to obtain the password ciphertext, and then distributes the password ciphertext to the second terminal and the door lock respectively through the door lock access management platform. The verification and unlocking module is used by the second terminal and the door lock to decrypt the ciphertext using their respective quantum session keys to obtain a temporary unlocking password. The verification and unlocking module is also used by the door lock to match and verify the received password input with the decrypted temporary unlocking password, and to verify the timeliness by combining the valid time information. After the verification is successful, the unlocking operation is performed.