Method and device for identifying abnormal unlocking behavior record of intelligent door lock

By combining a multi-dimensional weighted probability model with a veto mechanism and reading smart lock data using multiple communication protocols, the accuracy and device compatibility issues of abnormal unlocking behavior identification in existing technologies have been resolved, achieving efficient abnormal unlocking behavior identification and security report generation.

CN121921864APending Publication Date: 2026-04-24INST OF FORENSIC SCI OF MIN OF PUBLIC SECURITY
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
INST OF FORENSIC SCI OF MIN OF PUBLIC SECURITY
Filing Date
2025-12-09
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing smart door locks rely on a single judgment criterion for identifying abnormal unlocking behavior, without comprehensively considering multiple sources of information such as unlocking method, time distribution, and sensor alarms. This results in a large number of missed and false alarms, making it unable to effectively support security audits and forensic analysis. Furthermore, differences in data storage and communication protocols lead to poor device compatibility.

Method used

It adopts a comprehensive judgment mechanism that combines a multi-dimensional weighted probability model with a veto item, reads multi-source data from smart locks through multiple communication protocols such as serial port, Bluetooth, and Wi-Fi, displays abnormal events with visual charts, generates security reports, identifies high-frequency attack periods and geographical locations, and designs specialized anomaly detection algorithms for different unlocking methods, providing a general data reading framework that is compatible with multiple communication protocols and data sources.

Benefits of technology

It significantly improves the accuracy and reliability of identifying abnormal unlocking behavior, effectively captures differences between imitation behavior and biometrics, provides device adaptability and evidence-gathering applicability, and supports unified data acquisition and analysis from multiple communication protocols and data sources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121921864A_ABST
    Figure CN121921864A_ABST
Patent Text Reader

Abstract

The invention provides a recognition method and device for abnormal unlocking behavior records of an intelligent door lock, and the method comprises the steps: 1, reading all original unlocking records of a detected intelligent door lock, and enabling the unlocking records to comprise unlocking modes and unlocking time information; and 2, analyzing all the read original unlocking records according to a predefined rule, screening and identifying the unlocking records generated by an abnormal unlocking behavior, and the like. The device comprises a central processing module; and the communication interface module is connected with the central processing module. The method has the advantages that through a comprehensive judgment mechanism combining multi-source data fusion, weighted probability and one-ticket override and a special analysis algorithm aiming at different unlocking modes, high-precision and low-false-alarm recognition of abnormal unlocking behaviors is achieved, the method has high compatibility and evidence obtaining supporting capacity, and the method is suitable for popularization and application. Security auditing, case evidence obtaining, user self-examination and other scenes are effectively served, and the post-event security analysis level of the intelligent door lock is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of smart door lock technology, specifically relating to a method and device for identifying abnormal unlocking behavior records of smart door locks. Background Technology

[0002] With the popularization of IoT technology and smart home concepts, smart door locks are becoming an increasingly important component of security systems in homes and commercial establishments. Smart door locks typically feature multiple unlocking methods, such as fingerprint recognition, passwords, IC cards, and facial recognition, and can record relevant information about various unlocking events, including time, method, user identification, unlocking result, and sensor status. This historical record provides a data foundation for post-event analysis of door lock usage behavior and identification of abnormal opening traces.

[0003] Currently, most smart lock security management relies on real-time alarm functions, such as locking after multiple failed authentication attempts or alarms triggered by abnormal sensors. However, these mechanisms are mainly used for in-process protection and immediate alerts, lacking the ability to conduct in-depth and systematic analysis of accumulated historical records. For post-event analysis scenarios such as police investigations or user self-checks for security risks, existing technologies often only provide raw log browsing or simple filtering, failing to automatically identify and risk-rating massive amounts of unlocking records based on multi-dimensional rules and probability models, making it difficult to efficiently filter out truly suspicious abnormal opening events.

[0004] Furthermore, there are numerous brands and models of smart locks, with significant differences in their data storage locations and communication protocols. For example, data may be stored in local Flash memory, the manufacturer's cloud, or the user's mobile app, and reading methods involve various technologies such as serial ports, Bluetooth, Wi-Fi, and even physical chip disassembly. Existing analytical methods typically lack a unified and compatible data acquisition and parsing framework, making it difficult to adapt to the actual environments of different devices and causing considerable inconvenience for evidence collection and investigation.

[0005] In published patent applications, for example, Chinese Invention Patent Application Publication No. CN107195036A discloses a method and system for identifying abnormal unlocking of a smart door lock. The method includes the following steps: A) Initialization settings; B) Acquiring real-time image information: When the smart door lock detects an unauthorized mechanical unlocking action or an incorrect authorized unlocking password, it triggers an image acquisition module to acquire real-time image information of the smart door lock; C) Transmission to a cloud server; D) Remote push from the cloud server: After receiving the real-time image information, the cloud server sends an alarm message and the received real-time image information to the authorized user's client, and the cloud server also transmits a deadlock command to the smart door lock. This invention proposes a method and system for identifying abnormal unlocking of a smart door lock, which uses a cloud server to store image information. This solves the limitation of existing smart cloud locks, which can only use low-resolution image acquisition modules due to limited storage capacity, allowing the system of this application to operate without a dedicated memory card or storage device for storing image information.

[0006] The existing technologies described above rely on a single criterion for identifying abnormal behavior. They fail to comprehensively consider multi-source information such as unlocking methods, time distribution, and sensor alarms, and lack a comprehensive analytical model that combines rule-based judgment with weighted probability assessment. This results in limited ability to identify highly concealed and habit-mimicking abnormal unlocking behaviors, leading to numerous false alarms and missed detections, and failing to effectively support security audits and forensic analysis.

[0007] In view of the above-mentioned technical problems in the existing technology, this application provides a method and device for identifying abnormal unlocking behavior records of smart door locks. Summary of the Invention

[0008] This application proposes a method and device for identifying abnormal unlocking behavior records of smart door locks.

[0009] The following technical solution is adopted in this application: The method for identifying abnormal unlocking behavior records of the smart door lock includes the following steps: In step 1, by establishing a communication connection with the smart lock under test, all original unlocking records are read from at least one data storage location based on the data storage protocol corresponding to the lock model. The data storage location includes at least one of the smart lock's local Flash memory, the smart lock's network server, or the user terminal APP.

[0010] Step 2: Analyze all the original unlocking records read according to predefined rules, and filter and identify unlocking records generated by abnormal unlocking behavior.

[0011] Step 3: Visualize the abnormal opening records identified in Step 2 using visualization charts (such as time series charts, bar charts, and heat maps) to statistically analyze the frequency distribution of abnormal events and identify high-frequency attack periods. For smart locks that support GPS positioning (such as some shared accommodation or merchant locks), mark the geographical location of the abnormal events using map APIs. Generate log audit and report: Regularly (e.g., monthly) audit and analyze all abnormal unlocking records to investigate whether there are regular attack patterns (such as multiple trial and error within the same time period, repeated attempts from the same unfamiliar face, etc.), and generate security reports to provide users with security posture assessment and improvement suggestions.

[0012] Furthermore, in step 1, the communication connection is established by directly establishing a wired connection with the UART interface of the smart door lock through a serial communication protocol.

[0013] Furthermore, the predefined rules in step 2 include: comprehensively judging the anomaly probability P of a single unlocking record based on a weighted probability calculation model and a veto item; The weighted probability calculation model is as follows: ; In the formula: Wm is the weighting coefficient of the unlocking method anomaly dimension, Fm is the unlocking method anomaly probability function; the unlocking method anomaly probability function is calculated based on the degree of anomaly of the current recorded specific unlocking method relative to the mainstream unlocking methods in the historical unlocking records of this door lock; Wt is the weighting coefficient of the unlocking time anomaly dimension, Ft is the unlocking time anomaly probability function; the unlocking time anomaly probability function is calculated based on the degree of anomaly of the current recorded unlocking time point relative to the historical unlocking time distribution of this door lock; A single unlocking record is considered an independent judgment item under the comprehensive judgment of a veto system: when an unlocking record contains a definite hard anomaly indicator, the record is directly judged as an abnormal record; definite hard anomaly indicators include at least one of the following: the door lock is opened when it is not properly locked, mechanical damage is detected, high-frequency and high-intensity electromagnetic pulse interference is detected, the record is locked after multiple consecutive unlocking failures, and abnormal power outage is recorded.

[0014] Further, in step 2, the calculation method of the unlocking method anomaly probability function Fm includes: counting the usage frequency of various unlocking methods in the lock's historical records, and determining the method with the lowest usage frequency as having a high anomaly probability, including: extracting all successful unlocking records from the smart lock's historical log, and recording the total number of successful unlocking records as total_unlocks; counting the number of times each unlocking method appears as count(method_i); calculating the usage frequency of each unlocking method as freq(method_i) = count(method_i) / total_unlocks; for the unlocking method method_current of the current record, the corresponding unlocking method anomaly probability function value is: Fm(method_current) = 1 - freq(method_current).

[0015] Furthermore, in step 2, the calculation method of the unlocking method anomaly probability function Fm also includes: analyzing multiple password input events. If the input time interval pattern between each numeric character in a certain input event has a significant statistical difference from the stable and continuous input time interval pattern in the vast majority of successful unlocking events of the door lock, then the record is determined to be an anomaly trace. This includes: reading all historical numeric password unlocking records (R1, R2, ..., Rn) from the smart door lock's database or log; extracting the input time interval between numeric characters for each record Ri to form a feature vector Vi; standardizing all feature vectors; performing cluster analysis on the feature vector set (V1, V2, ..., Vn) using the unsupervised clustering algorithm DBSCAN; and identifying noise points in the cluster analysis results as anomaly traces.

[0016] Furthermore, the predefined rules in step 2 also include: performing cluster analysis on all unlocking failure records that occur within a specific time window; If the cluster analysis results show that multiple records use passwords that are highly similar in string or input time interval patterns, or that the facial image recognition or pattern passwords used are close in feature space, then the records in that cluster are collectively identified as an abnormal opening behavior sequence.

[0017] Furthermore, in step 2, the calculation method of the unlocking method abnormal probability function Fm also includes: analyzing the liveness detection results in the face recognition unlocking record. If the liveness detection fails or the matching degree is lower than the preset threshold, the record is determined to be an abnormal trace.

[0018] Further, in step 2, the calculation method of the unlocking time anomaly probability function Ft is as follows: establish a time distribution model of the historical unlocking time of the door lock, and determine the unlocking record that appears in the low probability time window as having a high anomaly probability. Specifically, collect the timestamps of all historical successful unlocking records of the smart door lock; use kernel density estimation to construct the probability density function p(t) of the unlocking time point based on the timestamp; for an unlocking record that occurs at a specific time T, calculate its time anomaly probability function value as: Ft=1-p(T), where p(T) is the normalized probability density estimate.

[0019] The present invention also provides a device for identifying abnormal unlocking behavior records of smart door locks that implements the above method, comprising: Central processing module; The communication interface module, which is connected to the central processing module, is used to establish a connection with the smart lock and read all original unlocking records; The data identification module, which is connected to the central processing module, has a built-in weighted probability calculation model and a veto rule. It is used to analyze all original unlocking records and calculate the probability of abnormality in order to identify abnormal unlocking records. The sensor module connected to the central processing module includes at least one of the following: mechanical lock cylinder sensor, panel vibration sensor, door status sensor, and lock tongue status sensor; The output module, connected to the central processing module, is used to display the recognition results and the probability of anomalies.

[0020] Compared with the prior art, the superior effects of the present invention are as follows: 1. The method and device for identifying abnormal unlocking behavior records of smart door locks described in this invention realizes the comprehensive collection and fusion analysis of multi-source and multi-dimensional unlocking data of smart door locks, breaks through the limitations of traditional single judgment criteria, and significantly improves the accuracy and reliability of abnormal identification. 2. The method and device for identifying abnormal unlocking behavior records of smart door locks described in this invention innovatively proposes a comprehensive judgment mechanism that combines a "weighted probability model" and a "veto item," which takes into account both the flexibility of multi-factor probability assessment and ensures rapid and accurate judgment of high-risk behaviors. 3. The method and device for identifying abnormal unlocking behavior records of smart door locks described in this invention have designed special abnormal detection algorithms for different types of unlocking methods, such as pattern passwords, numeric passwords, and facial recognition, which can effectively capture the differences between imitation behavior and biometric features and prevent covert abnormal unlocking. 4. The method and device for identifying abnormal unlocking behavior records of smart door locks described in this invention provide a universal data reading framework that is compatible with multiple communication protocols and data sources. It supports serial port, Bluetooth, Wi-Fi, cloud API and physical chip-level reading, and has strong device adaptability and practicality for verification. Attached Figure Description

[0021] Figure 1 This is a schematic diagram of the structure of the identification device for recording abnormal unlocking behavior of the smart door lock in this application. Detailed Implementation

[0022] To better understand the above-mentioned objectives, features and advantages of this application, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be noted that, unless otherwise specified, the embodiments and features in the embodiments of this application can be combined with each other.

[0023] like Figure 1 As shown, the present invention provides a method for identifying abnormal unlocking behavior records of smart door locks, comprising the following steps: Step 1: Read all original unlocking records of the smart lock under inspection. The unlocking records include unlocking method and unlocking time information. Step 2: Analyze all the original unlocking records read according to the predefined rules, and filter and identify the unlocking records generated by abnormal unlocking behavior.

[0024] Step 3: Display the abnormal opening records identified in Step 2 using visualization charts (such as time series charts, bar charts, and heat maps). This can help to statistically analyze the frequency distribution of abnormal events and identify high-frequency attack periods. For smart locks that support GPS positioning (such as some shared accommodation or merchant locks), the geographical locations of abnormal events can be marked using map APIs. Generate log audit and report: Regularly (e.g., monthly) audit and analyze all abnormal unlocking records to investigate whether there are regular attack patterns (such as multiple trial and error within the same time period, repeated attempts from the same unfamiliar face, etc.), and generate security reports to provide users with security posture assessment and improvement suggestions.

[0025] Specifically, in step 1, the unlocking record includes, but is not limited to, the unlocking method, unlocking time, unlocking personnel identification (such as fingerprint ID, password ID, card ID, etc.), unlocking result (success / failure), and auxiliary data related to the unlocking behavior collected by the smart lock's built-in sensors (such as liveness detection score, matching score, sensor trigger status, etc.).

[0026] Specifically, in step 1, by establishing a communication connection with the smart lock under test, and based on the specific model of the lock and its corresponding proprietary data storage and communication protocol, all original unlocking records are read from at least one data storage location. The data storage location includes at least one of the smart lock's local Flash memory, the smart lock's network server, or the user terminal APP. The methods for establishing the communication connection include, but are not limited to: Wired connection: A physical connection is established directly with the debugging interface or dedicated communication interface reserved on the smart door lock motherboard via serial communication protocols (such as UART, RS-232 / 485, etc.). Tools such as USB to TTL modules are required for level conversion and interface adaptation. Communication and data reading are performed according to the protocol documents provided by the manufacturer (including instruction set, baud rate, data frame format, verification method, etc.).

[0027] Wireless connectivity: Through the Bluetooth (BLE) or Wi-Fi module supported by the smart lock, a data communication channel can be indirectly established using its pass-through function or the manufacturer's dedicated SDK / API to read the records stored in the lock body.

[0028] Network access: For networked smart locks, after identity authentication and authorization, the unlocking records can be retrieved from the cloud server through the official API interface provided by the manufacturer.

[0029] Direct storage and reading: When data cannot be obtained through the communication interface, or when judicial evidence collection is required, the Flash storage chip on the smart door lock motherboard can be physically removed. The chip pins can be directly connected through chip clip components (such as SOIC clips, Pompclips, etc.). With the help of a programmer or a dedicated reading device, the original data image in the chip can be read according to the storage address mapping, encoding method and necessary decryption method provided by the manufacturer, and then the unlocking record can be parsed.

[0030] Specifically, in step 1, the data read also includes abnormal opening trace data generated by various security sensors of the smart lock when triggered. These sensors include: Mechanical lock cylinder sensor: used to detect abnormal rotation or force on the lock cylinder, and its data can indicate technical unlocking attempts (such as prying or tin foil unlocking); Panel vibration sensor: usually a multi-axis accelerometer, used to detect abnormal vibration signals generated when subjected to external impacts, prying, etc. Door status sensor (door magnetic sensor): used to monitor the opening and closing status of the door and the change in the gap between the door and the door frame in real time, and to determine whether the door has been opened without normal unlocking. Locking tongue status sensor: used to monitor the extension and retraction status of the locking tongue and determine whether the locking tongue position has changed without the normal process; These sensor data are typically processed by the smart lock's control system using built-in algorithms (such as fixed threshold judgment or machine learning algorithms) to generate alarm event records, which are then stored together with other unlocking records. When reading data, these raw or processed sensor event data should be retrieved as much as possible.

[0031] Specifically, in step 2, all original unlocking records are analyzed according to predefined rules to filter and identify unlocking records generated by abnormal unlocking behavior: The core of the predefined rule is to comprehensively judge the abnormal probability P of a single unlocking record based on a weighted probability calculation model and combined with one or more "veto" items.

[0032] The weighted probability calculation model is as follows: ,in: Wm is the weighting coefficient (0≤Wm≤1) for the unlocking method anomaly dimension. Its specific value can be adjusted according to the actual security strategy and is used to measure the importance of unlocking method anomalies in the overall anomaly judgment. Fm is the probability function of abnormal unlocking method (0≤Fm≤1). Its value is calculated based on the specific unlocking method and related characteristics of the record, relative to the degree of abnormality of the mainstream unlocking mode or user habits reflected in the historical unlocking records of the door lock. Wt is the weighting coefficient for the unlocking time anomaly dimension (0≤Wt≤1, and usually Wm+Wt=1), used to measure the importance of unlocking time anomalies in the overall anomaly judgment; Ft is the probability function of unlocking time anomalies (0≤Ft≤1). Its value is calculated based on the unlocking time of the record and the degree of anomaly of the time distribution model constructed by the historical unlocking timestamps of the door lock. The "one-vote veto" option means that if a lock-picking record meets any of the following conditions, it will be directly judged as a highly suspicious abnormal opening record without weighted probability calculation: The liveness score associated with this record is lower than the preset liveness threshold. The record is clearly marked as an alarm event triggered by a vibration sensor, lock cylinder sensor, door magnetic sensor, etc.

[0033] The unlocking result of this record is marked as a failure, and the number of consecutive failures exceeds the threshold; Setting a "veto" option can significantly improve the accuracy and timeliness of detecting known high-risk abnormal behaviors: Different brands and models of smart door locks support different unlocking methods. Normal unlocking methods typically include: fingerprint recognition, facial recognition, numeric password, pattern password, NFC / IC card, mechanical key, remote app unlocking, temporary password, Bluetooth unlocking, etc. The probability function Fm of an abnormal unlocking method needs to be calculated using one or more of the following methods (e.g., taking the maximum value, average value, or a combination of strategies) depending on the specific unlocking method type: Method 1, based on statistical judgment of the frequency of unlocking methods: This applies to all types of unlocking methods, based on the assumption that legitimate users typically use one or a few mainstream unlocking methods they are accustomed to. The specific calculation steps are as follows: a) Extract all successful unlock records from the door lock history log, and record the total number of times as total_unlocks; b) Count the number of times each unlocking method (method_i) occurs: count(method_i); c) Calculate the usage frequency of each unlocking method: freq(method_i) = count(method_i) / total_unlocks; d) For the unlocking method method_current of the current record, define its unlocking method abnormal probability function value as: Fm(method_current) = 1 - freq(method_current); As can be seen from the calculation steps above, the less frequently a method is used, the closer its anomaly probability Fm value is to 1 (high anomaly probability). For example, if 95% of the unlocks in the history are completed by fingerprint, then the Fm value of a card unlock is about 0.05, while the Fm value of a rare remote app unlock may be as high as 0.98 or more. Method 2, Anomaly Detection Based on Pattern Unlocking Dynamic Biometric Parameters: Specifically designed for pattern-based unlocking, its principle lies in the fact that different users exhibit individual differences in the dynamic characteristics of their gestures (such as speed, acceleration, pressure, and timing) when drawing the same or different patterns. This makes it difficult for imitators to completely replicate the pattern. The specific calculation steps are as follows: a) Read all historical pattern unlock records from the database or logs. Each record should contain time-series data of the drawing process, including but not limited to: touch point coordinate sequence, timestamp of each coordinate point, and applied pressure value (if supported). b) Calculate a feature vector Xi for each historical record. The feature vector should contain features that capture the unique dynamic behavior of the individual, specifically: Velocity profile: average velocity, standard deviation of velocity, and velocity ratio of each segment; Acceleration characteristics: average acceleration; Pressure characteristics: mean pressure, variance of pressure variation; Temporal characteristics: total drawing time, interval time between strokes ("flight time"); Geometric features (privacy must be considered to prevent password leakage; they can be combined with dynamic features): rate of change of corner angles, relative proportion of stroke lengths; c) Standardize all features (e.g., Z-score standardization) to eliminate the influence of different feature units and numerical ranges; d) Dimensionality reduction techniques such as PCA (Principal Component Analysis) or t-SNE can be used to project high-dimensional feature vectors into a low-dimensional space, which facilitates visualization and improves the efficiency of subsequent clustering algorithms; e) Apply the unsupervised clustering algorithm DBSCAN (Density-Based Spatial Clustering of Applications with Noise) to perform clustering analysis on the standardized feature vector dataset: Adjust two core parameters: eps (neighborhood radius) and min_samples to determine the minimum number of samples required to form the core cluster; After the algorithm is run, each record will be assigned a cluster label. f) Generate the anomaly probability function Fm: For records whose cluster label is not -1 (i.e., belong to a certain cluster), Fm=0.0 (or a very low value) is considered normal operation; For a record with a cluster label of -1 (i.e., marked as a noise point), calculate its distance d to the nearest core cluster. The distance d can be mapped to the (0, 1] interval through the sigmoid function or min-max normalization, and defined as the Fm value. The farther the distance, the closer Fm is to 1, and the higher the probability of an anomaly. Method 3: Anomaly detection based on numeric password input time interval patterns: Specifically designed for unlocking via numeric passwords, this method works by recognizing that users develop muscle memory and cognitive habits for specific numeric passwords, resulting in a stable and unique keystroke rhythm pattern. In contrast, unauthorized individuals (such as thieves or strangers) attempting the same password exhibit statistically abnormal input rhythm patterns due to fundamental differences in their cognitive processes (recall, trial and error, visual observation followed by imitation) and muscle memory compared to legitimate users. The specific calculation steps are as follows: a) Read all historical numeric password unlock records (R1, R2, ..., Rn) from the database or logs; b) For each record Ri, extract the input time interval (Inter - key Latency) between its numeric characters to form a feature vector Vi. For example, for a 6 - digit password, 5 time intervals will be generated: Vi = [Δt1, Δt2, Δt3, Δt4, Δt5]; c) Normalize all interval features; d) Apply the unsupervised clustering algorithm DBSCAN to perform clustering analysis on the set of feature vectors {V1, V2,..., Vn}; e) After running the algorithm: Records labeled 0, 1, 2,... belong to different clusters, representing normal operation modes of different users (such as User A, User B) or the same user in different states, with Fm = 0.0; Records labeled - 1 are marked as noise (outliers), with Fm = 1.0 (or a high probability value calculated based on the distance to the nearest cluster); Method 4, based on the judgment of live detection and matching score in face recognition, specifically for the face recognition unlocking method, directly uses the confidence score output by the face recognition module for judgment. The specific calculation steps are as follows: a) Obtain two key indicators output during the face recognition process from the records: liveness_score: Live detection score (0 - 1), the higher the score, the greater the likelihood of a real face.

[0034] matching_score: Face feature matching score (0 - 1), the higher the score, the higher the similarity to the registered face.

[0035] b) Construct the anomaly probability function Fm: Rule - based: If liveness_score < liveness_threshold or matching_score < matching_threshold, then Fm = 1.0; otherwise Fm = 0.0; The thresholds are preset by the security policy (such as liveness threshold 0.8, matching threshold 0.75); Probability - based: Fm_liveness = 1 - liveness_score; Fm_matching = 1 - matching_score; Take Fm = max(Fm_liveness, Fm_matching) as the final anomaly probability. The provided continuous probability value is more flexible; The unlocking time anomaly probability function Ft is calculated as follows: a) Collect the timestamps of all historical successful unlocking records of this smart door lock; b) Using nonparametric methods such as kernel density estimation (KDE), a probability density function p(t) for the unlocking time point is constructed based on these timestamp data; KDE can generate a smooth, continuous time distribution model, which can better capture the daily routine. c) For a lock unlocking record that occurs at a specific time T, calculate its temporal anomaly probability function value as: Ft=1-p(T), where p(T) is the normalized probability density estimate, which means that the Ft value of a lock unlocking that occurs at a time point with very low probability density (such as late at night or early morning) will be close to 1 (high anomaly probability); while the Ft value of a lock unlocking that occurs at a time point with high probability density (such as when returning home from work) will be close to 0. d) To further improve accuracy, the time distribution model can be divided into weekday mode and weekend / holiday mode, and supports regular (such as weekly or monthly) automatic updates to adapt to possible changes in residents' daily routines by using new normal unlocking records.

[0036] The above are all methods for filtering abnormal records from successful unlocking records. This invention also includes cluster analysis of unlocking failure records within a specific time window to identify potential abnormal unlocking behavior sequences. The specific steps are as follows: a) Define a time window: Based on actual security needs, set a reasonable time window length (e.g., 5 minutes, 30 minutes, or 1 hour. This time window length is set according to the specific situation of the smart lock. For example, for smart locks with a rule that temporarily locks after multiple unlocking failures, the time window length can be appropriately increased) to aggregate and analyze all unlocking failure records that occur within the window. b) Data extraction: Extract all unlocking failure records within a specific time window from the original unlocking records. These records include, but are not limited to, password input failure, fingerprint matching failure, and facial recognition failure. c) Feature extraction: For each failed record, relevant features are extracted for cluster analysis: For records of failed password unlocking, extract the password string itself (if the record contains the attempted password) and the input time interval pattern (such as the Inter-key Latency feature vector described in Method 3). For records of failed face recognition, extract the facial image feature vector (if the record contains a matching score or feature data). For other unlocking methods, similarly extract the available features; d) Cluster analysis: Clustering algorithms (such as DBSCAN, K-means, etc.) are applied to cluster the extracted features. The goal of clustering is to group failed records with similar features. For password failure records, calculate the similarity between password strings (e.g., using edit distance or the same character ratio) and the Euclidean distance or cosine similarity between input time interval patterns. If multiple records are highly similar in password strings or input time interval patterns, they may come from the same illegitimate opener. For failed face recognition records, calculate the Euclidean distance between facial feature vectors. If the facial features of multiple records are close in distance in the feature space, they may come from the same person. e) Behavioral sequence identification: If the cluster analysis results show that a cluster contains multiple failed records and these records are highly similar in features, then the records in the cluster are collectively identified as an abnormal unlocking behavior sequence. This indicates that someone may have tried to unlock the door multiple times within this time window, using similar methods or operated by the same person. f) Anomaly Probability Adjustment: For identified behavioral sequences, they can be treated as a whole anomalous event and assigned a high anomalous probability. For example, in a weighted probability model, a high Fm value can be set for these records individually, or they can be directly marked as anomalous by a veto item. In this way, targeted attack behaviors, such as password guessing attacks or multiple attempts by the same person to perform face recognition, can be detected, thereby improving the accuracy of anomalous behavior identification.

[0037] The present invention also provides a device for identifying abnormal unlocking behavior records of smart door locks, comprising: Central processing module; The communication interface module, which is connected to the central processing module, is used to establish a connection with the smart lock and read all original unlocking records; The data identification module, which is connected to the central processing module, has a built-in weighted probability calculation model and a veto rule. It is used to analyze all original unlocking records and calculate the probability of abnormality in order to identify abnormal unlocking records. The output module, connected to the central processing module, is used to display the recognition results and the probability of anomalies.

[0038] Specifically, the communication interface module includes a core control module, a serial communication interface module, a data storage module, a USB communication module, a status indicator module, and a power supply module, among which: The core control module uses an STM32F103C8T6 microcontroller, powered by a 3.3V supply provided by an LM1117-3.3 voltage regulator in the power supply module, and sharing a common ground with the system. The key pin configurations of this microcontroller are as follows: PA9 and PA10 pins of the USART1 interface are connected to the data input and output terminals of the RS485 module, respectively, for differential serial communication with the smart lock; PB6 and PB7 pins of the I2C1 interface are connected to the EEPROM storage module for storing unlocking records; PA2 and PA3 pins of the USART2 interface are connected to the USB-to-TTL module for serial data interaction with the host computer; GPIO pin PC13 is connected to the status indicator module to drive LEDs to indicate system status. The RS485 serial communication interface module uses the MAX485 chip as its core to achieve differential signal conversion. Its data input (DI) terminal is connected to the microcontroller's PA9 pin (USART1_TX), and its data output (RO) terminal is connected to the PA10 pin (USART1_RX). The enable terminals (DE / RE) are controlled by the microcontroller's PB0 pin, configured to transmit mode when high and receive mode when low. The differential signal terminals A and B are directly connected to the corresponding terminals of the smart lock's RS485 interface, with A connected to A and B connected to B. To improve signal integrity, a 120Ω terminating resistor R1 is connected in parallel between lines A and B. TVS diodes are also connected between A and ground for electrostatic discharge protection. The A and B differential signal lines of the RS485 communication interface use shielded twisted-pair cabling, with a 120Ω matching resistor at the end to suppress signal reflection and improve communication reliability. The data storage module uses an AT24C256 EEPROM chip and communicates with the microcontroller via the I2C bus. Its serial clock SCL pin is connected to the microcontroller's PB6 (I2C1_SCL), and its serial data SDA pin is connected to PB7 (I2C1_SDA). 10kΩ pull-up resistors R2 and R3 are connected in series on the SCL and SDA lines, respectively. The data storage module is powered by 3.3V and shares a common ground with the control system. To accommodate larger data storage needs, the EEPROM module can be replaced with an SPI interface SD card module. In this case, it needs to be connected to the microcontroller's SPI1 interface pins, namely PA5 (SCK), PA6 (MISO), and PA7 (MOSI). The USB-to-TTL module uses the CH340G chip to implement USB protocol conversion between the MCU and the host computer. Its transmit pin TXD is connected to PA3 (USART2_RX) of the microcontroller, and its receive pin RXD is connected to PA2 (USART2_TX). This module is powered by the 5V output of the power supply module (LM1117-5.0 regulator) and shares a common ground with the system. The status indicator module includes an LED and a 1kΩ current-limiting resistor R4 connected in series with it. The positive terminal of the LED is connected to a 3.3V power supply via the resistor, and the negative terminal is connected to the PC13 pin of the microcontroller. When PC13 outputs a low level, the LED lights up, which can be used to indicate communication status or standby status. The power module input is a 12V DC power supply, which can be drawn from the smart lock power supply or an external adapter. A 0.5A fuse F1 is connected in series in the input circuit for overcurrent protection. The power module has two regulated outputs: one outputs 5V through an LM1117-5.0 voltage regulator chip to power the USB to TTL module, and a 100μF electrolytic capacitor C1 is connected in parallel at the output for filtering; the other outputs 3.3V through an LM1117-3.3 to power the STM32 microcontroller, MAX485 chip, and EEPROM module, and a 100μF electrolytic capacitor C2 is connected in parallel at the output for filtering.

[0039] This application is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of this application. Various changes and modifications can be made to this application without departing from the spirit and scope thereof, and all such changes and modifications fall within the scope of this application as claimed. The scope of protection of this application is defined by the appended claims.

Claims

1. A method for identifying abnormal unlocking behavior records of a smart door lock, characterized in that, Includes the following steps: Step 1: Read all original unlocking records of the smart lock under inspection. The unlocking records include unlocking method and unlocking time information. Step 2: Analyze all the original unlocking records read according to predefined rules, and filter and identify unlocking records generated by abnormal unlocking behavior; Step 3: Visualize the abnormal opening records identified in Step 2 using charts to statistically analyze the frequency distribution of abnormal events and identify high-frequency attack periods. For smart locks that support GPS positioning, use map APIs to mark the geographical locations of abnormal events. Log auditing and reporting generation: Regularly audit and analyze all abnormal unlocking records to identify any recurring attack patterns and generate security reports, providing users with security posture assessments and improvement suggestions.

2. The method according to claim 1, characterized in that, In step 1, by establishing a communication connection with the smart door lock under test, all original unlocking records are read from at least one data storage location based on the data storage protocol corresponding to the door lock model. Data storage locations include at least one of the following: the smart lock's local Flash memory, the smart lock's network server, or the user terminal APP.

3. The identification method according to claim 2, characterized in that, The communication connection is established by directly establishing a wired connection with the UART interface of the smart door lock through the serial communication protocol.

4. The identification method according to claim 1, characterized in that, The predefined rules in step 2 include: comprehensively judging the anomaly probability P of a single unlocking record based on a weighted probability calculation model and a veto item; The weighted probability calculation model is as follows: ; Where: Wm is the weighting coefficient of the unlocking method anomaly dimension, Fm is the unlocking method anomaly probability function; the unlocking method anomaly probability function is calculated based on the degree of anomaly of the specific unlocking method recorded now relative to the mainstream unlocking methods in the historical unlocking records of this door lock; Wt is the weighting coefficient of the unlocking time anomaly dimension, Ft is the unlocking time anomaly probability function; the unlocking time anomaly probability function is calculated based on the degree of anomaly of the unlocking time point recorded now relative to the historical unlocking time distribution of this door lock; The veto item is an independent judgment item: when there is a specific hard anomaly in the unlocking record, the record is directly judged as an abnormal record; the specific hard anomaly includes at least one of the following: the door lock is opened when it is not properly locked, mechanical damage is detected, high frequency and high intensity electromagnetic pulse interference is detected, the record is locked after multiple consecutive unlocking failures, and abnormal power failure is recorded.

5. The identification method according to claim 4, characterized in that, The calculation method for the abnormal unlocking method probability function Fm includes: statistically analyzing the usage frequency of various unlocking methods in the lock's historical records, and determining the method with the lowest usage frequency as having a high abnormal probability.

6. The identification method according to claim 4, characterized in that, The calculation method of the unlocking method abnormal probability function Fm also includes: analyzing multiple password input events. If the input time interval pattern between each numeric character in a certain input event has a significant statistical difference from the stable and continuous input time interval pattern in the vast majority of successful unlocking events of the door lock, then the record is determined to be an abnormal trace.

7. The identification method according to claim 4, characterized in that, The predefined rules in step 2 also include: performing cluster analysis on all unlocking failure records that occur within a specific time window; If cluster analysis results show that multiple records use passwords that are highly similar in string or input time interval patterns, or use facial images that are close in feature space, then the records in that cluster are collectively identified as an abnormal opening behavior sequence.

8. The identification method according to claim 4, characterized in that, The calculation method of the unlocking method abnormal probability function Fm includes: analyzing the liveness detection results in the face recognition unlocking record. If the liveness detection fails or the matching degree is lower than the preset threshold, the record is determined to be an abnormal trace.

9. The identification method according to claim 4, characterized in that, The abnormal probability function Ft of unlocking time is calculated as follows: establish a time distribution model of the historical unlocking time of the door lock, and determine the unlocking records that appear in the low probability time window as having a high abnormal probability.

10. A device for identifying abnormal unlocking behavior records of a smart door lock for implementing the identification method according to any one of claims 1-9, characterized in that, include: Central processing module; The communication interface module, which is connected to the central processing module, is used to establish a connection with the smart lock and read all original unlocking records; The data identification module, which is connected to the central processing module, has a built-in weighted probability calculation model and a veto rule. It is used to analyze all original unlocking records and calculate the probability of abnormality in order to identify abnormal unlocking records. The output module, connected to the central processing module, is used to display the recognition results and the probability of anomalies.

Citation Information

Patent Citations

  • Method for identifying abnormal unlocking of intelligent door lock and system thereof

    CN107195036A