User-defined information interaction method and system of NFC ornament
By performing signal stability verification and encryption on the authentication information of NFC devices, a hash comparison data set is generated. Combined with security assessment and dynamic encryption configuration, the problem of low security in NFC interaction is solved, and higher security and data integrity are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- JIAXING ZHAOS BUTTON CO LTD
- Filing Date
- 2025-12-08
- Publication Date
- 2026-05-08
AI Technical Summary
Current NFC interaction technologies have low security, making identity information easy for attackers to reverse engineer, and lack in-depth protection measures.
By collecting identity verification information, verifying signal stability using a preset format, generating standard verification data, encrypting it using preset verification rules, generating a hash comparison data set using one-way hashing and hash comparison, matching it with a preset database, sending personalized information and conducting a security assessment, and finally updating the encryption configuration parameters.
It improves the protection of NFC devices, reduces the risk of leakage of users' sensitive information and privacy, solves the problems of data loss and format conflict in traditional technologies, and realizes full-process evaluation and dynamic encryption configuration optimization.
Smart Images

Figure CN121997352A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of NFC jewelry interaction technology, and in particular to a method and system for user-defined information interaction in NFC jewelry. Background Technology
[0002] Currently, in the field of modern intelligent interaction, near-field communication technology has become an important bridge connecting people and devices due to its convenience and security, especially in identity recognition and personalized information interaction, where it has shown irreplaceable value.
[0003] In one existing technology, NFC interaction schemes collect basic user identity information according to a common near-field protocol, organize it in a standard format, compare it with a pre-stored template, and if verification is successful, transmit preset standard information while simultaneously encrypting the data and recording basic logs such as interaction time and device identification. However, existing encryption methods have flaws; repeated fields in the identity information can create identifiable patterns in the ciphertext, allowing attackers to reverse-engineer the data characteristics. Existing technologies rely solely on simple encryption to protect data, lacking deep protection measures such as secondary verification and anomaly detection, resulting in low security.
[0004] In summary, existing technologies suffer from low levels of protection. Summary of the Invention
[0005] This invention provides a user-defined information interaction method and system for NFC jewelry to improve device security.
[0006] Firstly, in order to solve the above-mentioned technical problems, the present invention provides a user-defined information interaction method for NFC jewelry, comprising: Collect identity verification information, combine it with a preset identity format, and perform signal stability verification on the identity verification information to obtain standard verification data; The standard verification data is processed using preset verification rules to obtain encrypted verification data; The encrypted verification data is compared with a preset encrypted verification template. If the comparison result meets the preset comparison threshold, the encrypted verification data is subjected to one-way hashing to obtain a hash comparison data set. Based on the hash comparison data set, it is matched with a preset hash database. If the matching result meets the preset matching threshold, personalized information content is extracted from the hash comparison data set. The personalized information content is sent to the target device. If the personalized information content is transmitted completely, a security risk assessment is performed to obtain the security assessment result. If the security assessment result meets the preset assessment threshold, the encryption configuration parameters of the security assessment result are updated to obtain secure encrypted data.
[0007] In one optional implementation, the step of collecting authentication information, combining it with a preset identity format, and performing signal stability verification on the authentication information to obtain standard verification data includes: The authentication information is collected from the user terminal and processed in combination with a preset identity format to obtain the original input signal; The original input signal is subjected to transmission signal stability verification. If the strength of the original input signal is lower than a preset signal threshold, the original input signal is corrected to determine the preliminary verification dataset. According to the preset compatibility standard, the preliminary verification dataset is subjected to compatibility verification. If the preliminary verification dataset does not meet the format requirements, it is standardized to obtain the standard verification data.
[0008] In one optional implementation, after processing the standard verification data using preset verification rules to obtain encrypted verification data, the method further includes: Based on the encrypted verification data, the transmission signal strength is extracted. If the transmission signal strength is lower than a preset signal strength threshold, the backup signal transmission channel is activated to obtain the initial transmission data set. The initial transmission data set is used for detection. If data is missing, the initial transmission data set is interpolated and filled to obtain a complete transmission data set. The complete transmission data set is logically compared with the preset logical verification rules to determine whether the result meets the requirements. If not, the complete transmission data set is removed; if so, the encrypted verification data is determined.
[0009] In one optional implementation, the encrypted verification data is compared with a preset encrypted verification template. If the comparison result meets a preset comparison threshold, the encrypted verification data undergoes one-way hashing to obtain a hash comparison data set, including: The encrypted verification data is compared with a preset encrypted verification template. If the comparison result meets the preset comparison threshold, the encrypted verification data is subjected to one-way hashing to generate a set of hash verification values. Obtain timestamp information, associate and bind the timestamp information with the hash verification value set to obtain a timestamp verification combination; The timestamp verification combination is stored and checked. If an anomaly is detected, the field content of the log record is extracted to obtain a log data set. The log data set is associated and bound with the timestamp verification set to obtain a hash comparison data set.
[0010] In one optional implementation, the step of matching the hash comparison data set with a preset hash database, and extracting personalized information content from the hash comparison data set if the matching result meets a preset matching threshold, includes: The hash comparison data set is compared with the preset hash database to obtain the comparison result; If the comparison result meets the preset matching threshold, the personalized information data associated with the hash comparison data set is extracted from the preset hash database to obtain the personalized information set; By combining preset anomaly rules, the interactive behavior of the personalized information set is compared, anomalies are marked, and anomaly evaluation results are obtained. The anomaly assessment results are associated and bound with the personalized information set, and the data content is adjusted to obtain personalized output content.
[0011] In one optional implementation, after sending the personalized information content to the target device and, if the personalized information content is transmitted completely, a security risk assessment is performed, and the security assessment result is obtained, the method further includes: The target device is monitored in real time to obtain signal fluctuation data and device adaptation parameters; Based on the signal fluctuation data and the device adaptation parameters, the stability of the transmission environment is analyzed, and the personalized information content is sent to the target device.
[0012] In one optional implementation, if the security assessment result meets a preset assessment threshold, then updating the encryption configuration parameters of the security assessment result to obtain secure encrypted data includes: If the security assessment result matches the preset assessment threshold, then the interaction record data is extracted from the interaction log; Based on the interaction record data, a scan is performed according to the hidden danger indicators in the security assessment results, and configuration update requirements are obtained based on the scan results; Based on the configuration update requirements, the encryption configuration parameters of the security assessment results are dynamically corrected to obtain the secure encrypted data.
[0013] Secondly, the present invention provides a user-defined information interaction method and system for NFC jewelry, including: The information collection and verification module is used to collect identity verification information, and in combination with a preset identity format, to perform signal stability verification on the identity verification information to obtain standard verification data. The data encryption module is used to process the standard verification data using preset verification rules to obtain encrypted verification data; The encryption comparison hash module is used to compare the encryption verification data with a preset encryption verification template. If the comparison result meets the preset comparison threshold, the encryption verification data is subjected to one-way hash processing to obtain a hash comparison data set. The hash matching extraction module is used to match the hash comparison data set with a preset hash database. If the matching result meets the preset matching threshold, personalized information content is extracted from the hash comparison data set. The security assessment module is used to send the personalized information content to the target device. If the personalized information content is transmitted completely, a security risk assessment is performed to obtain the security assessment result. The policy generation module is used to update the encryption configuration parameters of the security assessment result if the security assessment result meets the preset assessment threshold, so as to obtain secure encrypted data.
[0014] Thirdly, the present invention also provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement a user-defined information interaction method for an NFC accessory as described in any of the above.
[0015] Fourthly, the present invention also provides a computer-readable storage medium comprising a stored computer program, wherein, when the computer program is executed, it controls the device where the computer-readable storage medium is located to execute any one of the above-described user-defined information interaction methods for NFC jewelry.
[0016] Compared with the prior art, the present invention has the following beneficial effects: (1) This invention uses symmetric encryption to initially verify data, and a communication interruption recovery mechanism to deal with transmission anomalies. Then, a verification value is generated by one-way hashing and bound to a timestamp and log to form comparison data, which reduces the risk of leakage of users' sensitive information privacy and solves the problem of traditional single encryption and easy data loss.
[0017] (2) By combining a specific near-field communication protocol, a preset acquisition frequency and an input format to limit the time window, the present invention simultaneously performs transmission signal strength verification and device compatibility processing, performs secondary acquisition and correction when the signal is weak and standardization processing when the format is inconsistent, and generates verification data through multi-dimensional verification, thus solving the problems of data loss and format conflict in traditional technologies.
[0018] (3) This invention assesses risks by comparing them with historical data based on transmission integrity, security scoring standards, and thresholds. If the risk threshold is met, the encryption mechanism is dynamically modified according to the hidden danger index update cycle and configuration parameters to generate an optimization strategy, which solves the problems of traditional technology lacking full-process assessment and fixed encryption configuration. Attached Figure Description
[0019] Figure 1 This is a schematic flowchart of a user-defined information interaction method for NFC jewelry provided in the first embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of a user-defined information interaction system for NFC jewelry provided in the second embodiment of the present invention. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0021] Reference Figure 1 The first embodiment of the present invention provides a user-defined information interaction method for NFC jewelry, including the following steps: S11, Collect identity verification information, combine it with a preset identity format, and perform signal stability verification on the identity verification information to obtain standard verification data; S12, the standard verification data is processed using preset verification rules to obtain encrypted verification data; S13, compare the encrypted verification data with the preset encrypted verification template. If the comparison result meets the preset comparison threshold, perform one-way hash processing on the encrypted verification data to obtain a hash comparison data set. S14. Based on the hash comparison data set, match it with the preset hash database. If the matching result meets the preset matching threshold, extract personalized information content from the hash comparison data set. S15, the personalized information content is sent to the target device. If the personalized information content is transmitted completely, a security risk assessment is performed to obtain the security assessment result. S16, if the security assessment result meets the preset assessment threshold, then update the encryption configuration parameters of the security assessment result to obtain secure encrypted data.
[0022] In step S11, the collected identity verification information, combined with a preset identity format, is subjected to signal stability verification to obtain standard verification data, including: The authentication information is collected from the user terminal and processed in combination with a preset identity format to obtain the original input signal; The original input signal is subjected to transmission signal stability verification. If the strength of the original input signal is lower than a preset signal threshold, the original input signal is corrected to determine the preliminary verification dataset. According to the preset compatibility standard, the preliminary verification dataset is subjected to compatibility verification. If the preliminary verification dataset does not meet the format requirements, it is standardized to obtain the standard verification data.
[0023] It should be noted that when a user wears a smartwatch that supports Near Field Communication Protocol version 2.0 and brings the watch close to the identity authentication terminal device, the terminal device establishes a stable near field communication link with the smartwatch and begins collecting information at a preset frequency of 5 times per second. This obtains the user's 16-digit unique digital identifier, such as 1234567890123456, and heart rate biometric data, such as 72 beats per minute, which are combined to obtain the core identity verification information. In NFC identity verification scenarios, the static data collection frequency is usually set to 3-10 times per second. The core purpose is to use redundant collection to combat the instantaneous interference of short-range communication, which is a common choice in the industry to balance power consumption and reliability.
[0024] It is worth noting that, subsequently, the collection time was marked for the compliance information to be retained. All valid data collected within the 1-minute time window were marked with the corresponding second-level timestamp between 14:30:00 and 14:31:00 on 2023-10-10. For example, the timestamp corresponding to 1234567890123456 is 14:30:25 on 2023-10-10, and the timestamp corresponding to heart rate data is 14:30:25 on 2023-10-10. Finally, the system integrates these timestamped, compliant identity information into a unified structure, forming a structured raw input signal containing a unique identifier, biometric data, and a collection timestamp, for example: {"unique_code":"1234567890123456","biometric_data":{"heart_rate":72},"collection_time":"2023-10-10 14:30:25"} The transmission strength of the original input signal is monitored in real time. For example, if the signal values are collected five times in succession and are -68dBm, -70dBm, -69dBm, -71dBm, and -72dBm respectively, the average signal strength is calculated to be -70dBm. After comparing it with the preset signal threshold of -60dBm, the signal transmission is determined to be unstable. Mainstream mid-to-high-end mobile phones and smartwatches have begun to adopt multi-antenna array designs, such as 2-4 groups of miniature NFC antennas distributed in different areas of the device; after determining that the signal transmission is unstable, the receiving power of each antenna is analyzed. For example, when the watch is close to the back of the phone, the back antenna is activated; when it is close to the side, the side auxiliary antenna is activated, and the antenna channel with the highest receiving gain is automatically switched to achieve directional reception of the signal in the area directly in front of it. Then, the heart rate fluctuation details that were not fully received due to weak signal are retried at the original sampling frequency of 5 times per second. After the second acquisition, the signal strength was monitored again. Five acquisitions were made within 1 second, with acquisition values of -58dBm, -57dBm, -59dBm, -56dBm, and -55dBm, respectively. The average signal strength reached -57dBm, which met the preset threshold requirement. Subsequently, the integrated structured information was checked to confirm that no fields such as unique identifier, biometric data, and acquisition timestamp were missing, and a preliminary verification dataset was formed.
[0025] The preset -60dBm signal threshold is based on the basic receiving sensitivity of most consumer-grade NFC devices, ranging from -70dBm to -65dBm, to determine the hardware critical range for effective data parsing. This is then combined with common interaction distances of 0-5 cm between the user's smartwatch and the terminal device, interference factors such as metal obstructions in the daily environment, and other wireless devices, to add a redundancy of 5-10dBm to the hardware critical value. Furthermore, through 100 sets of scenario tests with different distances and interference intensities, it was confirmed that when the signal strength is ≥-60dBm, the data transmission success rate can stably reach over 99.5%.
[0026] It is worth noting that, firstly, the preset device compatibility standard library is called to load the core compatibility standards such as JSON data format, UTF-8 encoding method, field naming rules (unique identifier is uniformly unique_code, biometric data is uniformly biometric_data, and collection timestamp is uniformly collection_time) and the list of supported smartwatch models; and the preliminary verification dataset is verified item by item.
[0027] For example, if the field names do not conform to the unified rules, the field names in the collected JSON data are the old firmware's default "user unique code", "biometric feature", and "collection time", which do not match the system's current unified "unique_code", "biometric_data", and "collection_time". The system will then initiate a format conversion and automatically correct the field names based on the preset field mapping table (which is pre-configured for field rules for different brands and firmware devices). The mapping rules are as follows: "User Unique Code" is mapped to `unique_code`, "Biometric Attributes" to `biometric_data`, and "Collection Time" to `collection_time`. Format and encoding are preserved: the JSON format and UTF-8 encoding remain unchanged throughout the process; only field key names are modified to avoid data structure corruption due to format conversion. After standardization, integrity verification is performed again. Integrity verification ensures that `unique_code` is a 16-digit number, `biometric_data` contains a heart rate value within the range of 40-180 beats / minute, and `collection_time` conforms to the ISO 8601 format. For example, confirming that `unique_code` is 1234567890123456, `biometric_data` contains a heart rate, and `collection_time` is 2023-10-10 14:30:25, all fields are complete and without missing data, the data logic is consistent and without contradictions, and the format and encoding fully comply with compatibility standards, forming standard verification data. If any undefined fields are detected, a log is recorded and the original data is temporarily stored for subsequent compatibility updates.
[0028] In step S12, after processing the standard verification data using preset verification rules to obtain encrypted verification data, the process further includes: Based on the encrypted verification data, the transmission signal strength is extracted. If the transmission signal strength is lower than a preset signal strength threshold, the backup signal transmission channel is activated to obtain the initial transmission data set. The initial transmission data set is used for detection. If data is missing, the initial transmission data set is interpolated and filled to obtain a complete transmission data set. The complete transmission data set is logically compared with the preset logical verification rules to determine whether the result meets the requirements. If not, the complete transmission data set is removed; if so, the encrypted verification data is determined.
[0029] It should be noted that the system's preset verification rule library is loaded first. This library contains data integrity verification requirements, covering all core fields such as unique identifiers, biometric data, and collection timestamps. For example, heart rate must be within the range of 40-180 beats per minute, the unique identifier must be a 16-digit numeric value, and the collection timestamp must be within a valid time window. Next, the standard verification data is verified item by item to confirm that all core fields are complete, values conform to preset ranges, and logic is consistent. For example, verifying that the unique identifier 1234567890123456 is a 16-digit numeric value and that a heart rate of 72 beats per minute is within the compliant range. If abnormal data is found, the re-collection process is triggered directly. After successful verification, the data enters the data preprocessing stage.
[0030] It's worth noting that the data is then standardized according to preset rules, serializing structured data (such as {"unique_code":"1234567890123456","biometric_data":{"heart_rate":72},"collection_time":"2023-10-10 14:30:25"}) into a JSON string. Simultaneously, a 16-bit random salt value (strictly limited to 0-9, az, AZ, e.g., "87654321abcdefgh") generated by a cryptographically secure pseudo-random number generator is added to prevent brute-force attacks on plaintext data. Then, the preset AES-256 encryption algorithm is called, using the system's pre-stored encryption key to encrypt the concatenated string of serialized data and salt value.
[0031] Specifically, first, the system retrieves a pre-stored 32-byte (256-bit) binary key, in the example format 0x1A2B3C4D5E6F7A8B9C0D1E2F3A4B5C6D7E8F9A0B1C2D3E4F5A6B7C8D9E0F1A2B. This key is generated by a hardware security module and rotated every 90 days, and is stored using a key encryption method with double encryption. The serialized string is then converted to a binary plaintext byte stream using UTF-8 encoding, and a 16-byte (128-bit) initialization vector (IV) is generated using a cryptographically secure pseudo-random number generator. If the plaintext byte stream length is not a multiple of 16 bytes, it is padded according to the PKCS#7 standard. Finally, using AES-GCM security mode, the key, IV, and padded plaintext are input into the OpenSSL authentication encryption library. Version 3.0+ generates a ciphertext body and a 128-bit (16-byte) authentication tag, which is then Base64 encoded to a fixed 24 characters. Finally, the binary data of the ciphertext body, authentication tag, and IV are converted into Base64 strings to form encrypted verification data.
[0032] It should be noted that after the encrypted verification data is generated, the transmission signal strength of this near-field communication is extracted from its associated metadata (stored in a key-value table in a temporary cache, indexed by the data ID of the signal record before encryption). For example, if the extracted result is -68dBm, this strength is compared with a preset -60dBm signal threshold. If it is lower than the threshold, the current NFC transmission channel is determined to be unstable, and the preset Bluetooth BLE 5.0 backup channel is immediately triggered. After the backup channel is activated, the complete encrypted verification data is retransmitted at a rate of once per second for three consecutive times. Each transmission carries a timestamp in milliseconds (e.g., 2023-10-10 14:30:25.789), and the receiving end verification time interval error must be less than 50ms.
[0033] It's worth noting that each group of data in the initial transmission data set undergoes field integrity and format checks, verifying the core fields (encrypted_data, IV, auth_tag, salt, encryption_algorithm, validation_status) for missing or abnormal data. The encrypted data integrity verification standard requires: the auth_tag to be 128-bit binary data, with a Base64 encoded length of 24 characters; the encrypted_data format must conform to the AES-GCM output specification, and its validity must be verified through decryption testing; the algorithm must be the system-predefined AES-256. If an anomaly is found, such as the second group of data lacking an auth_tag, the third group of encrypted_data being insufficient in length, or an incorrect algorithm identifier, a NACK signal is sent to the sender, specifying the anomaly type and requesting retransmission within 100ms. If the retransmission is still ineffective after three attempts, the user is prompted to bring the device closer again. Ultimately, only fully compliant data is retained as a candidate.
[0034] In this invention, a preset logical verification rule library is loaded to perform logical comparison on candidate data. The rules include: encryption_algorithm must be "AES-256", validation_status must be "passed", IV must be a 16-byte Base64 encoded value, auth_tag must be a 24-character Base64 encoded value, and salt must be a 16-bit alphanumeric combination. Additionally, the transmission consistency verification includes the following rules: based on continuous signal strength sampled 5 times per second, a 5-second window is used to calculate the standard deviation, which must not exceed ±5dBm, and the timestamp interval error must be less than 50ms.
[0035] For example, the first set of data met all the rules and had the best signal stability, so it passed the verification; the second set of data was removed because of a missing auth_tag; the third set of data was removed because it did not meet the transmission consistency rules due to historical deviations in algorithm identification and excessive signal fluctuations. All abnormal data were logged in detail, including the anomaly type, occurrence time, and associated device information. Finally, the set with the best signal strength and no transmission anomalies was selected from the compliant data and determined as the final encryption verification data.
[0036] In step S13, the encrypted verification data is compared with a preset encrypted verification template. If the comparison result meets a preset comparison threshold, the encrypted verification data undergoes one-way hash processing to obtain a hash comparison data set, including: The encrypted verification data is compared with a preset encrypted verification template. If the comparison result meets the preset comparison threshold, the encrypted verification data is subjected to one-way hashing to generate a set of hash verification values. Obtain timestamp information, associate and bind the timestamp information with the hash verification value set to obtain a timestamp verification combination; The timestamp verification combination is stored and checked. If an anomaly is detected, the field content of the log record is extracted to obtain a log data set. The log data set is associated and bound with the timestamp verification set to obtain a hash comparison data set.
[0037] It should be noted that a preset encryption verification template is loaded first. The template includes the core field structure specifications and field weight allocation. Field matching uses a 100-point scoring system. The core field `encrypted_data` receives 60 points for a perfect match. The verification fields `IV` and `auth_tag` each receive 10 points, with a base length of 16 bytes. One point is deducted for each missing byte. The auxiliary fields `salt` and `algorithm` each receive 10 points. The `salt` field is a 16-character fixed-length string with a character set limited to 0-9, az, and AZ. One point is deducted for each illegal character. The `algorithm` field must perfectly match the predefined identifier; 5 points are deducted for capitalization errors. Fields are verified in the order of `encrypted_data` → `IV` → `auth_tag` → `salt` → `algorithm`. The total score is calculated by adding the base score of 60 points to the additional points. The total score must be ≥90 points, and each field must have a score ≥0 points.
[0038] In one possible implementation, a one-way hash is performed on the encrypted verification data. The SHA-256 algorithm is used to calculate the hash value in three levels. First, the Base64 encoded data of `encrypted_data` is decoded into binary data to calculate the first-level hash. Then, the binary data of `IV` and `auth_tag` are concatenated to calculate the second-level hash. Finally, the two hash values are concatenated in big-endian order to form a 512-bit data block to calculate the third-level complete data hash value. All hash calculations undergo RFC 6234 standard message padding, block processing, and 64 rounds of compression function iterations to generate a 256-bit original hash value, which is then converted into a lowercase 64-bit hexadecimal string.
[0039] It's worth noting that the system automatically acquires the millisecond-level timestamp of the current data processing and binds it to a three-level hash checksum set to generate a timestamp checksum combination. This combination is written to a specified path in the SQLite encrypted database. During storage checks, a storage threshold is dynamically set based on the average size of a single record (2KB), with the maximum value among 5%, 10MB, and 100MB of total storage space. If an anomaly is detected, log records at or above level 3 are extracted according to a 1-5 anomaly rating system: Level 1 is a warning anomaly, Level 2 is a general anomaly, Level 3 is a serious anomaly, Level 4 is a major anomaly, and Level 5 is a fatal anomaly. The anomaly identifier uses the format "anomaly code (6 digits) - timestamp - device ID," ultimately forming a complete hash comparison data set.
[0040] In step S14, the hash comparison data set is matched with a preset hash database. If the matching result meets a preset matching threshold, personalized information content is extracted from the hash comparison data set, including: The hash comparison data set is compared with the preset hash database to obtain the comparison result; If the comparison result meets the preset matching threshold, the personalized information data associated with the hash comparison data set is extracted from the preset hash database to obtain the personalized information set; By combining preset anomaly rules, the interactive behavior of the personalized information set is compared, anomalies are marked, and anomaly evaluation results are obtained. The anomaly assessment results are associated and bound with the personalized information set, and the data content is adjusted to obtain personalized output content.
[0041] It should be noted that a preset hash database is loaded first, containing historically valid hash verification combinations, associated data IDs, and corresponding verification baseline values. This database is encrypted and uses the associated data ID (ENC20231010143025) in the hash comparison dataset as an index. The database is then used to extract the historical baseline hash set corresponding to this ID, including the core ciphertext baseline hash, verification combination baseline hash, and complete data baseline hash. If the hash value matching degree reaches 100%, the consistency verification result is "passed." The three hash values in this hash comparison dataset are then compared one by one with the baseline value. For example, if the core ciphertext hash value 5f7d28e91a3c5b7d9e2f4a6c8e0d2b4f6a8c0e2d4f6a8c0e2d4f6a8c0e2d4f6a8c0e2d4f6a8c0e2d4f6a matches the baseline value perfectly, and the matching degree of the verification combination hash value and the complete data hash value also reaches 100%, the overall matching degree requirement is met, and the consistency verification result is "passed."
[0042] Since the consistency check passed, the system extracts the corresponding data from the personalized information partition of the preset hash database based on the user's unique identifier associated with the ID (obtained by matching from the database association table). This data covers three core categories: basic user information, permission configuration, and historical interaction preferences, forming a personalized information set.
[0043] For example,{ "user_id":"U20230510001", "basic_info":{ "username":"Zhang San", "cert_type":"ID card", "cert_no":"610XXXXXXXXXXXXXXXX" }, "permission_config":{ "access_level":"Level 1 access", "available_functions":["Data Query","Business Processing","Record Export"] }, "interaction_preference":{ "recent_login_time":["2023-10-09 08:30:15","2023-10-08 14:20:36"], "frequently used_function":"Business processing", "interaction_time_window":"08:00-18:00" } } It's worth noting that a pre-defined exception rule library is loaded, including rules such as: interaction time exceeding the range set by `interaction_time_window`; using functions other than `frequently_used_function` more than three times consecutively; login device inconsistent with historically frequently used devices; and permission calls exceeding the function range corresponding to the `access_level`. Based on the interaction behavior data in the personalized information set, combined with the real-time information of this operation, such as the operation time 2023-10-10 14:30:25, the operation function "business processing", and the login device being a historically frequently used device, a comparison is made: this operation time was within the 08:00-18:00 window, the operation function was the frequently used "business processing", the login device was consistent with the historical records, and no exception rules were triggered, therefore it was marked as "no exception". At the same time, a compliance explanation of the interaction behavior was added to form the exception assessment result.
[0044] For example,{ "abnormal_flag": "no_abnormal", "abnormal_details": [], "compliance_description": "The time of this operation, the function used, and the logged-in device are all consistent with the user's personalized interaction preferences, and there is no behavior that violates the preset exception rules." } The anomaly assessment results are bound to the personalized information set using ID as the association key. Combined with the assessment conclusion of "no anomalies," the data content is adjusted according to the preset output template. This includes retaining the anonymized display of basic user information (hiding the middle 8 digits of the ID card), fully displaying permission configurations and available functions, highlighting frequently used function entries, and supplementing the security verification mark of this operation, ultimately generating personalized output content.
[0045] For example,{ "user_id":"U20230510001", "output_content":{ "greeting":"Hello, Zhang San (ID card number: 610XXXXXXXXX6789)", "permission_info":"You currently have level one permission and can use the following functions: data query, business processing, and record export." "recommended_function":"High-frequency function: Business processing (click to quickly access)", "operation_status":"The security check for this operation passed; no abnormal behavior was recorded." "service_hint":"Service hours: 08:00-18:00. Please contact customer service if you have any questions." }, "abnormal_evaluation":{ "abnormal_flag":"no_abnormal", "compliance_description": "The time of this operation, the function used, and the logged-in device are all consistent with the user's personalized interaction preferences, and there is no behavior that violates the preset exception rules." } } In step S15, the personalized information content is sent to the target device. If the personalized information content is transmitted completely, a security risk assessment is performed to obtain the security assessment result.
[0046] In one possible implementation, after sending the personalized information content to the target device and, if the personalized information content is transmitted completely, a security risk assessment is performed, and the security assessment result is obtained, the method further includes: The target device is monitored in real time to obtain signal fluctuation data and device adaptation parameters; Based on the signal fluctuation data and the device adaptation parameters, the stability of the transmission environment is analyzed, and the personalized information content is sent to the target device.
[0047] It should be noted that when performing real-time status monitoring of the target device, the transmission signal strength of the target device is recorded at fixed time intervals, such as every 5 seconds, to obtain signal fluctuation data. At the same time, device adaptation parameters are collected synchronously, including the near-field communication protocol version supported by the device and the compatibility of data transmission formats.
[0048] It is worth noting that the fixed time interval of 5 seconds is based on the fact that most NFC signal interference is instantaneous. The 5-second interval can cover its typical fluctuation cycle, avoiding the capture of redundant small fluctuations due to the interval being too short, and also prevent the interval from missing key instantaneous attenuation due to the interval being too long, ensuring timely triggering of signal enhancement mechanisms.
[0049] It should be noted that, based on the acquired signal fluctuation data and device adaptation parameters, a comprehensive analysis of the transmission environment stability is performed. If the signal fluctuation data shows that the signal strength is consistently above the preset threshold of -60dBm, and the device adaptation parameters indicate that the target device supports the currently used near-field communication protocol and data format, the transmission environment is determined to be stable. If the signal strength frequently falls below the threshold or there are device adaptation conflicts, the transmission environment is determined to be unstable. Once the transmission environment is determined to be stable, the personalized information content is sent to the target device using the TLS 1.3 protocol.
[0050] For example, the personalized output content is first sent to the target device through an encrypted transmission channel, such as the TLS 1.3 protocol. During the transmission, a data fragmentation and verification mechanism is enabled simultaneously, and the data is fragmented into 4KB segments. The fragmentation efficiency and verification accuracy of the data transmission are matched according to the actual situation of the personalized output content, and each segment is attached with a SHA-256 hash verification value.
[0051] In this embodiment, after the target device receives the data, it performs a transmission integrity check according to a preset judgment rule. First, it splices all data fragments and verifies the consistency of the SHA-256 hash check value of each fragment with the sender's, ensuring that each fragment has not been tampered with or damaged. Then, it checks the total length of the complete data. The actual length of the received data is 6842 bytes, which perfectly matches the original length of the sender. Finally, it checks whether the core fields (user_id, output_content, abnormal_evaluation) are missing or have abnormal formats (e.g., checking whether user_id is a 10-bit fixed encoding format, whether output_content contains the greeting and permission_info subfields, and whether abnormal_evaluation has an abnormal_flag flag). After full-dimensional verification confirms that there are no abnormalities, the transmission is finally determined to be complete.
[0052] The security risk assessment process was then initiated, loading a pre-set security assessment rule base. This included rules regarding whether the data transmission channel was encrypted, whether personalized information was anonymized, whether the anomaly assessment result was "no anomaly," and whether the target device was a trusted device. A trusted device refers to a device that has undergone multi-dimensional verification, has a legitimate identity, compliant security status, and is authorized to access personalized information transmission and interaction. Each rule was compared individually. This transmission used a TLS 1.3 encrypted channel, the user's ID information was anonymized, the anomaly assessment result was "no anomaly," and the target device was a long-term trusted device linked to by the user. No security risk rules were triggered, ultimately resulting in a security assessment result of "Security Level: Level 1 (No Security Risks)."
[0053] In step S16, if the security assessment result meets a preset assessment threshold, the encryption configuration parameters of the security assessment result are updated to obtain secure encrypted data, including: If the security assessment result matches the preset assessment threshold, then the interaction record data is extracted from the interaction log; Based on the interaction record data, a scan is performed according to the hidden danger indicators in the security assessment results, and configuration update requirements are obtained based on the scan results; Based on the configuration update requirements, the encryption configuration parameters of the security assessment results are dynamically corrected to obtain the secure encrypted data.
[0054] It should be noted that a preset assessment threshold (security level ≥ Level 1 and no high-risk hidden danger indicators) is first loaded. The security assessment result of "Security Level: Level 1 (no security risks)" is then compared with the threshold. Since the threshold requirement is fully matched, the interaction record extraction mechanism is triggered. Using user_id:U20230510001 and data_id:ENC20231010143025 as association conditions, the full set of interaction record data for this user within the past 30 days is extracted from the system interaction log library. This data covers core dimensions such as transmission channels, encryption configurations, operational behaviors, and history of hidden dangers, forming an interaction record data set.
[0055] The security assessment results extract potential vulnerabilities. For example, if no new vulnerabilities are found, but historical records indicate a potential risk of "lower transmission channel version," a targeted scan is performed on the encryption configuration and transmission channel information in the interaction record dataset, based on preset vulnerability scanning rules such as a transmission channel version ≥ TLS 1.3, encryption algorithms compatible with the latest security standards, and a key rotation cycle ≤ 90 days. For instance, if a user is found to have used a TLS 1.2 channel once within the last 30 days, even though it has now been upgraded to TLS 1.3, the configuration must be solidified to avoid rollback; simultaneously, the encryption key rotation cycle is found to be 120 days, exceeding the preset 90-day security threshold.
[0056] Based on the scan results, the configuration update requirements were clearly defined, the transmission channel configuration was solidified, TLS 1.3 and above were forcibly locked, and downgraded use was prohibited; the AES-256 key rotation cycle was shortened from 120 days to 90 days; and a real-time verification mechanism for the transmission channel version was added to avoid abnormal downgrades.
[0057] Based on the configuration update requirements, the original encryption configuration parameters in the security assessment results are dynamically corrected. The transmission channel configuration adds a "force lock TLS 1.3+" rule and supplements the downgrade detection trigger conditions. In the key management parameters, the "key rotation cycle" is corrected from 120 days to 90 days, and the key rotation reminder mechanism is updated accordingly. The original core security configurations such as AES-256-GCM algorithm and SHA-256 hash verification are retained, and a new parameter for channel version verification frequency (once every 5 minutes) is added.
[0058] After the correction is completed, the updated encryption configuration parameters, security assessment results, and configuration correction logs are integrated to form secure encrypted data.
[0059] For example:{ "data_id":"ENC20231010143025", "user_id":"U20230510001", "updated_encryption_config":{ "algorithm":"AES-256-GCM", "key_length":"256 bits", "key_rotation_cycle":"90 days", "hash_algorithm":"SHA-256", "transmission_channel":"TLS 1.3+ (mandatory locking, no downgrading)", "channel_check_frequency":"Check every 5 minutes", "validation_rules":["Channel version ≥ TLS 1.3", "Key rotation ≤ 90 days", "Hash checksum matching rate reaches 100%"] }, "security_evaluation_result":{ "security_level":"Level 1 (No security risks)", "hidden_dangers":[], "historical_hidden_dangers":["Lower transport channel version (TLS 1.2)"], "compliance_rate":"100%" }, "configuration_modification_log":{ "modify_time":"2023-10-10 14:35:12", "original_params":{ "key_rotation_cycle":"120 days", "transmission_channel":"TLS 1.3", "channel_check_frequency":"None" }, "updated_params":{ "key_rotation_cycle":"90 days", "transmission_channel":"TLS 1.3+ (mandatory locking, no downgrading)", "channel_check_frequency": "Once every 5 minutes" }, "modify_reason": "Optimizes transmission channel security, shortens key rotation cycle, and reduces potential security risks" } } In summary, this invention discloses a user-defined information interaction method for NFC jewelry, which solves the problem of low security in the use of NFC jewelry.
[0060] Reference Figure 2 The second embodiment of the present invention provides a user-defined information interaction system for NFC jewelry, including: The information collection and verification module is used to collect identity verification information, and in combination with a preset identity format, to perform signal stability verification on the identity verification information to obtain standard verification data. The data encryption module is used to process the standard verification data using preset verification rules to obtain encrypted verification data; The encryption comparison hash module is used to compare the encryption verification data with a preset encryption verification template. If the comparison result meets the preset comparison threshold, the encryption verification data is subjected to one-way hash processing to obtain a hash comparison data set. The hash matching extraction module is used to match the hash comparison data set with a preset hash database. If the matching result meets the preset matching threshold, personalized information content is extracted from the hash comparison data set. The security assessment module is used to send the personalized information content to the target device. If the personalized information content is transmitted completely, a security risk assessment is performed to obtain the security assessment result. The policy generation module is used to update the encryption configuration parameters of the security assessment result if the security assessment result meets the preset assessment threshold, so as to obtain secure encrypted data.
[0061] It should be noted that the user-defined information interaction system for NFC jewelry provided in this embodiment of the invention is used to execute all the process steps of the user-defined information interaction method for NFC jewelry in the above embodiment. The working principle and beneficial effects of the two are one-to-one, so they will not be described again.
[0062] This invention also provides an electronic device. The electronic device includes a processor, a memory, and a computer program stored in the memory and executable on the processor, such as a user-defined information interaction program for NFC jewelry. When the processor executes the computer program, it implements the steps in the various embodiments of the user-defined information interaction method for NFC jewelry described above, for example... Figure 1 The step S11 shown. Alternatively, when the processor executes the computer program, it implements the functions of each module / unit in the above-described device embodiments, such as the information acquisition and verification module.
[0063] For example, the computer program may be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present invention. The one or more modules / units may be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in the electronic device.
[0064] The electronic device may be a desktop computer, laptop, handheld computer, or smart tablet, etc. The electronic device may include, but is not limited to, a processor and memory. Those skilled in the art will understand that the above components are merely examples of electronic devices and do not constitute a limitation on the electronic device. It may include more or fewer components than described above, or combine certain components, or different components. For example, the electronic device may also include input / output devices, network access devices, buses, etc.
[0065] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the electronic device, connecting all parts of the electronic device via various interfaces and lines.
[0066] The memory can be used to store the computer programs and / or modules. The processor implements various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory and by calling data stored in the memory. The memory may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0067] Wherein, if the modules / units integrated in the electronic device are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that the content included in the computer-readable medium can be appropriately added or removed according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electrical carrier signals and telecommunication signals.
[0068] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.
[0069] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above descriptions are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. In particular, it should be noted that any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention for those skilled in the art.
Claims
1. A method for user-defined information interaction in NFC jewelry, characterized in that, include: Collect identity verification information, combine it with a preset identity format, and perform signal stability verification on the identity verification information to obtain standard verification data; The standard verification data is processed using preset verification rules to obtain encrypted verification data; The encrypted verification data is compared with a preset encrypted verification template. If the comparison result meets the preset comparison threshold, the encrypted verification data is subjected to one-way hashing to obtain a hash comparison data set. Based on the hash comparison data set, it is matched with a preset hash database. If the matching result meets the preset matching threshold, personalized information content is extracted from the hash comparison data set. The personalized information content is sent to the target device. If the personalized information content is transmitted completely, a security risk assessment is performed to obtain the security assessment result. If the security assessment result meets the preset assessment threshold, the encryption configuration parameters of the security assessment result are updated to obtain secure encrypted data.
2. The user-defined information interaction method for NFC jewelry according to claim 1, characterized in that, The collected identity verification information, combined with a preset identity format, is used to perform signal stability verification on the identity verification information to obtain standard verification data, including: The authentication information is collected from the user terminal and processed in combination with a preset identity format to obtain the original input signal; The original input signal is subjected to transmission signal stability verification. If the strength of the original input signal is lower than a preset signal threshold, the original input signal is corrected to determine the preliminary verification dataset. According to the preset compatibility standard, the preliminary verification dataset is subjected to compatibility verification. If the preliminary verification dataset does not meet the format requirements, it is standardized to obtain the standard verification data.
3. The user-defined information interaction method for NFC jewelry according to claim 1, characterized in that, After processing the standard verification data using preset verification rules to obtain encrypted verification data, the process further includes: Based on the encrypted verification data, the transmission signal strength is extracted. If the transmission signal strength is lower than a preset signal strength threshold, the backup signal transmission channel is activated to obtain the initial transmission data set. The initial transmission data set is used for detection. If data is missing, the initial transmission data set is interpolated and filled to obtain a complete transmission data set. The complete transmission data set is logically compared with the preset logical verification rules to determine whether the result meets the requirements. If not, the complete transmission data set is removed; if so, the encrypted verification data is determined.
4. The user-defined information interaction method for NFC jewelry according to claim 1, characterized in that, The encrypted verification data is compared with a preset encrypted verification template. If the comparison result meets a preset comparison threshold, the encrypted verification data undergoes one-way hashing to obtain a hash comparison data set, including: The encrypted verification data is compared with a preset encrypted verification template. If the comparison result meets the preset comparison threshold, the encrypted verification data is subjected to one-way hashing to generate a set of hash verification values. Obtain timestamp information, associate and bind the timestamp information with the hash verification value set to obtain a timestamp verification combination; The timestamp verification combination is stored and checked. If an anomaly is detected, the field content of the log record is extracted to obtain a log data set. The log data set is associated and bound with the timestamp verification set to obtain a hash comparison data set.
5. The user-defined information interaction method for NFC jewelry according to claim 1, characterized in that, The step involves matching the hash comparison data set with a preset hash database. If the matching result meets a preset matching threshold, personalized information content is extracted from the hash comparison data set, including: The hash comparison data set is compared with the preset hash database to obtain the comparison result; If the comparison result meets the preset matching threshold, the personalized information data associated with the hash comparison data set is extracted from the preset hash database to obtain the personalized information set; By combining preset anomaly rules, the interactive behavior of the personalized information set is compared, anomalies are marked, and anomaly evaluation results are obtained. The anomaly assessment results are associated and bound with the personalized information set, and the data content is adjusted to obtain personalized output content.
6. The user-defined information interaction method for NFC jewelry according to claim 1, characterized in that, The process of sending the personalized information content to the target device, and if the personalized information content is transmitted completely, then performing a security risk assessment, and after obtaining the security assessment result, further includes: The target device is monitored in real time to obtain signal fluctuation data and device adaptation parameters; Based on the signal fluctuation data and the device adaptation parameters, the stability of the transmission environment is analyzed, and the personalized information content is sent to the target device.
7. The user-defined information interaction method for NFC jewelry according to claim 1, characterized in that, If the security assessment result meets the preset assessment threshold, the encryption configuration parameters of the security assessment result are updated to obtain secure encrypted data, including: If the security assessment result matches the preset assessment threshold, then the interaction record data is extracted from the interaction log; Based on the interaction record data, a scan is performed according to the hidden danger indicators in the security assessment results, and configuration update requirements are obtained based on the scan results; Based on the configuration update requirements, the encryption configuration parameters of the security assessment results are dynamically corrected to obtain the secure encrypted data.
8. A user-defined information interaction system for NFC jewelry, characterized in that, include: The information collection and verification module is used to collect identity verification information, and in combination with a preset identity format, to perform signal stability verification on the identity verification information to obtain standard verification data. The data encryption module is used to process the standard verification data using preset verification rules to obtain encrypted verification data; The encryption comparison hash module is used to compare the encryption verification data with a preset encryption verification template. If the comparison result meets the preset comparison threshold, the encryption verification data is subjected to one-way hash processing to obtain a hash comparison data set. The hash matching extraction module is used to match the hash comparison data set with a preset hash database. If the matching result meets the preset matching threshold, personalized information content is extracted from the hash comparison data set. The security assessment module is used to send the personalized information content to the target device. If the personalized information content is transmitted completely, a security risk assessment is performed to obtain the security assessment result. The policy generation module is used to update the encryption configuration parameters of the security assessment result if the security assessment result meets the preset assessment threshold, so as to obtain secure encrypted data.