Dual-layer security degradation interaction control method and readable storage medium

CN122673010APending Publication Date: 2026-09-01HANSONG NANJING TECH LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610829643.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-10
Publication Date
2026-09-01

AI Technical Summary

Technical Problem

[0006]本发明的目的在于提供一种双层安全降级交互控制方法,以解决现有技术中安全防护粗暴、体验断层的问题

Benefits of technology

该方案的主要效果在于把产品的预防安全隐患变成系统内生能力,而不是事后补救。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122673010A_ABST
    Figure CN122673010A_ABST
Patent Text Reader

Abstract

This invention discloses a dual-layer security degradation interactive control method and a readable storage medium, comprising the following steps: real-time monitoring of product operating indicators and construction of anomaly detection vectors; based on dual-layer anomaly judgment logic, when any operating indicator exceeds a threshold or a combination of anomalies occurs, determining whether to enter a safety mode based on the type and severity of the anomaly, and identifying the corresponding safety mode; in normal mode, allowing voice, lights, mechanical actions, and network content to be output collaboratively according to the scenario; in safety mode, dynamically adjusting the product's working mode according to the security degradation level, the dynamic adjustment of the working mode includes: shutting down the heating module, limiting the length of continuous voice, reducing the frequency of actions and cutting off unnecessary network connections, retaining only low-risk lights or short-pulse mechanical actions; starting a stable window timer in each safety mode, and gradually restoring after the anomaly disappears and continues to meet the preset duration. This invention solves the problems of crude security protection and discontinuous user experience in the prior art.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of intelligent hardware control technology, specifically relating to a two-layer safety degradation interactive control method and a readable storage medium suitable for children's intelligent toys. Background Technology

[0002] Existing smart plush toys typically feature voice interaction, physical movement, internet connectivity, and heating capabilities. However, existing technologies have the following drawbacks: Limited safety protection: In case of overheating, jamming, or low battery, the hardware is usually protected by directly cutting off the power or shutting down, causing the toy to suddenly "die," resulting in a very poor user experience and easily causing panic in children.

[0003] Lack of anomaly differentiation: The inability to distinguish between transient anomalies and persistent faults causes the system to frequently fluctuate between normal operation and safety protection.

[0004] The recovery mechanism is rigid: the recovery conditions are singular and it is impossible to set different recovery thresholds for different types of faults (such as motor jamming requiring manual intervention for confirmation).

[0005] Therefore, a smart degradation control solution is needed that can both ensure safety and maintain a sense of companionship. Summary of the Invention

[0006] The purpose of this invention is to provide a two-layer security degradation interactive control method to solve the problems of crude security protection and disjointed user experience in the prior art.

[0007] To achieve the above objectives, the present invention adopts the following technical solution: a two-layer security degradation interactive control method, comprising the following steps: S1, monitors product performance indicators in real time and constructs anomaly detection vectors; S2, based on the two-layer anomaly judgment logic, when any operating indicator exceeds the threshold or a combination of anomalies occurs, the system determines whether to enter the safe mode based on the type and severity of the anomaly, and determines the corresponding safe mode. S3, in normal mode, allows voice, light, mechanical movements and network content to be output collaboratively according to the scene; S4. In safe mode, the working mode of the product is dynamically adjusted according to the security degradation level. The dynamic adjustment of the working mode includes: turning off the heating module, limiting the length of continuous voice, reducing the frequency of actions and cutting off unnecessary network connections, and only retaining low-risk lights or short pulse mechanical actions. S5 starts a stable window timer in each safety mode, and only resumes gradually after the anomaly disappears and the preset duration is met.

[0008] Furthermore, the operating indicators include temperature, battery, motor, electroacoustics, and communication; the anomaly detection vector is an n-dimensional feature vector Vt=[v1,v2,...,vn], which includes original values, statistical features, and combined features of multiple operating indicators.

[0009] Furthermore, step S2 specifically includes the following process: First, a threshold layer is set, which includes two levels of threshold indicators. The first level is the attention threshold: if the indicator exceeds the attention threshold, the system records it as a soft anomaly, but does not immediately enter the safe mode. The second level is the action threshold: if the indicator exceeds the action threshold, the system immediately determines it as a hard anomaly and triggers the safe mode. Secondly, abnormal situations are categorized, and corresponding security modes are set: Type A anomalies are single-point exceedances, meaning a single indicator exceeds the action threshold; when a Type A anomaly occurs, the system immediately enters L3 mode. Type B anomalies are continuous over-limits, which means that when a single indicator exceeds the attention threshold but does not reach the action threshold, and the duration exceeds the set time T seconds; when a Type B anomaly occurs, the power of the heating module is reduced first, and then the L1 mode is entered.

[0010] Type C anomalies are combined anomalies, which refer to multiple indicators exceeding the attention threshold simultaneously; when a Type C anomaly occurs, the system immediately enters L2 mode.

[0011] Furthermore, the security degradation level includes at least: L1 mode is the economy mode, which limits voice length and adjusts the product's action frequency to 20% of normal. L2 mode is a normal restriction mode. In normal restriction mode, the heating module and motor are disabled, and the voice is restricted to pre-recorded short audio. L3 mode is a life support-only mode, in which only the LED heartbeat light is retained and all interaction and communication are disabled.

[0012] Furthermore, S5 starts a stable window timer in each safety mode, and only resumes gradually after the anomaly disappears and the preset duration is met, including the following situations; For temperature anomalies, the recovery threshold is a temperature that is below the attention threshold for 30 seconds. For motor stall, the user performs a release action as a manual confirmation; When the battery is low, an external charger is detected and the battery level is higher than the action threshold.

[0013] Furthermore, the scenario-based collaborative output in step S3 includes: In everyday casual conversation scenarios, it includes voice interaction, accompanied by following lights; In bedtime companionship scenarios, reduce voice volume and light brightness, and disable motor vibration; In a silent environment, disable voice and internet access, and only keep the ultra-low brightness light on.

[0014] As a preferred embodiment of this application, different degradation priorities and recovery thresholds are set for different anomaly types.

[0015] This application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described two-layer security degradation interactive control method.

[0016] The advantages of this invention over the prior art are: The main effect of this solution is to transform the prevention of safety hazards in products into an inherent capability of the system, rather than a reactive measure.

[0017] First, it can promptly abandon some of the product's high-energy-consuming functions when an abnormality occurs, thereby reducing the risks of overheating, jamming, malfunctions, and continuous noise, making it particularly suitable for children's toys.

[0018] Secondly, the tiered downgrade system can avoid the sudden change in experience caused by a direct power outage. Users can still perceive that the toy is still responding, but it is operating in a more conservative way.

[0019] Third, the stable window mechanism can prevent abnormal shaking from causing frequent mode switching, improving reliability and consistency. In low-risk mode, local movements and soft light feedback are retained, ensuring safety without making the toy completely lose its companionship feel.

[0020] In summary, this solution can significantly reduce the probability of after-sales issues, complaints, and safety incidents. Attached Figure Description

[0021] Figure 1 This is a schematic diagram of the method flow of the present invention. Detailed Implementation

[0022] To facilitate understanding by those skilled in the art, the present invention will be further described below with reference to embodiments and accompanying drawings. The content mentioned in the embodiments is not intended to limit the present invention.

[0023] Example 1:

[0024] This invention provides a two-layer security degradation interactive control method, which is applied to intelligent plush toys and specifically includes the following steps: S1, Data Acquisition and Vector Construction: Real-time monitoring of toy operating indicators such as temperature, battery, motor, electroacoustics, and communication. Data format is time series data, such as temperature sampled every 2 seconds.

[0025] The data format includes: All sampled data from each sensor is time-series data. For example, the temperature sensor outputs a floating-point value every 2 seconds, in °C. The IMU (accelerometer) outputs 16-bit integer or floating-point data along the x, y, and z axes at a frequency of 100Hz.

[0026] The system constructs an n-dimensional anomaly detection vector Vt. At each sampling time t, the system constructs an n-dimensional feature vector V_t = [v1, v2, ..., vn]. The collected data includes raw values ​​such as the current temperature value Temp_t and the battery voltage Batt_V_t; statistical features such as the rate of change of temperature ΔTemp / Δt over the past 10 seconds and the sliding window variance of the motor current; and combined features such as a combined flag indicating "motor start + instantaneous peak current > threshold".

[0027] S2, construct a two-layer anomaly judgment logic. When any indicator exceeds the threshold or a combination of anomalies occurs, the system determines which mode to enter. First, a threshold layer is set. In the solution provided in this implementation, the first layer is the detection layer: two levels of threshold indicators are set. The first level is the Warning Threshold: if the indicator exceeds this value, the system records it as a soft anomaly, but does not immediately enter the safe mode; the second level is the Action Threshold: if the indicator exceeds this value, the system immediately determines it as a hard anomaly and triggers the safe mode.

[0028] The second layer is the decision layer: it determines the anomaly type based on the detection results. In this embodiment, the anomaly types include the following three categories: A, B, and C. Type A anomalies are single-point over-limits, meaning that when a single indicator, such as temperature, exceeds the action threshold, a severe overheating situation occurs, which is directly judged as a Type A anomaly. When a Type A anomaly occurs, it immediately enters L2 / L3.

[0029] Type B anomalies are characterized by continuous over-limits. This occurs when a single indicator exceeds the attention threshold but does not reach the action threshold, and the duration exceeds a set time T seconds (e.g., 30 seconds). In such cases, a continuous high temperature (temperature > action threshold, e.g., 60℃) is considered a Type B anomaly. When a Type B anomaly occurs, the power of the heating module is first reduced, and then the process enters L1 mode.

[0030] Type C anomalies are combined anomalies, which refer to multiple indicators, such as increased motor current and no change in IMU. If both indicators exceed their respective thresholds, the system will determine it as a Type C anomaly, that is, the motor is stalled / jammed, and immediately enter L2.

[0031] The L1, L2, and L3 mentioned above represent three different levels of safety modes. The higher the number, the higher the safety mode level. For the aforementioned anomaly types, the anomaly type and the conditions for entering a safety mode are as follows: Type A anomaly: Immediately enters the highest level safety mode, L3. Type B anomaly: Delayed entry; first, the power of the heating module is reduced; if it does not recover after T seconds, then safety mode L1 is entered. Type C anomaly: Immediately enters L2; ​​first, the power of the heating module is reduced, and the motor drive output is cut off first.

[0032] S3, in normal mode, allows voice, light, mechanical movements and network content to be output collaboratively according to the scene; Scene 1: Casual Chat Collaboration Strategy: Primarily based on voice interaction. When the user briefly presses the button, the system enters "listening" mode, pauses Bluetooth music, and illuminates a cyan light. After processing and synthesizing the response speech, the speaker plays a clear TTS text message, while the chest LED light follows the rhythm of the speech with a "cyan breathing" effect. After the output is complete, playback resumes if there was previously playing Bluetooth music.

[0033] Scene 2: Bedtime companionship Collaboration Strategy: When the ambient light sensor detects that the light has dimmed or the "Companion Mode" set in the App has been entered, the system reduces the interaction priority. The voice output volume is automatically reduced by 30%, the chest light changes to a warm white slow breathing light at 10% brightness (cycle 5-8 seconds), motor vibration (if present) is completely disabled, and the speaker output mainly consists of soft short phrases (such as "Goodnight").

[0034] Scene 3: Holding in Silence Collaborative Strategy: When the pressure sensor detects a continuous hug (>5 seconds) without voice input, the system enters a "silent companionship" state. Voice output and network content updates are disabled, and only the chest LED is kept on display with extremely low brightness (<5%) and ultra-slow breathing (10-second cycle) to simulate the "presence" of quiet companionship and avoid disturbance.

[0035] S4, in safe mode, automatically shuts down the heating module, limits the length of continuous voice, reduces the frequency of actions, and cuts off unnecessary network connections, retaining only low-risk lights or short-pulse mechanical actions.

[0036] Component list: LED light board, speaker (voice output), motor (vibration motor), wireless communication module (Wi-Fi / Bluetooth), main control chip, battery.

[0037] Operating mode classification (from high to low): L0 - Full-featured mode (normal mode): Unrestricted.

[0038] L1-Economy Mode (Safety Mode-Mild): Limits voice length (≤5 seconds per message) and reduces action frequency to 20% of normal.

[0039] L2 - Normal Restriction Mode (Safety Mode - Medium): Disables heat-generating modules (such as main controller frequency reduction) and motors. Restricts voice to 2 seconds of pre-recorded audio.

[0040] L3 - Life Support Only Mode (Safety Mode - Severe): Only the LED heartbeat light is retained (flashes once at 1Hz), and all interaction and communication are disabled.

[0041] Scenario-based modality selection logic: Scenario: Mild overheating → Enter L1. Power off non-core peripherals, retain basic voice interaction.

[0042] Scenario: Motor stalls → Enters L2. Immediately disables the enable pin of the motor driver chip; other modules are temporarily unaffected.

[0043] Scenario: Battery voltage too low (<3.3V) → Enter L2 mode. Force disable Wi-Fi (maximum power consumption module) to ensure remaining battery power can support core functions.

[0044] S5, in safe mode, a stable window timer is started, and it is only allowed to resume when the abnormality disappears and the preset duration is met. Stabilization window: This refers to the time interval from the moment all abnormal indicators fall below the attention threshold until the system begins to perform recovery operations. For example, the stabilization window can be set to 10 seconds.

[0045] Recovery: This refers to gradually or directly reverting from the current security mode to a higher-level normal mode (L0). For example, reverting from L2 (normal restricted mode) to L1 (economic mode), or directly back to L0.

[0046] The solution provided in this application implements a tiered degradation system. The system is reset with multiple safety modes, dynamically selecting between L1, L2, or L3 degradation states based on the anomaly type (A / B / C) and severity determined in S2. For example, a motor stall will enter an L2 degradation state characterized by shutting down the action output, while excessively high temperatures may preferentially enter an L1 degradation state characterized by limiting heat generation. This avoids the abrupt change in user experience caused by a one-size-fits-all power outage.

[0047] The following section will explain the recovery logic sequence for different anomaly types: For temperature anomalies: Degradation: Prioritize shutting down or reducing the frequency of the main controller and disabling high-load Wi-Fi tasks (L1 / L2).

[0048] Recovery: Once the temperature drops below the threshold and stabilizes, the Wi-Fi connection will be restored first, followed by a gradual restoration of the main control frequency, and finally, full-function voice control will be restored. Recovery threshold: Temperature < 45℃ for 30 seconds.

[0049] For motor stall: Degradation: Immediately disconnect the motor power supply (L2).

[0050] Recovery: The user needs to perform a "release action" (such as a short press of the button or shaking the toy) as manual confirmation. The system will only restore the motor function after it re-detects that there is no stall. The recovery threshold is higher and requires user intervention.

[0051] For low battery: Downgrade: Retain low-risk lighting, disable Wi-Fi and motors.

[0052] Restore: Never automatically restore. Wi-Fi and other functions will only be re-enabled after a USB-C charging connection is detected and the battery level is above a safe threshold (e.g., >3.7V).

[0053] S6 sets different degradation priorities and recovery thresholds for different anomaly types. For example, in case of temperature anomalies, it prioritizes shutting down heating elements; in case of motor stall, it prioritizes shutting down motion outputs. This method achieves a balance between safety protection and user experience through functional reduction.

[0054] As can be seen from the above embodiments, the present invention can provide a two-layer architecture: through the decoupling of the anomaly detection layer and the hierarchical response layer, accurate security decisions are achieved.

[0055] Graded downgrade: Unlike the traditional method of cutting off power in one go, this invention dynamically retracts the function according to the type of abnormality (such as overheating when the temperature is high or the motor is stuck). Users can still perceive the toy's vital signs (such as the light breathing), avoiding sudden changes in the experience.

[0056] Anti-shake and confirmation: The stable window mechanism prevents frequent switching caused by accidental triggering; a manual confirmation step is set up for dangerous abnormalities such as motor stall, which improves physical safety.

[0057] This invention has many specific applications. The above description is only a preferred embodiment of this invention. It should be noted that for those skilled in the art, several improvements can be made without departing from the principle of this invention, and these improvements should also be considered within the scope of protection of this invention.

Claims

1. A two-layer security degradation interactive control method, characterized in that, Includes the following steps: S1, monitors product performance indicators in real time and constructs anomaly detection vectors; S2, based on the two-layer anomaly judgment logic, when any operating indicator exceeds the threshold or a combination of anomalies occurs, the system determines whether to enter the safe mode based on the type and severity of the anomaly, and determines the corresponding safe mode. S3, in normal mode, allows voice, light, mechanical movements and network content to be output collaboratively according to the scene; S4. In safe mode, the working mode of the product is dynamically adjusted according to the security degradation level. The dynamic adjustment of the working mode includes: turning off the heating module, limiting the length of continuous voice, reducing the frequency of actions and cutting off unnecessary network connections, and only retaining low-risk lights or short pulse mechanical actions. S5 starts a stable window timer in each safety mode, and only resumes gradually after the anomaly disappears and the preset duration is met.

2. The two-layer security degradation interactive control method according to claim 1, characterized in that, The operational metrics include temperature, battery, motor, electroacoustics, and communication; the anomaly detection vector is an n-dimensional feature vector Vt=[v1,v2,...,vn], which includes original values, statistical features, and combined features of multiple operational metrics.

3. The two-layer security degradation interactive control method according to claim 1, characterized in that, S2 specifically includes the following process: First, a threshold layer is set, which includes two levels of threshold indicators. The first level is the attention threshold: if the indicator exceeds the attention threshold, the system records it as a soft anomaly, but does not immediately enter the safe mode. The second level is the action threshold: if the indicator exceeds the action threshold, the system immediately determines it as a hard anomaly and triggers the safety mode. Secondly, abnormal situations are categorized, and corresponding security modes are set: Type A anomalies are single-point exceedances, meaning a single indicator exceeds the action threshold; when a Type A anomaly occurs, the system immediately enters L3 mode. Type B anomalies are continuous over-limits, which means that when a single indicator exceeds the attention threshold but does not reach the action threshold, and the duration exceeds the set time T seconds; when a Type B anomaly occurs, the power of the heating module is reduced first, and then the L1 mode is entered. Type C anomalies are combined anomalies, which refer to multiple indicators exceeding the attention threshold simultaneously; when a Type C anomaly occurs, the system immediately enters L2 mode.

4. The two-layer security degradation interactive control method according to claim 3, characterized in that, The security degradation levels include at least: L1 mode is the economy mode, which limits voice length and adjusts the product's action frequency to 20% of normal. L2 mode is a normal restriction mode. In normal restriction mode, the heating module and motor are disabled, and the voice is restricted to pre-recorded short audio. L3 mode is a life support-only mode, in which only the LED heartbeat light is retained and all interaction and communication are disabled.

5. The two-layer security degradation interactive control method according to claim 1, characterized in that, S5, in each safety mode, starts a stabilization window timer. The stabilization window refers to the time interval from the moment when all abnormal indicators fall back below the attention threshold to the moment when the system starts to perform recovery operations. Recovery is only performed step by step when the abnormality disappears and continues to meet the preset duration, including the following situations. For temperature anomalies, the recovery threshold is a temperature that is below the attention threshold for 30 seconds. For motor stall, the user performs a release action as a manual confirmation; When the battery is low, an external charger is detected and the battery level is higher than the target threshold.

6. The two-layer security degradation interactive control method according to claim 1, characterized in that, S3 also includes, in normal mode, scenarios for collaborative output based on the scene, including: In everyday casual conversation scenarios, it includes voice interaction, accompanied by following lights; In bedtime companionship scenarios, reduce voice volume and light brightness, and disable motor vibration; In a silent environment, disable voice and internet access, and only keep the ultra-low brightness light on.

7. The two-layer security degradation interactive control method according to any one of claims 1 to 6, characterized in that, Different downgrade priorities and recovery thresholds are set for different anomaly types.

8. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, implements the two-layer security degradation interactive control method as described in any one of claims 1 to 7.