Modular toy system and authentication control method thereof
Patent Information
- Application Number
- CN202611102319.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-23
- Publication Date
- 2026-09-18
AI Technical Summary
[0008]2.电子模块化方案的局限:部分声称支持“电子模块化”的玩具,其模块更换通常依赖于专用且复杂的连接器,成本高昂、不易获得;或者仅实现简单的物理接通,仅能供电而无数据通信,主板无法识别连接了何种模块,更无法实现智能的协同控制
本发明通过统一的连接器接口和串行总线协议,实现了功能模块的“即插即用”。消费者可在同一基座平台上获得完全不同的玩具体验,从遥控车变为喷雾车、泡泡车、水弹车等,产品生命周期极大延长,实现功能扩展灵活性;
Smart Images

Figure CN122768699A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of children's toy technology, and more specifically, to a modular toy system and its authentication control method. Background Technology
[0002] Currently, the children's toy market is flooded with toys that have fixed functions. Take remote-controlled toy cars as an example: once a consumer buys one, its function is limited to basic actions like moving forward, backward, and turning. These toys offer limited gameplay and struggle to hold children's attention for long. After a brief period of novelty, children often abandon them, ending the toy's lifespan. From the toy manufacturer's perspective, once a traditional fixed-function toy is sold, the connection between the manufacturer and the user is essentially severed. Manufacturers cannot learn about users' habits and preferences, cannot continuously provide new ways to play and content, and cannot generate sustained revenue from sold products.
[0003] The emergence of modular toys has provided a completely new approach to solving the above problems.
[0004] First, modular toys allow children to freely combine and expand the toy's functions according to their own wishes. A basic chassis can be transformed into a spray car, a bubble car, a water bullet car, or even a running and singing sound and light robot by changing different functional modules. Each module change provides a completely new play experience. This "one platform, multiple ways to play" characteristic can continuously stimulate children's desire to explore and greatly extend the toy's life cycle.
[0005] Secondly, modular toys are highly valuable for developing children's hands-on skills. Unlike traditional toys that are "ready to play out of the box," modular toys require children to actively participate—selecting modules, aligning interfaces, plugging them in, and matching the outer shell. This seemingly simple process subtly develops children's hand-eye coordination, spatial imagination, and logical thinking abilities. Through the cycle of "building-testing-modifying," children experience the joy and sense of accomplishment of creation, an educational value that traditional fixed-function toys cannot provide.
[0006] Furthermore, modular toys possess a natural social attribute. Children can exchange their functional modules, showcase their "creations," and even collaborate to build more complex combinations. This process of sharing and communication further enhances the toy's appeal and users' continued engagement.
[0007] Although the concept of modularity has been reflected in the toy industry, existing solutions still have obvious shortcomings: 1. Limited to structural deformation: Most mainstream modular toys on the market (such as building blocks) remain at the level of assembling physical structures. Children can build different shapes, but the electronic functions of the toys (such as movements, sound and light effects, special effects, etc.) do not change substantially with the structural changes.
[0008] 2. Limitations of electronic modular solutions: Some toys that claim to support "electronic modularity" usually rely on special and complex connectors for module replacement, which are costly and hard to obtain; or they only achieve simple physical connection, which can only provide power but not data communication. The motherboard cannot identify which module is connected, let alone achieve intelligent collaborative control.
[0009] 3. Lack of an effective accessory protection mechanism: In existing solutions, even if physical connections between modules are achieved, there is a lack of an effective authentication mechanism for accessories. Third-party manufacturers can easily produce compatible modules, seize the original parts market at low prices, and severely dampen the enthusiasm of original manufacturers to continuously develop new accessories.
[0010] How to build a standardized, low-cost, intelligently identifiable, easily expandable, and effective modular toy hardware platform that prevents the use of unauthorized accessories, allowing children to assemble and replace functional modules themselves, gaining fun and growth in the process of constantly creating new ways to play, while establishing a sustainable "platform + accessories" business model for toy manufacturers, is an urgent problem to be solved. Summary of the Invention
[0011] The purpose of this invention is to provide a modular toy system and its authentication control method, which can improve the expansion flexibility, stability, reliability, authorization security and economy of the modular toy hardware platform.
[0012] This invention provides a modular toy system, comprising: Motherboard, integrated microcontroller, power management unit, first communication interface and at least one second communication interface; The motherboard is used to electrically connect the integrated microcontroller, power management unit, first communication interface and second communication interface; The integrated microcontroller is used to control the wireless communication module through the motherboard and the first communication interface, and to control the functional expansion module through the motherboard and the second communication interface; The power management unit is used for battery charging and discharging management; The first communication interface is connected to a wireless communication module, which is used to receive external control commands. The second communication interface is used to detachably connect a function expansion module, which includes functional circuitry.
[0013] Furthermore, it also includes a power supply control circuit and a voltage regulator circuit. The power supply control circuit is electrically connected to the battery and the second communication interface to control the power supply of the function expansion module. The voltage regulator circuit is electrically connected to the battery and the first communication interface to reduce the battery voltage and then provide power to the integrated microcontroller and the first communication interface.
[0014] Furthermore, it also includes a multiplexing / isolation circuit, which is electrically connected to the integrated microcontroller and the second communication interface, for communication and authentication control between the integrated microcontroller and the functional expansion module, and for isolating different functional expansion modules.
[0015] Furthermore, it also includes an insertion detection circuit, which is electrically connected to the integrated microcontroller and the second communication interface. The insertion detection circuit is pulled up to a high level by a pull-up resistor. The insertion detection circuit is configured to: confirm that the function expansion module pulls the insertion detection circuit down to a low level to determine that a function expansion module has been inserted; and confirm that the insertion detection circuit returns to a high level to determine that the function expansion module has been removed.
[0016] Furthermore, it also includes an interrupt notification circuit, which is electrically connected to the integrated microcontroller and the second communication interface for transmitting an interrupt signal.
[0017] Furthermore, the first communication interface is also used to detachably connect the wireless communication module and provide a power channel for the wireless communication module. The integrated microcontroller and the wireless communication module perform serial data communication and authentication control through the first communication interface.
[0018] Furthermore, the first and second communication interfaces use Type-C connectors, FPC sockets, or pin headers.
[0019] Furthermore, the functional expansion module includes at least one of the following functional circuits: motor drive, recording playback, atomization generation, bubble generation, and water bullet launch; the functional expansion module is provided with a physical connector that matches the second communication interface.
[0020] The present invention also provides an authentication control method for the above-mentioned modular toy system, comprising: The confirmation function expansion module pulls the insertion detection circuit down to a low level to determine that a function expansion module has been inserted. The power supply control circuit is used to connect the battery and the second communication interface to provide power to the functional expansion module. A random challenge code is generated using the base and sent to the functional extension module via the second communication interface; The functional extension module uses the symmetric key, the module's unique identifier, and the random challenge code to generate a response code using an encryption algorithm; Based on the symmetric key, the module's unique identifier, and the random challenge code, the integrated microcontroller generates the expected response code using an encryption algorithm. Once the response code is confirmed to match the expected response code, the power supply control circuit and the second communication interface are used to maintain the power supply and serial data communication of the functional expansion module. If the response code is found to be inconsistent with the expected response code, the power supply control circuit is used to disconnect the battery and the second communication interface, cutting off the power supply and serial data communication of the function expansion module.
[0021] Furthermore, the authentication control method further includes: The wireless communication module pulls the insertion detection circuit down to a low level to confirm that a wireless communication module has been inserted. A random challenge code is generated using the base and sent to the wireless module through the first communication interface; The wireless communication module uses the symmetric key, the module's unique identifier, and the random challenge code to generate a response code using an encryption algorithm. Based on the symmetric key, the module's unique identifier, and the random challenge code, the integrated microcontroller generates the expected response code using an encryption algorithm. Confirm that the response code matches the expected response code, and maintain serial data communication between the first communication interface and the integrated microcontroller and wireless communication module; If the response code is found to be inconsistent with the expected response code, the serial data communication between the first communication interface and the integrated microcontroller and wireless communication module is disconnected.
[0022] Implementing the modular toy system and its authentication control method provided by this invention has the following beneficial effects: This invention achieves "plug-and-play" functionality through a unified connector interface and serial bus protocol. Consumers can enjoy completely different toy experiences on the same base platform, transforming from remote-controlled cars to spray cars, bubble cars, water bullet cars, etc., greatly extending the product lifecycle and enabling flexible functional expansion. This invention utilizes standardized connectors and mature serial bus protocols that are widely used and have extremely low cost in the consumer electronics field. It eliminates the need for customized dedicated connectors or communication chips, significantly reducing the hardware cost of modular toys and making them commercially viable for large-scale adoption, thereby reducing system costs. This invention, through the standardized connector's foolproof design, durable plugging and unplugging characteristics, and ease of use, perfectly meets the usage scenarios of child users. The male and female connector configuration can be optimized according to product needs to improve child-friendliness. This invention employs a dual-power supply design via lithium battery output. One path directly provides a higher voltage to the functional modules to meet the demands of high-power devices such as motors, while the other path, after voltage regulation, provides a stable 3.3V operating voltage to the MCU and wireless communication module. The functional modules can also incorporate their own voltage regulation circuits to flexibly meet the voltage requirements of different chips, thus improving the rationality of the power supply architecture. This invention isolates the serial buses of each module from each other through an I2C multiplexing / isolation circuit. A communication failure in one module will not affect other modules. The highly reliable bus isolation design significantly improves the stability and reliability of the system.
[0023] This invention employs independent detection pins and polling methods for each interface, achieving simplicity and non-interference. Simultaneously, the interrupt signal line supports either a shared mode (saving MCU I / O resources) or an independent mode (faster response). Utilizing efficient insertion detection and flexible interrupt notification, the system can be flexibly configured according to actual needs, realizing a complete bidirectional communication architecture.
[0024] This invention employs a two-stage driving scheme that uses an NPN transistor to drive a P-MOSFET, ensuring reliable switching and flexible level matching. It can quickly cut off the power supply to unauthorized modules when authentication fails, thus achieving reliable power supply control. This invention employs challenge-response authentication, using a random challenge code for each authentication attempt to effectively prevent replay attacks. The symmetric key and UID are stored in the internal FLASH memory of the base MCU and the module slave chip, respectively, eliminating the need for an external authentication chip and balancing security and cost. An anti-brute-force locking mechanism further enhances system security, achieving a highly secure authentication mechanism. This invention implements key authentication through a serial bus and independently controls the power supply of the module based on the authentication result, forming a complete genuine accessory authentication mechanism. Unauthorized modules will be immediately powered off after being inserted, effectively preventing the use of third-party compatible modules, protecting the "selling platform + selling accessories" business model, and achieving effective commercial protection. This invention enables flexible upgrades to wireless communication methods through the independent design of the first communication interface; the authentication mechanism of the second communication interface ensures the controllability of functional components; the existence of multiple alternatives (multiple serial ports, multiple bus isolation methods, multiple connector specifications, and multiple power supply control schemes) gives the platform a high degree of flexibility and adaptability at all technical levels, achieving a platform architecture that balances openness and closedness. Attached Figure Description
[0025] The present invention will be further described below with reference to the accompanying drawings and embodiments. In the accompanying drawings: Figure 1 This is a block diagram of the base main control board architecture provided by the present invention; Figure 2 This is a block diagram of the base main control board circuit provided by the present invention; Figure 3 This is a schematic diagram of a single interface pin connection provided by the present invention; Figure 4 This is a schematic diagram of the pin connections of the first communication interface provided by the present invention; Figure 5 This is a circuit block diagram of the functional expansion module provided by the present invention (taking the motor drive module as an example). Figure 6 This is a block diagram of the power supply and power-off circuit principle of the submodule provided by the present invention (9014+AO3401 scheme). Figure 7 This is a schematic diagram of the combined state of each module plugged into the base (toy car application scenario). Figure 8 This is a flowchart of the authentication control method provided by the present invention. Detailed Implementation
[0026] To provide a clearer understanding of the technical features, objectives, and effects of the present invention, specific embodiments of the present invention will now be described in detail with reference to the accompanying drawings.
[0027] Example 1: Figure 1 A schematic diagram of the modular toy system of this embodiment is shown. In this embodiment, the modular toy system includes: Motherboard, integrated microcontroller, power management unit, first communication interface and at least one second communication interface; The motherboard is used to electrically connect the integrated microcontroller, power management unit, first communication interface and second communication interface; The integrated microcontroller is used to control the wireless communication module through the motherboard and the first communication interface, and to control the functional expansion module through the motherboard and the second communication interface; The power management unit is used for battery charging and discharging management; The first communication interface is connected to a wireless communication module, which is used to receive external control commands. The second communication interface is used to detachably connect a function expansion module, which includes functional circuitry.
[0028] Specifically, the system also includes a power supply control circuit and a voltage regulator circuit. The power supply control circuit is electrically connected to the battery and the second communication interface to control the power supply to the function expansion module. The voltage regulator circuit is electrically connected to the battery and the first communication interface to reduce the battery voltage and then provide power to the integrated microcontroller and the first communication interface.
[0029] Specifically, the system further includes a multiplexing / isolation circuit, which is electrically connected to the integrated microcontroller and the second communication interface for communication and authentication control between the integrated microcontroller and the functional expansion modules, and for isolating different functional expansion modules.
[0030] Specifically, the system further includes an insertion detection circuit, which is electrically connected to the integrated microcontroller and the second communication interface, and is pulled up to a high level by a pull-up resistor.
[0031] Specifically, the insertion detection circuit is configured to: confirm that the function expansion module pulls the insertion detection circuit down to a low level to determine that a function expansion module has been inserted; and confirm that the insertion detection circuit returns to a high level to determine that the function expansion module has been removed.
[0032] Specifically, it also includes an interrupt notification circuit, which is electrically connected to the integrated microcontroller and the second communication interface for transmitting an interrupt signal.
[0033] Specifically, the first communication interface is also used to detachably connect the wireless communication module and provide a power channel for the wireless communication module. The integrated microcontroller and the wireless communication module perform serial data communication and authentication control through the first communication interface.
[0034] Specifically, the first and second communication interfaces use Type-C connectors, FPC sockets, or pin headers.
[0035] Specifically, the functional expansion module includes at least one of the following functional circuits: motor drive, recording playback, atomization generation, bubble generation, and water bullet launch; the functional expansion module is provided with a physical connector that matches the second communication interface.
[0036] Specifically, the wireless communication module is a 2.4G RF circuit, a Bluetooth module, or a WiFi module.
[0037] Example 2: This embodiment provides an authentication control method, including: The confirmation function expansion module pulls the insertion detection circuit down to a low level to determine that a function expansion module has been inserted. The power supply control circuit is used to connect the battery and the second communication interface to provide power to the functional expansion module. A random challenge code is generated using the base and sent to the function extension module through the second communication interface; specifically, a random challenge code is generated based on the symmetric key and sent to the function extension module through the second communication interface. The functional extension module generates a response code using an encryption algorithm based on the symmetric key, the module's unique identifier, and the random challenge code; Based on the symmetric key, the module's unique identifier, and the random challenge code, the integrated microcontroller generates the expected response code using an encryption algorithm. Once the response code is confirmed to match the expected response code, the power supply control circuit and the second communication interface are used to maintain the power supply and serial data communication of the functional expansion module. If the response code is found to be inconsistent with the expected response code, the power supply control circuit is used to disconnect the battery and the second communication interface, cutting off the power supply and serial data communication of the function expansion module.
[0038] Specifically, authentication control methods also include: The wireless communication module pulls the insertion detection circuit down to a low level to confirm that a wireless communication module has been inserted. A random challenge code is generated using the base and sent to the wireless module through the first communication interface; Specifically, a random challenge code is generated based on the symmetric key and sent to the wireless communication module through the first communication interface; The wireless communication module generates a response code using an encryption algorithm based on the symmetric key, the module's unique identifier, and the random challenge code; Based on the symmetric key, the module's unique identifier, and the random challenge code, the integrated microcontroller generates the expected response code using an encryption algorithm. Confirm that the response code matches the expected response code, and maintain serial data communication between the first communication interface and the integrated microcontroller and wireless communication module; If the response code is found to be inconsistent with the expected response code, the serial data communication between the first communication interface and the integrated microcontroller and wireless communication module is disconnected.
[0039] Specifically, authentication control methods also include: Interrupt handling: During normal module operation, if the MCU detects that the common interrupt signal line is pulled low, it polls all in-situ I2C Slaves and reads data from each module.
[0040] Unplug detection: When the MCU detects that a detection pin of a certain interface has returned to a high level during polling, it determines that the module has been unplugged. The MCU sets the corresponding GPIO to a low level, shuts off the power supply, releases the I2C address resources of that interface, and updates the list of modules in place.
[0041] Example 3: (I) Core Inventive Concept This embodiment uses a standardized physical interface as the communication carrier of the serial bus protocol, and is supplemented by a bus-based challenge-response authentication mechanism to achieve plug-and-play functionality, automatic identification, and genuine protection of functional modules.
[0042] In conventional electronic design thinking, standardized interfaces such as Type-C are typically used for high-speed data transmission or fast charging. This embodiment overcomes this technical bias by utilizing its stable, pluggable, foolproof physical structure and basic power supply capabilities to carry low-speed, low-cost serial bus signals that support multi-device addressing on specific pins. This seemingly inefficient use of resources effectively solves the pain points in the toy industry, such as loose interfaces, difficulty for children to plug and unplug, and the inability of motherboards to recognize different modules.
[0043] Meanwhile, this embodiment inserts a hardware pin level change detection module, and then performs key authentication via a serial bus. After successful authentication, the module is continuously powered, thus achieving effective interception of unauthorized accessories in the absence of a dedicated authentication chip.
[0044] Furthermore, this embodiment extends the authentication mechanism to the wireless communication module connected to the first communication interface. When the wireless communication module is inserted into the base, the base performs the same challenge-response authentication on the module via the UART protocol. If authentication succeeds, power is maintained and wireless communication is established; if authentication fails, the base does not establish normal communication with the module and may optionally output a prompt message. Thus, all pluggable modules on the base platform (whether functional or communication modules) are protected by a unified authentication mechanism, achieving complete closed-loop management of platform components.
[0045] (II) Overall Technical Solution like Figure 1 As shown, the MCU extends the I2C bus to multiple connector interfaces through an I2C multiplexing / isolation circuit (such as CA9546Y). The lithium battery output is divided into two paths: the first path directly supplies power to the VCC of each interface through the power supply control circuit; the second path, after being regulated to 3.3V by an SGM-2019-3.3, supplies power to the MCU and the wireless communication module. The detection pins of each connector are independently connected to the MCU's I / O port, and the module insertion is detected by polling. The interrupt signals of all modules share a single interrupt line connected to a single I / O port of the MCU. The VCC power supply of each interface is independently controlled by the MCU's GPIO.
[0046] In this embodiment, the modular toy system includes: Base (motherboard): integrates a microcontroller (MCU), a power management unit, a first communication interface, and at least one second communication interface.
[0047] The first communication interface is used for detachable connection of a wireless communication module. The wireless communication module can be a 2.4G RF module, Bluetooth module, WiFi module, etc., and is responsible for receiving external control commands. This interface uses a Type-C connector and carries the UART serial communication protocol through specific pins to establish serial data communication with the wireless communication module. Simultaneously, this interface provides power to the wireless communication module. In other embodiments, this interface can also use an FPC socket, pin header, or other detachable connection methods. This first communication interface also supports authentication of the inserted wireless communication module, and its authentication mechanism is the same as the authentication mechanism of the second communication interface for functional expansion modules.
[0048] The second communication interface includes a physical connector. The base has a first connector, and the functional expansion module has a second connector; the first and second connectors are mating, pluggable connector pairs. In the current embodiment, the base uses a Type-C male connector, and the functional module uses a Type-C female connector. The microcontroller provides a serial bus (currently implemented as an I2C bus) through specific pins of the physical connector. This second communication interface simultaneously carries communication and power supply functions. Multiple second communication interfaces on the base are connected to the MCU's I2C bus via I2C multiplexing / isolation circuitry to prevent a single module's I2C bus failure from affecting the normal communication of other modules.
[0049] Functional expansion modules: These include various functional circuits (such as motor drive, recording playback, atomization, bubble generation, water bullet launch, etc.). Each module has a second connector that mates with the first connector on the base end, allowing for pluggable connection to the base and communication with it via the serial bus. The module end features a limiting design in its housing structure, ensuring that the connector is only inserted into the base in the correct orientation.
[0050] Insertion detection mechanism: The base pulls a specific detection pin of the physical connector high and connects it to the MCU's I / O port; the function expansion module pulls the corresponding pin low. The MCU periodically reads the level status of each I / O port through polling. When the detection pin changes from high to low, it determines that a module has been inserted; when the detection pin returns to high, it determines that the module has been removed. The detection pin of each connector interface is independently connected to a different I / O port of the MCU, enabling independent detection for each interface.
[0051] Authentication and Power Supply Control: The base is configured to supply power to the interface when a functional expansion module is detected to be connected. After the module is powered on, the MCU performs challenge-response authentication on the module via the serial bus. The base and the functional expansion module pre-store the same symmetric key. During authentication, the base generates a random challenge code and sends it to the module; the module generates a response code based on the symmetric key, the module's unique identifier, and the random challenge code using a preset algorithm and returns it; the base independently calculates the response code in the same way and compares it with the response code returned by the module. If the comparison matches, authentication is successful, power supply continues, and the corresponding control protocol is loaded; if authentication fails, power supply to the module is cut off.
[0052] like Figure 2 As shown, the MCU manages each connector interface through the following GPIOs: I / O detection submodule insertion / removal (each interface independent): polling reads used to detect module insertion / removal. I / O submodule shared interrupt line (all modules share one): interrupt mode, used to receive active data reporting notifications from the modules. I / O control submodule power supply (each interface independent): output mode, power supply on / off controlled by a 9014+AO3401 circuit. The power management unit divides the lithium battery output into two paths: the first path directly supplies power to each interface (via the power supply control circuit), and the second path is regulated to 3.3V by an SGM-2019-3.3 to power the MCU and wireless communication module.
[0053] like Figure 3 The diagram illustrates the core electrical connections of the connector pair. Serial bus signals (such as I2C's SDA / SCL) can reuse the Type-C D+, D- pins or SBU pins; insertion detection uses a separate pin (pull-up to VCC on the base side, connected to GND on the module side); interrupt notification signals are shared by all modules and aggregated to the MCU. VCC power supply is independently controlled by the base MCU's GPIO via a 9014+AO3401 circuit. In other implementations, a female connector can be used on the base side, and a male connector on the functional module side, as long as they form a mutually compatible pluggable connection. The physical connector is not limited to the Type-C specification. (Note: This diagram uses a Type-C interface as an example to illustrate the core electrical connections at the functional level. Other types of physical connectors can also be used in other implementations.) like Figure 4The diagram illustrates the core electrical connections of the connector pair. Serial signals (such as UART's RX / TX) can reuse the Type-C D+, D- pins, or SBU pins, depending on the situation. Currently, there is insertion detection functionality, but no separate power supply control function for this interface has been added. Power supply control functionality can be added as needed. In this embodiment, the base uses a male connector, and the wireless module uses a female connector. In other embodiments, the base can also use a female connector, and the functional module can use a male connector, as long as they form a mutually compatible pluggable connection. The physical connector is not limited to the Type-C specification.
[0054] like Figure 5 As shown: The functional expansion module connects to the base via a second connector. The I2C slave chip inside the module stores key information. The module's detection pin is grounded (pulled low). When inserted into the base, the pull-up detection pin on the base is pulled low and detected by the base's polling. An interrupt signal line is used for the module to actively notify the base to read data (all modules share a single line). A similar voltage regulator circuit (such as SGM-2019-3.3) can be installed inside the module to step down the interface input voltage to the operating voltage required by the chips inside the module. The module's housing structure uses a limiting design to ensure that the connector is inserted into the base only in the correct orientation.
[0055] like Figure 6 The diagram illustrates the power supply control circuit for a single interface in the current implementation. The MCU's GPIO is connected to the base of an NPN transistor (9014) via a current-limiting resistor R_base. When the GPIO outputs a high level, the 9014 is turned on, pulling the gate of the P-MOSFET (AO3401) low, thus turning on the P-MOSFET and powering on the interface VCC (using the lithium battery voltage directly). When the GPIO outputs a low level, the 9014 is turned off, the P-MOSFET gate is pulled up to VCC_SYS by a pull-up resistor, turning off the P-MOSFET and de-powering the interface VCC. By default, the GPIO outputs a low level, and the interface has no power supply. The MCU determines whether to set the GPIO high for continuous power supply based on the authentication result.
[0056] like Figure 7 As shown: The base and functional expansion modules are connected via mating connectors for pluggable connection. In the current implementation, the base uses a male connector and the module uses a female connector. Users can freely replace the functional modules and housing as needed.
[0057] like Figure 8As shown: The system uses a polling method to detect module insertion, with each interface detection pin independently connected to the MCU I / O port. After insertion, power is supplied first, followed by challenge-response authentication. If authentication fails, power is immediately cut off and the number of failures is recorded. After three consecutive failures, a 2-second lockout occurs. All modules share a single line connected to a single MCU I / O port for the interrupt signal. Upon detecting an interrupt, the MCU polls all in-situ slaves to read data.
[0058] (III) Supplementary Explanation of Communication Mechanism I2C Master-Slave Communication and Interrupt Notification Mechanism: In standard I2C communication, the base motherboard acts as the I2C Master, and the functional modules act as I2C Slaves. The Master initiates the communication, and all read and write operations are actively initiated by the Master.
[0059] To address the issue of the Master not being promptly notified when the Slave needs to actively report data (such as sensor data, button events, etc.), this system incorporates an interrupt notification mechanism in addition to the serial bus. In the current implementation, interrupt signals from all functional modules are aggregated through connector interfaces and connected to a single interrupt signal line via a single I / O port of the MCU (configured in interrupt mode). When any functional module needs to report data, it pulls the level low through this shared interrupt line. Upon detecting the interrupt, the MCU polls all modules already plugged into the base and authenticated. Data from each module is then read via the I2C bus. This shared interrupt line design maximizes the conservation of MCU I / O port resources.
[0060] This mechanism enables bidirectional communication between Master and Slave command issuance and Slave and Master active reporting, giving the system complete interactive capabilities.
[0061] UART Communication and Authentication of the First Communication Interface: The first communication interface carries the UART protocol via a Type-C connector. The UART_TX and UART_RX pins of the base MCU are connected to the wireless communication module via specific pins of the Type-C connector (such as SBU or D+, D- pins). When the wireless communication module is inserted and detected by the base, the base first supplies power to the module (this power supply path is either on by default or controlled by an independent MOSFET, but the power supply will not be cut off after authentication failure to ensure basic module operation). Subsequently, the base MCU initiates a challenge-response authentication to the module via the UART protocol, the process of which is the same as the authentication process of the functional modules. If authentication is successful, the base establishes a normal communication channel with the wireless module, receives remote control commands, and forwards them to other functional modules. If authentication fails, the base may ignore the module's communication request or only allow it to send non-control information (such as prompting the user that the module is not authorized).
[0062] This design ensures that the first communication interface is consistent with the second communication interface in terms of physical form, communication protocol, and authentication logic. The entire platform uses only one standard interface (Type-C) to achieve unified connection and authentication of all modules, which greatly improves the user experience and completes the accessory protection of the communication module.
[0063] (iv) Detailed explanation of the challenge-response authentication mechanism The I2C Master and the I2C Slave use a challenge-response authentication mechanism based on symmetric keys, and the specific process is as follows: The MCU generates a 4-byte random challenge code R and sends it to the module via the I2C bus. The sending format is: START + SLAVE_ADDR(W) + 0xEF + R[0..3] + STOP, where 0xEF is the challenge-response authentication command code.
[0064] After receiving the command, the module reads its own unique identifier (UID, 12 bytes), and based on the pre-stored symmetric key Key, uses a preset algorithm to perform a hash calculation on the combination of UID and random challenge code R to generate a 4-byte response code Resp = SipHash(Key, UID || R)[0..3].
[0065] The module returns the UID (12 bytes) and the response code Resp (4 bytes) to the MCU via the I2C bus. The return format is: START + SLAVE_ADDR(R) + UID[0..11] + Resp[0..3] + STOP.
[0066] The MCU independently calculates the expected response code Expected = SipHash(Key, UID || R)[0..3] based on the same symmetric key Key and algorithm, and compares it with the Resp returned by the module. If Expected == Resp, authentication is successful; otherwise, authentication fails.
[0067] If authentication fails, the MCU records the number of failures. In the current implementation, after three consecutive authentication failures, the base locks the module for 2 seconds, during which time it refuses to initiate authentication requests again to prevent brute-force attacks.
[0068] Key and identifier storage instructions: The base and the functional expansion module pre-store the same symmetric key, which is burned into their respective non-volatile memories at the factory. In the current implementation, the symmetric key on the base side is stored in the internal FLASH memory of the base MCU; the symmetric key and unique identifier (UID) on the functional expansion module side are both stored in the internal FLASH memory of the module's I2C slave chip. In other implementations, an internal EEPROM of the MCU, an external EEPROM chip, an external FLASH chip, an OTP memory, or other non-volatile storage media can also be used.
[0069] In the current implementation, the base MCU uses the PY32F002B, and the I2C slave chip for the functional module uses either the STC8H1K17 or the PY32F002B. The hash algorithm used for challenge-response authentication is SipHash-2-4 to accommodate the computing capabilities of both MCUs.
[0070] Example 4: In this embodiment, the modular toy system includes: 1. Base (motherboard) The base motherboard integrates the following core circuits: Microcontroller (MCU): As the control core of the entire system, it runs the serial bus communication protocol, key authentication logic, and control protocols for each module.
[0071] Power Management Unit: Integrated lithium battery charge and discharge management circuit.
[0072] The lithium battery output voltage is divided into two paths: the first path directly supplies power to the VCC pin of each Type-C interface through the power supply control circuit (9014+AO3401) of each interface, providing power to the functional expansion module; the second path is stepped down to 3.3V through a voltage regulator circuit (currently using SGM-2019-3.3 LDO chip) to supply power to the MCU on the base and the wireless communication module connected through the first communication interface.
[0073] The first communication interface is used for detachable connection of the wireless communication module. In the current implementation, the base uses a Type-C male connector, and the wireless communication module uses a Type-C female connector. The base MCU's UART_TX and UART_RX communicate with the wireless communication module through specific pins of the Type-C connector (such as SBU1 / SBU2 or D+ / D-) to achieve serial data communication. This interface also includes a detection pin (pull-up to VCC, pull-down on the module side) for the base to poll and detect the insertion and removal of the wireless module. For power supply, the VCC of this interface is directly provided by the power management unit (or through a normally-on MOSFET) to ensure the module is powered on. When the insertion of the wireless module is detected, the base initiates a challenge-response authentication via the UART.
[0074] In other implementations, the interface may also use an FPC socket as the physical connector, but its communication protocol and authentication logic remain unchanged.
[0075] The current demo uses an external 2.4G RF module, which can be replaced with a Bluetooth or WiFi module in the future. All modules interact with the MCU through the same communication protocol.
[0076] Second communication interface (expansion interface): Multiple first connectors are led out from the base (the current demo has 4 Type-C male connectors, expandable to more). The MCU's I2C bus is first connected to an I2C multiplexing / isolation circuit (currently using a CA9546Y multiplexer), and then connected to each connector after multiplexing / isolation. Specific pins of each connector are multiplexed as the SDA (data line) and SCL (clock line) signals of the I2C bus. The I2C signals of each interface are isolated from each other through the multiplexing / isolation circuit, ensuring that an I2C bus failure in a single module (such as a short circuit in SDA / SCL) will not affect the communication of other normal modules.
[0077] Insertion detection circuit: The base connects a specific detection pin of the connector to a high level via a pull-up resistor and links it to an I / O port of the MCU. Each interface's detection pin is independently connected to a different I / O port of the MCU. In its main loop, the MCU periodically reads the level status of each I / O port using a polling method. When a pin changes from high to low, it determines that a module has been inserted; when it changes from low to high, it determines that the module has been removed.
[0078] Interrupt Notification Circuit: In addition to the serial bus, the system also has an interrupt signal line. In the current implementation, interrupt signals from all functional modules are aggregated through the connector interface and connected to a single I / O port of the MCU (configured in interrupt mode) via a shared interrupt signal line. When any functional module has data to actively report, it pulls the level low through this shared interrupt line. After detecting the interrupt, the MCU polls the I2C slaves of all in-place modules and reads the data from each module. This shared interrupt line design maximizes the conservation of MCU I / O port resources.
[0079] Power Supply Control Circuit: The VCC power supply path for each connector interface is controlled by a switching circuit controlled by an independent GPIO from the MCU. In the current implementation, this switching circuit uses a two-stage driving scheme where an NPN transistor (9014) drives a P-MOSFET (AO3401). The MCU's GPIO is connected to the base of the 9014 via a current-limiting resistor. The collector of the 9014 is connected to the system power supply via a pull-up resistor and then to the gate of the AO3401. When the GPIO outputs a high level, the 9014 is turned on, pulling the gate of the AO3401 low, turning on the AO3401 and powering on the interface VCC (directly using the lithium battery voltage). When the GPIO outputs a low level, the 9014 is turned off, the gate of the AO3401 is pulled high by the pull-up resistor, turning off the AO3401 and de-energizing the interface VCC. By default, the GPIO outputs a low level, and the interface has no power supply. The MCU determines whether to set the GPIO high for continuous power supply based on the authentication result.
[0080] 2. Functional Expansion Module Each expansion module is equipped with a second connector (currently implemented as a Type-C female connector) that matches the first connector on the base, and integrates an I2C slave chip (or functional MCU). The chip stores authentication key information. The module grounds (pulls low) the connector's detection pin. The module's interrupt signal line is connected to an I / O port of the I2C slave chip to actively notify the base to read data. After receiving power through the interface, the expansion module can have a similar voltage regulator circuit (such as the SGM-2019-3.3 LDO chip) internally to step down the input voltage to the operating voltage required by the internal chips. The module's housing structure uses a limiting design to ensure the connector is inserted into the base only in the correct orientation, preventing connection problems caused by reverse insertion.
[0081] The currently implemented functional extension modules include: Motor drive module: Onboard motor driver chip, addressed by the motherboard via I2C address. Supports connection of 2 or 4 DC motors. The motherboard controls the motor's direction and speed via I2C commands.
[0082] Recording, playback, and lighting module: Features an onboard voice chip and LED driver, pre-recorded fixed audio, and supports real-time recording. The motherboard uses I2C commands to invoke playback, recording, and lighting actions.
[0083] Atomization Simulation Module: Onboard atomizing plate driving circuit generates fog through I2C instructions to simulate special effects such as car exhaust.
[0084] Other planned functional expansion modules include, but are not limited to: bubble generation module, water bullet launching module, AI camera module, sensor module, etc.
[0085] 3. Work Process (1) Initialization: After the base is powered on, the MCU initializes the I2C bus and configures each GPIO (the detection pin is set to input pull-up, the interrupt pin is set to input interrupt mode, and the power supply control pin is set to output low level to turn off the power supply).
[0086] (2) Polling detection: The MCU periodically reads the detection pin level corresponding to each connector interface in the main loop. When a detection pin changes from high to low, the MCU determines that a functional expansion module has been inserted into that interface.
[0087] (3) Power supply: The MCU sets the corresponding power supply control GPIO to high level, drives AO3401 to conduct through 9014, and supplies power to the VCC of the interface (directly providing lithium battery voltage).
[0088] (4) Challenge-Response Authentication: After the module is powered on and initialized, the MCU initiates a challenge-response authentication process to the module via the I2C bus. In the current implementation, the specific authentication steps are as follows: The MCU generates a 4-byte random challenge code R and sends it to the module via the I2C bus with command code 0xEF. The module reads its own 12-byte unique identifier (UID), and based on the pre-stored symmetric key, uses the SipHash-2-4 algorithm to perform hash calculation on the combination of UID and R to generate a 4-byte response code Resp; The module returns 16 bytes of data, including the UID (12 bytes) and Resp (4 bytes), to the MCU via the I2C bus; The MCU independently calculates the expected response code (Expected) based on the same symmetric key and SipHash-2-4 algorithm, and compares it with the Resp returned by the module. If they match, authentication passes; otherwise, authentication fails.
[0089] (5) Power supply control: (5.1) For the functional expansion module connected to the second communication interface: Authentication successful: The MCU maintains a high level on the GPIO pin and continues to supply power. Then, the control protocol corresponding to this module is loaded, and the module enters normal operating mode.
[0090] Authentication failed: The MCU sets the GPIO to low level, shuts down the AO3401, and cuts off the power supply. Unauthorized modules cannot work.
[0091] (5.2) For the wireless communication module connected to the first communication interface: For the wireless communication module connected to the first communication interface, the MCU maintains power supply after detecting insertion and performs challenge-response authentication via the UART protocol. If authentication succeeds, communication is established and remote control data is received; if it fails, the module is marked as unauthorized, and communication is not established with it, but power supply is still maintained (allowing the module to indicate an error status). (6) Interrupt handling: During normal operation of the module, if the MCU detects that the common interrupt signal line is pulled low, it will poll all the I2C Slave of the in-situ modules and read data from each module.
[0092] (7) Unplug detection: When the MCU detects that the detection pin of a certain interface has returned to a high level during polling, it determines that the module has been unplugged. The MCU sets the corresponding GPIO to a low level, shuts off the power supply, releases the I2C address resources of the interface, and updates the list of modules in place.
[0093] It should be noted that the communication protocol can be replaced with a serial bus carried on the connector, not limited to the I2C protocol, and can also be replaced with other serial bus protocols such as SPI, CAN, single-wire serial port, etc.
[0094] It should be noted that the multi-serial-port architecture can be replaced by multiple independent serial communication interfaces. The microcontroller connects to multiple expansion interfaces through these independent serial communication interfaces, and each functional expansion module communicates point-to-point with the microcontroller through its respective serial communication interface. This alternative solution also enables plug-and-play functionality and authentication-based power control for the modules.
[0095] It should be noted that bus isolation can be implemented in various ways: the serial bus can achieve bus isolation between interfaces through an I2C multiplexer (such as CA9546Y), an I2C buffer, an I2C switch chip, or an isolation circuit built with discrete components. The interrupt signal line is connected independently of the bus isolation circuit.
[0096] It should be noted that the physical interface can be replaced with: the connector pair between the base and the module is not limited to Type-C; other types of pluggable physical connectors can be used, as long as they can carry the aforementioned serial bus protocol and provide power supply through specific pins. The male and female socket configurations of the first connector on the base end and the second connector on the module end can also be interchanged, as long as they form a mutually compatible pluggable connection.
[0097] It should be noted that the product form can be replaced with the same base and functional expansion modules, which can be moved as a whole into different shells such as toy cars, toy boats, toy airplanes, and toy robots.
[0098] It should be noted that the authentication method can be implemented in various ways: the preset algorithm in the challenge-response authentication is not limited to SipHash-2-4, and can be replaced with other hash algorithms or encryption algorithms. The length of the random challenge code and the length of the unique identifier can be adjusted according to security requirements. The authentication mechanism can also adopt other shared key-based authentication methods, such as direct comparison of symmetric keys, asymmetric key signature verification, digital certificate verification, etc.
[0099] It should be noted that the key and identifier storage method can be replaced by: the symmetric key and unique identifier are not limited to being stored in the MCU's internal FLASH, but can also be stored in the MCU's internal EEPROM, external EEPROM chip, external FLASH chip, OTP memory or other non-volatile storage media.
[0100] It should be noted that anti-brute-force attack mechanisms can be implemented in various ways: the locking mechanism is not limited to "locking for 2 seconds after 3 failures". The failure threshold and locking time can be adjusted according to security needs, and other anti-brute-force attack measures can also be adopted.
[0101] It should be noted that the MCU chip can be replaced with: the base MCU is not limited to STC8H1K17, and the function module I2C slave chip is not limited to PY32F002B. They can all be replaced with other microcontrollers with equivalent functions.
[0102] It should be noted that the detection method can be implemented in a variety of ways: module insertion detection is not limited to specific pin level changes, and other pins or mechanical switches, Hall sensors, and other detection methods can also be used.
[0103] It should be noted that interrupt notification methods can be implemented in various ways: the interrupt signal line can be shared by all modules (saving I / O resources), or each functional module can be assigned an independent interrupt signal line, which is connected to different I / O ports of the MCU (for faster response).
[0104] It should be noted that the power supply control method can be implemented in various ways: the power supply control circuit is not limited to the 9014+AO3401 solution, and can also be replaced by a single P-MOSFET, N-MOSFET, power switch chip, load switch, relay or other controllable switching device.
[0105] It should be noted that the power supply architecture can be implemented in various ways: the branching method for power supply to the functional circuits and interface power supply inside the base is not limited to the above scheme, and other voltage regulator chips (such as different models of LDOs or DC-DC converters) or power management schemes can also be used. The step-down scheme inside the functional expansion module can also be flexibly selected.
[0106] It should be noted that the wireless communication module can be connected in various ways: the first communication interface is not limited to the FPC socket, but can also use other detachable connection methods such as Type-C, header and socket, board-to-board connectors, etc.
[0107] It should be noted that the authentication and interface form of the first communication interface can be implemented in various ways: in addition to using a Type-C connector to carry the UART protocol, the first communication interface can also use an FPC or other connectors. Regardless of the physical interface used, its authentication mechanism can be the same as or different from that of the second communication interface; for example, both can use challenge-response authentication. Furthermore, the handling strategy after authentication failure can be flexibly configured, such as cutting off power supply, maintaining power supply but restricting functions, or only allowing error messages to be sent.
[0108] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of the present invention without departing from the spirit and scope of the claims. All of these forms are within the protection scope of the present invention.
Claims
1. A modular toy system, characterized in that, include: Motherboard, integrated microcontroller, power management unit, first communication interface and at least one second communication interface; The motherboard is used to electrically connect the integrated microcontroller, power management unit, first communication interface and second communication interface; The integrated microcontroller is used to control the wireless communication module through the motherboard and the first communication interface, and to control the functional expansion module through the motherboard and the second communication interface; The power management unit is used for battery charging and discharging management; The first communication interface is connected to a wireless communication module, which is used to receive external control commands. The second communication interface is used to detachably connect a function expansion module, which includes functional circuitry.
2. The system according to claim 1, characterized in that, It also includes a power supply control circuit and a voltage regulator circuit. The power supply control circuit is electrically connected to the battery and the second communication interface to control the power supply of the function expansion module. The voltage regulator circuit is electrically connected to the battery and the first communication interface to reduce the battery voltage and then provide power to the integrated microcontroller and the first communication interface.
3. The system according to claim 1, characterized in that, It also includes a multiplexing / isolation circuit, which is electrically connected to the integrated microcontroller and the second communication interface for communication and authentication control between the integrated microcontroller and the functional expansion module, and for isolating different functional expansion modules.
4. The system according to claim 1, characterized in that, It also includes an insertion detection circuit, which is electrically connected to the integrated microcontroller and the second communication interface. The insertion detection circuit is pulled up to a high level by a pull-up resistor. The insertion detection circuit is configured to: confirm that the function expansion module pulls the insertion detection circuit down to a low level to determine that a function expansion module has been inserted; and confirm that the insertion detection circuit returns to a high level to determine that the function expansion module has been removed.
5. The system according to claim 1, characterized in that, It also includes an interrupt notification circuit, which is electrically connected to the integrated microcontroller and the second communication interface for transmitting an interrupt signal.
6. The system according to claim 1, characterized in that, The first communication interface is also used to detachably connect the wireless communication module and provide a power channel for the wireless communication module. The integrated microcontroller and the wireless communication module perform serial data communication and authentication control through the first communication interface.
7. The system according to claim 1, characterized in that, The first and second communication interfaces use Type-C connectors, FPC sockets, or pin headers.
8. The system according to claim 1, characterized in that, The functional expansion module includes at least one of the following functional circuits: motor drive, recording playback, atomization generation, bubble generation, and water bullet launch; the functional expansion module is provided with a physical connector that matches the second communication interface.
9. An authentication control method for a modular toy system as described in any one of claims 1-8, characterized in that, include: The confirmation function expansion module pulls the insertion detection circuit down to a low level to determine that a function expansion module has been inserted. The power supply control circuit is used to connect the battery and the second communication interface to provide power to the functional expansion module. A random challenge code is generated using the base and sent to the functional extension module via the second communication interface; The functional extension module uses the symmetric key, the module's unique identifier, and the random challenge code to generate a response code using an encryption algorithm; Based on the symmetric key, the module's unique identifier, and the random challenge code, the integrated microcontroller generates the expected response code using an encryption algorithm. Once the response code is confirmed to match the expected response code, the power supply control circuit and the second communication interface are used to maintain the power supply and serial data communication of the functional expansion module. If the response code is found to be inconsistent with the expected response code, the power supply control circuit is used to disconnect the battery and the second communication interface, cutting off the power supply and serial data communication of the function expansion module.
10. The method according to claim 9, characterized in that, The authentication control method further includes: The wireless communication module pulls the insertion detection circuit down to a low level to confirm that a wireless communication module has been inserted. A random challenge code is generated using the base and sent to the wireless module through the first communication interface; The wireless communication module uses the symmetric key, the module's unique identifier, and the random challenge code to generate a response code using an encryption algorithm. Based on the symmetric key, the module's unique identifier, and the random challenge code, the integrated microcontroller generates the expected response code using an encryption algorithm. Confirm that the response code matches the expected response code, and maintain serial data communication between the first communication interface and the integrated microcontroller and wireless communication module; If the response code is found to be inconsistent with the expected response code, the serial data communication between the first communication interface and the integrated microcontroller and wireless communication module is disconnected.