Method and system for providing management services
Through the first and second access control platform systems, the high cost problem of access control system management for small and medium-sized companies has been solved, more affordable management services have been achieved, and dependence on on-site security personnel has been reduced.
Patent Information
- Application Number
- CN202110385935.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-04-29
- Filing Date
- 2021-04-09
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2041-04-09
AI Technical Summary
Small and medium-sized companies face high costs and management complexity when managing their access control systems. Existing access control platforms with limited management capabilities are expensive and require on-site security personnel to manage.
A system including a first access control platform and a second access control platform is adopted. The first platform receives hardware events, access requests and management requests at a gateway, and the second platform operates in a cloud computing network or a local server to process and update data in a license database and a hardware event database, thereby providing more affordable management services.
This system enables access control systems in multiple locations to be managed by a central security team, reducing the need for on-site security personnel and lowering management costs. It is suitable for small and medium-sized companies.
Smart Images

Figure CN113572723B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This application claims the benefit of U.S. Provisional Application No. 63 / 007,680, filed April 9, 2020, and U.S. Provisional Application No. 63 / 017,052, filed April 29, 2020, the contents of which are hereby incorporated in their entirety. Background Art
[0003] Access control systems prevent unauthorized individuals from accessing protected areas. In order to gain access to a protected area, authorized access credentials must be presented to an access control device (e.g. a card reader).
[0004] Authorized credentials can be presented to the access control device using a variety of known technologies (e.g., RFID cards, fobs, or mobile devices). The decision to grant access (e.g., by opening a door) is typically nearly instantaneous. This decision is typically calculated at the controller by checking a permissions database to determine if a permission exists that is linked to the requester's access credentials. If a permission is linked to the credentials, the access control system unlocks the door as requested, granting access to the requester.
[0005] In standard access control platforms, a permissions database is maintained at a central server (e.g., which can be on-site or cloud-based), and relevant portions of the permissions database are downloaded to the individual controllers that control the locks at the doors. Maintaining the correct permissions list for each cardholder is an administrative process that can be complex, time-consuming, and error-prone. To manage such systems, on-site security personnel are typically employed. These on-site security personnel typically both manage the permissions database and provide monitoring services (e.g., viewing live video streams from on-site cameras). However, as a company grows, a single location with one team of security personnel quickly becomes multiple locations, each with its own team of security personnel managing their own access control system. As can be expected, this can be costly for companies to manage their access control systems.
[0006] To ease the administrative burden, managed access control platforms have been developed. These platforms are typically managed by a third party (e.g., a company specializing in managed access control systems). These platforms offer a range of services (e.g., video management, identity management, visitor access, surveillance, etc.) and can be fully customized to meet a company's needs. However, installing a managed access control platform can be very expensive (e.g., requiring robust on-site equipment), and while the platform may offer impressive services, it may not currently be affordable for small and medium-sized companies. Consequently, small and medium-sized companies typically use limited access control platforms that require on-site security personnel for management.
[0007] Therefore, there remains a need for a system that provides management services at a more affordable cost so that small and medium-sized companies can avoid or at least mitigate the high costs typically associated with managing their access control systems. Summary of the Invention
[0008] According to one embodiment, a system for providing management services is provided. The system includes: a first access control platform and a second access control platform. The first access control platform is configured to receive at least one of a hardware event, an access request event, and a management request event from at least one gateway. The first access control platform includes at least one of a licensing database, a hardware event database, and a management database. The hardware event database is configured to store at least one hardware event. The licensing database is configured to store at least one authorized access credential. The management database is configured to store at least one management request event. The second access control platform is configured to receive at least one hardware event from the hardware event database and / or receive a management request event from the management database.
[0009] According to additional or alternative embodiments, the first access control platform is operable in a cloud computing network, and the second access control platform is operable in at least one of a cloud computing network and a local server system.
[0010] According to an additional or alternative embodiment, the gateway is configured at the premises.
[0011] According to an additional or alternative embodiment, the second access control platform is configured to process at least one hardware event.
[0012] According to an additional or alternative embodiment, the access request event includes access credentials.
[0013] According to an additional or alternative embodiment, the first access control platform is configured to compare the access credentials with the authorized access credentials in the permissions database.
[0014] According to an additional or alternative embodiment, the management request event comprises a request to add / remove at least one authorized access credential to / from the permissions database.
[0015] According to an additional or alternative embodiment, the second access control platform is configured to add / remove at least one access credential to / from the permission database.
[0016] According to an additional or alternative embodiment, the management request event comprises a request to add / remove at least one security device to / from the hardware event database.
[0017] According to an additional or alternative embodiment, the second access control platform is configured to add / remove at least one security device to / from the hardware event database.
[0018] According to another aspect of the present disclosure, a method for providing a management service is provided. The method includes the steps of subscribing a first location and a second location to a first access control platform. The first location includes a first gateway. The second location includes a second gateway. The method includes the steps of subscribing a service provider to a second access control platform. The method includes the steps of transmitting at least one hardware event from at least one of the first gateway and the second gateway to the first access control platform. The first access control platform includes a hardware event database configured to store at least one hardware event. The method includes the steps of transmitting at least one hardware event from the first access control platform to the second access control platform. The second access control platform is configured to process at least one hardware event.
[0019] According to an additional or alternative embodiment, the method further comprises a step for transmitting at least one management request event from at least one of the first gateway and the second gateway to the first access control platform, the first access control platform comprising a management database.
[0020] According to an additional or alternative embodiment, the method further comprises a step for transmitting at least one management request event from the first access control platform to the second access control platform.
[0021] According to an additional or alternative embodiment, the management request event includes a request to add / remove at least one security device to / from the hardware event database, and the second access control platform is configured to add / remove at least one security device to / from the hardware event database.
[0022] According to additional or alternative embodiments, the hardware events for the first location and the second location are independently processed by the second access control platform.
[0023] According to another aspect of the present disclosure, a method for providing a management service is provided. The method includes the steps of subscribing a first location and a second location to a first access control platform. The first location includes a first gateway. The second location includes a second gateway. The method includes the steps of subscribing a service provider to a second access control platform. The method includes the steps of transmitting at least one access request event including an access credential from at least one of the first gateway and the second gateway to the first access control platform. The first access control platform includes a permission database configured to store authorized access credentials. The first access control platform is configured to compare the access credential with the authorized access credential.
[0024] According to an additional or alternative embodiment, the method further comprises a step for transmitting at least one management request event from at least one of the first gateway and the second gateway to the first access control platform, the first access control platform comprising a management database.
[0025] According to an additional or alternative embodiment, the method further comprises a step for transmitting at least one management request event from the first access control platform to the second access control platform.
[0026] According to an additional or alternative embodiment, the management request event comprises a request to add / delete at least one authorized access credential to / from the permission database, and the second access control platform is configured to add / delete at least one authorized access credential to / from the permission database.
[0027] According to an additional or alternative embodiment, the authorized access credentials for the first location and the second location are independently updated by the second access control platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The subject matter which is regarded as the disclosure is particularly pointed out at the conclusion of the specification and distinctly claimed in the claims. The following description of the drawings should not be considered limiting in any way. Referring to the drawings, similar elements are numbered the same:
[0029] Figure 1 is a schematic illustration of a system for providing management services according to one aspect of the present disclosure, the system having a first access control platform and a second access control platform.
[0030] Figure 2 is a flowchart illustrating a first embodiment of a method for providing a management service according to one aspect of the present disclosure.
[0031] Figure 3 is a flowchart illustrating a second embodiment of a method for providing a management service according to one aspect of the present disclosure. DETAILED DESCRIPTION
[0032] A system and method for providing management services are provided. The system enables the provision of management services at a more affordable cost so that small and medium-sized companies can avoid or at least mitigate the high costs typically associated with managing their access control systems. The system includes a first access control platform and a second access control platform. The first access control platform is configured to receive at least one of a hardware event, an access request event, and a management request event from at least one gateway. The first access control platform includes at least one of a licensing database, a hardware event database, and a management database. The hardware event database is configured to store at least one hardware event. The licensing database is configured to store authorized access credentials. The management database is configured to store at least one management request event. The second access control platform is configured to receive at least one hardware event from the hardware event database and / or a management request event from the management database. The second access control platform can be configured to update the licensing database and / or the hardware event database (e.g., after receiving a management request event from the management database).
[0033] This system enables a single company to use a more affordable access control platform (e.g., the first access control platform) at the company's satellite locations, while employing a more robust access control platform (e.g., the second access control platform) at the company's headquarters. This system enables a company to manage all access control systems at all different locations from a single location (e.g., the headquarters). This system allows a company to have a central team of security personnel manage all locations, rather than employing security personnel at multiple locations.
[0034] Additionally, the system can enable a third-party service provider to offer management services to multiple companies that would otherwise have to manage their own access control systems through existing systems. For example, multiple different companies can utilize an affordable access control platform (e.g., a first access control platform), and a single third-party service provider can manage all of each company's access control systems (e.g., using a second access control platform) from a single location (e.g., at the third-party service provider's office). This can enable these companies to avoid having to manage their own access control systems.
[0035] It is contemplated that the first access control platform may include security devices installed at a local location or building facility, as well as a cloud-based security system supported by a cloud computing network. Security devices may include, but are not limited to, card readers, video cameras, motion detectors, entry lock mechanisms, hardware access panels, voice recognition devices, and various other biometric systems. A gateway, such as a router, may be used to establish one or more signal communications between the cloud computing network and one or more devices located at the local location (e.g., security devices, mobile devices, computing devices, mobile tablets, security cameras, etc.). For example, one or more devices may operate one or more applications capable of exchanging data (e.g., access request event data and / or management request event data) with the cloud computing network (e.g., via the gateway). It is contemplated that devices connected to the first access control platform may have limited control functionality (e.g., lock / unlock specific entrances, global lock / unlock commands, etc.). For example, adding or removing authorized access credentials from the permission database, as well as adding / removing security devices connected to the hardware event database, may only be possible through the second access control platform.
[0036] It is contemplated that the second access control platform may include one or more devices (e.g., computers, tablets, mobile devices). These devices may be installed at a local location or facility (e.g., at the headquarters of a third-party service provider or company) and may be supported by a local server system (e.g., a local server system installed at the local location or facility). However, it is contemplated that the second access control system may be supported by a cloud computing network. For example, in some instances, the devices may be connected to the cloud computing network (e.g., using a gateway).
[0037] Regardless of how the connection is made, the device can be able to provide service functionality to a venue utilizing the first access control platform through its connection to the second access control platform. For example, a device connected to the second access control platform can provide security monitoring functionality (e.g., such as monitoring and recording locations where access is granted and / or denied, motion detection, unauthorized access vulnerabilities, and surveillance video cameras) to a venue utilizing the first access control platform. Additionally, a device connected to the second access control platform can provide management functionality (e.g., such as adding / removing authorized credentials from the first access control platform's permissions database and / or adding / removing security devices to / from its connection to the first access control platform's hardware event database).
[0038] It is contemplated that management functions can be facilitated by transmitting a management request event from a device (e.g., a mobile device, a computing device, or a mobile tablet) connected to a first access control platform. For example, a request to add / remove authorized access credentials and / or security devices can be entered into a mobile application or webpage using the device connected to the first access control platform. This management request event can be stored in a management database, which can transmit the management request event to a second access control platform, where it can be processed (e.g., by security personnel) using the device connected to the second access control platform.
[0039] Referring now to the accompanying drawings, Figure 1 An exemplary system 100 for providing management services is shown in FIG. Figure 1 A first access control platform 110 and a second access control platform 120 are shown. The first access control platform 110 is configured to receive at least one of hardware events (e.g., which may include data from security devices at a given location 130, 140), access request events (e.g., originating from access control devices such as card readers at a given location 130, 140), and management request events (e.g., originating from mobile devices, computing devices, or mobile tablets connected to the first access control platform 110) from at least one gateway 131, 141. It should be appreciated that each location 130, 140 (e.g., of a given company) may include multiple gateways 131, 141. However, for the sake of brevity and simplicity, each location 130, 140 is depicted with only one gateway 131, 141. A gateway 131, 141 can be understood as a piece of networking hardware (e.g., a router) that allows data (e.g., hardware events, access request events, and / or management request events) to flow across a network (e.g., from a given location 130, 140 to the first access control platform 110).
[0040] The first access control platform 110 may include at least one of a permissions database 111, a hardware event database 112, and a management database 113. It should be appreciated that each of the permissions database 111, the hardware event database 112, and the management database 113 may include a computer-readable storage medium (e.g., for storing received data), which may include any of the following: a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), a portable compact disk read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device (e.g., a punch card with instructions recorded thereon or a raised structure in grooves), and any suitable combination thereof. In some instances, multiple databases (e.g., the permissions database 111, the hardware event database 112, and / or the management database 113) may utilize the same computer-readable storage medium. As used herein, a computer-readable storage medium should not be construed as inherently a transient signal, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse traveling through a fiber optic cable), or an electrical signal transmitted through an electrical wire. It is contemplated that the computer-readable storage medium may be off-premises (e.g., located remotely from the premises 130, 140) and accessible via the cloud computing network of the first access control platform 110. This means that, in some instances, the first access control platform 110 may be operable within the cloud computing network.
[0041] Computer-readable storage media may enable storage of hardware events via the hardware event database 112, storage and / or processing of access request events and authorized access credentials in the permissions database 112, and storage of management request events in the management database 113. In some instances, the access request event includes the access credential. In some instances, the first access control platform 110 is configured to compare the received access credential with the authorized access credentials stored in the permissions database 112. In some instances, the second access control platform 120 is configured to manage (e.g., add or delete authorized access credentials) the permissions database 111 and / or manage (e.g., add or delete security devices) the hardware event database 112. For example, an administrator utilizing the second access control platform 120 can delete unused permissions, infrequently used permissions, or reclassify permissions for a given location 130 or 140 from the permissions database 111. Additionally, an administrator utilizing the second access control platform 120 can add or delete security devices to or from the hardware event database 112 (e.g., enable or disable security devices from transmitting hardware events to the hardware event database).
[0042] It is anticipated that dispatching first responders to specific locations 130, 140 may be possible via the second access control platform 120. For example, when monitoring hardware events from locations 130, 140, the received data may indicate a threat that is currently occurring or may soon occur at a given location 130, 140. Accordingly, first responders may be contacted (e.g., via any communication method) and dispatched to the specific location 130, 140. This monitoring and dispatching of first responders may be accomplished without requiring any intervention from personnel at the specific location 130, 140 where the hardware event originated.
[0043] Furthermore, it is contemplated that the provision of management services can be modified based on the specific needs of a site 130, 140. For example, a site 130, 140 may desire off-site security monitoring capabilities (e.g., through a third-party service provider) without off-site management of the permissions database. Alternatively, a site 130, 140 may desire off-site management of the permissions database (e.g., through a third-party service provider) without off-site security monitoring capabilities. It is contemplated that, through the system 100, the specific needs of a given site 130, 140 can be matched without the need for additional services.
[0044] exist Figure 2 An exemplary method 200 for providing management services (e.g., with off-site security monitoring) is shown in FIG. For example, Figure 1The method 200 is performed using the exemplary system 100 shown. The exemplary system 100 includes a first access control platform 110 (e.g., connected to one or more locations 130, 140 via one or more gateways 131, 141) and a second access control platform 120 (e.g., connected to a device 121 operated by a service provider). The method 200 includes a step 210 for subscribing the first location 130 and the second location 140 to the first access control platform 110. The first location 130 includes a first gateway 131, and the second location 140 includes a second gateway 141. The method 200 provides a step 220 for subscribing a service provider (e.g., which can be interpreted as a person located at a company's headquarters or employed by a third party) to the second access control platform 120. The method 200 provides a step 230 for transmitting at least one hardware event from at least one of the first gateway 131 and the second gateway 141 to the first access control platform 110. The method 200 also provides a step 240 for transmitting at least one hardware event from the first access control platform 110 to the second access control platform 120. The second access control platform 120 is configured to process at least one hardware event (e.g., via one or more microprocessors and / or by a person utilizing the second access control platform 120). As described above, processing of the hardware event can be used to determine whether to dispatch a first responder to the first location 130 or the second location 140. In some instances, hardware events for the first location 130 and the second location 140 are processed independently by the second access control platform 120. In some instances, a first responder is dispatched only to the location 130, 140 having a gateway 131, 141 that transmitted the hardware event (e.g., containing data indicating a need for a first responder).
[0045] exist Figure 3 An exemplary method 300 for providing management services (eg, off-site management with a permissions database) is shown in FIG. For example, Figure 1The method 300 is performed using the exemplary system 100 shown in FIG. The exemplary system 100 includes a first access control platform 110 (e.g., connected to one or more locations 130, 140 via one or more gateways 131, 141) and a second access control platform 120 (e.g., connected to a device 121 operated by a service provider). The method 300 includes a step 310 for subscribing the first location 130 and the second location 140 to the first access control platform 110. The first location 130 includes a first gateway 131, and the second location 140 includes a second gateway 141. The method 300 provides a step 320 for subscribing a service provider (e.g., which can be interpreted as a person located at a company's headquarters or employed by a third party) to the second access control platform 120. The method 300 also provides a step 330 for transmitting at least one access request event including access credentials from at least one of the first gateway 131 and the second gateway 141 to the first access control platform 110. The first access control platform 110 is configured to compare the access credentials with authorized access credentials stored in the permissions database 112. The method 300 may provide a step 340 for updating the permissions database 112 via the second access control platform 120 by adding or deleting at least one access credential from the permissions database 112. As described above, such an update to the permissions database 112 may be facilitated by transmitting an administration request event from the administration database 113 of the first access control platform 110 to the second access control platform 120. It is contemplated that the authorization credentials for the first location 130 and the second location 140 may be independently updated by the second access control platform 120.
[0046] In the context of describing the present invention, the use of the terms "a / an", "the" and similar referential terms should be interpreted as covering both the singular and the plural, unless otherwise indicated herein or clearly contradicted by the context. The use of any and all examples or exemplary language (e.g., "such as", "for example", "for example", etc.) provided herein is intended only to better illustrate the present invention and does not limit the scope of the present invention unless otherwise stated. No language in the specification should be construed as indicating any non-claimed element as essential to the practice of the present invention.
[0047] Although the present disclosure has been described with reference to one or more exemplary embodiments, it will be understood by those skilled in the art that various changes may be made and equivalents may be substituted for elements thereof without departing from the scope of the present disclosure. Additionally, many modifications may be made to adapt specific circumstances or materials to the teachings of the present disclosure without departing from the substantive scope of the present disclosure. Therefore, it is intended that the present disclosure is not limited to the specific embodiments disclosed as the best mode intended for carrying out the present disclosure, but rather that the present disclosure will include all embodiments falling within the scope of the claims.
Claims
1. A system for providing management services, the system comprising: a first access control platform, the first access control platform being configured to receive at least one of a hardware event, an access request event, and a management request event from at least one gateway, the first access control platform comprising at least one of a permission database, a hardware event database, and a management database, the hardware event database being configured to store at least one hardware event, the permission database being configured to store at least one authorized access credential, and the management database being configured to store at least one management request event; as well as a second access control platform, the second access control platform being configured to receive at least one hardware event from the hardware event database and / or receive a management request event from the management database; wherein the management request event comprises a request to add or remove at least one authorized access credential to or from the permission database; wherein the second access control platform is configured to add / remove at least one access credential to / from the permission database; The authorized access credentials for the first access control platform and the second access control platform are independently added / removed through the second access control platform.
2. The system for providing management services according to claim 1, wherein: The first access control platform is operable in a cloud computing network, and the second access control platform is operable in at least one of a cloud computing network and a local server system.
3. The system for providing management services according to claim 1, wherein: The gateway is configured at the location.
4. The system for providing management services according to claim 1, wherein: The second access control platform is configured to process at least one hardware event.
5. The system for providing management services according to claim 1, wherein: The access request event includes access credentials.
6. The system for providing management services according to claim 5, wherein: The first access control platform is configured to compare the access credentials with the authorized access credentials in the permissions database.
7. The system for providing management services according to claim 1, wherein: The management request event includes a request to add or remove at least one security device to or from the hardware event database.
8. The system for providing management services according to claim 1, wherein: The second access control platform is configured to add or remove at least one security device to or from the hardware event database.
9. A method for providing a management service, the method comprising: Subscribing a first location and a second location to a first access control platform, wherein the first location includes a first gateway and the second location includes a second gateway; Subscribing the service provider to the second access control platform; transmitting at least one hardware event from at least one of the first gateway and the second gateway to the first access control platform, the first access control platform comprising a hardware event database configured to store the at least one hardware event; as well as transmitting at least one hardware event from the first access control platform to the second access control platform, the second access control platform being configured to process the at least one hardware event; transmitting at least one management request event from at least one of the first gateway and the second gateway to the first access control platform, the first access control platform including a management database; transmitting at least one management request event from the first access control platform to the second access control platform, the management request event comprising a request to add or remove at least one or more authorized access credentials for accessing the first place or the second place to or from the permission database, and the second access control platform being configured to add or remove at least one or more authorized access credentials for accessing the first place or the second place to or from the permission database, and The authorized access credentials for the first place and the second place are independently added / removed through the second access control platform.
10. The method for providing management services according to claim 9, wherein: The management request event includes a request to add or remove at least one security device to or from the hardware event database, and the second access control platform is configured to add or remove at least one security device to or from the hardware event database.
11. The method for providing management services according to claim 9, wherein: The hardware events for the first location and the second location are independently processed by the second access control platform.
12. A method for providing a management service, the method comprising: Subscribing a first location and a second location to a first access control platform, wherein the first location includes a first gateway and the second location includes a second gateway; Subscribing the service provider to the second access control platform; transmitting, from at least one of the first gateway and the second gateway, at least one access request event including access credentials for the first location or the second location to the first access control platform, the first access control platform including a permission database configured to store authorized access credentials for the first location or the second location, the first access control platform configured to compare the access credentials with the authorized access credentials; transmitting at least one management request event from at least one of the first gateway and the second gateway to the first access control platform, the first access control platform including a management database; as well as At least one management request event is transmitted from the first access control platform to the second access control platform, wherein the management request event includes a request to add / delete at least one authorized access credential for the first place or the second place to / from the permission database, and the second access control platform is configured to add / delete at least one authorized access credential for the first place or the second place to / from the permission database, wherein the authorized access credentials for the first place and the second place are independently added / removed by the second access control platform.
Citation Information
Patent Citations
Takeover Processes in Security Network Integrated with Premise Security System
US20090165114A1