An intelligent access permission network system and method, electronic device and medium

The intelligent access control network system uses machine learning and deep learning algorithms to automatically generate and optimize access permissions, solving the problems of low efficiency and poor security in traditional access control management, and achieving efficient, flexible and secure access control management.

CN116416723BActive Publication Date: 2026-02-03SHANGHAI YUNSI SMART INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211626293.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-16
Publication Date
2026-02-03
Estimated Expiration
2042-12-16

AI Technical Summary

Technical Problem

Traditional access control methods are inefficient, cumbersome to operate, prone to lax management, have low security, and are difficult to implement refined access control.

Method used

An intelligent access control network system is adopted, including a permission generation module, a permission calculation module, and an intelligent engine module. It uses machine learning algorithms to generate and detect access permissions, automatically generates and updates permission rules in real time, and optimizes permission settings by combining frequency analysis and deep learning models.

Benefits of technology

It improves the efficiency and security of access control management, achieves refined access control, reduces manual operations, and enhances the system's flexibility and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116416723B_ABST
    Figure CN116416723B_ABST
Patent Text Reader

Abstract

The application discloses an intelligent access permission network system and method, electronic equipment and medium, including permission generation module, permission calculation module, intelligent engine module, the permission generation module can generate permission according to personnel, role, permission and the like, the permission calculation module can obtain the corresponding permission of personnel according to access permission information, and the corresponding permission of personnel is detected;Initialization module can initialize the system parameters, the background verification module can verify the access permission information corresponding to personnel in background, and the scheduling module can monitor and schedule the permission generation module and the permission calculation module.The application automatically generates permission rules and updates the rules in real time, improves the efficiency of access permission management under the condition of meeting the safety.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates primarily to the field of access control management technology, and in particular to an intelligent access control network system, method, electronic device, and medium. Background Technology

[0002] Access control and security management systems are new, modern security management systems that integrate computer-aided automatic identification technology and modern security management measures. They involve numerous new technologies, including electronics, mechanics, optics, computer technology, communication technology, and biotechnology. They are an effective measure for achieving security management at the entrances and exits of important departments.

[0003] Access control management falls under the category of security management. Traditional management methods primarily include two approaches: personnel-based management and rule-based management. Personnel-based management allows for precise settings regarding access permissions to individual users, but it's inefficient. It requires manually designing permissions for each user and each door, involving numerous steps and is cumbersome. Furthermore, it cannot overlook any permissions and tends to be a crude, inefficient approach, failing to achieve precise access control. This method relies on access control administrators, requiring a certain level of expertise and responsiveness, and in practice, it often results in crude management and low security. Summary of the Invention

[0004] The purpose of this application is to provide an intelligent access control network system, method, electronic device, and medium that can improve the efficiency of access control management while satisfying security requirements.

[0005] Firstly, this application provides an intelligent access control network system, comprising: a permission generation module, a permission calculation module, and an intelligent engine module; the permission generation module, the permission calculation module, and the intelligent engine module are interconnected; the permission generation module is used to obtain personnel identity information and generate access control permission information corresponding to the personnel based on machine learning algorithms; the permission calculation module is used to obtain the personnel's permissions for any access control based on the access control permission information, and to detect the personnel's permissions for any access control, obtain the permission detection result, and open the door corresponding to any access control based on the permission detection result; the intelligent engine module includes an initialization module, a background verification module, and a scheduling module; the initialization module is used to initialize and set system parameters, the background verification module is used to perform background verification of the access control permission information corresponding to the personnel, and the scheduling module is used to monitor and schedule the permission generation module and the permission calculation module.

[0006] In this application, the intelligent access control network system includes a permission generation module, a permission calculation module, and an intelligent engine module. The permission generation module can generate permissions according to personnel, roles, and permissions. The permission calculation module can obtain the permissions corresponding to personnel based on access control permission information and check the permissions corresponding to personnel. The initialization module can initialize and set system parameters. The background verification module can perform background verification of the access control permission information corresponding to personnel. The scheduling module can monitor and schedule the permission generation module and the permission calculation module.

[0007] In one implementation of the first aspect, the personnel's identity information includes name, role, position, work location, time, and access control application; the access control permission information includes the access control application time period, behavior type, and confidence level; the behavior type includes allowed entry, prohibited entry, alarm, and allowed entry with alert; the system parameters include access control level and the range of the access control application time period.

[0008] In one implementation of the first aspect, the permission generation module is further used to: obtain the historical access control permission information corresponding to the personnel and the applied access control based on the access control application; when there are several consecutive instances in the historical identity information corresponding to the personnel where the behavior is not allowed to enter but the door is manually opened by a higher-level administrator, the behavior corresponding to the personnel is set to allow entry.

[0009] In this application, historical identity information refers to the access control permission information corresponding to a person at several historical moments. This application can generate access control permission information corresponding to a person using frequency analysis. That is, when there are several consecutive instances in the historical identity information of a person where the behavior is "not allowed" but the door is manually opened by a higher-level administrator, the behavior corresponding to the person is set to "allowed".

[0010] In one implementation of the first aspect, the access control permission information corresponding to the personnel is generated based on a machine learning algorithm, including: inputting the personnel's identity information into a deep learning model, and outputting the personnel's access control permission information through the deep learning model.

[0011] This application employs machine learning algorithms to obtain access control information corresponding to individuals. The application trains its algorithm by labeling existing data to determine whether new data should be granted or denied access.

[0012] In one implementation of the first aspect, before inputting the identity information corresponding to the personnel into the deep learning model and outputting the access control information corresponding to the personnel through the deep learning model, the method further includes: obtaining the identity information of different personnel; labeling the identity information of different personnel to obtain a training set of labeled historical identity information; the labels correspond to the behavior types; and training the deep learning model using the labeled historical identity information training set to obtain the trained deep learning model.

[0013] In one implementation of the first aspect, the access permissions of a person for any access control device are obtained based on the access control permission information, and the person's permissions for any access control device are checked to obtain the permission check result. The door corresponding to any access control device is then opened based on the permission check result. This includes: when it is detected that a person intends to open a door corresponding to any access control device, obtaining the person's access control permission information; when the access control permission information indicates that the person has several access control permissions, extracting a permission-allowed set and a permission-denied set from the several access control permissions; obtaining the confidence level of the permission-allowed set, the number of elements in the permission-allowed set, and the number of elements in the permission-denied set; when the number of elements in the permission-allowed set is greater than the number of elements in the permission-denied set, and the confidence level of the permission-allowed set is greater than the confidence level threshold, setting the person's permission for any access control device to allow entry, and opening the door corresponding to any access control device.

[0014] In this application, an individual can have multiple access control permission settings. From these multiple permission settings, a permission allowed set and a permission denied set can be obtained. The number of elements in the permission allowed set is greater than the number of elements in the permission denied set. Only when the confidence level of the permission allowed set is greater than a certain confidence level threshold can the door be opened effectively.

[0015] The confidence level of a set can be the average value of each element in the set, and the confidence threshold can be the confidence level of the set that grants the permission to deny.

[0016] In one implementation of the first aspect, the access control permission information corresponding to the personnel is verified in the background, including: when the detection personnel pre-opens any door corresponding to any access control, obtaining the behavior in the personnel's identity information corresponding to any access control; when the personnel's permissions for any access control are inconsistent with the behavior in the personnel's identity information corresponding to any access control, issuing a system reminder, and updating the confidence level of the personnel's identity information corresponding to any access control.

[0017] Secondly, this application discloses an intelligent access control network method, comprising: obtaining personnel identity information and generating access control permission information corresponding to the personnel based on a machine learning algorithm; obtaining the personnel's permissions for any access control according to the access control permission information, detecting the personnel's permissions for any access control, obtaining permission detection results, opening the door corresponding to any access control according to the permission detection results; initializing system parameters, and performing background verification and monitoring scheduling of the personnel's access control permission information.

[0018] Thirdly, this application provides an electronic device, comprising: a memory storing multiple instructions; and a processor loading instructions from the memory to execute steps as described in the intelligent access control network method.

[0019] Fourthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by an electronic device, implements the steps in the above-described intelligent access control network method.

[0020] This application's system consists of a permission generation module, a permission calculation module, and a rule engine module. The permission generation module can generate permissions based on personnel, roles, and permissions. The permission calculation module can obtain the corresponding permissions for personnel based on access control permission information and check the corresponding permissions. The initialization module can initialize and set system parameters. The background verification module can perform background verification of the access control permission information corresponding to personnel. The scheduling module can monitor and schedule the permission generation module and the permission calculation module. This application automatically generates permission rules and updates the rules in real time, improving the efficiency of access control permission management while meeting security requirements. Attached Figure Description

[0021] Figure 1 This is a schematic diagram illustrating an application scenario according to an embodiment of this application.

[0022] Figure 2a This is a flowchart illustrating an embodiment of the intelligent access control network method of this application.

[0023] Figure 2b This is a schematic diagram of personnel access control information according to an embodiment of this application.

[0024] Figure 3 This is a schematic diagram of the structure of an intelligent access control network system according to an embodiment of this application.

[0025] Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of this application. Detailed Implementation

[0026] The following specific examples illustrate the implementation of this application. Those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. This application can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this application. It should be noted that, unless otherwise specified, the following embodiments and features in the embodiments can be combined with each other.

[0027] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of this application. Therefore, the drawings only show the components related to this application and are not drawn according to the number, shape and size of the components in actual implementation. In actual implementation, the form, number of elements and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.

[0028] The following embodiments of this application provide an intelligent access control network system, method, electronic device, and medium. For example, Figure 1 This is a schematic diagram illustrating an application scenario according to an embodiment of this application. The application scenario may include a server 10, a storage unit 11, and several different doors 12. Each door is equipped with a corresponding smart access control system. The smart access control system, server 10, and storage unit 11 are interconnected. The storage unit 11 can store personnel identity information, etc. The server 10 can obtain the personnel identity information and generate access control permission information corresponding to the personnel based on a machine learning algorithm; obtain the personnel's permissions for any door according to the access control permission information, and check the personnel's permissions for any door according to the access control permission information to obtain the permission check result; open the door corresponding to any door according to the permission check result; initialize system parameters, perform background verification of the personnel's access control permission information, and perform monitoring and scheduling, etc.

[0029] The technical solutions in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0030] like Figure 2a As shown, with server 10 as the execution entity, this embodiment provides an intelligent access control network method, including steps S210 to S230, as follows:

[0031] S210 and server 10 obtain the identity information of the personnel and generate the access control permission information corresponding to the personnel based on machine learning algorithms.

[0032] In this embodiment, the personnel's identity information includes name, role, position, work location, time, and access control application; access control permission information includes the access control application time period, behavior type, and confidence level; behavior type includes allow entry, prohibit entry, alarm, and allow entry with reminder.

[0033] For example, roles can include ordinary employees, managers, etc.; positions can include security guards, warehouse keepers, technicians, etc.; access control requests can include the company gate, finance office, etc.; and work locations can include warehouses, computer rooms, etc. Specifically, for example, in the identity information of a person named Xiao Wang, the role is ordinary employee, the position is warehouse keeper, the work location is warehouse A; the date is November 22, 2022, and the access control request is for the finance office, etc.

[0034] Regarding personnel access control information, such as Figure 2b As shown, there are two roles: ordinary employees and managers. Ordinary employees can configure access control for the company gate, with the access control application period being 9:00-18:00 on weekdays, the behavior type being "allow entry", and the confidence level being 1. Managers can configure access control for the finance office, with the access control application period being 13:30-15:30 every Friday afternoon, the behavior type being "allow entry and alert", and the confidence level being 0.5.

[0035] In one embodiment, generating access control permission information corresponding to a person includes: obtaining the historical access control permission information corresponding to the person and the applied access control based on the access control application; when there are several consecutive instances in the historical identity information corresponding to the person that indicate that entry is not allowed but the door is manually opened by a higher-level administrator, the behavior corresponding to the person is set to allow entry.

[0036] In this application, historical identity information refers to the identity information corresponding to a person at several historical moments. This application can generate access control permission information corresponding to a person using frequency analysis. That is, when a person's historical identity information shows several consecutive instances where entry was prohibited but the door was manually opened by a higher-level administrator, the person's corresponding behavior is set to allow entry based on the access control request.

[0037] In one embodiment, generating access control information corresponding to personnel based on machine learning algorithms includes: inputting the personnel's identity information into a deep learning model, and outputting the personnel's access control information through the deep learning model.

[0038] This application employs machine learning algorithms to obtain access control information corresponding to individuals. The application trains its algorithm by labeling existing data to determine whether new data should be granted or denied access.

[0039] In one embodiment, before inputting the identity information corresponding to the personnel into the deep learning model and outputting the access control information corresponding to the personnel through the deep learning model, the method further includes: obtaining the identity information of different personnel; labeling the identity information of different personnel to obtain a training set of labeled historical identity information; the labels correspond to the behavior types; and training the deep learning model using the labeled historical identity information training set to obtain a trained deep learning model.

[0040] In this application, the deep learning model can be a convolutional neural network, a random forest, etc., which can automatically generate and output access control information corresponding to personnel.

[0041] This application allows for manual or automated permission settings. The automated method generates permissions based on factors such as user, role, and behavior.

[0042] S220 and Server 10 obtain the permissions of personnel for any access control system based on the access control permission information, and check the permissions of personnel for any access control system to obtain the permission check result. Based on the permission check result, they open the door corresponding to any access control system.

[0043] In one embodiment, obtaining a person's access permissions for any given access control system based on access control permission information, detecting the person's permissions for any given access control system to obtain a permission detection result, and opening the door corresponding to any given access control system based on the permission detection result includes: when it is detected that a person intends to open the door corresponding to any given access control system, obtaining the person's access control permission information; when the access control permission information indicates that the person has several access control permissions, extracting a permission-allowed set and a permission-denied set from the several access control permissions; obtaining the confidence level of the permission-allowed set, the number of elements in the permission-allowed set, and the number of elements in the permission-denied set; when the number of elements in the permission-allowed set is greater than the number of elements in the permission-denied set, and the confidence level of the permission-allowed set is greater than the confidence level threshold, setting the person's permission for any given access control system to allow entry, and opening the door corresponding to any given access control system.

[0044] In this application, an individual can have multiple access control permission settings. From these multiple permission settings, a permission-allowed set and a permission-denied set can be obtained. The number of elements in the permission-allowed set is greater than the number of elements in the permission-denied set. Only when the confidence level of the permission-allowed set is greater than a certain confidence threshold can the door be opened effectively. In other embodiments, the confidence level corresponding to the permission-denied set can also be obtained. Only when the number of elements in the permission-allowed set is greater than the number of elements in the permission-denied set, and the confidence level of the permission-denied set is less than a certain confidence threshold for the denial set, can the door be opened effectively.

[0045] The confidence level of a set can be the average of the elements in the set. For example, the access control information for Finance Manager Li includes access control information for the company main gate, Finance Office A, Finance Office B, Computer Room A, and Computer Room B. The behavior type for the access control information for the company main gate is "Allowed to enter," with a confidence level of 1; the behavior type for Finance Office A is "Allowed to enter," with a confidence level of 1; the behavior type for Finance Office B is "Allowed to enter," with a confidence level of 0.7; the behavior type for Computer Room A is "Not allowed to enter," with a confidence level of 1; and the behavior type for Computer Room B is "Not allowed to enter," with a confidence level of 1. Then, from several access control permissions, we extract the allowed set and the denied set. The allowed set is (Company Main Gate: 1; Finance Office A: 1; Finance Office B: 0.7), and the denied set is (Company Room A: 1; Company Room B: 1). The allowed set has 3 elements, and the denied set has 2 elements. The confidence level of the allowed set is (1+1+0.7) / 3 = 0.9. In this embodiment, the confidence threshold can be set to 0.5. When it is detected that a person is trying to open the door corresponding to Finance Office C, since the number of elements in the allowed set (3) is greater than the number of elements in the denied set (2), and the confidence level of the allowed set (0.9) is greater than the confidence threshold (0.5), Finance Office C can be opened effectively.

[0046] In this embodiment, the permission calculation module generates corresponding permissions for users according to their roles. Since the system automatically generates rules, user behavior may contradict each other, and rules have confidence levels. In this case, the permission calculation module will perform permission calculations as follows: Dangerous behaviors are prioritized, meaning rules with higher priority and confidence, such as prohibited behaviors and alarms, are given priority. When multiple rules exist, they are calculated as a set, merging the permissions for multiple roles of the user. The permission calculation module also calculates permission contradictions and provides corresponding alerts. These contradictions include: 1) an incorrect access control order, where a secondary access control permission is allowed, but a higher-level access control permission is not, causing the secondary access control permission to become invalid; 2) a problem with the user's permission settings, where a user's permission is set to disallow, but their actual behavior is allowed. In this case, the system will issue an alert and update the confidence level.

[0047] S230 and Server 10 initialize system parameters and perform background verification and monitoring of personnel access control information.

[0048] In this embodiment, the following steps are involved: rule setting: setting the initial content of the system, such as the access control level, system time, etc.; permission verification: the system will periodically perform background verification of permissions, such as permission merging, permission errors, etc.; monitoring and scheduling: the module will monitor and schedule the permission generation module and the permission calculation module.

[0049] System parameters include access control levels and the range of access control periods requested. For example, Finance Room A can be set as Level 3 access control, Computer Room A as Level 2 access control, and the company main entrance as Level 1 access control, etc. The higher the access control level, the stronger the security. The range of time periods for requesting company access control can be from 7:00 AM to 10:00 PM every weekday, and the range of time periods for requesting access control for Finance Room A can be from 2:00 PM to 5:00 PM every Wednesday, and so on.

[0050] In one embodiment, the background verification of access control permission information corresponding to personnel includes: when a detection personnel pre-opens any door corresponding to an access control, obtaining the behavior in the personnel's identity information corresponding to any access control; when the personnel's permissions for any access control are inconsistent with the behavior in the personnel's identity information corresponding to any access control, issuing a system reminder, and updating the confidence level of the personnel's identity information corresponding to any access control.

[0051] In this embodiment, when a new user enters the intelligent access control network system, the system can automatically extract all permissions of the user's role and personal permissions, thereby generating user-specific permissions and refining the permission network based on user feedback. Through continuous refinement by the system and users, the system can generate flexible, resilient, and secure access control, thus constructing a permission model. This embodiment updates permissions in real time, improving the efficiency of access control management while ensuring security.

[0052] For example, if Xiao Wang is a regular employee and his / her access to the finance office is not configured, he / she cannot enter and must apply for manual approval each time. If this occurs multiple times (e.g., three times) and follows a pattern (e.g., every Friday afternoon), the system will automatically generate an access rule. This means that before Xiao Wang enters the finance office again, the system will automatically grant him / her access. When Xiao Wang arrives at the finance office, he / she can enter within a specified time and notify the relevant access control administrator. The access control administrator will receive the notification and can control the system-generated rule. As Xiao Wang enters the system multiple times without the access control administrator taking any action, the confidence level of this rule will gradually increase.

[0053] This application can generate permissions based on personnel, roles, and permissions. The permission calculation module can obtain the corresponding permissions for each person based on access control permission information and check those permissions. It can also initialize system parameters, perform background verification of access control permission information for each person, and monitor and schedule access control. This application automatically generates permission rules and updates them in real time, improving the efficiency of access control permission management while ensuring security.

[0054] The scope of protection of the intelligent access control network method in this application is not limited to the execution order of the steps listed in this embodiment. Any solution implemented by adding, subtracting, or replacing steps in the prior art based on the principles of this application is included within the scope of protection of this application.

[0055] This application also provides an intelligent access control network system. The intelligent access control network system can implement the intelligent access control network method of this application. However, the implementation device of the intelligent access control network system of this application includes, but is not limited to, the structure of the intelligent access control network system listed in this embodiment. All structural modifications and substitutions of the prior art made according to the principles of this application are included within the protection scope of this application.

[0056] like Figure 3 As shown, this application also provides an intelligent access control network system, including: a permission generation module 310, a permission calculation module 320, and an intelligent engine module 330. The permission generation module 310, permission calculation module 320, and intelligent engine module 330 are interconnected. The permission generation module 310 is configured to acquire personnel identity information and generate access control permission information corresponding to the personnel based on a machine learning algorithm. The permission calculation module 320 is configured to acquire the personnel's permissions for any access control based on the access control permission information, detect the personnel's permissions for any access control, obtain the permission detection result, and open the door corresponding to any access control based on the permission detection result. The intelligent engine module 330 includes an initialization module, a background verification module, and a scheduling module. The initialization module is configured to initialize system parameters, the background verification module is configured to perform background verification of the personnel's access control permission information, and the scheduling module is configured to monitor and schedule the permission generation module and the permission calculation module.

[0057] In this application, the intelligent access control network system includes a permission generation module, a permission calculation module, and an intelligent engine module. The permission generation module can generate permissions according to personnel, roles, and permissions. The permission calculation module can obtain the permissions corresponding to personnel based on access control permission information and check the permissions corresponding to personnel. The initialization module can initialize and set system parameters. The background verification module can perform background verification of the access control permission information corresponding to personnel. The scheduling module can monitor and schedule the permission generation module and the permission calculation module.

[0058] In one embodiment, the personnel's identity information includes name, role, position, work location, time, and access control application; access control permission information includes the access control application time period, behavior type, and confidence level; behavior type includes allowed entry, prohibited entry, alarm, and allowed entry with alert; system parameters include access control level and the range of the access control application time period.

[0059] In one embodiment, the permission generation module is further configured to: obtain the historical access permission information corresponding to the personnel and the applied access permission based on the access permission application; when there are several consecutive instances in the historical identity information corresponding to the personnel where the behavior is not allowed but the door is manually opened by a higher-level administrator, set the behavior corresponding to the personnel to allow entry.

[0060] In this application, historical identity information refers to the access control permission information corresponding to a person at several historical moments. This application can generate access control permission information corresponding to a person using frequency analysis. That is, when there are several consecutive instances in the historical identity information of a person where the behavior is "not allowed" but the door is manually opened by a higher-level administrator, the behavior corresponding to the person is set to "allowed".

[0061] In one embodiment, generating access control information corresponding to personnel based on machine learning algorithms includes: inputting the personnel's identity information into a deep learning model, and outputting the personnel's access control information through the deep learning model.

[0062] This application employs machine learning algorithms to obtain access control information corresponding to individuals. The application trains its algorithm by labeling existing data to determine whether new data should be granted or denied access.

[0063] In one embodiment, before inputting the identity information corresponding to the personnel into the deep learning model and outputting the access control information corresponding to the personnel through the deep learning model, the method further includes: obtaining the identity information of different personnel; labeling the identity information of different personnel to obtain a training set of labeled historical identity information; the labels correspond to the behavior types; and training the deep learning model using the labeled historical identity information training set to obtain a trained deep learning model.

[0064] In one embodiment, obtaining a person's access permissions for any given access control system based on access control permission information, detecting the person's permissions for any given access control system to obtain a permission detection result, and opening the door corresponding to any given access control system based on the permission detection result includes: when it is detected that a person intends to open the door corresponding to any given access control system, obtaining the person's access control permission information; when the access control permission information indicates that the person has several access control permissions, extracting a permission-allowed set and a permission-denied set from the several access control permissions; obtaining the confidence level of the permission-allowed set, the number of elements in the permission-allowed set, and the number of elements in the permission-denied set; when the number of elements in the permission-allowed set is greater than the number of elements in the permission-denied set, and the confidence level of the permission-allowed set is greater than the confidence level threshold, setting the person's permission for any given access control system to allow entry, and opening the door corresponding to any given access control system.

[0065] In this application, an individual can have multiple access control permission settings. From these multiple permission settings, a permission allowed set and a permission denied set can be obtained. The number of elements in the permission allowed set is greater than the number of elements in the permission denied set. Only when the confidence level of the permission allowed set is greater than a certain confidence level threshold can the door be opened effectively.

[0066] The confidence level of a set can be the average value of each element in the set, and the confidence threshold can be the confidence level of the set that grants the permission to deny.

[0067] In one embodiment, the background verification of access control permission information corresponding to personnel includes: when a detection personnel pre-opens any door corresponding to an access control, obtaining the behavior in the personnel's identity information corresponding to any access control; when the personnel's permissions for any access control are inconsistent with the behavior in the personnel's identity information corresponding to any access control, issuing a system reminder, and updating the confidence level of the personnel's identity information corresponding to any access control.

[0068] In practice, the above modules can be implemented as independent entities or combined in any way to be implemented as the same or several entities. For the specific implementation of the above modules, please refer to the previous method implementation examples, which will not be repeated here.

[0069] As shown above, this application can generate permissions based on personnel, roles, and permissions. The permission calculation module can obtain the corresponding permissions for each person based on access control permission information and check those permissions. It can also initialize system parameters, perform background verification of access control permission information for each person, and monitor and schedule access control. This application automatically generates permission rules and updates them in real time, improving the efficiency of access control management while ensuring security.

[0070] In the embodiments provided in this application, it should be understood that the disclosed systems or methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For instance, the division of modules / units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or units may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interfaces, devices, or modules or units, and may be electrical, mechanical, or other forms.

[0071] The modules / units described as separate components may or may not be physically separate. The components shown as modules / units may or may not be physical modules; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules / units can be selected to achieve the objectives of the embodiments of this application, depending on actual needs. For example, the functional modules / units in the various embodiments of this application may be integrated into one processing module, or each module / unit may exist physically separately, or two or more modules / units may be integrated into one module / unit.

[0072] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0073] This application also provides an electronic device, which can be a terminal, a server, or other similar device. The terminal can be a mobile phone, tablet computer, smart Bluetooth device, laptop computer, personal computer, etc.; the server can be a single server or a server cluster composed of multiple servers, etc.

[0074] In some embodiments, the intelligent access control network system provided in this application can also be integrated into multiple electronic devices. For example, the intelligent access control network system can be integrated into multiple servers, and the intelligent access control network method of this application can be implemented by multiple servers.

[0075] In this embodiment, a server will be used as an example for detailed description. For example, ... Figure 4As shown, it illustrates a schematic diagram of the server structure involved in an embodiment of this application. Specifically:

[0076] The server may include components such as a processor 410 with one or more processing cores, a memory 420 with one or more computer-readable storage media, a power supply 430, an input module 440, and a communication module 450. Those skilled in the art will understand that... Figure 4 The server architecture shown does not constitute a limitation on the server and may include more or fewer components than illustrated, or combine certain components, or have different component arrangements. Wherein:

[0077] The processor 410 is the control center of the server, connecting various parts of the server through various interfaces and lines. It performs various server functions and processes data by running or executing software programs and / or modules stored in the memory 420, and by calling data stored in the memory 420, thereby providing overall monitoring of the server. In some embodiments, the processor 410 may include one or more processing cores; in some embodiments, the processor 410 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may also not be integrated into the processor 410.

[0078] The memory 420 can be used to store software programs and modules. The processor 410 executes various functional applications and data processing by running the software programs and modules stored in the memory 420. The memory 420 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the server, etc. In addition, the memory 420 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device. Accordingly, the memory 420 may also include a memory controller to provide the processor 410 with access to the memory 420.

[0079] The server also includes a power supply 430 that supplies power to the various components. In some embodiments, the power supply 430 can be logically connected to the processor 410 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The power supply 430 may also include one or more DC or AC power supplies, recharging systems, power fault detection circuits, power converters or inverters, power status indicators, and other arbitrary components.

[0080] The server may also include an input module 440, which can be used to receive input numeric or character information, and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function control.

[0081] The server may also include a communication module 450. In some embodiments, the communication module 450 may include a wireless module, through which the server can perform short-range wireless transmission, thereby providing wireless broadband internet access for personnel. For example, the communication module 450 can be used to help personnel send and receive emails, browse web pages, and access streaming media.

[0082] Although not shown, the server may also include a display unit, etc., which will not be described in detail here. Specifically, in this embodiment, the processor 410 in the server loads the executable files corresponding to the processes of one or more applications into the memory 420 according to the following instructions, and the processor 410 runs the applications stored in the memory 420, thereby realizing the various functions of the confidence calculation device.

[0083] In some embodiments, this application also provides a computer-readable storage medium. Those skilled in the art will understand that all or part of the steps in the methods of the above embodiments can be implemented by a program instructing a processor, and the program can be stored in a computer-readable storage medium. The storage medium is a non-transitory medium, such as random access memory, read-only memory, flash memory, hard disk, solid-state drive, magnetic tape, floppy disk, optical disk, and any combination thereof. The above storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., digital video disc (DVD)), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0084] This application embodiment may also provide a computer program product, which includes one or more computer instructions. When the computer instructions are loaded and executed on a computing device, all or part of the flow or function according to the embodiments of this application is generated. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, or data center to another website, computer, or data center via wired (e.g., coaxial cable, fiber optic, digital personnel line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.

[0085] When the computer program product is executed by a computer, the computer performs the method described in the foregoing method embodiments. The computer program product may be a software installation package; when the foregoing method is required, the computer program product can be downloaded and executed on the computer.

[0086] The descriptions of the processes or structures corresponding to the above figures each have their own emphasis. For parts of a process or structure that are not described in detail, please refer to the relevant descriptions of other processes or structures.

[0087] The above embodiments are merely illustrative of the principles and effects of this application and are not intended to limit this application. Any person skilled in the art can modify or alter the above embodiments without departing from the spirit and scope of this application. Therefore, all equivalent modifications or alterations made by those skilled in the art without departing from the spirit and technical concept disclosed in this application should still be covered by the claims of this application.

Claims

1. An intelligent access control network system, characterized in that, include: The module consists of a permission generation module, a permission calculation module, and an intelligent engine module. The permission generation module, the permission calculation module, and the intelligent engine module are interconnected and communicate with each other. The permission generation module is used to obtain the identity information of the personnel and generate access control permission information corresponding to the personnel based on machine learning algorithms. The identity information of the personnel includes the application for access control. The permission generation module is further configured to: obtain the historical access permission information of the person and the application access permission based on the application access permission; when the historical identity information of the person has several consecutive behaviors that are not allowed to enter but are manually opened by a higher-level administrator, set the behavior of the person to allow entry; The permission calculation module is used to obtain the permissions of the personnel for any access control according to the access control permission information, and to detect the permissions of the personnel for any access control to obtain the permission detection result, and to open the door corresponding to any access control according to the permission detection result; The intelligent engine module includes an initialization module, a background verification module, and a scheduling module; The initialization module is used to initialize and set system parameters, the background verification module is used to perform background verification of the access control permission information corresponding to the personnel, and the scheduling module is used to monitor and schedule the permission generation module and the permission calculation module.

2. The system according to claim 1, characterized in that, The personnel's identity information includes name, role, position, work location, and time; the access control permission information includes the access control application time period, behavior type, and confidence level; the behavior type includes allow entry, prohibit entry, alarm, and allow entry with reminder; the system parameters include access control level and the range of the access control application time period.

3. The system according to claim 1, characterized in that, The process of generating access control information corresponding to the personnel based on machine learning algorithms includes: The identity information corresponding to the person is input into the deep learning model, and the access control permission information corresponding to the person is output through the deep learning model.

4. The system according to claim 1, characterized in that, Before inputting the identity information corresponding to the person into the deep learning model and outputting the access control permission information corresponding to the person through the deep learning model, the method further includes: Obtain the identity information of different individuals; The identity information of the different individuals is labeled to obtain a training set of labeled historical identity information; the labels correspond to the behavior types. The deep learning model is trained using the tagged historical identity information training set to obtain the trained deep learning model.

5. The system according to claim 1, characterized in that, The step of obtaining the access permissions of the personnel for any access control gate based on the access control permission information, detecting the personnel's permissions for any access control gate to obtain a permission detection result, and opening the door corresponding to any access control gate based on the permission detection result includes: When it is detected that the person is about to open any door corresponding to the access control system, the access control permission information of the person is obtained; When the personnel in the access control permission information have several access control permissions, extract the permission allowed set and the permission denied set from the several access control permissions; Obtain the confidence level corresponding to the permission-allowed set, the number of elements corresponding to the permission-allowed set, and the number of elements corresponding to the permission-denied set; When the number of elements corresponding to the permission-allowed set is greater than the number of elements corresponding to the permission-denied set, and the confidence level corresponding to the permission-allowed set is greater than the confidence level threshold, the personnel's permission for any one of the access control gates is set to allow entry, and the door corresponding to any one of the access control gates is opened.

6. The system according to claim 5, characterized in that, The background verification of the access control permission information corresponding to the personnel includes: When the system detects that the person is about to open any door corresponding to an access control system, it retrieves the person's identity information and the behavior corresponding to that access control system. When the permissions of the person regarding any of the access control points are inconsistent with the behavior corresponding to any of the access control points in the person's identity information, the system will issue a reminder and update the confidence level of the person's identity information corresponding to any of the access control points.

7. A method for intelligent access control network, characterized in that, include: The system obtains the identity information of personnel and generates access control permission information corresponding to the personnel based on machine learning algorithms. The identity information of personnel includes access control application. Based on the access control application, the system obtains the historical access control permission information of the personnel and the access control application. If there are several consecutive instances in the historical identity information of the personnel that indicate that they cannot enter but are manually opened by a higher-level administrator, the behavior corresponding to the personnel is set to allow entry. Based on the access control permission information, obtain the personnel's permissions for any access control, check the personnel's permissions for any access control, obtain the permission check result, and open the door corresponding to any access control based on the permission check result; The system parameters are initialized, and the access control permission information corresponding to the personnel is verified and monitored in the background.

8. An electronic device, characterized in that, The electronic device includes: The memory stores multiple instructions; A processor that loads instructions from the memory to perform the steps of the method as described in claim 7.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by an electronic device, it performs the steps of the method of claim 7.

Citation Information

Patent Citations

  • Hospital personnel access control method and system, storage medium, equipment and terminal

    CN113191725A