A gate unit networking control system
By using a secure terminal without IP firewall in the gate network control system to safely process data transmission, the problem of insufficient security protection of the gate network control system in the prior art is solved, and effective protection of the communication network is achieved.
Patent Information
- Application Number
- CN202311299850.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-09
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2043-10-09
AI Technical Summary
Due to the architectural limitations of the equipment processing unit, the existing gate network control system cannot effectively deploy the network protection system, resulting in insufficient security performance of network communication and being vulnerable to hackers, resulting in user personal privacy leakage and gate failure.
A secure terminal equipped with an IP-free firewall is used to connect to the gate and the information transmission port of the detection device to provide security protection based on network access control, ensuring that data transmission must be processed by a secure terminal, thereby preventing illegal intrusion by hackers.
Effectively prevent hackers from illegally invading the communication network of the gate network control system, protecting user privacy, avoiding gate failure, and improving the system's security protection capabilities.
Smart Images

Figure CN117155702B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a gate machine networking control system. Background Art
[0002] The gate is an entrance and exit management device used for entrance and exit management. It is widely used in office buildings, shopping malls, subway stations, bus stations, airports and other places. With the development of Internet of Things technology, the functions of gates are gradually increasing. On the basis of controlling access, existing gates can collect personal information of passers-by through the configured face recognition components, NFC components, scanning components and other identification components, and rely on the Internet of Things to interactively process the information of passers-by, which can realize functions such as access control, visitor registration, and ticket checking. The existing technology has basically realized the intelligent control of the gate network control system, and can adjust the working parameters such as the gate release direction and access authority. However, the existing gate network control system is limited by the architecture of the equipment processing unit and it is almost impossible to deploy a network protection system, resulting in insufficient network communication security performance. The cracking of detection equipment such as cameras and NFC has led to the snooping of users' personal privacy, and the gate communication network has been hijacked and destroyed by Trojan viruses, resulting in the failure of the gate.
[0003] The invention patent with the publication number CN113783868A discloses a method for protecting the security of the gate IoT based on commercial cryptography to solve the technical problem of gate IoT security. The technical solution of this patent includes: using the commercial cryptographic algorithm SM2 to authenticate the gate device and the back-end gate IoT security system gateway; the gate IoT security system gateway adopts the dual host mode of the internal and external networks, and the internal network host and the external network host are isolated by non-network mode; using the commercial cryptographic algorithm SM4 and IPSecVPN protocol to establish a secure encrypted tunnel to protect the transmission data between the gate device and the gate IoT security system gateway.
[0004] The processing unit of the gate machine is mainly an embedded microprocessor, and its performance and architecture are difficult to support the deployment of protection software such as Endpoint Detection and Response (EDR). If a security gateway or other equipment is used to provide network security protection for the gate machine equipment, since the security gateway needs to occupy an IP address and allocate the IP address of its subordinate gate machines, the number of nodes and topological layers of the communication network in the gate machine network control system will increase, making the management of the communication network more difficult. In addition, since the IP address of the security gateway can be detected, the security gateway is also at risk of being attacked by Trojan viruses, and the security protection problem of the gate machine network control system cannot be solved.
[0005] In addition, on the one hand, there are differences in the understanding of those skilled in the art; on the other hand, when the applicant made this invention, a large number of documents and patents were studied, but due to space limitations, all details and content were not listed in detail. However, this does not mean that this invention does not possess the features of these prior arts. On the contrary, this invention already possesses all the features of the prior arts, and the applicant reserves the right to add relevant prior arts in the background art. Summary of the Invention
[0006] The processing unit of the turnstile in the prior art is mainly an embedded microprocessor, and its performance and architecture are difficult to support the deployment of security software such as Endpoint Detection and Response (EDR). When using devices such as security gateways to provide network security protection for turnstile devices, since the security gateway needs to occupy an IP address and allocate IP addresses to its subordinate turnstiles, the number of nodes and the topological layers of the communication network in the turnstile networking control system are increased, resulting in an increase in the management difficulty of the communication network. If the IP address of the security gateway is detected, the security gateway is at risk of being attacked by Trojan viruses. Therefore, how to solve the security protection problem of the turnstile networking control system has not been well solved in the prior art.
[0007] Aiming at the deficiencies of the prior art, the present invention discloses a turnstile networking control system from the first aspect. The turnstile networking control system may include: turnstiles, detection devices, processing devices, and security terminals. The processing device is configured to be able to adjust the working parameters of the turnstiles based on the environmental parameters collected by the detection devices. Preferably, a security terminal is connected to the information transmission ports of the turnstiles and the detection devices. The security terminal provides security protection based on network access control for the turnstiles and the detection devices by using the IP-free firewall carried thereon. Through the security protection of the IP-free firewall, the present invention effectively prevents hackers from illegally intruding into the communication network of the turnstile networking control system to steal user privacy information and avoids affecting the normal operation of the turnstile networking control system.
[0008] Preferably, in the present invention, by connecting the security terminal carrying the IP-free firewall to the information transmission ports of the turnstiles and the detection devices, the data received or sent by the turnstiles and the detection devices all pass through the security terminal. Preferably, the processing device sends authentication data to the turnstiles and the detection devices, and the security terminal identifies and processes the authentication data according to the preset inspection rules. When the security terminal confirms that the authentication data conforms to the preset inspection rules, the turnstiles and the detection devices realize networking communication with the processing device. The advantage of such a setting is that the IP-free firewall can form a device that data transmission must pass through, achieving the effect of preventing intrusion into the turnstiles according to the IP.
[0009] Preferably, the IP-free firewall installed on the security terminal can capture the data passing through the security terminal and identify and process it, thereby ensuring the security of the communication network of the gate networking control system, effectively preventing hackers from illegally intruding into the communication network of the gate networking control system to steal user privacy information, and avoiding affecting the normal operation of the gate networking control system.
[0010] Preferably, the processing device may include an operation management module and a protection management module. The operation management module is configured to be able to adjust the working parameters of the gate based on the environmental parameters collected by the detection device, thereby adjusting the personnel flow line. The protection management module and the security terminal form a protection component to provide security protection for the network communication between the processing device and the gate or the detection device.
[0011] According to a preferred embodiment, the authentication data may include the IP address of the processing device. When it is confirmed that the authentication data conforms to the preset inspection rules, the security terminal saves the IP address of the processing device locally on the security terminal and sends the authentication result data including the IP address of the gate or the detection device to the processing device.
[0012] Preferably, by sending the authentication result data including the IP address of the gate or the detection device to the processing device, the processing device determines the IP address of the gate or the detection device authenticated by the security terminal in the communication network, thereby determining the trusted IP address. Preferably, the processing device determines the trusted IP address in the communication network, and security protection based on the IP address can be achieved. When the IP address of the device accessing the data in the communication network is an untrusted IP address, the protection component composed of the protection management module and the security terminal can intercept the access from the untrusted IP address.
[0013] According to a preferred embodiment, in response to the receipt of the authentication result data, the processing device sends the configuration data including the IP-free firewall inspection rule update scheme to the IP address of the gate or the detection device. The security terminal identifies and processes the configuration data according to the preset inspection rules. When it is confirmed that the configuration data conforms to the preset inspection rules, the security terminal configures the installed IP-free firewall according to the update scheme and sends the configuration result data reflecting the successful configuration of the IP-free firewall to the processing device.
[0014] Preferably, after determining the IP address of the gate or the detection device, the processing device can configure the inspection rules of the IP-free firewall according to the data types, formats, etc. involved in the communication network used for gate control, so as to provide security protection for the data transmission of the gate or the detection device.
[0015] Preferably, configuring the inspection rules of the IP-free firewall according to the data types, formats, etc. involved in the communication network used for gate control enables the IP-free firewall to isolate the invalid broadcast packets and malicious accesses in the communication network.
[0016] According to a preferred embodiment, in response to receiving the configuration result data, the processing device confirms that the update of the inspection rules of the IP-free firewall installed on the security terminal is successful and saves the successfully updated inspection rules of the IP-free firewall installed on the security terminal and the IP addresses of the turnstiles or detection devices connected to the security terminal to the database.
[0017] Preferably, when sending data to the turnstile or detection device, the processing device can obtain the IP address of the data recipient and the inspection rules of the IP-free firewall protecting the recipient from the database, and then encapsulate the information to be transmitted into data that conforms to the inspection rules of the IP-free firewall of the recipient. Preferably, the inspection rules configured for the IP-free firewalls installed on different security terminals can be different, and the processing device can update the inspection rules of the IP-free firewall irregularly, thereby increasing the difficulty of cracking the IP-free firewall.
[0018] According to a preferred embodiment, when the processing device confirms that the configuration of the IP-free firewall installed on the security terminal is successful, the processing device forms a network connection with the turnstiles and detection devices that are connected to the security terminal at the information transmission ports to transmit the working data for regulating the working parameters of the turnstiles.
[0019] Preferably, the processing device adjusts the working parameters of the turnstiles based on the environmental parameters collected by the detection devices. When the configuration of the IP-free firewall installed on the security terminal is successful, the IP-free firewall installed on the security terminal can provide security protection for the working data for regulating the working parameters of the turnstiles.
[0020] According to a preferred embodiment, the IP-free firewall installed on the security terminal processes the working data received or sent by the turnstiles and detection devices according to the inspection rules. Preferably, the processing of the working data by the IP-free firewall includes: packaging the working data sent by the turnstiles and detection devices and inspecting the working data received by the turnstiles and detection devices.
[0021] Preferably, when the working data passes the security inspection, the security terminal releases the working data; otherwise, the security terminal intercepts the working data to make it invalid. Preferably, when the security terminal completes the security packaging of the sent data, the protection component sends the securely packaged working data to the target device, so that the securely packaged working data can pass the security inspection of the security terminal and / or the protection management module set in front of the target device, thus successfully completing the data transmission.
[0022] According to a preferred embodiment, the security terminal generates the operation log of the IP-free firewall and uploads the operation log to the processing device, so that the processing device can supervise the data transmission between the processing device and the turnstile or between the processing device and the detection device by verifying the local operation log and the operation log of the IP-free firewall.
[0023] Preferably, the processing device can determine the data receiving and sending conditions of the processing device, the turnstile and the detection device based on the local operation log and the operation log of the IP-free firewall. Preferably, the protection management module configured in the processing device can determine whether there is any omission in data sending or control between the processing device and the turnstile by comparing the data receiving and sending conditions of the processing device with those of the turnstile. Preferably, the protection management module can also determine whether there is any omission in data sending or control between the processing device and the detection device by comparing the data receiving and sending conditions of the processing device with those of the detection device.
[0024] Preferably, the processing device can also make turnstile management decisions based on the local operation log and the operation log of the IP-free firewall. For example, when the cinema is emptying after a show, the turnstiles for leaving are frequently used while the turnstiles for entering are hardly used, which is likely to cause congestion. The processing device can adjust some of the turnstiles for entering to turnstiles for leaving to avoid or relieve the congestion.
[0025] According to a preferred embodiment, the inspection rules include the identification features of different types of data and the processing measures for the corresponding types of data.
[0026] Preferably, the IP-free firewalls configured in each security terminal can inspect the data passing through the security terminal according to the inspection rules. If the data passing through the security terminal conforms to the identification features in the inspection rules, the data will be processed accordingly; if the data passing through the security terminal does not conform to the identification features in the inspection rules, the data will be invalidated. And the IP-free firewalls configured in each security terminal can be set with different inspection rules to further increase the difficulty of preventing illegal intrusion by hackers.
[0027] The present invention discloses a turnstile networking control method from a second aspect. The method may include:
[0028] Setting a security terminal equipped with an IP-free firewall at the information transmission ports of the turnstile and the detection device to process the data received or sent by the turnstile or the detection device; the processing device communicates with the security terminal using the IP addresses of the turnstile and the detection device and configures the IP-free firewall carried by the security terminal.
[0029] Preferably, when deployed, the security terminal can communicate using the network architecture of existing on-site devices without changing the existing on-site device network architecture. Preferably, the security terminal can be set at the information transmission ports of the turnstile and the detection device, enabling the security terminal to communicate using the IP addresses of the turnstile and the detection device without the need for additional IP address allocation.
[0030] According to a preferred embodiment, the method further includes: generating an operation log of the IP-free firewall carried by the security terminal for processing data received or sent by the turnstile and the detection device; and supervising the data transmission situation of the turnstile and the detection device based on the operation log.
[0031] Preferably, the operation log includes the first operation log of the protection management module and the second operation log of the security terminal. The protection management module can determine the data receiving and sending situations of the processing device, the turnstile, and the detection device based on the first operation log and the second operation log, and further determine whether there are any missed transmissions or missed controls between the processing device and the turnstile. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 is a simplified schematic diagram of a turnstile networking control system provided by the present invention;
[0033] Figure 2 is a communication network schematic diagram of a turnstile networking control system provided by the present invention;
[0034] Figure 3 is a structural schematic diagram of the turnstile of the present invention;
[0035] Figure 4 is a sectional structure diagram of the turnstile from a top view angle of the present invention;
[0036] Figure 5 is a schematic diagram of the information authentication process of the networking of the present invention.
[0037] LIST OF REFERENCE NUMERALS
[0038] 100: Turnstile networking control system; 110: Turnstile; 111: First turnstile; 112: Second turnstile; 113: Display component; 114: Sensor; 115: First guardrail; 116: Second guardrail; 117: Rotating shaft; 118: Barrier; 119: Passage; 120: Detection device; 121: First detection device; 122: Second detection device; 130: Processing device; 131: Operation management module; 132: Protection management module; 140: Security terminal; 141: First security terminal; 142: Second security terminal; 143: Third security terminal; 144: Fourth security terminal; 1191: First passage; 1192: Second passage. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0039] The following will be described in detail with reference to the accompanying Figure 1 drawings 2 and
[0040] Embodiment 1
[0041] This embodiment provides a gate networking control system 100. Referring to Figure 1 FIG. X (not shown), preferably, the gate networking control system 100 may include: a gate 110, a detection device 120, and a processing device 130. The processing device 130 is configured to be able to adjust the working parameters of the gate 110 based on the environmental parameters collected by the detection device 120. Preferably, a security terminal 140 is connected to the information transmission ports of the gate 110 and the detection device 120. The security terminal 140 provides security protection based on network access control for the gate 110 and the detection device 120 by using the non-IP networking technology. Preferably, in the present invention, by connecting the security terminal 140 equipped with a non-IP firewall to the information transmission ports of the gate 110 and the detection device 120, the data received or sent by the gate 110 and the detection device 120 all pass through the security terminal 140. Preferably, the processing device 130 sends authentication data to the gate 110 and the detection device 120, and the security terminal 140 identifies and processes the authentication data according to the preset inspection rules. When the security terminal 140 confirms that the authentication data conforms to the preset inspection rules, the gate 110 and the detection device 120 achieve networking communication with the processing device 130. Preferably, the non-IP firewall carried by the security terminal 140 can capture the data passing through the security terminal 140 and identify and process it, thereby ensuring the security of the communication network of the gate networking control system 100, effectively preventing hackers from illegally intruding into the communication network of the gate networking control system 100 to steal user privacy information, and avoiding affecting the normal operation of the gate networking control system 100.
[0042] Preferably, the gate 110 may include a first gate 111 and a second gate 112. Preferably, the first gate 111 and the second gate 112 may be gates 110 provided at different channel nodes.
[0043] Preferably, the gate networking control system 100 provided by the present invention can adjust the working parameters of the gate 110 to combine a personnel flow line suitable for the user's passage requirements.
[0044] Figure 3 The gate 110 in Figure 3 FIG. X Figure 4 is an example in the present invention. In Figure 3Two channels 119 are shown, including a first channel 1191 and a second channel 1192. The channel 119 is composed of a first guardrail 115, a second railing 116, and a barrier rod 118. The barrier rod 118 rotates through a rotating shaft 117 to form a door that can block or allow personnel to pass. In Figure 3 and Figure 4 , three barrier rods 118 are evenly distributed circumferentially along the rotating shaft 117 and are arranged centered on the rotating shaft 117. The rotating shaft 117 is connected to the gate networking control system 100 in a wired or wireless manner to transmit data information and / or instruction information. The rotating shaft 117 is controlled by a motor to rotate ( Figure 3 and Figure 4 not shown). The motor is controlled by the gate networking control system 100 to rotate to realize the opening and closing of the gate. When the sensor 114 detects the entry and exit of a person with an identity identifier, in response to the identification information of whether the person's identity information is legal, the gate networking control system 100 issues a control instruction to start or not start the gate. The motor and the rotating shaft 117 control the rotation of the barrier rod 118 to allow the person to pass through the channel 119.
[0045] The gate 110 is also provided with a plurality of sensors 114 and a display component 113. The plurality of sensors 114 and the display component 113 are respectively connected to the gate networking control system 100 in a wired or wireless manner to transmit data information and / or instruction information. The gate networking control system 100 generates first passage data related to time based on the opening and closing data of the barrier rod 118. The gate networking control system 100 is connected to the first server in a wired and / or wireless manner to store the first passage data in the first server.
[0046] Preferably, the detection device 120 may include a first detection device 121 and a second detection device 122. Preferably, the first detection device 121 and the second detection device 122 may be devices such as cameras for monitoring the personnel flow at each channel node.
[0047] The first detection device 121 and the second detection device 122 generate second passage data related to time based on the collected image data of the opening and closing of the barrier rod 118. The detection device 120 is connected to the second server in a wired and / or wireless manner to store the second passage data in the second server.
[0048] The first server and the second server are independent servers from each other. The first passage data is generated by the gate networking control system 100. The time of the first passage data is recorded based on the opening and closing of the gates 110. The second passage data is collected and judged by the detection device 120. The first time of the first passage data and the second time of the second passage data are not synchronized. Therefore, on the basis that the first server and the second server are independent of each other, there is no synchronous correlation between the first time and the second time. Preferably, the gate networking control system 100 provided by the present invention can monitor the personnel flow conditions of each channel node through the detection device 120, so as to obtain environmental parameters affecting the formulation of the gate control scheme, and thus formulate a gate control scheme suitable for the user's passage requirements. Preferably, the first gate 111, the second gate 112, the first detection device 121 and the second detection device 122 are all connected with a security terminal 140 at their information transmission ports, and are connected to the processing device 130 through the security terminal 140.
[0049] See Figure 2 , preferably, the processing device 130 may include an operation management module 131 and a protection management module 132. The operation management module 131 is configured to be able to adjust the working parameters of the gates 110 based on the environmental parameters collected by the detection device 120, so as to adjust the personnel flow line. The protection management module 132 and the security terminal 140 provide security protection for the network communication between the processing device 130 and the gates 110 or the detection device 120.
[0050] Preferably, the operation management module 131 and the protection management module 132 may be intelligent processing devices such as a computer. Preferably, the protection management module 132 is arranged at the information transmission port of the operation management module 131, so that the data received and sent by the operation management module 131 passes through the processing of the protection management module 132.
[0051] Preferably, after the gates 110 and the detection device 120 are connected to the security terminal 140, they can realize networking communication with the processing device 130 through a wireless network. Preferably, the security terminal 140 is provided with two information transmission ports, one of which is connected to the information transmission port of the gates 110 or the detection device 120, and the other realizes networking communication with the processing device 130 through a wireless network. See Figure 2 , preferably, the security terminal 140 may include: a first security terminal 141 connected to the first gate 111, a second security terminal 142 connected to the second gate 112, a third security terminal 143 connected to the first detection device 121, and a fourth security terminal 144 connected to the second detection device 122.
[0052] Preferably, the gates 110 and the detection device 120 can be networked with the processing device 130 through the security terminal 140.
[0053] Preferably, the processing device 130 sends authentication data to all IP addresses in the communication network. If the receiving IP address of the authentication data is the IP address of the turnstile 110 and the detection device 120, the authentication data sent by the processing device 130 to the turnstile 110 and the detection device 120 can be captured by the security terminal 140 provided at the information transmission ports of the turnstile 110 and the detection device 120. The security terminal 140 performs identification processing on the authentication data according to a preset inspection rule. When the security terminal 140 confirms that the authentication data conforms to the preset inspection rule, the turnstile 110 and the detection device 120 establish network communication with the processing device 130.
[0054] Preferably, the authentication data may include the IP address of the processing device 130. When it is confirmed that the authentication data conforms to the preset inspection rule, the security terminal 140 saves the IP address of the processing device 130 locally to the security terminal 140 and sends authentication result data including the IP address of the turnstile 110 or the detection device 120 to the processing device 130.
[0055] Preferably, by sending the authentication result data including the IP address of the turnstile 110 or the detection device 120 to the processing device 130, the security terminal 140 enables the processing device 130 to filter out the IP address of the turnstile 110 or the detection device 120 of the security terminal 140 from all the IP addresses in the communication network, so as to determine the trusted IP addresses in the communication network.
[0056] Preferably, after receiving the authentication result data, the processing device 130 can communicate with the trusted IP addresses in the communication network to achieve network operation. Preferably, after determining the trusted IP addresses in the communication network, the processing device 130 can configure the IP-free firewall installed on the security terminal 140 corresponding to each IP address. Preferably, after determining the IP address of the turnstile 110 or the detection device 120, the processing device 130 can configure the inspection rules of the IP-free firewall according to the data types, formats, etc. involved in the communication network used for turnstile control, so as to provide security protection for the data transmission of the turnstile 110 or the detection device 120.
[0057] Preferably, in response to receiving the authentication result data, the processing device 130 sends configuration data including an IP-free firewall inspection rule update scheme to the IP address of the turnstile 110 or the detection device 120. The security terminal 140 performs identification processing on the configuration data according to a preset inspection rule. When it is confirmed that the configuration data conforms to the preset inspection rule, the security terminal 140 configures the installed IP-free firewall according to the update scheme and sends configuration result data reflecting the successful configuration of the IP-free firewall to the processing device 130.
[0058] Preferably, in response to receiving the configuration result data, the processing device 130 confirms that the update of the inspection rules of the IP-free firewall installed on the security terminal 140 is successful and saves the successfully updated inspection rules of the IP-free firewall installed on the security terminal 140 and the IP addresses of the turnstile 110 or the detection device 120 connected to the security terminal 140 to the database.
[0059] Preferably, when sending data to the turnstile 110 or the detection device 120, the processing device 130 can obtain the IP address of the data recipient and the inspection rules of the IP-free firewall protecting the recipient from the database, and then encapsulate the information to be transmitted into data conforming to the inspection rules of the IP-free firewall of the recipient.
[0060] Preferably, when the processing device 130 confirms that the configuration of the IP-free firewall installed on the security terminal 140 is successful, the processing device 130 forms a network for communication with the turnstile 110 and the detection device 120 connected to the security terminal 140 at the information transmission port to transmit the working data for regulating the working parameters of the turnstile 110.
[0061] Preferably, the processing device 130 adjusts the working parameters of the turnstile 110 based on the environmental parameters collected by the detection device 120. When the configuration of the IP-free firewall installed on the security terminal 140 is successful, the IP-free firewall installed on the security terminal 140 can provide security protection for the working data for regulating the working parameters of the turnstile 110.
[0062] Preferably, the inspection rules include the identification features of different types of data and the processing measures for the corresponding types of data. Preferably, the identification features can include network ports and protocol headers.
[0063] Preferably, after capturing the transmitted data, the IP-free firewall installed on the security terminal 140 identifies the network port of the data. If the network port of the data does not conform to the network port in the identification features, the IP-free firewall intercepts the data. If the network port of the data does not conform to the network port in the identification features, the IP-free firewall parses the data according to the custom application layer protocol and determines the data type according to the protocol header. Preferably, in the present invention, the application layer protocol header can be composed of n bytes to represent different types of data. Preferably, the number of data types does not exceed 2 n 。
[0064] Preferably, in the preset inspection rule, the network port of the identification feature may be a specified special destination port. Preferably, the present invention can arbitrarily select a port within the port range of 0 to 65535 that is not occupied by the communication network of the gate networking control system 100 as the identification feature. Preferably, in this embodiment, the preset inspection rule may select port 16000 as the identification feature for authentication data, authentication result data, configuration data, and configuration result data. Preferably, the application layer protocol header in the preset inspection rule may consist of 3 bytes. Among them, 000 represents authentication data, 001 represents authentication result data, 010 represents configuration data, 011 represents configuration result data, and 100 represents working data, so that different types of data have different protocol features.
[0065] Preferably, the network ports of the identification features in the updated inspection rule may include the network port used by the gate networking control system 100 to transmit working data and the network ports used for authentication data, authentication result data, configuration data, and configuration result data. Preferably, the application layer protocol header in the updated inspection rule may also consist of 3 bytes. However, the data types represented by each protocol header may be different from those in the preset inspection rule. For example, in the updated inspection rule, 100 represents authentication data, 010 represents authentication result data, 011 represents configuration data, 001 represents configuration result data, and 000 represents working data. And the updated inspection rules of the IP-free firewalls carried by different security terminals 140 may also be different. Preferably, the IP-free firewalls configured on each security terminal 140 can inspect the data passing through the security terminal 140 according to the inspection rule. If the data passing through the security terminal 140 conforms to the identification feature in the inspection rule, the data will be processed accordingly; if the data passing through the security terminal 140 does not conform to the identification feature in the inspection rule, the data will be invalidated. And the IP-free firewalls configured on each security terminal 140 can set different inspection rules to further increase the difficulty of preventing illegal intrusion by hackers.
[0066] After networking, when the processing device 130 transmits data with the gate 110 or the detection device 120, it can package the transmitted data according to the inspection rule of the IP-free firewall carried by the security terminal 140 connected to the gate 110 or the detection device 120, so that the protocol header of the transmitted data conforms to the inspection rule of the corresponding IP-free firewall.
[0067] In the prior art, when at least one detection device in the detection device 120 is hacked by a hacker, the hacker obtains the control authority of the detection device (such as a camera). The captured image will be sent to the IP address designated by the relevant hacker. Or, when the turnstile 110 is hacked by a hacker, the hacker obtains the control authority of the turnstile. The turnstile 110 can respond to an incorrect access card or face recognition data and let through people who should not be let through. Based on this defect, in the present invention, the first access data and the second access data are set in the first server and the second server that are independent of each other. Preferably, a plurality of first servers and a plurality of second servers are in a wired and / or wireless data connection with the security terminal 140.
[0068] In the present invention, the processing device 130 verifies the security of the data based on the time difference between the time data of the first access data and the second access data, and controls the opening and closing of the turnstile 110. When the time difference between the time data of the first access data and the second access data is within the allowable range, the processing device 130 confirms that the opening instruction and the closing instruction of the turnstile are valid. When the time difference between the time data of the first access data and the second access data exceeds the allowable range, the processing device 130 confirms that the opening instruction and the closing instruction of the turnstile are invalid. When a hacker obtains the image of a single detection device or obtains the control right of the turnstile 110, since the hacker does not have the information on the allowable range of the time difference between the time data of the first access data and the second access data, it will cause the first access data and the second communication data to not be co-verified. Therefore, even if the hacker only controls the turnstile 110, the detection device 120 cannot obtain the instruction information that passes the verification. The detection device 120 will send a warning message to the processing device 130 based on the release behavior of the turnstile 110.
[0069] On the contrary, if the detection device 120 is hacked by a hacker and the captured picture is sent to the designated IP address, it will cause the second access data coordinated with the first access data of the turnstile 110 to be missing. Then, when the processing device 130 fails to co-verify the first access data and the second communication data, it refuses to open the turnstile 110 and will not let through irrelevant people.
[0070] In the actual operation process, since the security terminal 140 is set to package the working data, it is difficult for a hacker to obtain the first access data and the second access data simultaneously through the IP address, which increases the difficulty for the hacker to obtain the co-verification principle of the first access data and the second access data.
[0071] Preferably, the IP-free firewall installed on the security terminal 140 processes the working data received or sent by the turnstile 110 and the detection device 120 according to the inspection rules. Preferably, the processing of the working data by the IP-free firewall includes: independently packaging the working data sent by the turnstile 110 and the detection device 120 respectively, and inspecting the working data received by the turnstile 110 and the detection device 120. Preferably, in the case where the working data passes the security inspection, the security terminal 140 releases the working data; otherwise, the security terminal 140 intercepts the working data to make it invalid. Preferably, in the case where the security terminal 140 completes the security packaging of the sent data, the protection component sends the securely packaged sent data to the target device, so that the securely packaged working data can pass the security inspection of the security terminal 140 and / or the protection management module 132 provided in front of the target device, thereby successfully completing the data transmission.
[0072] Preferably, the security terminal 140 generates an operation log of the IP-free firewall and uploads the operation log to the processing device 130, so that the processing device 130 can supervise the data transmission situation between the processing device 130 and the turnstile 110 or between the processing device 130 and the detection device 120 by verifying the local operation log and the operation log of the IP-free firewall.
[0073] In the present invention, when a hacker tries to crack the turnstile 110 or the detection device 120 again, due to the lack of collaboratively verified working data, the security inspection cannot be passed, resulting in the captured image data being unable to pass through the security terminal alone and being intercepted by the security terminal 140.
[0074] Preferably, the processing device 130 can determine the data receiving and sending situations of the processing device 130, the turnstile 110, and the detection device 120 based on the local operation log and the operation log of the IP-free firewall. Preferably, the protection management module 132 configured in the processing device 130 can determine whether there is any missed sending or missed control between the processing device 130 and the turnstile 110 by comparing the data receiving and sending situations of the processing device 130 and the turnstile 110. Preferably, the protection management module 132 can also determine whether there is any missed sending or missed control between the processing device 130 and the detection device 120 by comparing the data receiving and sending situations of the processing device 130 and the detection device 120.
[0075] That is, when the first passage data and the second passage data cannot be collaboratively verified, it is very easy to detect the phenomenon of missed sending or missed control of a certain device, so as to intercept the data or give an early warning in time.
[0076] Preferably, the components of the gate networking control system 100 provided by the present invention can be divided into two categories. One category is the functional components for realizing intelligent regulation of the gate, including the operation management module 131, the gate 110, the detection device 120, etc. The other category is the protection components for protecting the communication network security of the functional components such as the operation management module 131, the gate 110, and the detection device 120. The protection components can include a protection management module 132 and several security terminals 140.
[0077] Preferably, the operation management module 131, the gate 110, and the detection device 120 can be data-connected through a wireless communication network, such as a local area network. The operation management module 131 can obtain the environmental parameters collected by the detection device 120 through the wireless communication network and generate control instructions transmitted to the gate 110 through the wireless communication network based on the environmental parameters to adjust the working parameters of the gate 110. Preferably, the gate networking control system 100 provided by the present invention can protect each functional component in the gate networking control system 100 by connecting the security terminal 140 to the gate 110 and the detection device 120 that need to be protected for communication network security and connecting the protection management module 132 to the operation management module 131. Preferably, a non-IP firewall is installed in the security terminal 140, and the protection management module 132 can configure the non-IP firewalls installed in each security terminal 140.
[0078] Preferably, the protection management module 132 and the operation management module 131 are arranged in the processing device 130, so that the protection management module 132 can utilize the existing communication architecture between the operation management module 131 and the gate 110 and the detection device 120 for communication security management without reconstructing the communication architecture. Preferably, the security terminal 140 is deployed by connecting to the information transmission ports of the gate 110 and the detection device 120, so that the existing network architecture of the on-site equipment does not need to be changed during deployment, and the security terminal 140 can also communicate with the operation management module 131 using the existing network architecture of the on-site equipment without additional IP address allocation.
[0079] Preferably, the protection management module 132 and the security terminal 140 protect the data transmission of each functional component in the gate networking control system 100, thereby constructing a protection network with the functional components of the gate networking control system 100 as the protection targets. Preferably, in the gate networking control system 100 provided by the present invention, the protection management module 132 is set at the information transmission port of the operation management module 131, so that the protection management module 132 can provide security protection for the operation management module 131. Preferably, the protection management module 132 can effectively control the content publishing permission of the operation management module 131 and intercept illegal access. Preferably, the protection management module 132 can also cooperate with the security terminal 140 to isolate invalid broadcast packets and malicious access in the communication network.
[0080] Preferably, the turnstile 110 and the detection device 120 can be networked with the processing device 130 through the security terminal 140. Preferably, the protection management module 132 can configure each security terminal 140, so as to network the protected turnstile 110 and detection device 120 with the processing device 130.
[0081] S1: Identify and process the data.
[0082] As Figure 5 shown, the protection components composed of the protection management module 132 and the security terminal 140 can identify and process the data sent and received by the functional components composed of the operation management module 131, the turnstile 110 and the detection device 120.
[0083] Preferably, the identification and processing may include: when the functional components such as the operation management module 131, the turnstile 110 and the detection device 120 receive data, the protection management module 132 or the security terminal 140 in the protection components performs a security check on the received data. When the functional components send data, the protection components perform security packaging on the sent data.
[0084] Since the security terminal 140 is equipped with a non-IP firewall, the protection management module 132 of the processing device 130 cannot determine whether the device corresponding to the IP address is the turnstile 110 and the detection device 120 inside the communication network of the gate networking control system 100 or an external device invading the communication network according to the IP address.
[0085] S2: Send authentication data.
[0086] As Figure 5As shown, the protection management module 132 can send authentication data to multiple IP addresses in the communication network. Preferably, the authentication data may include the IP address and MAC address of the protection management module 132. If a security terminal 140 is deployed in front of the protected turnstile 110 or detection device 120, the authentication data is captured by the security terminal 140, and the security terminal 140 generates a response and replies to the protection management module 132; if the authentication data does not pass through the security terminal 140, the authentication data becomes invalid.
[0087] Preferably, when the authentication data passes through the security terminal 140, the security terminal 140 first detects the destination port of the authentication data. If the destination port conforms to the rule, it continues to detect the application layer protocol header. If the security terminal 140 detects the application layer protocol header, the security terminal 140 processes the authentication data.
[0088] S3: Parse the authentication data and send authentication result data to the protection management module 132.
[0089] As Figure 5 shown, the processing of the authentication data by the security terminal 140 may include parsing the received authentication data, extracting the IP address and MAC address of the protection management module 132 in the authentication data and saving them locally in the security terminal 140, and then editing the MAC address of the security terminal 140 and the IP address of the protected turnstile 110 or detection device 120 into authentication result data and sending it to the protection management module 132.
[0090] Preferably, the security terminal 140 determines the communication address of the recipient of the authentication result data by reading the IP address and MAC address of the protection management module 132 obtained by parsing the received authentication data, and then sends the authentication result data to the protection management module 132. Preferably, the encapsulation of the authentication result data by the security terminal 140 includes: using the MAC address of the security terminal 140 and the IP address of the protected turnstile 110 or detection device 120 as the data content and adding a preset application layer protocol header.
[0091] Preferably, in response to receiving the authentication result data, the protection management module 132 parses it to obtain the MAC address of the security terminal 140 and the IP address of the protected turnstile 110 or detection device 120, and then determines the specific turnstile 110 or detection device 120 protected by the security terminal 140, and saves this information in the protection management module 132.
[0092] Preferably, the protection management module 132 traverses all IP addresses in the communication network, sends authentication data to them, and then determines the IP address of the turnstile 110 or detection device 120 protected by the security terminal 140 by receiving and parsing the authentication result data.
[0093] Preferably, based on the determination of the IP address of the protected turnstile 110 or detection device 120 in the communication network, the protection management module 132 sends configuration data capable of configuring the IP-free firewall carried by the security terminal 140 to the protected turnstile 110 or detection device 120. Preferably, the configuration data may include a custom application layer protocol header and inspection rules.
[0094] Preferably, the configuration data is captured by the security terminal 140 when passing through the security terminal 140 connected in front of the data transceiver port of the turnstile 110 or detection device 120.
[0095] Preferably, after the security terminal 140 captures the configuration data, the security terminal 140 first detects the destination port of the configuration data. If the destination port conforms to the rule, it continues to detect the application layer protocol header. If the security terminal 140 detects the application layer protocol header, the security terminal 140 parses the configuration data to obtain the inspection rules in the configuration data. Preferably, the security terminal 140 generates security rules for the IP-free firewall according to the inspection rules in the configuration data, and the security terminal 140 sends the log information of the security rules as configuration result data to the protection management module 132.
[0096] Preferably, the security terminal 140 uses the IP address and MAC address of the protection management module 132 saved locally in the security terminal 140 as the communication address of the configuration result data recipient, and then sends the configuration result data to the protection management module 132. Preferably, when editing the configuration result data, the security terminal 140 uses the log information of the security rules of the IP-free firewall carried by the security terminal 140 as the data content, adds a custom application layer protocol header, and uploads the data to the protection management module 132 after data encapsulation.
[0097] Preferably, after receiving the configuration result data containing the configuration result information, the protection management module 132 confirms that the security rules configuration of the IP-free firewall carried by the security terminal 140 is successful, and the protection management module 132 parses the configuration result data to obtain the security rules of the IP-free firewall in the security terminal 140 and saves them to the database.
[0098] Preferably, the security terminal 140 and the protection management module 132 can use the iptables software firewall and netfilter framework in the Linux system to implement the identification of data types. Preferably, when transmitting data, the security terminal 140 and the protection management module 132 can specify a special destination port as the identification feature of the data.
[0099] Preferably, the security terminal 140 can process the data received or sent by the turnstile 110 and the detection device 120, and generate an operation log for uploading to the protection management module 132, so that the protection management module 132 can adjust the inspection rules of the security terminal 140 based on the operation log uploaded by the security terminal 140.
[0100] Preferably, the protection management module 132 can update the inspection rules of the security terminal 140 irregularly based on preset rules. Preferably, each security terminal 140 can adopt different inspection rules. Preferably, the security terminal 140 and the protection management module 132 can further enhance the security of the protection network by updating the inspection rules of the security terminal 140 irregularly.
[0101] Preferably, the protection management module 132 can monitor the data transmission situation between the processing device 130 and the turnstile 110 or between the processing device 130 and the detection device 120 based on the local operation log and the operation log uploaded by the security terminal 140.
[0102] Preferably, the operation log of the protection management module 132 is the first operation log, and the operation log of the security terminal 140 is the second operation log. The protection management module 132 can determine the data receiving and sending situation of the processing device 130, the turnstile 110, and the detection device 120 based on the first operation log and the second operation log. Preferably, the protection management module 132 can determine whether there is any omission in sending or controlling between the processing device 130 and the turnstile 110 by comparing the data receiving and sending situation of the processing device 130 with that of the turnstile 110. Preferably, the protection management module 132 can also determine whether there is any omission in sending or controlling between the processing device 130 and the detection device 120 by comparing the data receiving and sending situation of the processing device 130 with that of the detection device 120.
[0103] Preferably, the protection management module 132 or the security terminal 140 can also perform marking processing on the data sent by the functional components. Preferably, the marking processing can include adding information marks to the data, so that the protection management module 132 can determine whether the data has been transmitted by verifying whether the information marks in the local operation log are consistent with the information marks in the operation log uploaded by the security terminal 140.
[0104] Preferably, the information marks can be recorded in the operation log by the protection management module 132 and the security terminal 140 as the identity certificates of the data, so that the protection management module 132 can check the first operation log and the second operation log according to the information marks, thereby determining the transmission track of the data corresponding to the information marks, and further determining whether the data has been transmitted.
[0105] Preferably, when a data transmission failure occurs between the processing device 130 and the turnstile 110 or between the processing device 130 and the detection device 120, the protection management module 132 can notify the faulty device to re - receive or re - send the transmission - failed data.
[0106] In a traditional turnstile system, since its control system is vulnerable to intrusion or tampering of management information, the turnstile networking control system 100 of the turnstile generally will not be assigned important management tasks, nor will it conduct joint management with a third - party platform or system. In the turnstile networking control system of the present invention, since it is provided with an IP firewall and operates according to preset inspection rules, its security performance is significantly improved. Therefore, it is more likely to be accepted by a third - party platform or system to implement partial management tasks and achieve service upgrade in terms of services. Preferably, the turnstile networking control system 100 adjusts the flow line of people in the controlled area of the turnstile 110 by adjusting the passing direction of the turnstile 110.
[0107] Preferably, the turnstile networking control system 100 can also establish a communication connection with a third - party service system. Preferably, the turnstile networking control system 100 can send the passing information of the turnstile 110 to the third - party service system, so that the third - party service system can provide services that fit the flow line of people based on the passing information of the turnstile 110.
[0108] Preferably, when the turnstile 110 is set at a transportation hub such as a subway station, the third - party service system can be a shared - bike dispatching system. Preferably, when the turnstile networking control system 100 adjusts the flow line of people in the subway station by adjusting the passing direction of the turnstile 110 in the subway station, the turnstile networking control system 100 can send the adjustment situation of the passing direction of the turnstile 110 to the shared - bike dispatching system. In response to receiving the passing - direction adjustment situation, the shared - bike dispatching system sets the exit of the main flow line of people in the subway station as the vehicle dropping point and the entrance of the main flow line of people in the subway station as the vehicle collection point to conduct shared - bike dispatching.
[0109] Preferably, the specific way for the turnstile networking control system 100 to adjust the flow line of people in the subway station can be:
[0110] S4: The operation management module 131 monitors the passing situation of people in the station through the detection device 120. In the case of congestion in the station, the operation management module 131 can generate a control instruction to adjust the passing direction of the turnstile 110 near the congested area, change the flow line of people in the subway station, and thus relieve the congestion.
[0111] Preferably, when adjusting the flow line of the personnel in the station, the operation management module 131 can send the adjustment situation of the passing direction of the turnstile 110 to the shared bicycle dispatching system, so that the shared bicycle dispatching system can dispatch shared bicycles according to the adjusted personnel flow line in the subway station.
[0112] Preferably, a plurality of first turnstiles 111 can be set at the first entrance and exit of the subway station; and a plurality of second turnstiles 112 can be set at the second entrance and exit; the first detection device 121 can be a camera monitoring the first entrance and exit of the subway station; the second detection device 122 can be a camera monitoring the second entrance and exit of the subway station. Preferably, the first turnstiles 111 set at the first entrance and exit and the second turnstiles 112 set at the second entrance and exit are provided, and both the first turnstiles 111 and the second turnstiles 112 include entrance turnstiles and exit turnstiles. Preferably, the first turnstiles 111 or the second turnstiles 112 can switch between the entrance turnstiles and the exit turnstiles by changing the passing direction.
[0113] Preferably, the operation management module 131 of the processing device 130 can determine the personnel flow situation at each entrance and exit of the subway station through the images collected by the first detection device 121 or the second detection device 122, and then adjust the working parameters of the first turnstiles 111 and the second turnstiles 112. Preferably, the working parameters of the first turnstiles 111 and the second turnstiles 112 can include the passing direction of the turnstiles. Preferably, when the operation management module 131 determines that there is congestion of personnel at the first entrance and exit or the second entrance and exit of the subway station through the images collected by the first detection device 121 or the second detection device 122, the operation management module 131 can adjust the working parameters of the first turnstiles 111 and the second turnstiles 112 by judging the ratio of the inbound crowd to the outbound crowd. Preferably, in the case of congestion at the first entrance and exit due to a large number of outbound personnel, the operation management module 131 can generate a control instruction to change the passing direction of some of the first turnstiles 111, so that some of the first turnstiles 111 serving as entrance turnstiles are converted into exit turnstiles, thereby increasing the number of outbound channels at the first entrance and exit. And in the case of congestion at the first entrance and exit due to a large number of outbound personnel, the operation management module 131 can also determine the personnel congestion situation at the second entrance and exit of the subway station through the images collected by the second detection device 122. If the number of users at the second entrance and exit of the subway station is small, the operation management module 131 can generate a control instruction and send it to the second turnstiles 112 to change the passing direction of some of the second turnstiles 112, so that some of the second turnstiles 112 serving as entrance turnstiles are converted into exit turnstiles, so that the outbound personnel can leave the subway station through the second turnstiles 112 channels, thereby adjusting the personnel flow line in the subway station and avoiding or alleviating the generation of congestion.
[0114] Preferably, the operation management module 131 may send the adjusted personnel flow line adjustment to the shared bicycle dispatching system. Preferably, according to the adjusted personnel flow line, the shared bicycle dispatching system may determine that the personnel passing through the first and second entrances and exits of the subway station are mainly outbound personnel, and there is a demand for the use of shared bicycles. Therefore, the shared bicycle dispatching system may set the first and second entrances and exits of the subway station as vehicle placement points for shared bicycle dispatching.
[0115] Preferably, when the operation management module 131 detects through the detection device 120 that there is congestion of inbound personnel at the first entrance and exit, the operation management module 131 may generate a control instruction to change the passing direction of some of the first turnstiles 111, so that some of the first turnstiles 111 serving as outbound turnstiles are converted into inbound turnstiles, thereby increasing the number of inbound channels at the first entrance and exit. Preferably, the operation management module 131 sends the adjustment situation of the passing direction of the first turnstiles 111 to the shared bicycle dispatching system, so that the shared bicycle dispatching system can learn that the number of inbound personnel at the first entrance and exit of the subway station has increased, that is, the number of idle shared bicycles near the first entrance and exit of the subway station has increased. The shared bicycle dispatching system may set the first entrance and exit of the subway station as a vehicle collection point and dispatch the shared bicycles parked at the first entrance and exit to other locations.
[0116] Preferably, the turnstiles 110 may also be set at the entrances and exits of the hospital, and the turnstile networking control system 100 may adjust the personnel flow line in the hospital by adjusting the working parameters of the turnstiles 110. Preferably, when the turnstiles 110 are set at the entrances and exits of the hospital, the third-party service system may be the epidemic analysis system of the hospital.
[0117] Preferably, when the turnstiles 110 are set at the entrances and exits of the hospital, the turnstile networking control system 100 may adjust the passing state of the turnstiles 110 according to the change in the number of hospital patients. Most of the existing hospital visiting channels are set as one-way channels to avoid the intersection of the waiting population and the population that has completed the visit, reducing the risk of cross-infection. Preferably, the operation management module 131 may monitor the personnel flow situation at the hospital entrance and exit according to the detection device 120. Preferably, the operation management module 131 may adjust the opening number of the turnstiles 110 at the hospital entrance and exit according to the personnel flow situation obtained from the detection device 120. Preferably, when the operation management module 131 detects through the detection device 120 that there is a crowd gathering at the hospital entrance, the operation management module 131 may generate a control instruction to increase the opening number of the turnstiles 110 at the hospital entrance, thereby increasing the number of hospital visiting channels.
[0118] Preferably, the operation management module 131 sends the adjustment situation of the turnstiles 110 at the entrances and exits of the hospital to the epidemic analysis system. Preferably, when the operation management module 131 generates a control instruction to increase the number of turnstiles 110 opened at the hospital entrance, the epidemic analysis system can, according to the change in the number of patients seeking medical treatment, especially the increase in the number of admitted patients, retrieve the medical records of the patients seeking medical treatment from the hospital's database, so as to determine the types of diseases that cause the increase in the number of patients seeking medical treatment and judge whether it enters the epidemic period of this disease.
[0119] Preferably, the specific method for the epidemic analysis system to judge the epidemic period of a disease can be: retrieving the medical records of the patients seeking medical treatment from the hospital's database; screening out the cases located within the radiation range of the hospital with the patient's place of residence as the screening condition; classifying and counting the screened cases according to the types of diseases to determine the number of patients seeking medical treatment for each disease; comparing the number of patients seeking medical treatment for each disease with the historical number of patients seeking medical treatment for this disease to judge whether this disease has entered the epidemic period. Preferably, the historical number of patients seeking medical treatment for a disease can be the number of patients with this disease received by the hospital the previous day, or the daily average value of the number of patients with this disease received by the hospital within a preset time, such as the daily average value of the number of patients with this disease received by the hospital last month. Preferably, the epidemic analysis system can determine that a disease has entered the epidemic period when the number of patients seeking medical treatment for a certain disease exceeds 30% of the historical number of patients seeking medical treatment for this disease.
[0120] Preferably, the epidemic analysis system can obtain the epidemic situation in the radiation area of the hospital through the above method. Preferably, after determining that a certain disease has entered the epidemic period, the epidemic analysis system can push the prevention knowledge of this disease to the community residents in the radiation area of the hospital through the hospital's information push platform to reduce the incidence rate of the community residents. The epidemic analysis system can also send a reminder to the hospital's material management system, so that the material management system reserves relevant materials for the epidemic to cope with the increasing number of epidemic patients, ensure that epidemic patients can receive timely treatment when seeking medical treatment, and avoid the situation of medical resource crunch.
[0121] Preferably, due to the differences in the communication protocols, information transmission ports, etc. of different turnstiles 110 and detection devices 120, there are both synchronous and asynchronous communication architectures in the communication network after networking. When the amount of data transmitted by the turnstiles 110 and detection devices 120 is large, in order to reduce the data processing volume of the security terminal 140 and the turnstiles 110 and detection devices 120, some devices in the communication network of the turnstile networking control system 100 can adopt a mechanism of sending without feedback to transmit data. At this time, the data transmission situation in the communication network is monitored by the protection management module 132 and the security terminal 140.
[0122] Preferably, when the image data collected by the first detection device 121 is sent to the processing device 130, the third security terminal 143 connected to the first detection device 121 can add an information tag to the image data. Preferably, the information tag can be a time tag of the image data passing through the third security terminal 143. Preferably, the time tag can include the address of the data sending device, the address of the data receiving device, and the moment when the data leaves the security terminal 140. Preferably, the third security terminal 143 records the time tag in its own operation log and uploads it to the protection management module 132 along with the operation log. Preferably, the protection management module 132 reads the time tag in the data when receiving the data and records it in the operation log. Preferably, the protection management module 132 can determine whether the data transmission is completed by comparing the time tags in its own operation log with the time tags in the operation log uploaded by the third security terminal 143. Preferably, if the same time tag appears in the first operation log and the second operation log, the data transmission is completed; if the same time tag does not appear in the first operation log and the second operation log, the data fails. Preferably, when the data transmission fails, the protection management module 132 can notify the data sending device to resend the failed data. For example, when the time tag corresponding to the image data collected by the first detection device 121 recorded in the second operation log uploaded by the third security terminal 143 does not appear in the first operation log of the protection management module 132, the protection management module 132 can notify the first detection device 121 to transmit the collected image data again.
[0123] Preferably, the gateway networking control system 100 provided by the present invention can provide information security protection through the protection network constructed by the security terminal 140 and the protection management module 132, prevent user information leakage, and avoid the situation that the gateway 110 is not controlled or the gateway 110 does not perform adjustment.
[0124] Embodiment 2
[0125] This embodiment is a further improvement of Embodiment 1, and repeated content will not be elaborated.
[0126] This embodiment provides a method for controlling the networking of the gateway 110. The method for controlling the networking of the gateway 110 may include: setting a security terminal 140 equipped with a non-IP firewall at the information transmission ports of the gateway 110 and the detection device 120, so as to process the data received or sent by the gateway 110 or the detection device 120; the processing device 130 communicates with the security terminal 140 using the IP addresses of the gateway 110 and the detection device 120, and configures the non-IP firewall carried by the security terminal 140.
[0127] Preferably, the security terminal 140 can be deployed at the information transmission ports of the turnstile 110 and the detection device 120 to communicate using the network architecture of the existing on-site devices without changing the existing on-site device network architecture. Preferably, the security terminal 140 can be set at the information transmission ports of the turnstile 110 and the detection device 120, so that the security terminal 140 can communicate using the IP addresses of the turnstile 110 and the detection device 120 without additional IP address allocation.
[0128] Preferably, the turnstile 110 networking control method further includes: generating an operation log of the IP-free firewall carried by the security terminal 140 for processing data received or sent by the turnstile 110 and the detection device 120; supervising the data transmission conditions of the turnstile 110 and the detection device 120 according to the operation log.
[0129] Preferably, the operation log includes the first operation log of the protection management module 132 and the second operation log of the security terminal 140. The protection management module 132 can determine the data reception and transmission conditions of the processing device 130, the turnstile 110, and the detection device 120 based on the first operation log and the second operation log, and then determine whether there are any missed transmissions or missed controls between the processing device 130 and the turnstile 110, and whether there are any missed transmissions or missed controls between the processing device 130 and the detection device 120.
[0130] It should be noted that the above specific embodiments are exemplary. Those skilled in the art can come up with various solutions inspired by the disclosed content of the present invention, and these solutions also fall within the scope of the disclosure of the present invention and within the protection scope of the present invention. Those skilled in the art should understand that the specification and drawings of the present invention are illustrative and do not constitute a limitation on the claims. The protection scope of the present invention is defined by the claims and their equivalents. Throughout the text, the features guided by "preferably" are only an optional way and should not be understood as being required to be set. Therefore, the applicant reserves the right to waive or delete relevant preferred features at any time. The specification of the present invention contains multiple inventive concepts. Phrases such as "preferably", "according to a preferred embodiment", or "optionally" indicate that the corresponding paragraphs disclose an independent concept. The applicant reserves the right to file divisional applications based on each inventive concept.
Claims
1. A gate networking control system, characterized in that, the gate networking control system at least includes: a gate (110), a detection device (120), a processing device (130) and a security terminal (140); The security terminal (140) without an IP firewall is set at the information transmission ports of the gate (110) and the detection device (120) to process the data received or sent by the gate (110) and the detection device (120); The processing device (130) sends authentication data to the gate (110) and the detection device (120), and the IP-firewall-free carried by the security terminal (140) identifies and processes the authentication data according to a preset inspection rule. When the IP-firewall-free confirms that the authentication data conforms to the preset inspection rule, the gate (110) and the detection device (120) communicate with the processing device (130) to form a network; The gate networking control system generates first passage data related to time based on the opening and closing data of the barrier rod (118) of the gate (110) and stores the first passage data in a first server. The detection device (120) generates second passage data related to time based on the collected image data of the opening and closing of the barrier rod (118) and stores the second passage data in a second server. The first server and the second server are independent of each other, and the first time of the first passage data is not synchronized with the second time of the second passage data. The processing device (130) verifies the security of the data based on the time difference of the time data of the first passage data and the second passage data, and controls the opening and closing of the gate (110).
2. The gate networking control system according to claim 1, characterized in that, the authentication data at least includes the IP address of the processing device (130); When it is confirmed that the authentication data conforms to the preset inspection rule, the security terminal (140) saves the IP address of the processing device (130) locally to the security terminal (140) and sends authentication result data including the IP address of the gate (110) or the detection device (120) to the processing device (130).
3. The gate networking control system according to claim 2, characterized in that, In response to the receipt of the authentication result data, the processing device (130) sends configuration data including an IP-firewall-free inspection rule update scheme to the IP address of the gate (110) or the detection device (120); The IP-firewall-free carried by the security terminal (140) identifies and processes the configuration data according to a preset inspection rule; When it is confirmed that the configuration data conforms to the preset inspection rule, the security terminal (140) configures the IP-firewall-free carried according to the update scheme and sends configuration result data reflecting the successful configuration of the IP-firewall-free to the processing device (130).
4. The gate networking control system according to claim 3, characterized in that, In response to receiving the configuration result data, the processing device (130) confirms that the update of the inspection rules of the IP-free firewall installed on the security terminal (140) is successful, and saves the successfully updated inspection rules of the IP-free firewall installed on the security terminal (140) and the IP addresses of the turnstile (110) or the detection device (120) connected to the security terminal (140) to the database.
5. The turnstile networking control system according to claim 4, wherein, when the processing device (130) confirms that the update of the inspection rules of the IP-free firewall installed on the security terminal (140) is successful, the processing device (130) performs networking communication with the turnstile (110) and the detection device (120) that are connected to the security terminal (140) at the information transmission port, so as to transmit the working data for regulating the working parameters of the turnstile (110).
6. The turnstile networking control system according to claim 5, wherein, the IP-free firewall installed on the security terminal (140) processes the working data received or sent by the turnstile (110) and the detection device (120). The processing of the working data by the IP-free firewall includes: independently packaging the working data sent by the turnstile (110) and the detection device (120) respectively, and inspecting the working data received by the turnstile (110) and the detection device (120).
7. The turnstile networking control system according to claim 6, wherein, the security terminal (140) generates an operation log of the IP-free firewall and uploads the operation log to the processing device (130), so that the processing device (130) supervises the data transmission situation between the processing device (130) and the turnstile (110) or between the processing device (130) and the detection device (120) by verifying the local operation log and the operation log of the IP-free firewall.
8. The turnstile networking control system according to claim 1, wherein, the inspection rules include the identification features of different types of data and the processing measures for the corresponding types of data.
9. A method of using the turnstile networking control system according to any one of claims 1 to 8, wherein, the method at least includes: setting a security terminal (140) equipped with an IP-free firewall at the information transmission ports of the turnstile (110) and the detection device (120), so as to process the data received or sent by the turnstile (110) or the detection device (120); the processing device (130) communicates with the security terminal (140) using the IP addresses of the turnstile (110) and the detection device (120), and configures the IP-free firewall installed on the security terminal (140).
10. The method according to claim 9, wherein, the method further includes: Generate an operation log for processing the data received or sent by the IP-free firewall installed on the security terminal (140) for the turnstile (110) and the detection device (120); Supervise the data transmission conditions of the turnstile (110) and the detection device (120) according to the operation log.
Citation Information
Patent Citations
Method and system for protecting safety of gate Internet of Things based on commercial password
CN113783868A
Subway pedestrian flow dynamic monitoring and high-precision identification gate system
CN110807859A
Distributed information network security protection method and system and readable storage medium thereof
CN116566682A
Medical equipment networking system and method
CN116707942A