Method and system for identifying security events in access control system

By using the AI/ML engine to identify and deal with unauthorized access in the access control system, the problem of difficulty in identifying and dealing with unauthorized access in a timely manner is solved, and higher security and reputation protection is achieved.

CN120068133APending Publication Date: 2025-05-30HONEYWELL INTERNATIONAL INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411675401.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-11-28
Filing Date
2024-11-21
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

Existing access control systems are difficult to identify and deal with the use of access control keys by unauthorized individuals in a timely manner, resulting in the possibility of unauthorized entry, endangering security and reputation.

Method used

Introducing artificial intelligence and machine learning (AI/ML) engines in the access control system, analyzing user, timestamp and location information in the access request, identify abnormal access behaviors, and issue an alarm or take corrective measures after confirmation by the security operator.

Benefits of technology

Effectively identify and respond to unauthorized access, improve security, reduce potential security threats and reputation damage, and ensure the reliability and effectiveness of access control systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068133A_ABST
    Figure CN120068133A_ABST
Patent Text Reader

Abstract

The invention relates to a method and a system for identifying security events in an access control system. An access control system includes an access control device for reading access control keys, each access control key associated with a corresponding one of a plurality of authorized users of the facility. The access requests from the access control device are presented to an artificial intelligence and / or machine learning (AI / ML) engine that identifies one or more of the plurality of access requests as tagged access requests that represent possible security events of the facility. One or more images from a security camera that captures a tagged access request are displayed for viewing by a security operator, and the security operator inputs a response that classifies the tagged access request as a legitimate access request or an illegal access request. An alert is issued when the response classifies the tagged access request as an illegal access request.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to access control systems, and more particularly to using artificial intelligence in an access control system to determine when an access control key is being misused. Background Art

[0002] Access control systems employ a large number of access control keys. An individual can present their access control key to an access control device so that the access control device can identify the individual and determine whether the individual is authorized to enter a space protected by the access control device. The access control key may be lost, but the individual may not immediately realize that their access control key has been lost or misplaced. After a few days, the individual will likely report that the access control key has been lost, resulting in the access control key being disabled and thus no longer available. However, until then, the access control key will remain valid and may be used by an individual who is not authorized to access the space protected by the access control device. This could mean that an individual may enter a building or a restricted area within a building without authorization, potentially endangering the safety of employees and valuable assets. This could mean that an individual may steal or damage property, including sensitive data, equipment, or other valuable assets. This could mean damage to the organization's reputation, resulting in loss of customer trust, negative media coverage, and a reduction in business opportunities. What is desired are methods and systems that allow an access control system to determine when an access control key is being used by an unauthorized individual. Summary of the Invention

[0003] The present disclosure generally relates to access control systems and, more particularly, to using artificial intelligence in an access control system to determine when an access control key is being misused. An example may exist in a method for using an access control system to identify security events in a facility, the access control system controlling access rights in the facility. The access control system includes one or more access control devices, each access control device located at a corresponding location in the facility for reading an access control key, each access control key being associated with a corresponding one of a plurality of authorized users of the facility. The exemplary method includes receiving a plurality of access requests from the one or more access control devices of the facility, wherein each access request of the plurality of access requests is generated in response to one of the access control keys being presented to one of the access control devices. Each access request of the plurality of access requests identifies: a particular authorized user associated with the access control key of the corresponding access request; a timestamp associated with the corresponding access request; a location identifier that identifies the location of the access control device associated with the corresponding access request. The plurality of access requests are presented to an artificial intelligence and / or machine learning (AI / ML) engine. The AI / ML engine identifies one or more of the plurality of access requests as flagged access requests, the flagged access requests indicating a possible security event in the facility. The exemplary method includes automatically displaying on a display one or more images from a security camera that captured the flagged access request for a security operator to view and receiving a response input by the security operator, wherein the response classifies the flagged access request as a legitimate access request or an illegal access request. The AI / ML engine is trained based on the flagged access request and the corresponding response received. When the response classifies the flagged access request as an illegal access request, an alarm is issued and / or corrective action is taken.

[0004] Another example may exist in an access control system for a facility. The exemplary access control system includes: one or more access control devices, each access control device located at a corresponding location in the facility for reading an access control key, each access control key being associated with a corresponding one of a plurality of authorized users of the facility; a display; one or more security cameras; a controller operatively coupled to the one or more access control devices, the display, and the one or more security cameras. The controller is configured to receive a plurality of access requests from the one or more access control devices, wherein each access request of the plurality of access requests is generated in response to one of the plurality of access control keys being presented to one of the access control devices, and wherein each access control key of the plurality of access control keys is associated with a specific one of the plurality of authorized users of the facility. The controller is configured to present the plurality of access requests to an artificial intelligence and / or machine learning (AI / ML) engine. The AI / ML engine is trained to learn the access behavior patterns of each of the plurality of authorized users over time and at the one or more access control devices. The AI / ML engine determines when any particular access request represents an anomaly in the learned access behavior pattern of the corresponding authorized user, thereby generating a flagged access request. When the AI / ML engine determines that a particular access request represents a flagged access request, the controller is configured to display on the display one or more images from one or more of the security cameras that captured the flagged access request for a security operator to view on the display. The controller is configured to receive a response from the security operator that classifies the flagged access request as a legitimate access request or an illegal access request. The controller retrains the AI / ML engine based on the flagged access request and the corresponding response received. The controller is configured to issue an alert and / or take corrective action when the response classifies the flagged access request as an illegal access request.

[0005] Another example may reside in a non-transitory computer-readable medium storing instructions that, when executed by one or more processors, cause the one or more processors to receive a plurality of access requests from one or more access control devices of a facility, where each access request of the plurality of access requests is generated in response to one of a plurality of access control keys being presented to one of the access control devices, and where each access control key of the plurality of access control keys is associated with a particular one of a plurality of authorized users of the facility. Cause the one or more processors to present the plurality of access requests to an artificial intelligence and / or machine learning (AI / ML) engine that is trained to learn access behavior patterns of each of the plurality of authorized users over time and at one or more access control devices. The AI / ML engine determines whether any particular access request represents an anomaly in the learned access behavior pattern of the corresponding authorized user, thereby generating a flagged access request. When the AI / ML engine determines that a particular access request represents a flagged access request, cause the one or more processors to display, on a display, one or more images from a security camera that captured the flagged access request for a security operator to view. Cause the one or more processors to receive a response from the security operator, where the response classifies the flagged access request as a legitimate access request or an illegal access request, and when the response classifies the flagged access request as an illegal access request, issue an alert and / or take corrective action.

[0006] The foregoing invention content is provided to facilitate understanding of some innovative features specific to the present disclosure and is not intended as a complete description. A full understanding of the present disclosure can be obtained by taking the entire specification, claims, drawings, and abstract as a whole. Brief Description of the Drawings

[0007] The present disclosure can be more fully understood in light of the following description of various examples in conjunction with the accompanying drawings, in which:

[0008] Figure 1 is a schematic block diagram showing an exemplary access control system;

[0009] Figure 2A 、 Figure 2B and Figure 2C collectively are flowcharts showing an exemplary method for identifying security events;

[0010] Figure 3 is a flowchart showing a series of exemplary steps that one or more processors may perform when executing executable instructions;

[0011] Figure 4 is a flowchart showing an exemplary method; and

[0012] Figure 5 is a flowchart showing an exemplary method.

[0013] While the present disclosure is subject to various modifications and alternative forms, specific details thereof have been shown by way of example in the drawings and will be described in detail. It should be understood, however, that the intention is not to limit the present disclosure to the particular examples described. On the contrary, the intention is to cover all modifications, equivalents, and alternatives falling within the spirit and scope of the present disclosure. Detailed Description

[0014] The following description should be read with reference to the drawings, in which like elements in different drawings are numbered in the same manner. The drawings are not necessarily to scale and depict examples that are not intended to limit the scope of the present disclosure. While examples of various elements are illustrated, those skilled in the art will recognize that many of the examples provided have suitable alternatives that can be utilized.

[0015] It is assumed herein that all numbers are modified by the term "about" unless the context clearly dictates otherwise. The recitation of numerical ranges by endpoints includes all numbers subsumed within that range (e.g., 1 to 5 includes 1, 1.5, 2, 2.75, 3, 3.80, 4, and 5).

[0016] As used in this specification and the appended claims, the singular forms "a," "an," and "the" include plural referents unless the context clearly dictates otherwise. As used in this specification and the appended claims, the term "or" is generally employed in its sense including "and / or" unless the context clearly dictates otherwise.

[0017] It should be noted that the recitation of "one embodiment," "some embodiments," "other embodiments," etc., in the specification is meant to indicate that a particular feature, structure, or characteristic described in connection with the embodiment may be included, but each embodiment may not necessarily include that particular feature, structure, or characteristic. Moreover, these phrases do not necessarily refer to the same embodiment. Additionally, when a particular feature, structure, or characteristic is described in connection with one embodiment, it is contemplated that the feature, structure, or characteristic may be described in connection with other embodiments whether or not explicitly described, unless there is a clear contrary indication.

[0018] Figure 1is a schematic block diagram showing an exemplary access control system 10 that can be deployed within a facility. The exemplary access control system 10 includes one or more access control devices 12, each located at a corresponding location within the facility, labeled 12a and 12b respectively. Although a total of two access control devices 12 are shown, it should be understood that the access control system 10 can include a greater number of access control devices 12, and can have, for example, access control devices 12 adjacent to each security door. Each of the access control devices 12 within the access control devices 12 can be configured to read an access control key, each access control key being associated with a corresponding one of a plurality of authorized users of the facility. In some cases, the access control key can be an access control card that can be scanned by any one of the access control devices 12. In some cases, the access control key can be a user mobile device loaded with an authorized access control key application, an access control key fob, user biometric information such as a fingerprint or retina that can be scanned by the access control devices 12, or any other suitable access control key that can be read or scanned by the access control devices 12.

[0019] The exemplary access control system 10 includes one or more security cameras 14, labeled 14a and 14b respectively. Although a total of two security cameras 14 are shown, it should be understood that the access control system 10 can include a greater number of security cameras 14, and can have, for example, security cameras 14 adjacent to each security door. In some cases, some of the security cameras 14 can be specifically assigned to a particular security door. In some cases, some of the security cameras 14 can be assigned to cover a particular area, and can have a field of view (FOV) that covers one or more security doors simultaneously.

[0020] The exemplary access control system 10 includes a display 16 that can be used to display, for example, video clips and / or live video streams or other images captured by one or more of the security cameras 14. The exemplary access control system 10 includes a controller 18 that is operatively coupled to the access control devices 12, the security cameras 14, and the display 16. The controller 18 can be a local computer, such as a desktop computer or a laptop computer. In some cases, the controller 18 can be a remote computer, such as a cloud-based server. The controller can be implemented within a control panel of the access control system 10. In any case, the controller 18 is configured to receive a plurality of access requests from one or more of the access control devices 12, where each of the plurality of access requests is generated in response to one of a plurality of access control keys being presented to one of the access control devices 12, and where each of the plurality of access control keys is associated with a particular one of a plurality of authorized users of the facility.

[0021] The controller 18 is configured to present the plurality of access requests to an artificial intelligence and / or machine learning (AI / ML) engine 20. For example, the AI / ML engine 20 may appear on a local computer, a remote computer, and / or a control panel of the access control system 10. The AI / ML engine 20 is trained to learn the access behavior patterns of each of the plurality of authorized users over time and on one or more access control devices 12. Based on the baseline, the AI / ML engine 20 determines when any particular access request represents an anomaly of the learned access behavior patterns of the corresponding authorized user, thereby generating a marked access request. When the AI / ML engine 20 determines that the particular access request represents a marked access request, the controller 18 is configured to display one or more images from one or more security cameras 14 that captured the marked access request on the display 16 for viewing by a security operator on the display 16. The controller 18 is configured to receive a response from the security operator, wherein the response classifies the marked access request as a legitimate access request or an illegal access request. The controller 18 is configured to retrain the AI / ML engine 20 based on the flagged access requests and the corresponding received responses, and to issue an alarm and / or take action when the response classifies the flagged access request as an illegal access request.

[0022] In some cases, when the response categorizes the tagged access request as an illegal access request, the controller 18 automatically takes corrective action. In some cases, the corrective action may include locking one or more access control devices 12 to prevent access to the corresponding area of ​​the facility. In some cases, the corrective action may include disabling an access control key associated with a specific authorized user associated with the tagged access request. The corrective action may include both of these actions. In some cases, the corrective action may include dispatching security personnel to handle the tagged access request.

[0023] Figure 2A , Figure 2B and Figure 2CIt is a flowchart of an exemplary method 22 for identifying security events of a facility using an access control system (such as access control system 10) for using access rights in a control facility. The access control system includes one or more access control devices (such as access control device 12), each access control device located at a corresponding location in the facility for reading an access control key, each access control key being associated with a corresponding one of a plurality of authorized users of the facility. Exemplary method 22 includes receiving a plurality of access requests from one or more access control devices of the facility, where each access request in the plurality of access requests is generated in response to one of the access control keys being presented to one of the access control devices, as indicated at block 24. Each access request in the plurality of access requests identifies a specific authorized user associated with the access control key of the corresponding access request, as indicated at block 24a. Each access request in the plurality of access requests identifies a timestamp associated with the corresponding access request, as indicated at block 24b. Each access request in the plurality of access requests identifies a location identifier that identifies the location of the access control device associated with the corresponding access request, as indicated at block 24c.

[0024] The plurality of access requests are presented to an artificial intelligence and / or machine learning (AI / ML) engine (such as AI / ML engine 20). The AI / ML engine identifies one or more of the plurality of access requests as flagged access requests, the flagged access requests indicating a possible security event of the facility, as indicated at block 26. Exemplary method 22 includes automatically displaying on a display (such as display 16) one or more images from a security camera (such as security camera 14) that captured the flagged access request for a security operator to view, as indicated at block 28. A received response is input by the security operator, where the response classifies the flagged access request as a legitimate access request or an illegal access request, as indicated at block 30. Then, the AI / ML engine trains or retrains the AI / ML engine based on the flagged access request and the corresponding received response, as indicated at block 32.

[0025] In some cases, the AI / ML engine can be trained based on a specific access request of a specific authorized user and the learned past behavior of the specific authorized user, where the past behavior is based on the past access requests of the specific authorized user. For example, the learned past behavior of the specific authorized user can include the pattern of the past access requests of the specific authorized user. In some cases, the pattern of the past access requests of the specific authorized user can include the pattern of one or more past access requests of the specific authorized user. In some cases, the pattern of the past access requests of the specific authorized user can include the pattern in the learned space, such as the pattern in one or more access control devices associated with one or more past access requests of the specific authorized user. When the response classifies the flagged access request as an illegal access request, an alert (and / or corrective action) is issued, as indicated at block 34.

[0026] In some cases, as Figure 2B shown, a pre-stored image of the specific authorized user associated with the access control key used in the flagged access request can be automatically retrieved and displayed on the display, as indicated at block 36. This can help the security operator determine whether the flagged access request is legal or illegal.

[0027] In some cases, one or more images from a security camera can be presented to the AI / ML engine associated with one or more of the multiple access requests, as indicated at block 38. The AI / ML engine can be trained based on the one or more images from the security camera to determine whether a specific access request of a specific authorized user is a flagged access request, as indicated at block 40.

[0028] In some cases, the exemplary method 22 can include performing facial recognition on one or more images of the security camera to identify one or more faces associated with one or more of the multiple access requests, as indicated at block 42. The AI / ML engine can be trained based on the one or more images identified through facial recognition to determine whether a specific access request of a specific authorized user is a flagged access request, as indicated at block 44.

[0029] In some cases, an AI / ML engine can be trained over a period of time, at least in part, based on facial recognition performed on real-time images from a security camera capturing an access request and a comparison of the recognized facial features to the facial features of an individual whose access requests were previously categorized (e.g., recently) as legitimate or illegitimate access requests by a security operator review. This intelligence can assist the AI / ML engine itself in making a determination as to whether any particular access request is a flagged access request and / or in categorizing a flagged access request as a legitimate or illegitimate access request. When a flagged access request is categorized as an illegitimate access request by the AI / ML engine, an alert can be issued and / or corrective action can be taken accordingly. Additionally, the AI / ML engine can address facial recognition issues related to aging when the pre-stored image of a particular authorized user is continuously updated with the most recently captured image of that user during any most recent historical flagged access event, which historical flagged access events were categorized as legitimate access requests based on responses from an operator.

[0030] In some cases, method 22 can include determining the severity level of each alert associated with a flagged access request categorized as an illegitimate access request, as indicated at block 46. Method 22 can include automatically taking corrective action at least in part based on the determined severity level, as indicated at block 48. For example, the action can include locking one or more access control devices and / or disabling an access control key associated with a particular authorized user associated with the flagged access request. In some cases, method 22 can include determining the severity level of each alert associated with a flagged access request categorized as an illegitimate access request, as indicated at block 50. In some cases, an alert corresponding to a flagged access request categorized as an illegitimate access request can be displayed on a display.

[0031] As Figure 2CAs shown, method 22 may further include automatically taking corrective measures based on the determined severity level, as indicated at block 54. For example, a severity level of "H" may indicate that a suspicious person is loitering near an area of higher importance (e.g., server room, conference room, generator room, private passenger cabin, locker area, etc.). A severity level of "L" may indicate that a suspicious person is loitering near an area of lower importance (e.g., canteen, parking lot, etc.). A severity level of "M" may indicate that a suspicious person is loitering near an area of medium importance (e.g., work floor, private work cabin, etc.). Severity level "H" / severity level "M" may fall under "alarm" (i.e., security department needs to take measures), while severity level "L" may fall under "incident" (i.e., no measures are required). The method may use event severity based on the degree of exposure, which depends on the area traversed by the suspect, and the system automatically sends the anomaly alarm along with the priority level to the security operator so that when the operator receives multiple anomaly alarm notifications (belonging to different access cards) simultaneously, the operator can prioritize which event to investigate first.

[0032] In some cases, determining the severity level does not necessarily have to be performed only after the operator has provided a response to classify the "tagged access request" as an "illegal access request", but can be performed by the AI / ML engine after identifying the access request as a "tagged access request", such that when presenting the operator with an image from the security camera that captured the "tagged access request", the operator is also aware of the "severity level" associated with the "tagged access request". In some cases, it is beneficial to emphasize the severity / priority level of the "tagged access request" to the operator because when the operator receives multiple "tagged access request" notifications (corresponding to different "access control keys / access cards") on the display simultaneously, this will help the operator prioritize which "tagged access request" to investigate first. Therefore, the system may display severity / priority level (high, medium, low) identifiers, where each "tagged access request" notification is displayed on the screen to convey the degree of exposure associated with each "tagged access request". A severity / priority level of "high" may indicate that a suspicious person is loitering near an area of higher importance (e.g., server room, conference room, generator room, CXO private cabin, locker area, etc.). A severity level of "low" may indicate that a suspicious person is loitering near an area of lower importance (e.g., canteen, parking lot, etc.). A severity level of "medium" may indicate that a suspicious person is loitering near an area of medium importance (e.g., work floor, private work cabin, etc.). The severity / priority level of each displayed "tagged access request" may be based on the degree of exposure associated with the "tagged access request", and the degree of exposure may, in some cases, depend on the area traversed by the suspect.

[0033] In some cases, when an anomaly is detected, based on a combination of one or more parameters such as the location, date, time, and severity of the anomaly, the system can determine a threat / suspiciousness score to predict a potential threat to the facility and accordingly issue an alert with an appropriate severity level and, in some cases, take appropriate corrective actions (e.g., blocking access, dispatching officers, having the operator cross-check with other integrated systems such as a video system to confirm the alert / event, etc.).

[0034] In some cases, method 22 can include storing different sensitivity levels for each of at least two of the multiple authorized users, as indicated at block 56. The AI / ML engine can use the stored sensitivity levels when identifying which one of one or more of the multiple access requests is identified as a flagged access request, as indicated at block 58. For example, when an authorized user is new to the facility, the AI / ML engine may not have had time to learn a very robust access behavior pattern for that user and can lower the sensitivity level of that user for a period of time to help reduce false positives. Once the AI / ML engine has had time to learn an appropriate access behavior pattern for that user, the sensitivity level of that user can be increased.

[0035] When the AI / ML engine identifies an access request as a flagged access request indicating a possible security event at the facility, method 22 can include automatically sending a notification to a specific authorized user corresponding to the flagged access request and waiting for a confirmation of the legitimacy of the access request from the specific authorized user within a predetermined time period, as indicated at block 60. In some cases, the specific authorized user must provide authentication information such as a PIN, biometric information, and / or other authentication information. When a confirmation of the legitimacy of the access request from the specific authorized user is received within the predetermined time period, method 22 can include classifying the flagged access request as a legitimate access request and sometimes not presenting the flagged access request to the security operator for classification, as indicated at block 62.

[0036] Figure 3 A flowchart showing a sequence of illustrative steps 64 that can be performed by one or more processors when executing instructions stored on a non-transitory computer-readable storage medium. For example, the one or more processors can be Figure 1A portion of the controller 18 shown. In this example, one or more processors receive multiple access requests from one or more access control devices of a facility, where each access request of the multiple access requests is generated in response to one of a plurality of access control keys being presented to one of the access control devices, and where each access control key of the plurality of access control keys is associated with a particular one of a plurality of authorized users of the facility, as indicated at block 66. One or more processors present the multiple access requests to an artificial intelligence and / or machine learning (AI / ML) engine, which is trained to learn the access behavior patterns of each of the plurality of authorized users over time and at one or more access control devices. The AI / ML engine determines whether any particular access request represents an anomaly in the learned access behavior pattern of the corresponding authorized user, thereby generating a flagged access request, as indicated at block 68. When the AI / ML engine determines that a particular access request represents a flagged access request, one or more processors display on a display one or more images from a security camera that captured the flagged access request for a security operator to view, as indicated at block 70. One or more processors receive a response from the security operator, where the response classifies the flagged access request as a legitimate access request or an illegal access request, as indicated at block 72. When the response classifies the flagged access request as an illegal access request, one or more processors issue an alert, as indicated at block 74. In some cases, the alert may include, but is not limited to, the following details, including for example pictures and / or videos of the event that triggered the alert, the time of the alert, the location of the event that triggered the alert, a list of past alerts caused by a particular user (a user identified by facial recognition, swiping a card, etc.), past alerts caused by a particular user that were reclassified as legitimate by the security operator, and / or any other appropriate information. When the user who triggered the alert registers with the security system, these details may include details about the particular registered user, such as a photo of the registered user, the access rights assigned to the registered user, the contact information of the registered user's supervisor, a list of past alerts caused by the registered user, and / or any other appropriate information.

[0037] In some cases, one or more processors may retrain the AI / ML engine based on the flagged access request and the received corresponding response. When the response classifies the flagged access request as an illegal access request, one or more processors may automatically take corrective actions. For example, the corrective actions may include one or more of the following: locking one or more access control devices and / or disabling the access control key associated with a particular authorized user, the particular authorized user being associated with the flagged access request. These are merely exemplary corrective actions.

[0038] Figure 4is a flowchart showing an exemplary method 76 for operating an access control system such as Figure 1 the access control system 10 shown. Method 76 begins at block 78. The user swipes their access card for the first time, as shown at block 80. At decision block 82, it is determined whether there is a behavior pattern available for the user. If not, control proceeds to block 84, where the behavior pattern is collected, and then loops back to block 86 and back to the top of method 76. If a behavior pattern is available for the user, control proceeds to block 88, where a virtual assistant is created for the user. At block 90, the virtual assistant predicts the user's expected path. In some cases, the virtual assistant can be part of an AI / ML engine such as AI / ML engine 20. The user moves to a subsequent card reader, as shown at block 92. At decision block 94, it is determined whether the user's behavior matches the expected path. If not, control proceeds to block 96, where an alert is triggered. In some cases, the alert and an image from a security camera that captures the user at the subsequent card reader can be presented to a security operator. The security operator can classify the user access request at the subsequent card reader as legitimate or illegal and can retrain the virtual assistant based on that classification. If the user's behavior matches the expected path, control proceeds to block 98, and the event is labeled as normal. Then, control returns to block 92. In some cases, if the user does not move to any other card reader, control can instead proceed to stop block 100.

[0039] Figure 5 is a flowchart showing a method for operating an access control system such as Figure 1Flowchart of an exemplary method 102 of an access control system such as the access control system 10 shown. Method 102 begins with a user swiping their access card, as indicated at block 104. The system verifies whether a behavior pattern is available for the user. If not, control proceeds to block 108, where machine learning begins to learn the user's behavior pattern. Otherwise, if so, control proceeds to block 110, where AI monitors their pattern as the cardholder moves between readers. At block 112, it is determined whether there is an anomaly in the cardholder's behavior. If not, control proceeds to block 114, where it is determined that the behavior is normal. From there, control returns to block 110. If there is an anomaly, control proceeds to block 116, where a suspicious alert / event is triggered. At block 118, an integrated VMS (Video Management System) within the facility can provide video of the cardholder's abnormal behavior. The access control system operator views the triggered alert / event and the provided video and confirms the alert / event, as indicated at block 120. It is determined whether the operator has confirmed the anomaly in the cardholder's behavior. If the operator has not confirmed the anomaly, control proceeds to block 124, where the operator provides confirmation that the access request is valid. From there, control returns to block 110. If the operator confirms the anomaly detection at block 122, control proceeds to block 126 and corrective action is taken. In some cases, corrective action is taken automatically, while in other cases, the operator initiates the appropriate corrective action.

[0040] Although several exemplary embodiments of the present disclosure have been described as such, those skilled in the art will readily appreciate that other embodiments can be made and used within the scope of the appended claims herein. However, it should be understood that the present disclosure is illustrative in many respects. Changes can be made to the details, particularly those related to the shape, size, arrangement of parts, and the exclusion and order of steps, without departing from the scope of the present disclosure. Of course, the scope of the present disclosure is defined by the language of the appended claims.

Claims

1. A method for identifying a security event of a facility using an access control system, the access control system controlling access rights in the facility, the access control system comprising one or more access control devices, each access control device being located at a corresponding position in the facility for reading an access control key, each access control key being associated with a corresponding one of a plurality of authorized users of the facility, the method comprising: A plurality of access requests are received from the one or more access control devices of the facility, wherein each of the plurality of access requests is generated in response to one of the access control keys being presented to one of the access control devices, and wherein each of the plurality of access requests identifies: a specific authorized user associated with the access control key corresponding to the access request; a timestamp associated with the corresponding access request; a location identifier identifying a location of the access control device associated with the corresponding access request; presenting the plurality of access requests to an artificial intelligence and / or machine learning (AI / ML) engine, the AI / ML engine identifying one or more access requests from the plurality of access requests as flagged access requests, the flagged access requests representing a possible security incident for the facility; automatically displaying one or more images from a security camera that captured the tagged access request on a display for viewing by a security operator; receiving a response entered by the security operator, wherein the response classifies the flagged access request as a legitimate access request or an illegitimate access request; training the AI / ML engine based on the labeled access requests and the corresponding responses received; as well as When the response categorizes the flagged access request as an illegal access request, an alert is issued and / or corrective action is taken.

2. The method according to claim 1, comprising: A pre-stored image of the particular authorized user associated with the access control key used in the signed access request is automatically displayed.

3. The method according to claim 1, wherein the AI / ML engine is trained based on a specific access request of a specific authorized user and learned past behavior of the specific authorized user to determine whether the specific access request of the specific authorized user is a marked access request, and the past behavior is based on past access requests of the specific authorized user. 4 . The method of claim 3 , wherein the learned past behavior of the specific authorized user comprises a learned pattern of past access requests of the specific authorized user.

5. The method according to claim 1, comprising: presenting one or more images from the security camera to the AI / ML engine associated with one or more access requests of the plurality of access requests; as well as The AI / ML engine is trained based on one or more images from the security camera.

6. The method according to claim 1, comprising: performing facial recognition on the one or more images of the security camera to identify one or more faces associated with one or more access requests of the plurality of access requests; as well as The AI / ML engine is trained based on one or more faces recognized by the facial recognition.

7. The method according to claim 1, comprising: determining a severity level of each alarm in a plurality of severity levels associated with a flagged access request classified as an illegal access request; as well as An action is automatically taken based at least in part on the determined severity level.

8. The method of claim 7, wherein the measures include one or more of: locking one or more access control devices, dispatching security personnel, and / or disabling an access control key associated with the particular authorized user associated with the flagged access request.

9. The method according to claim 1, comprising: When the AI / ML engine identifies the access request as a flagged access request indicating a possible security incident at the facility, automatically sending a notification to the specific authorized user corresponding to the flagged access request, and waiting for confirmation from the specific authorized user that the access request is legitimate within a predetermined time period; as well as When confirmation that the access request is legitimate is received from the specific authorized user within the predetermined time period, the marked access request is directly classified as a legitimate access request instead of continuing to display the image for viewing by the security operator.

10. An access control system for a facility, the access control system comprising: one or more access control devices, each access control device located at a corresponding location in the facility for reading an access control key, each access control key being associated with a corresponding one of a plurality of authorized users of the facility; monitor; one or more security cameras; a controller operatively coupled to the one or more access control devices, the display, and the one or more security cameras, the controller being configured to: receiving a plurality of access requests from the one or more access control devices, wherein each of the plurality of access requests is generated in response to one of a plurality of access control keys being presented to one of the access control devices, and wherein each of the plurality of access control keys is associated with a particular one of a plurality of authorized users of the facility; presenting the plurality of access requests to an artificial intelligence and / or machine learning (AI / ML) engine trained to learn access behavior patterns of each of the plurality of authorized users over time and on the one or more access control devices, the AI / ML engine determining when any particular access request represents an anomaly from the learned access behavior pattern of the corresponding authorized user, thereby generating a flagged access request; When the AI / ML engine determines that the particular access request represents a flagged access request, displaying on the display one or more images from one or more security cameras that captured the flagged access request for viewing on the display by a security operator; receiving a response, wherein the response classifies the marked access request as a legitimate access request or an illegitimate access request; retraining the AI / ML engine based on the tagged access requests and the corresponding responses received; as well as When the flagged access request is classified as an illegal access request, an alarm is issued and / or corrective measures are taken.