Fire-fighting access control management method and system based on Internet of Things
By building a multi-level Internet of Things access control network architecture and introducing multi-modal biometric recognition and graph neural network, the problems of unified identity authentication and dynamic permission management of access control systems in cross-building environments are solved, and the security and management efficiency of the system are improved.
Patent Information
- Application Number
- CN202510542456.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-07-18
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the existing technology, the access control systems of each building rely on independent deployment and lack a unified identity authentication mechanism. Especially under the conditions of cross-building traffic and dynamic changes in permissions, it is difficult to achieve intelligent linkage management, resulting in difficulty in synchronizing user permissions, low security and management efficiency.
Build a multi-level Internet of Things access control network architecture, adopting central management units, building-level control units and front-end access control units, combining the National Secret SM4 encryption algorithm, multi-modal biometric recognition and graph neural network to realize unified user identity management and dynamic authority determination.
It realizes unified management of user identities and local distributed authentication in cross-building environments, improves the security and management efficiency of the system, and enhances the intelligent judgment of access rights and abnormal behavior recognition capabilities.
Smart Images

Figure CN120343069A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of Internet of Things and intelligent security technology, and in particular relates to a fire access control management method and system based on the Internet of Things. Background Art
[0002] At present, with the continuous expansion of enterprise parks, office buildings and urban complexes, the number of buildings has increased and the mobility of personnel has increased, which has put forward higher requirements for unified management and flexible permission control across buildings of access control systems. However, traditional access control systems are mostly deployed independently, and the systems are not interconnected. Identity authentication and permission verification rely on local databases, lacking the ability to unify global identities and coordinate dynamic permissions. For example, in the existing technology, if a user needs to pass through multiple buildings, it is often necessary to enter permissions separately in each building, which makes maintenance complicated; after the user leaves or the permissions are changed, it is difficult to synchronize to each building in time, which poses a great security risk; in addition, traditional access control systems usually only rely on statically configured role or attribute access control (such as RBAC or ABAC), which is difficult to dynamically adjust according to the actual behavior characteristics and access patterns of users, and cannot effectively identify potential abnormal behaviors. Existing technologies cannot fully meet the management needs for distributed authentication, intelligent permission judgment and high security in a cross-building environment. Therefore, there is an urgent need for an access control management method that can achieve unified user identities across the entire network, local intelligent determination of permissions, and identification of abnormal behaviors even when buildings are widely distributed and communication conditions are unstable, so as to improve the intelligence level, security, and management efficiency of the system. Summary of the invention
[0003] In view of the above-mentioned technical deficiencies, the purpose of the present invention is to propose a fire access control management method based on the Internet of Things, aiming to solve the technical problems in the prior art that the access control systems of various buildings mostly rely on independent deployment and lack a unified identity authentication mechanism, especially under the conditions of cross-building access and dynamic changes in permissions, and it is difficult to achieve intelligent linkage management.
[0004] In order to solve the above technical problems, the present invention adopts the following technical solutions: The present invention provides a fire access control management method based on the Internet of Things.
[0005] The fire access control management method based on the Internet of Things includes:
[0006] Step S10: construct a multi-level IoT access control network architecture including a central management unit, a building-level control unit, and a front-end access control unit;
[0007] Step S20: Establish a user identity data structure in the central management unit, process the user identity data structure using the national secret SM4 symmetric encryption algorithm to obtain a structured data packet, and send the structured data packet to the building-level control unit;
[0008] Step S30: When the access control device corresponding to the front-end access control unit receives a user access request, collect the current multi-modal biometric data of the user, compare the multi-modal biometric data with the user biometric set, and calculate the similarity score;
[0009] Step S40: Preset a similarity score threshold. When the similarity score is greater than the similarity score threshold, the building-level control unit loads the user's historical access log and calculates the behavior deviation value δ according to the user's historical access log; the central management unit loads the building department association information and calculates the node access score S according to the building department association information;
[0010] Step S50: Obtain the static permission matching, and generate the final access control determination result by combining the behavior deviation value δ and the node access score S with the static permission matching.
[0011] Preferably, in step S10, the front-end access control unit includes an access card reader unit, a camera unit, a fingerprint recognition unit, an iris scanner unit, and an electronic lock unit; the front-end access control unit accesses the corresponding building-level control unit through a local area network; the building-level control unit is connected to the central management unit through the MQTT or HTTPS protocol.
[0012] Preferably, in step S30, the multi-modal biometric data includes real-time face image data, real-time fingerprint image data, and real-time iris image data; the calculation of the similarity score specifically includes:
[0013] Obtain the user face image data, user fingerprint image data, and user iris image data in the user biometric set;
[0014] For the real-time face image data and the user face image data, use the pre-trained face recognition neural network FaceNet to extract the real-time face image feature vector and the user face image feature vector, and calculate the cosine similarity between the two vectors according to the real-time face image feature vector and the user face image feature vector to obtain the face similarity L1;
[0015] For the real-time fingerprint image data and the user fingerprint image data, adopt a graph structure comparison method based on minutiae matching to calculate the fingerprint similarity L2;
[0016] For the real-time iris image data and the user iris image data, adopt a Hamming distance comparison method based on Gabor wavelet coding to calculate the iris similarity L3;
[0017] Combine the face similarity L1, the fingerprint similarity L2, and the iris similarity L3 and use a weighted fusion method to calculate the similarity score.
[0018] Preferably, in step S40, the steps of the building-level control unit loading the user's historical access logs and calculating the behavior deviation value δ according to the user's historical access logs specifically include: the building-level control unit loads the user's historical access logs, extracts the behavior feature vectors according to the user's historical access logs, and the behavior feature vectors include the current behavior vector x now and the historical behavior baseline vector x hist , where the current behavior vector includes the current time, the current access door ID, and the current building ID; the historical behavior baseline vector is calculated based on the moving average method; the behavior deviation value δ = ||x now -x hist ||.
[0019] Preferably, in step S40, the steps of the central management unit loading the building-department association information and calculating the node access score S according to the building-department association information specifically include:
[0020] The central management unit loads the building-department association information, constructs an identity relationship graph G according to the building-department association information, and the node types of the identity relationship graph G include user nodes U, access control nodes D, building nodes B, and department nodes O;
[0021] Initialize the nodes of the identity relationship graph G to obtain a multi-dimensional vector representation, and the multi-dimensional vector representation includes structural attributes, statistical attributes, and time behavior characteristics;
[0022] Use a graph convolutional neural network to perform multiple rounds of propagation and iteration on the identity relationship graph G to capture the relationship characteristics between the user node U and the access control node D, and output the user node embedding vector and the access control node embedding vector;
[0023] Calculate the node access score S according to the user node embedding vector and the access control node embedding vector.
[0024] Preferably, in step S50, the steps of obtaining the static permission matching, combining the behavior deviation value δ and the node access score S with the static permission matching, and generating the final access control access determination result, the formula expression of the final access control access determination result is:
[0025]
[0026] where Auth is the final access control access determination result, u is the user ID, is the set of user IDs in the static permission matching, δ is the behavior deviation value, T behav is the preset behavior deviation value threshold, S is the node access score, T score is the preset node access score threshold.
[0027] Preferably, after step S50, the step of generating the final access control passing determination result by combining the behavior deviation value δ and the node passing score S with static permission matching further includes:
[0028] If Auth = 1, the building-level control unit issues an unlocking instruction to the front-end access control device;
[0029] If Auth = 0, the building-level control unit issues a refusal-to-unlock instruction and a local sound and light warning trigger instruction to the front-end access control unit.
[0030] The present invention also provides an Internet of Things-based fire protection access control management system, including:
[0031] An access control network architecture construction module for constructing a multi-level Internet of Things access control network architecture including a central management unit, a building-level control unit, and a front-end access control unit;
[0032] A user identity data construction module for establishing a user identity data structure in the central management unit, processing the user identity data structure using the national secret SM4 symmetric encryption algorithm to obtain a structured data packet, and sending the structured data packet to the building-level control unit;
[0033] A multi-modal biometric verification module for collecting the current multi-modal biometric data of a user when the access control device corresponding to the front-end access control unit receives a user access request, comparing the multi-modal biometric data with the user biometric set, and calculating a similarity score;
[0034] A passing index calculation module for presetting a similarity score threshold. When the similarity score is greater than the similarity score threshold, the building-level control unit loads the user's historical access log and calculates the behavior deviation value δ according to the user's historical access log; the central management unit loads the building department association information and calculates the node passing score S according to the building department association information;
[0035] A determination result output module for obtaining static permission matching, and generating a final access control passing determination result by combining the behavior deviation value δ and the node passing score S with static permission matching.
[0036] The present invention also provides a computer program product, including an Internet of Things-based fire protection access control management program, and the Internet of Things-based fire protection access control management program, when executed by a processor, implements the Internet of Things-based fire protection access control management method described above.
[0037] The beneficial effects of the present invention are as follows: It constructs a multi-level Internet of Things access control system architecture, realizes the unified management and local distributed authentication of user identities in a cross-building environment, solves the problem that access permissions in the prior art are difficult to synchronize and control in real time and uniformly, and effectively improves the security and scalability of the system.
[0038] The multi-modal biometric recognition and graph neural network inference mechanism are introduced, and the access score is dynamically calculated by combining user behavior analysis, realizing the intelligent judgment of access rights and the recognition of abnormal behaviors, and enhancing the accuracy and flexibility of the access control system in allocating access rights under complex usage scenarios. Brief Description of the Drawings
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0040] Figure 1 It is a schematic flowchart of the first embodiment of a fire access control management method based on the Internet of Things according to the present invention.
[0041] Figure 2 It is a schematic diagram of a multi-level Internet of Things access control network architecture of a fire access control management method based on the Internet of Things according to the present invention.
[0042] Figure 3 It is a schematic diagram of the equipment of a fire access control management method based on the Internet of Things according to the present invention. Detailed Embodiments
[0043] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0044] Embodiment 1: As Figure 1 shown, it is a schematic flowchart of the first embodiment of a fire access control management method based on the Internet of Things according to the present invention, and the first embodiment of a fire access control management method based on the Internet of Things according to the present invention is proposed.
[0045] In the first embodiment, the fire access control management method based on the Internet of Things includes:
[0046] Step S10: Construct a multi-level Internet of Things access control network architecture including a central management unit, a building-level control unit, and a front-end access control unit;
[0047] It should be noted that in step S10, the front-end access control unit includes an access control card reader unit, a camera unit, a fingerprint recognition unit, an iris scanner unit, and an electronic lock unit; the front-end access control unit accesses the corresponding building-level control unit through a local area network; the building-level control unit is connected to the central management unit through the MQTT or HTTPS protocol.
[0048] It should be understood that the front-end access control unit conducts data communication with the building-level control unit corresponding to the building where it is located through a local area network (such as an Ethernet, Wi-Fi, or ZigBee network) to achieve real-time transmission of local identity authentication requests. As an edge computing node, the building-level control unit establishes an encrypted communication channel with the central management unit through the MQTT or HTTPS protocol, which is not only used to receive the configured user identity and permission data sent down, but also can, when necessary, transmit abnormal events or access logs back to the central management unit in real time to ensure the timeliness and security of data synchronization.
[0049] For example, as Figure 2 shown in the schematic diagram of the multi-level Internet of Things access control network architecture, in the application of an office building, after the front-end access control unit receives a user's card swiping request and completes biometric identification, it transmits the request data to the building control unit through Wi-Fi. After edge processing by the building control unit through the local area network, it only takes about 200 milliseconds to complete identity authentication and access control unlocking response, greatly improving the access efficiency.
[0050] Step S20: Establish a user identity data structure in the central management unit, process the user identity data structure using the national commercial cryptography standard SM4 symmetric encryption algorithm to obtain a structured data packet, and send the structured data packet to the building-level control unit;
[0051] It should be noted that the user identity data structure at least includes: a user unique identity identifier, a user permission set, and a user biometric template set, where the biometric template set can include various biometric templates such as face feature encoding, fingerprint template data, and iris encoding. This structure supports unified registration and multi-point universality to ensure cross-building identity consistency.
[0052] It can be understood that to ensure the security and compliance of identity data during network transmission, this embodiment selects the national commercial cryptography standard SM4 algorithm to encrypt and package the user identity data. The encrypted structured data packet has the property of being non-tamperable and can only be decrypted and used by a legitimate building control unit.
[0053] It should be understood that before the structured data packet is sent, security fields such as timestamps and digital signatures can also be attached to further enhance the ability to resist replay attacks. The data can be sent using Message Queuing (MQTT) or Restful API based on HTTPS. The central management unit can choose asynchronous push or periodic synchronization according to the actual access status of the building to ensure data consistency.
[0054] For example, in a scenario of a full-staff permission adjustment, the administrator sets a certain department as "only allowed to access Building A and Building C" on the central platform, immediately re-encrypts the permission set of the users in this department and generates a structured data packet, which is pushed to the building control units of Building A and Building C. Since the control unit of Building B does not contain the corresponding permissions and does not need to be synchronized, the permission synchronization efficiency is improved and the communication load is reduced.
[0055] Step S30: When the access control device corresponding to the front-end access control unit receives a user access request, collect the current multi-modal biometric data of the user, compare the multi-modal biometric data with the user biometric set, and calculate the similarity score.
[0056] It should be noted that in step S30, the multi-modal biometric data includes real-time face image data, real-time fingerprint image data, and real-time iris image data. The calculation of the similarity score specifically includes:
[0057] Obtain the user face image data, user fingerprint image data, and user iris image data in the user biometric set.
[0058] For the real-time face image data and the user face image data, use the pre-trained face recognition neural network FaceNet to extract the real-time face image feature vector and the user face image feature vector, and calculate the cosine similarity between the two vectors according to the real-time face image feature vector and the user face image feature vector to obtain the face similarity L1.
[0059] For the real-time fingerprint image data and the user fingerprint image data, use the graph structure comparison method based on minutiae matching to calculate the fingerprint similarity L2.
[0060] For the real-time iris image data and the user iris image data, use the Hamming distance comparison method based on Gabor wavelet coding to calculate the iris similarity L3.
[0061] Combine the face similarity L1, fingerprint similarity L2, and iris similarity L3 and use the weighted fusion method to calculate the similarity score.
[0062] It should be noted that the steps for calculating the fingerprint similarity L2 by using the graph structure comparison method based on minutiae matching for real-time fingerprint image data and user fingerprint image data specifically include: First, perform image preprocessing on the real-time fingerprint image data and the user fingerprint image data respectively, including grayscale conversion, denoising, image enhancement, and ridge thinning, so as to extract a clear ridge structure; Then, extract the minutiae feature information from the two images respectively. Minutiae include ridge endings and bifurcations, and each minutia records its position coordinates and orientation angle in the image; Next, construct a local structure graph model based on the minutiae, analyze its adjacent topological relationship, and match the set of minutiae between the real-time graph and the template graph, with appropriate rotation, translation, and scale adjustment during the process to adapt to finger placement errors; Further, within the set error tolerance, count the number of successfully matched minutia pairs in the two images and compare it with the total number of minutiae in the two images; Finally, calculate the similarity score of the fingerprint image according to the proportional relationship between the number of successfully matched minutia pairs and the total number of reference nodes as the fingerprint similarity L2.
[0063] The steps for calculating the iris similarity L3 by using the Hamming distance comparison method based on Gabor wavelet coding for real-time iris image data and user iris image data specifically include: First, perform preprocessing on the real-time collected iris image, including the localization and segmentation of the iris region. Identify the outer ring of the iris and the pupil boundary through the edge detection algorithm to obtain the complete iris region; Then, normalize and expand the iris region by using the polar coordinate transformation method to generate a rectangular iris image of a unified size for subsequent feature extraction; Next, use the Gabor wavelet filter to extract the local texture features of the normalized iris image, and perform binary processing on the obtained filtering response to generate a binary coding template corresponding to the iris image; Further, perform a bit-by-bit comparison between the binary template of the real-time iris image and the user template, count the number of different bits among them, and calculate the Hamming distance between the two; Finally, normalize the Hamming distance value from the overall coding length to obtain the iris similarity L3.
[0064] It should be understood that the steps for calculating the similarity score by using the weighted fusion method in combination with the face similarity L1, the fingerprint similarity L2, and the iris similarity L3 can dynamically optimize the contribution degrees of each modality according to the individual recognition performance of the user, and further improve the recognition efficiency and anti-counterfeiting ability.
[0065] For example, in a scene with insufficient light, the confidence level of user face recognition is low, and the face similarity score is low. Automatically increase the proportion of fingerprint and iris recognition. When the fingerprint and iris match well, the comprehensive similarity score still meets the threshold requirements, ensuring the normal passage of the user and avoiding false rejection due to the failure of a single modality.
[0066] Step S40: Preset a similarity score threshold. When the similarity score is greater than the similarity score threshold, the building-level control unit loads the user's historical access logs and calculates the behavior deviation value δ based on the user's historical access logs; the central management unit loads the building-department association information and calculates the node access score S based on the building-department association information.
[0067] It should be noted that in step S40, the steps for the building-level control unit to load the user's historical access logs and calculate the behavior deviation value δ based on the user's historical access logs specifically include: the building-level control unit loads the user's historical access logs and extracts the behavior feature vectors from the user's historical access logs. The behavior feature vectors include the current behavior vector x now and the historical behavior baseline vector x hist , where the current behavior vector includes the current time, the current access door ID, and the current building ID; the historical behavior baseline vector is calculated based on the moving average method; the behavior deviation value δ = ||x now - x hist ||.
[0068] In step S40, the steps for the central management unit to load the building-department association information and calculate the node access score S based on the building-department association information specifically include: the central management unit loads the building-department association information and constructs an identity relationship graph G. The node types of the identity relationship graph G include user nodes U, access control nodes D, building nodes B, and department nodes O; initialize the nodes of the identity relationship graph G to obtain a multi-dimensional vector representation, and the multi-dimensional vector representation includes structural attributes, statistical attributes, and time behavior characteristics; use a graph convolutional neural network to perform multiple rounds of propagation and iteration on the identity relationship graph G to capture the relationship characteristics between the user node U and the access control node D, and output the user node embedding vector and the access control node embedding vector; calculate the node access score S based on the user node embedding vector and the access control node embedding vector.
[0069] It can be understood that by comparing the vector distance between the current behavior and the user's past behavior baseline, sudden changes in the user's behavior pattern can be effectively identified, such as abnormal time periods, non-usual access points, or sudden cross-building behaviors, etc., and then a behavior deviation value is formed for subsequent risk judgment.
[0070] It should be understood that the behavior deviation value is not an absolute basis for rejecting access, but rather an auxiliary factor for dynamic permission judgment. Multi-level response strategies can be set according to the degree of deviation, such as triggering multi-factor authentication, manual confirmation, or rejecting access.
[0071] For example, User A usually passes through the No. 3 gate of Building A from 8:00 to 10:00. When attempting to enter the access control of the control room in Building B at 1:30 in the early morning, the current behavior vector is significantly different from the historical average feature vector, and the calculated deviation value is higher than the risk threshold, thus triggering a high-security response to avoid potential unauthorized access risks.
[0072] Step S50: Obtain the static permission matching, and combine the behavior deviation value δ and the node access score S with the static permission matching to generate the final access control access determination result.
[0073] It should be noted that in step S50, the step of obtaining the static permission matching, combining the behavior deviation value δ and the node access score S with the static permission matching to generate the final access control access determination result, the formula expression of the final access control access determination result is:
[0074]
[0075] Among them, Auth is the final access control access determination result, u is the user ID, is the set of user IDs in the static permission matching, δ is the behavior deviation value, T behav is the preset behavior deviation value threshold, S is the node access score, T score is the preset node access score threshold.
[0076] After step S50, the step of combining the behavior deviation value δ and the node access score S with the static permission matching to generate the final access control access determination result further includes:
[0077] If Auth = 1, the building-level control unit issues an unlocking instruction to the front-end access control device;
[0078] If Auth = 0, the building-level control unit issues a refusal to unlock instruction and a local audible and visual warning trigger instruction to the front-end access control unit.
[0079] It can be understood that this determination strategy integrates static permissions, dynamic behavior rationality, and graph reasoning results, improving the flexibility and robustness of access determination, avoiding the blocking problem of "authorized but not configured but behavior is reasonable", and also preventing the risk of "permissions exist but behavior is abnormal" access, with higher practical adaptability.
[0080] It should be understood that this step supports the configuration of different levels of authorization policies. For example, in high-security areas, a strict policy can be set: only when the user is within the permission set and the behavior is normal is access allowed; while in low-risk areas, visitors or new employees with high node scores can be allowed to obtain temporary access permissions, supporting administrator background auditing and permission record keeping.
[0081] For example, a certain operation and maintenance personnel u is not in the static authorization list of the computer room door, but their behavior deviation value is low (during normal working hours) and the node access score S = 0.92 exceeds the threshold of 0.85. According to the set temporary intelligent release policy, it is automatically determined that Auth(u) = 1, allowing them to pass and recording the log; if the behavior deviation value of this person is too high or the score is low, even if the permission exists, they can be automatically rejected, and a local audible and visual alarm or an administrator review process is triggered.
[0082] Embodiment 2: In addition, a fire control access management system based on the Internet of Things provided by the present invention adopts a fire control access management method based on the Internet of Things in the above embodiment, and can solve the technical problem of a fire control access management based on the Internet of Things. Compared with the prior art, the beneficial effects of a fire control access management system based on the Internet of Things provided by the present invention are the same as those of the fire control access management method based on the Internet of Things provided in the above embodiment, and other technical features in the fire control access management system based on the Internet of Things are the same as the features disclosed in the above embodiment method, and will not be elaborated here.
[0083] Embodiment 3: The present invention provides a fire control access management device based on the Internet of Things. Please refer to Figure 3, An Internet of Things-based fire control access management device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute an Internet of Things-based fire control access management method in the first embodiment above. An Internet of Things-based fire control access management device in an embodiment of the present invention may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistant), PADs (Portable Application Description), PMPs (Portable Media Player), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. An Internet of Things-based fire control access management device is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present invention. An Internet of Things-based fire control access management device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM: Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of an Internet of Things-based fire control access management device are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow an Internet of Things-based fire control access management device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows an Internet of Things-based fire control access management device having various systems, it should be understood that it is not required to implement or have all the systems shown. More or fewer systems may be implemented or had alternatively.
[0084] Embodiment 4: The present invention further provides a computer program product, including a computer program, which when executed by a processor implements the steps of a fire control access management method based on the Internet of Things as described above. The computer program product provided by the present invention can solve the technical problems of a fire control access management based on the Internet of Things. Compared with the prior art, the beneficial effects of the computer program product provided by the present invention are the same as those of the fire control access management method based on the Internet of Things provided in the above embodiment, and will not be elaborated here.
[0085] Specifically, according to the embodiments disclosed by the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment disclosed by the present invention includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by a processing device 1001, it executes the above functions defined in the methods of the embodiments disclosed by the present invention.
[0086] It should be understood that various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.
[0087] Obviously, those skilled in the art can make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.
Claims
1. An Internet of Things-based fire control access management method, characterized in that, The method includes: Step S10: Construct a multi-level Internet of Things access control network architecture including a central management unit, a building-level control unit, and a front-end access control unit; Step S20: Establish a user identity data structure in the central management unit, process the user identity data structure using the national cryptographic SM4 symmetric encryption algorithm to obtain a structured data packet, and send the structured data packet to the building-level control unit; Step S30: When the access control device corresponding to the front-end access control unit receives a user access request, collect the current multi-modal biometric data of the user, compare the multi-modal biometric data with the user biometric set, and calculate a similarity score; Step S40: Preset a similarity score threshold. When the similarity score is greater than the similarity score threshold, the building-level control unit loads the user's historical access log and calculates the behavior deviation value δ according to the user's historical access log; the central management unit loads the building department association information and calculates the node access score S according to the building department association information; Step S50: Obtain static permission matching, and generate a final access control access determination result by combining the behavior deviation value δ and the node access score S with the static permission matching.
2. The method for managing a fire control access control based on the Internet of Things according to claim 1, wherein, In step S10, the front-end access control unit includes an access card reader unit, a camera unit, a fingerprint recognition unit, an iris scanner unit, and an electronic lock unit; the front-end access control unit accesses the corresponding building-level control unit through a local area network; the building-level control unit is connected to the central management unit through the MQTT or HTTPS protocol.
3. The method for managing a fire control access control based on the Internet of Things according to claim 1, characterized in that, In step S30, the multi-modal biometric data includes real-time face image data, real-time fingerprint image data, and real-time iris image data; the calculation of the similarity score specifically includes: Obtain the user face image data, user fingerprint image data, and user iris image data in the user biometric set; Use the pre-trained face recognition neural network FaceNet to extract the real-time face image feature vector and the user face image feature vector for the real-time face image data and the user face image data, and calculate the cosine similarity between the two vectors according to the real-time face image feature vector and the user face image feature vector to obtain the face similarity L1; Adopt a graph structure comparison method based on minutiae point matching for the real-time fingerprint image data and the user fingerprint image data to calculate the fingerprint similarity L2; Adopt a Hamming distance comparison method based on Gabor wavelet coding for the real-time iris image data and the user iris image data to calculate the iris similarity L3; Combine the face similarity L1, the fingerprint similarity L2, and the iris similarity L3 and use a weighted fusion method to calculate the similarity score.
4. A method for managing fire access control based on the Internet of Things according to claim 1, characterized in that, In step S40, the steps for the building-level control unit to load the user's historical access logs and calculate the behavior deviation value δ according to the user's historical access logs specifically include: The building-level control unit loads the user's historical access logs, extracts the behavior feature vectors according to the user's historical access logs, and the behavior feature vectors include the current behavior vector x now and the historical behavior baseline vector x hist , where the current behavior vector includes the current time, the current access door ID, and the current building ID; the historical behavior baseline vector is calculated based on the moving average method; the behavior deviation value δ = ||x now -x hist ||.
5. The method for managing a fire control access control based on the Internet of Things according to claim 1, characterized in that, In step S40, the steps for the central management unit to load the building department association information and calculate the node access score S according to the building department association information specifically include: The central management unit loads the building department association information and constructs an identity relationship graph G according to the building department association information. The node types of the identity relationship graph G include user nodes U, access control nodes D, building nodes B, and department nodes O; Initialize the nodes of the identity relationship graph G to obtain a multi-dimensional vector representation, which includes structural attributes, statistical attributes, and temporal behavior characteristics; Use a graph convolutional neural network to perform multiple rounds of propagation iterations on the identity relationship graph G to capture the relationship characteristics between the user node U and the access control node D, and output the user node embedding vector and the access control node embedding vector; Calculate the node access score S based on the user node embedding vector and the access control node embedding vector.
6. The method for managing a fire control access control based on the Internet of Things according to claim 1, characterized in that, In step S50, the step of obtaining the static permission matching, combining the behavior deviation value δ and the node access score S with the static permission matching to generate the final access control access determination result, and the formula expression of the final access control access determination result is: Among them, Auth is the final access control determination result, u is the user ID, is the set of user IDs in static permission matching, δ is the behavior deviation value, T behav is the preset behavior deviation value threshold, S is the node access score, T score is the preset node access score threshold.
7. The method for managing a fire control access control based on the Internet of Things according to claim 6, characterized in that, After step S50, the step of combining the behavior deviation value δ and the node access score S with the static permission matching to generate the final access control access determination result further includes: If Auth = 1, the building-level control unit issues an unlocking instruction to the front-end access control device; If Auth = 0, the building-level control unit issues a refusal to unlock instruction and a local sound and light warning trigger instruction to the front-end access control unit.
8. An Internet of Things-based fire control access management system, which is applied to an Internet of Things-based fire control access management method described in any one of claims 1-7, and is characterized in that, The Internet of Things-based fire access control management system includes: An access control network architecture construction module for constructing a multi-level Internet of Things access control network architecture including a central management unit, a building-level control unit, and a front-end access control unit; A user identity data construction module for establishing a user identity data structure in the central management unit, processing the user identity data structure using the national secret SM4 symmetric encryption algorithm to obtain a structured data packet, and sending the structured data packet to the building-level control unit; A multi-modal biometric verification module for collecting the current multi-modal biometric data of the user when the access control device corresponding to the front-end access control unit receives a user access request, comparing the multi-modal biometric data with the user biometric set, and calculating a similarity score; A traffic index calculation module for presetting a similarity score threshold. When the similarity score is greater than the similarity score threshold, the building-level control unit loads the user's historical access log and calculates the behavior deviation value δ based on the user's historical access log; the central management unit loads the building department association information and calculates the node access score S based on the building department association information; A determination result output module for obtaining the static permission matching, and generating a final access control access determination result by combining the behavior deviation value δ and the node access score S with the static permission matching.
9. A fire control access management device based on the Internet of Things, characterized in that The Internet of Things-based fire access control management device includes: a memory, a processor, and an Internet of Things-based fire access control management program stored on the memory and executable on the processor. When the Internet of Things-based fire access control management program is executed by the processor, it implements the Internet of Things-based fire access control management method according to any one of claims 1 to 7.
10. A computer program product, characterized in that, The computer program product includes an Internet of Things-based fire access control management program, and when the Internet of Things-based fire access control management program is executed by a processor, it implements the Internet of Things-based fire access control management method according to any one of claims 1 to 7.
Citation Information
Cited By
Abnormal separation alarm system and method for mobile positioning terminal
CN120897162A