A temporary permission hierarchical management method and system based on RFID

By activating access control points step by step under a global lockdown, allowing for one-time door opening in response to any identity credential, and relaying access permissions through a relay activation signal, the flexibility problem of access control in emergency situations in existing technologies is solved, achieving controlled evacuation and improving emergency evacuation efficiency and safety.

CN120636030BActive Publication Date: 2025-11-21JIANGSU HAIKANG BORUI ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511023505.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2025-11-21
Estimated Expiration
2045-07-24

AI Technical Summary

Technical Problem

Existing RFID-based access control methods lack flexibility in responding to emergencies, resulting in an inability to provide flexible and controlled evacuation access in emergency situations, thus affecting emergency evacuation efficiency and safety.

Method used

By generating path guidance instructions under a global lockdown, access control points are activated at each level to enter a guidance/relay standby state, responding to any identity credentials to open the door once, and passing access permissions are transmitted through relay activation signals to ensure that personnel can pass one-way along the preset evacuation route.

Benefits of technology

Under a global lockdown, it provides temporary, controlled, and directional access to pre-set evacuation routes, improving the efficiency and safety of emergency evacuations while maintaining the lockdown status of other areas, thus enhancing the system's flexibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120636030B_ABST
    Figure CN120636030B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of permission hierarchical management, in particular to a temporary permission hierarchical management method and system based on RFID, which comprises the following steps: when a sudden event triggering a global blocking state is detected, a path guiding instruction is generated by a control center; the path guiding instruction is sent to a starting access control point in a path definition; after the starting access control point receives the path guiding instruction, the starting access control point enters a guiding standby state, and in the guiding standby state, a one-time door opening action is executed in response to the triggering of any identity certificate; after the next access control point receives a relay activation signal, the next access control point enters a relay standby state from a blocking state; in the relay standby state, the next access control point executes a one-time door opening action in response to the triggering of any identity certificate; after each access control point completes the sending of a corresponding relay activation signal, the access control point returns to the blocking state. The above method improves the efficiency and safety of emergency evacuation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of hierarchical access control, specifically to a temporary hierarchical access control method and system based on RFID. Background Technology

[0002] In large event venues and similar settings, access control systems based on Radio Frequency Identification (RFID) technology are commonly used to manage crowd entry and exit and area access. These systems issue RFID cards with different access levels to individuals with varying identities, enabling fine-grained control over different functional areas within the venue. However, in practical applications, especially in responding to emergencies, existing access control methods have certain limitations. In emergencies such as fire alarms or security alerts, security systems typically execute the highest-level pre-set emergency plan, such as forcibly locking down key areas or the entire venue. At this time, all regular RFID card access is suspended to ensure the highest level of security isolation. While this blanket lockdown strategy ensures security, it can introduce new problems in complex situations, making the system lack necessary flexibility.

[0003] To address the aforementioned issues, existing technologies urgently need improvement. Summary of the Invention

[0004] The purpose of this invention is to address the aforementioned shortcomings by proposing a temporary access control method and system based on RFID.

[0005] The present invention adopts the following technical solution:

[0006] A method for hierarchical management of temporary access rights based on RFID, comprising the following steps:

[0007] S1: When a sudden event that triggers a global lockdown is detected, the control center generates a path guidance instruction based on the evacuation path definition that includes multiple ordered access control points. The path guidance instruction includes the path identifier, the next access control point identifier, and the authorized validity period.

[0008] S2: Send the path guidance instruction to the starting access control point in the path definition;

[0009] S3: After receiving the path guidance instruction, the starting access control point enters the guidance standby state. In the guidance standby state, it responds to the triggering of any identity credential, performs a one-time door opening action, and sends a relay activation signal to the next access control point based on the path guidance instruction.

[0010] S4: After receiving the relay activation signal, the next access control point will enter the relay standby state from the blocked state.

[0011] S5: In the relay standby state, the next access control point responds to the trigger of any identity credential, performs a one-time door opening action, and continues to pass the relay activation signal to the access control point located after the next access control point in the path definition;

[0012] S6: After each access control point completes the corresponding relay activation signal transmission, it returns to the blocked state.

[0013] The above scheme can provide temporary, controlled, and directional access to pre-set evacuation routes under a global lockdown, improving the efficiency and safety of emergency evacuation while maintaining the lockdown status of other areas and enhancing the system's flexibility.

[0014] Furthermore, this application also proposes to include the following steps in S3:

[0015] In response to the triggering of any identity credential, an opening command is sent to the door drive component associated with the starting access control point, and physical status information is obtained from the status sensor associated with the door.

[0016] Based on the physical state information, determine whether the door is already in the open position;

[0017] When the judgment result is yes, the starting access control point sends a relay activation signal to the next access control point.

[0018] The above solution ensures that the relay signal is sent only after the door is actually opened, thus improving system reliability.

[0019] Furthermore, this application also proposes to include the following steps in S3:

[0020] Respond to any identity credential trigger and determine whether the trigger is the first trigger in the guided standby state;

[0021] If the judgment result is yes, then the door opening action is executed, a relay activation signal is sent to the next access control point, and a timer is started to suppress subsequent trigger responses;

[0022] During the timing period, if a subsequent identity credential is received, the door opening action will not be performed, nor will the relay activation signal be sent.

[0023] By using the above scheme, subsequent triggering is suppressed through timing, which avoids repeated door opening and signal transmission, thus improving the stability of the system.

[0024] Furthermore, this application also proposes that, in step S5, when a route reassignment request is detected, a permission reassignment instruction is sent to the next access control point. The permission reassignment instruction is used to instruct the next access control point to forward the relay activation signal to another preset access control point when the relay activation signal is transmitted, so that the other access control point enters the relay standby state from the blocked state.

[0025] The above scheme provides the ability to dynamically reassign routes, enhancing the flexibility of emergency evacuation.

[0026] Furthermore, this application also proposes that, in step S5, after the next access control point forwards the relay activation signal to another access control point, it starts a timer for receiving forwarding confirmation information;

[0027] If no forwarding confirmation message is received from another access control point before the timeout, the relay activation signal is deemed to have failed to forward, and a failure notification is sent to the control center.

[0028] After receiving the failure notification, the control center sends a remedial activation command to another access control point, so that the other access control point goes from the blocked state to the relay standby state.

[0029] The above scheme adds forwarding confirmation and remediation mechanisms, improving the success rate and reliability of route reassignment.

[0030] Furthermore, this application also proposes that when a remedial activation command or relay activation signal is received at another preset access control point, the other preset access control point extracts the path identifier corresponding to the evacuation path from the received remedial activation command or relay activation signal.

[0031] The other preset access control point determines whether it is already in the relay standby state corresponding to the extracted path identifier based on the extracted path identifier.

[0032] When the judgment result is negative, another preset access control point is controlled to enter the relay standby state corresponding to the extracted path identifier.

[0033] The above scheme ensures that the reassigned access control points correctly enter the corresponding relay standby state, avoiding state confusion.

[0034] Furthermore, this application also proposes to include the following steps in S6:

[0035] After sending the relay activation signal, wait to receive confirmation information from the next access control point. The confirmation information indicates that the next access control point has entered the relay standby state.

[0036] Upon receiving confirmation, the initial access control point is restored to the locked state.

[0037] By adopting the above approach, waiting for confirmation information before restoring the blockade ensures the successful transmission of the relay signal and improves the reliability of the system.

[0038] Furthermore, this application also proposes that step S6 further includes the following steps:

[0039] If no confirmation is received within the preset waiting time, the relay activation signal is deemed to have failed to be sent.

[0040] In response to the judgment result, the door associated with the initial access control point is kept in the open position;

[0041] Send a path interruption notification to the preset control center, containing the identifier of the starting access control point and the identifier of the next access control point.

[0042] The above solution provides a fault handling mechanism by keeping the gate open and notifying the control center when the relay signal fails to be sent, thus avoiding path interruption.

[0043] Furthermore, this application also proposes that the steps for maintaining the door associated with the initial access control point in the open position include:

[0044] While performing the action of keeping the door in the open position, listen for door closing commands from the control center;

[0045] When a door closing command is received from the control center, the action of maintaining the door in the open position is terminated.

[0046] Perform the action of closing the door.

[0047] The above solution provides a means for the control center to remotely close the door, enhancing the control capability of the door in fault conditions.

[0048] Furthermore, this application also proposes an RFID-based temporary access control system, applied to the aforementioned RFID-based temporary access control method. This system includes:

[0049] The path generation module is used to send a path guidance instruction to the starting access control point based on the path definition containing multiple ordered access control points. The path guidance instruction includes the information of the next access control point.

[0050] The initial access control module is used to enter the guidance standby state after receiving the path guidance instruction, respond to the trigger of any identity credential, execute the door opening action, and send a relay activation signal to the next access control point;

[0051] After receiving the relay activation signal, the relay control module performs a state transition, changing from the blocked state to the relay standby state.

[0052] After the recovery module sends a relay activation signal, it restores the starting access control point to the blocked state.

[0053] The path interruption module is used to keep the door open and send a path interruption notification to the control center when a path interruption signal is received.

[0054] The instruction processing module is used to receive path interruption notifications and issue door closing instructions according to predetermined emergency operations, thereby terminating door opening and executing the closing action.

[0055] The above scheme provides a system solution for implementing the above method, which is convenient for practical deployment and application.

[0056] As can be seen from the above, the RFID-based temporary access control method and system provided in this application generates path guidance instructions based on the evacuation route definition under a global lockdown state, enabling access control points to enter a guidance / relay standby state. This allows for one-time door opening in response to any identity credential, and the transmission of access permissions is achieved through a relay activation signal. Thus, while maintaining a global lockdown, it provides temporary, controlled, and directional access capabilities for preset routes. This improves the efficiency and safety of emergency evacuation while maintaining the lockdown status of other areas, enhancing the system's flexibility.

[0057] To further understand the features and technical content of the present invention, please refer to the following detailed description and drawings of the present invention. However, the drawings provided are for reference and illustration only and are not intended to limit the present invention. Attached Figure Description

[0058] Figure 1 This is a flowchart of the method of the present invention;

[0059] Figure 2 This is a schematic diagram of the overall structure of the present invention. Detailed Implementation

[0060] The following specific embodiments illustrate the implementation of the present invention. Those skilled in the art can understand the advantages and effects of the present invention from the content disclosed in this specification. The present invention can be implemented or applied through other different specific embodiments, and various details in this specification can also be modified and changed based on different viewpoints and applications without departing from the spirit of the present invention. Furthermore, the accompanying drawings of the present invention are for simple illustrative purposes only and are not depictions of actual dimensions; this is stated in advance. The following embodiments will further describe the relevant technical content of the present invention in detail, but the disclosed content is not intended to limit the scope of protection of the present invention.

[0061] This embodiment provides a method and system for hierarchical management of temporary access rights based on RFID, combined with... Figure 1 and Figure 2 As shown.

[0062] refer to Figure 1 A method for hierarchical management of temporary access rights based on RFID, comprising the following steps:

[0063] S1: When a sudden event that triggers a global lockdown is detected, the control center generates a path guidance instruction based on the evacuation path definition that includes multiple ordered access control points. The path guidance instruction includes the path identifier, the next access control point identifier, and the authorized validity period.

[0064] S2: Send the path guidance instruction to the starting access control point in the path definition;

[0065] S3: After receiving the path guidance instruction, the starting access control point enters the guidance standby state. In the guidance standby state, it responds to the triggering of any identity credential, performs a one-time door opening action, and sends a relay activation signal to the next access control point based on the path guidance instruction.

[0066] S4: After receiving the relay activation signal, the next access control point will enter the relay standby state from the blocked state.

[0067] S5: In the relay standby state, the next access control point responds to the trigger of any identity credential, performs a one-time door opening action, and continues to pass the relay activation signal to the access control point located after the next access control point in the path definition;

[0068] S6: After each access control point completes the corresponding relay activation signal transmission, it returns to the blocked state.

[0069] The global lockdown state refers to the system being in the highest level of security isolation mode. In this mode, regular authentication and access control are suspended or overridden to restrict the movement of people. This can be achieved by a central control system issuing unified commands to all access control points, such as forcibly locking all doors and rejecting any identity credential scanning requests. Its primary purpose is to quickly establish physical isolation and ensure area security in the event of an emergency.

[0070] An emergency is an unplanned event that requires the activation of an emergency response. It can include various types such as fire alarms, security alarms, and equipment malfunctions. Its main purpose is to trigger the system's emergency plan and enter a specific operating mode.

[0071] A control center is an entity responsible for the centralized management and coordination of the entire access control or security system. It can be implemented using one or more servers, dedicated hardware controllers, or a software platform. Its main functions are to receive event information, store configuration data, generate control commands, and distribute them to various access control points.

[0072] An ordered access control point refers to multiple access control devices arranged in a preset order. It may include access control terminals equipped with RFID readers, door drive components, and status sensors. Its main purpose is to define a specific path in space, ensuring that personnel can only move along that path.

[0073] Evacuation route definition refers to a data structure pre-configured in the control center, which contains the sequence information of ordered access control points that constitute an evacuation route. It can be stored in the form of a list, array, or database records. Its main purpose is to quickly designate an available emergency evacuation route when needed.

[0074] Route guidance instructions are data messages generated by the control center and sent to access control points. They include information such as the route identifier, the next access control point identifier, and the authorized validity period. Their main purpose is to initiate the activation process of evacuation routes and provide necessary guidance information to access control points along the routes.

[0075] The "Guidance Standby" state refers to a special operating mode that the initial access control point in an evacuation route enters after receiving a route guidance instruction. In this state, the access control point is ready to respond to triggers from any identification credential. Its main purpose is to ensure that the starting point of the evacuation route can be activated by any person to begin the evacuation process.

[0076] Any identity credential refers to any identification medium detected by an access control reader. This can include RFID cards with different access levels, or even cards without valid permissions. Its primary purpose is to respond to access requests in emergency situations without requiring detailed verification of the person's identity.

[0077] A one-time door opening action refers to the access control point performing a single door opening operation after a trigger response. This operation can involve the door closing immediately after opening, automatically closing after a preset time, or allowing the door to open again only after it has closed completely. Its main purpose is to ensure that the door can promptly return to a closed state after allowing personnel to pass, preventing non-evacuation personnel from entering or deviating from the designated path.

[0078] A relay activation signal is a data signal sent from one access control point to the next access control point in an evacuation path. This signal is used to notify the next access control point to enter a standby state. Its main purpose is to achieve step-by-step, sequential activation of the evacuation path, forming a one-way passageway.

[0079] Relay standby mode refers to a special operating mode that other access control points along the evacuation route, besides the initial access control point, enter after receiving a relay activation signal. In this state, the access control points are ready to respond to triggering by any identification credential. Its main purpose is to ensure that subsequent access control points along the evacuation route can be activated sequentially to facilitate the passage of evacuees.

[0080] Returning to a locked-down state refers to the operational mode where the access control point, after completing its task within the evacuation route, returns to a globally locked-down state. This is primarily to ensure that after evacuees have passed through and completed the relay activation, the access control point can re-enforce the highest level of security isolation functions, maintaining the security of other areas of the venue.

[0081] The core innovation of this application lies in introducing an evacuation path definition based on orderly access control points under a global lockdown, and utilizing a step-by-step transmission mechanism of path guidance instructions and relay activation signals, combined with the access control points' response to any identity credential and one-time door opening action, thereby opening a temporary, controllable, and one-way evacuation channel for people with mixed identities without lifting the global lockdown. This achieves the effect of rapidly responding to emergencies, ensuring the safe evacuation of personnel, and maintaining the safe isolation of other areas.

[0082] The solution in this application achieves its function through the following steps: When the system detects a sudden event that triggers a global lockdown, the control center generates a path guidance instruction based on a predefined evacuation route containing multiple ordered access control points. This instruction includes information identifying the route, the identifier of the next access control point in the route, and the validity period of the route. Subsequently, the control center sends this path guidance instruction to the starting access control point in the evacuation route. Upon receiving the instruction, the starting access control point changes its operating state from the global lockdown state to the guidance standby state. In the guidance standby state, the starting access control point can respond to any identity credential triggering and perform a one-time door opening action, allowing personnel to pass. Simultaneously, based on the received path guidance instruction, the starting access control point sends a relay activation signal to the next access control point defined in the route. Upon receiving this relay activation signal, the next access control point also changes its operating state from the global lockdown state to the relay standby state. In relay standby mode, this access control point can also respond to any identification credential trigger, performing a one-time door opening action and continuing to pass the relay activation signal to the next access control point in the path. This process proceeds sequentially along the evacuation route, forming a relay chain of activation signals. After each access control point completes sending the relay activation signal to the next access control point, it returns to a globally blocked state. Through this mechanism of tiered activation, one-time passage, and timely restoration of blockage, it ensures that evacuees can pass through sequentially along the preset path, preventing them from arbitrarily entering other areas along the path, while maintaining the blockage status of areas outside the evacuation route.

[0083] In some preferred embodiments, this application is implemented as follows: Assume a fire alarm in a large venue triggers a global system lockdown. The control center, according to a pre-set emergency plan, selects an evacuation route from the main exhibition hall to the safety exit, which passes through access control points A, B, and C in sequence. The control center generates a route guidance instruction, including the route identifier "EVAC-HALL1-EXIT2", the next access control point identifier "Access Control Point B", and a validity period of "15 minutes", and sends this instruction to access control point A. Upon receiving the instruction, access control point A's controller enters a guidance standby state. At this time, any person holding an RFID card, regardless of their original permissions, can swipe their card in front of the reader at access control point A. Access control point A will then perform an opening action, such as unlocking the electromagnetic lock and automatically locking it after a few seconds. Simultaneously, access control point A's controller sends a relay activation signal to access control point B via the network, the signal containing the route identifier "EVAC-HALL1-EXIT2". Upon receiving the signal, the controller at access point B transitions from a blocked state to a relay standby state, ready to respond to any card swipe trigger. When a person passes through access point A, its controller returns to the blocked state. Subsequently, the person arrives at access point B and triggers it with an arbitrary card swipe. Access point B then performs an opening action and sends a relay activation signal to access point C. Access point C, upon receiving the signal, enters the relay standby state. Access point B then reopens the blocked state after sending the signal. Personnel then pass through access point C in sequence. Access point C performs an opening action; as it is the end point of the path, it may not send another relay signal and returns to the blocked state after opening. The entire process creates a temporary passageway open only along a preset path.

[0084] The above technical solution provides a temporary and controllable evacuation route for evacuees after a global lockdown is triggered by an emergency. This method allows individuals with mixed identities to trigger access control using any identification credentials, solving the problem of not being able to pre-authorize each person individually. Through relay activation and a one-time door opening action, it ensures that people can only move in one direction along the preset path and cannot enter other non-open rooms along the path, improving the safety of the evacuation process. Simultaneously, the entire process does not require lifting or changing the mandatory lockdown status of other areas of the venue, maintaining the security level of other areas and avoiding unnecessary security risks.

[0085] This application further proposes to include the following steps in S3:

[0086] In response to the triggering of any identity credential, an opening command is sent to the door drive component associated with the starting access control point, and physical status information is obtained from the status sensor associated with the door.

[0087] Based on the physical state information, determine whether the door is already in the open position;

[0088] When the judgment result is yes, the starting access control point sends a relay activation signal to the next access control point.

[0089] Among them, triggering any identity credential means that the access control point receives any signal input used for identity recognition or authorization verification. Specifically, it can be an RFID reader sensing an RFID card, a biometric device recognizing a biometric feature, or a password input device receiving a password input. Its purpose is to initiate the response process of the access control system.

[0090] Among them, the door drive component refers to the actuator responsible for performing the physical opening and closing actions of the door. Specifically, it can be an electric push rod, a hydraulic cylinder, an electromagnetic lock, or a motor-driven robotic arm. Its purpose is to change the physical state of the door according to the received instructions.

[0091] Among them, the status sensor refers to the sensing device used to monitor the physical position or status of the door in real time. Specifically, it can be a limit switch, proximity sensor, photoelectric sensor or angle encoder. Its purpose is to provide objective data on the current status of the door.

[0092] Among them, physical state information refers to the data collected by the state sensor that reflects the current physical state of the door. Specifically, it can be information such as whether the door is in the fully open position, the opening angle of the door, or whether the door is blocked. Its purpose is to provide a basis for the system to judge the state of the door.

[0093] The open position refers to the physical position or state in which the door has been moved to allow people to pass normally. Specifically, it can be that the door is fully open, the door has been moved to a preset opening angle, or the locking mechanism on the door has been released. Its purpose is to ensure that the passage is unobstructed.

[0094] This application's solution, upon receiving a trigger from any identification credential at the initial access control point, first sends an opening command to the associated door drive component, attempting to open the door. Simultaneously, the system acquires physical status information returned by the door's associated status sensors, reflecting the door's actual physical state. Based on this information, the system determines whether the door has reached the preset opening position. Only when the determination confirms the door is indeed in the open position will the initial access control point send a relay activation signal to the next access control point in the path. This mechanism ensures that the relay activation signal is sent synchronously with the door's actual opening state, preventing the erroneous activation of the next access control point when the door is not open. It is precisely this added verification step regarding the door's actual opening state that makes the relay process of the entire evacuation route more reliable, improving the efficiency and safety of personnel evacuation in emergencies.

[0095] In some preferred embodiments, when the initial access control point is in a guidance standby state, for example, after receiving a path guidance instruction from the control center, once any identification credential, such as a regular employee RFID card, is detected in front of the initial access control's reader, the initial access control point will immediately send an opening instruction to the electric sliding door motor controlling the door. Simultaneously, a limit switch installed at the end of the sliding door frame continuously monitors the door's physical position. When the electric sliding door motor drives the door to the fully open position, the door edge triggers the limit switch, which then returns a physical status message indicating "door open" to the initial access control point. Upon receiving this message, the initial access control point determines that the door is indeed in the open position. Only when this determination is "yes" will the initial access control point send a relay activation signal to the next preset access control point in the path via a network or dedicated communication line, notifying it to enter a relay standby state.

[0096] By employing the aforementioned technical solution, when the initial access control point responds to the identity credential trigger to execute the door opening action, a step of judging the actual physical state of the door is added. The system no longer relies solely on sending the door opening command, but instead confirms that the door is indeed in the open position only after obtaining physical state information returned by status sensors. This effectively avoids the situation where subsequent access control points mistakenly enter the relay standby state due to the door failing to open successfully. This ensures that each access control point on the evacuation route activates the next point only when the door is actually passable, improving the reliability and smoothness of the entire evacuation process and guaranteeing that personnel can effectively evacuate according to the preset route in emergencies.

[0097] This application further proposes to include the following steps in S3:

[0098] Respond to any identity credential trigger and determine whether the trigger is the first trigger in the guided standby state;

[0099] If the judgment result is yes, then the door opening action is executed, a relay activation signal is sent to the next access control point, and a timer is started to suppress subsequent trigger responses;

[0100] During the timing period, if a subsequent identity credential is received, the door opening action will not be performed, nor will the relay activation signal be sent.

[0101] The process of determining whether a trigger is the first trigger in the guided standby state refers to identifying the first valid identity credential trigger signal received after the access control point enters the guided standby state. This can be achieved by maintaining a status flag, which is set to an initial value upon entering the guided standby state and modified after the first trigger is received and processed. Its purpose is to distinguish subsequent repeated trigger signals. Activating a timer to suppress subsequent trigger responses involves activating a timer or timing mechanism that remains valid within a set time window. This can be implemented using a software or hardware timer, with the purpose of setting a time interval during which subsequent trigger signals are ignored. During the timer's validity period, if a subsequent identity credential trigger is received, neither the door opening action nor the sending of a relay activation signal will be performed. This means that within the timer's valid period, even if the access control point receives a new identity credential trigger signal, the system will not perform a door opening operation or send a relay activation signal to the next access control point. This aims to prevent redundant operations caused by repeated triggers within a short period.

[0102] This application's solution, upon responding to any identity credential trigger, first determines whether the trigger is the first trigger in the guided standby state. If it is the first trigger, it executes an opening action and sends a relay activation signal to the next access control point, while simultaneously starting a timer. During the timer's validity period, any subsequent identity credential triggers are ignored, and no opening or signal transmission actions are performed. This mechanism ensures that after the access control point enters the guided standby state, it only responds to the first valid trigger within a set time window, executing one opening and one signal transmission. After the timer expires, the access control point can return to a state capable of responding to new first triggers (if the evacuation route process has not yet been completed). Thus, this solution, combined with the basic evacuation route guidance and relay activation mechanism, enables temporarily opened evacuation routes to operate more stably and orderly in emergency evacuation scenarios, avoiding repeated opening and closing of access control points and signal confusion caused by crowd congestion or misoperation. It is precisely this effective suppression of repeated triggers that improves the efficiency and safety of the entire evacuation process.

[0103] In some preferred embodiments, specifically, after the initial access control point receives the path guidance instruction and enters the guidance standby state, an internal system state variable, for example named `isFirstTriggerHandled`, is initialized to false. When an identity credential is read and triggers the access control, the system first checks the state of `isFirstTriggerHandled`. If `isFirstTriggerHandled` is false, it is determined to be the first trigger. At this time, the access controller sends an opening instruction to the associated door drive component and sends a relay activation signal to the next access control point specified in the path guidance instruction via the communication interface. Simultaneously, a software timer is started, set to a duration of, for example, 15 seconds, and `isFirstTriggerHandled` is set to true. Within the next 15 seconds, if the system receives another identity credential trigger signal, the controller checks `isFirstTriggerHandled` and finds it to be true, then it does not perform the actions of opening the door and sending the relay activation signal. After the 15-second countdown ends, the timer callback function can reset `isFirstTriggerHandled` to false so that it can respond to a new first trigger in the next time window (if needed).

[0104] The above technical solution effectively avoids redundant door opening actions and repeated activation signal transmissions caused by repeated triggering of access control points within a short period of time. This reduces the ineffective use of system resources, improves the response efficiency and stability of the access control system, reduces equipment wear and safety risks that may result from repeated operations, and ensures the reliability of temporary routes in emergency evacuation scenarios.

[0105] This application further proposes that in step S5, when a route reassignment request is detected, a permission reassignment instruction is sent to the next access control point. The permission reassignment instruction is used to instruct the next access control point to forward the relay activation signal to another preset access control point when the relay activation signal is transmitted, so that the other access control point enters the relay standby state from the blocked state.

[0106] Among them, route reassignment request refers to a signal or instruction that needs to change the currently executing evacuation route. It can be generated through manual input, automatic system detection, or linkage with other security systems. Its purpose is to respond to emergencies and adjust the evacuation direction. Permission reassignment instruction refers to an instruction sent by the control center or other decision-making unit to the access control point to modify the relay activation signal forwarding target. It can include information such as the new target access control point identifier and reassignment effective conditions. Its purpose is to change the transmission direction of the relay activation signal. Another preset access control point refers to the access control point designated as the new relay activation signal receiver when a route reassignment request occurs. It can be pre-configured during system initialization or dynamically determined by the control center when a route reassignment request is detected. Its purpose is to provide alternative evacuation route entrances.

[0107] This application's solution introduces a route reassignment function on top of the existing access control relay activation evacuation mechanism, enabling dynamic adjustment of evacuation routes. In the basic scheme, the relay activation signal is transmitted step-by-step along a preset ordered path, driving access control points to open sequentially. When a route reassignment request is detected, such as an anomaly at the next access control point on the original path, the system no longer simply waits or fails, but instead sends a permission reassignment command to that next access control point. This command alters the behavior logic of the next access control point, causing it to, upon receiving the relay activation signal from the previous access control point, no longer pass the signal to the next access control point on the original path as originally planned, but instead, according to the permission reassignment command, forward the relay activation signal to another preset access control point. Upon receiving the forwarded relay activation signal, this other access control point transitions from a blocked state to a relay standby state, thus becoming the starting point or intermediate node of a new evacuation route. This mechanism allows the system to smoothly guide evacuees to new, available routes without interrupting the already initiated evacuation process. In this way, this application overcomes the lack of flexibility of the basic scheme when facing path obstacles, and improves the reliability and adaptability of the evacuation system.

[0108] In some preferred embodiments, a specific example is given below. Assume a planned evacuation route passes through access control points A, B, and C. According to the basic scheme, after receiving a route guidance instruction, access control point A responds by triggering an activation and sends a relay activation signal to access control point B. Access control point B, upon receiving the signal, enters a relay standby state, responds by triggering an activation and sends a relay activation signal to access control point C. Now, if, while access control point B is in a relay standby state, the system detects a malfunction in access control point C, preventing it from opening normally, a route reassignment request is generated. At this time, the control center can send a permission reassignment instruction to access control point B. This instruction instructs access control point B, when it receives a relay activation signal from access control point A (or after it is already in a relay standby state and has responded to a trigger), not to send the relay activation signal to access control point C, but instead forward it to another pre-set access control point D, which is located on a backup evacuation route. After receiving the relay activation signal forwarded by access control point B, access control point D changes from the blocked state to the relay standby state, ready to respond to the trigger to open, thereby switching the evacuation route from A->B->C to A->B->D->...

[0109] Through the above technical solution, this application can quickly and flexibly adjust the evacuation route when the original evacuation route is obstructed during the evacuation process of an emergency, and forward the relay activation signal to the access control point on the backup route, thereby ensuring the continuity and effectiveness of the evacuation process and improving the response capability and safety of the evacuation system.

[0110] This application further proposes that the next access control point in step S5 includes the following steps:

[0111] After the relay activation signal is forwarded to another access control point, a timer is started to receive the forwarding confirmation information;

[0112] If no forwarding confirmation message is received from another access control point before the timeout, the relay activation signal is deemed to have failed to forward, and a failure notification is sent to the control center.

[0113] After receiving the failure notification, the control center sends a remedial activation command to another access control point, so that the other access control point goes from the blocked state to the relay standby state.

[0114] The process involves several key steps: **Starting a timer for receiving forwarding confirmation information:** This involves activating a timer to monitor whether a specific response message is received within a preset time window. A fixed timer duration can be set to detect anomalies during signal forwarding promptly. **Forwarding confirmation information:** This information, sent back by the access control point that received the forwarded signal, indicates that it has successfully received and processed the signal. It can be a data packet containing a specific identifier or status code, providing feedback to the sender. **Determining relay activation signal forwarding failure:** This involves determining whether signal transmission was successful based on whether a forwarding confirmation message was received before the timer expires. This can be achieved by checking the timer status and whether a specific response message was received, identifying situations where the signal was not effectively delivered. **Failure notification:** This involves reporting the signal forwarding failure to the upper-level control system. It can be an alarm message containing the reason for the failure and information related to the access control point's identifier, triggering the control center to take subsequent remedial measures. A remedial activation command is a command sent directly from the control center to the target access control point to force it into a specific working state. Specifically, it can be a control command containing a target status identifier and a path identifier. Its purpose is to bypass the failed forwarding process and directly restore the path function.

[0115] This application's solution adds a timed confirmation step after the access control point attempts to forward the relay activation signal, allowing the access control point to actively detect whether the forwarding was successful. If no confirmation is received after the timeout, the forwarding is considered a failure, and this situation is promptly reported to the control center. Upon receiving the failure notification, the control center no longer relies on relay forwarding between access control points but directly sends a remedial activation command to the next expected access control point. This mechanism adds a fault-tolerant and remedial layer for forwarding failures to the original relay activation and route reassignment scheme based on path definition. Through direct intervention from the control center, potentially problematic inter-access control communication links can be effectively bypassed, ensuring that the target access control point can be activated and enter relay standby mode, thereby guaranteeing the continuity and reliability of the evacuation route and preventing the entire route from being interrupted due to forwarding failures in intermediate links.

[0116] In some preferred embodiments, specifically, assuming an evacuation route is initially defined as passing through access control A, access control B, and access control C. During the evacuation, the control center detects that the route needs to be reassigned to pass through access control A, access control B, and access control D. The control center sends a permission reassignment instruction to access control B, instructing it to forward the relay activation signal received from access control A to access control D. After receiving the relay activation signal from access control A, access control B attempts to send a message containing relay activation information to access control D via the network. After sending this message, access control B immediately starts a timer, for example, setting the waiting time to 5 seconds, to receive forwarding confirmation information from access control D. If access control B fails to receive forwarding confirmation information from access control D within the set 5 seconds, access control B determines that the relay activation signal to access control D has failed to forward. Subsequently, access control B generates a failure notification, including the identifiers of access control B and access control D and a forwarding failure status code, and sends the notification to the control center. Upon receiving the failure notification from access control B, the control center immediately generates a remedial activation command. This command includes a path identifier and an instruction to access control D to enter relay standby mode, and is sent directly to access control D via the network. Upon receiving the remedial activation command from the control center, access control D transitions from its current blocked state to relay standby mode, thus successfully establishing a path connection from access control B to access control D and ensuring unobstructed evacuation routes.

[0117] The above technical solution can promptly detect problems when relay activation signal forwarding fails and remedy them through direct intervention from the control center, ensuring that the expected access control point can enter the relay standby state. This effectively avoids evacuation path interruption caused by forwarding failure and improves the reliability of the system in reassigning routes during emergencies.

[0118] This application further proposes a technical solution to solve the above problems, which includes the following steps:

[0119] When a backup activation command or relay activation signal is received at another preset access control point, the other preset access control point extracts the path identifier corresponding to the evacuation path from the received backup activation command or relay activation signal.

[0120] The other preset access control point determines whether it is already in the relay standby state corresponding to the extracted path identifier based on the extracted path identifier.

[0121] When the judgment result is negative, another preset access control point is controlled to enter the relay standby state corresponding to the extracted path identifier.

[0122] In the above steps, some technical features need to be explained. The path identifier refers to information used to uniquely identify an evacuation route, which can be implemented using numerical codes, strings, or other unique identifiers. The relay standby state corresponding to the extracted path identifier refers to a state in which the access control point is ready to respond to a specific path identifier received, triggering and transmitting an activation signal. This can be understood as the access control point being activated and associated with a specific evacuation route.

[0123] The solution presented in this application achieves precise control of the access control point's state through the coordinated operation of the aforementioned steps. Specifically, its working principle is as follows: This application solves the above-mentioned problem because when another pre-set access control point receives an activation command (remedial activation command or relay activation signal), it does not directly change its own state, but instead extracts a path identifier from the command. Because of this extracted path identifier, the access control point can identify which specific evacuation route the command is targeting. Based on this, the access control point determines whether it is currently in a relay standby state corresponding to that path identifier, according to the extracted path identifier. This determination process is crucial; it allows the access control point to check whether it has already been activated by a command for the same path. Only when the determination result is negative, i.e., the access control point has not yet entered a relay standby state for that specific path, does it execute a state transition, controlling itself to enter the relay standby state corresponding to the extracted path identifier. This path identifier-based state determination mechanism effectively avoids duplicate activation caused by repeatedly receiving activation commands for the same path, and also avoids potential state conflicts or erroneous activations when receiving commands for different paths.

[0124] To more clearly illustrate the technical solution of this application, a specific example is provided below. In some preferred embodiments, another preset access control point can be configured with a communication module for receiving remedial activation commands or relay activation signals. These commands or signals can adopt a specific data packet format, which includes a field for storing path identifiers. After receiving the data packet, the processing unit inside the access control point parses the data packet and reads the path identifier from the preset field. The processing unit can maintain an internal status register or storage area to record which path identifiers the current access control point has entered the relay standby state for. The processing unit queries the internal status record based on the read path identifier. If the query result shows that the state corresponding to the path identifier has not yet been activated, the processing unit updates the internal status record and switches the operating state of the access control point to the relay standby state corresponding to the path identifier. If the query result shows that the state corresponding to the path identifier is already activated, the processing unit discards the command and does not perform the state switching operation.

[0125] Through the above technical solution, this application effectively solves the problems existing in the prior art and brings positive technical effects. Specifically, when another preset access control point receives an activation command, it can identify the evacuation route to which the command belongs and determine whether it is already in a standby state for that route. This effectively avoids access control status confusion caused by repeatedly receiving the same command or simultaneously receiving different commands, ensuring that the access control point only enters a relay standby state for specific evacuation routes that have not been activated. This improves the accuracy and reliability of the access control system's status in route reassignment or remedial activation scenarios, helps maintain the effectiveness of preset evacuation routes, and ensures the efficiency and safety of personnel evacuation.

[0126] This application further proposes to include the following steps in S6:

[0127] After sending the relay activation signal, wait to receive confirmation information from the next access control point. The confirmation information indicates that the next access control point has entered the relay standby state.

[0128] Upon receiving confirmation, the initial access control point is restored to the locked state.

[0129] The confirmation message refers to specific data or signals returned by the next access control point, indicating that it has successfully received the relay activation signal and entered the relay standby state. This can be implemented using specific message types or data packets in network communication protocols. Its purpose is to provide a mechanism for the sender to verify whether the receiver's state transition was successful. The relay standby state is a temporary operating mode entered by the access control point after receiving the relay activation signal. In this mode, the access control point responds to triggers from any identity credential, performing a one-time door opening action. This can be implemented using a software state machine or control logic, and its purpose is to allow unspecified personnel to pass through the access control. The blocked state is the default security mode of the access control point under normal or emergency conditions. In this mode, the access control point rejects scanning requests for regular identity credentials. This can also be implemented using a software state machine or control logic, and its purpose is to restrict personnel access.

[0130] The proposed solution involves a process where, after the initial access control point sends a relay activation signal, it does not immediately return to the blocked state. Instead, it waits to receive confirmation from the next access control point, indicating that the next access control point has successfully entered the relay standby state. Only after receiving this confirmation does the initial access control point return to the blocked state. This mechanism ensures that the next access control point has successfully entered the relay standby state and is ready to respond to subsequent identity credential triggering before the initial access control point completes its task and exits the guided standby state. This avoids evacuation path disruptions caused by unsuccessful relay activation signal transmission or the next access control point failing to correctly transition its state.

[0131] In some preferred embodiments, assume that the first access control point on the evacuation route is access control point A, and the next access control point is access control point B. When access control point A sends a relay activation signal to access control point B according to the route guidance instructions, this signal can be a network data packet containing a specific protocol header and the identifier of access control point B, sent through the local area network within the venue. After sending, the control program of access control point A enters a waiting loop, listening for specific responses from access control point B. After receiving the data packet, access control point B parses the instructions within it, transitions its internal state machine from the blocked state to the relay standby state, and sends an acknowledgment data packet to access control point A. This data packet can contain the identifier of access control point A and a status code indicating successful operation. After receiving this acknowledgment data packet, access control point A parses and verifies its validity, confirming that access control point B has successfully entered the relay standby state. At this time, the control program of access control point A restores its own state to the blocked state and can execute the action of closing the door.

[0132] Through the above technical solution, after sending the relay activation signal, the initial access control point can clearly know whether the relay activation signal was successfully delivered and whether the next access control point has successfully entered the relay standby state by waiting for and receiving confirmation information from the next access control point. This effectively solves the problem that the initial access control point cannot determine whether the relay process was successful, avoids evacuation path interruptions caused by information asymmetry or transmission failure, and thus improves the reliability and safety of the entire temporary evacuation path activation process.

[0133] This application further proposes that S6 also include the following steps:

[0134] If no confirmation is received within the preset waiting time, the relay activation signal is deemed to have failed to be sent.

[0135] In response to the judgment result, the door associated with the initial access control point is kept in the open position;

[0136] Send a path interruption notification to the preset control center, containing the identifier of the starting access control point and the identifier of the next access control point.

[0137] The preset waiting time refers to the maximum allowed time interval during which the system expects to receive confirmation information after sending the relay activation signal. This time interval can be configured based on factors such as network environment and device response speed. The confirmation information is a message returned by the next access control point indicating that it has successfully received the relay activation signal and entered relay standby mode. It may include path identifiers, sender identifiers, and receiver identifiers. Determining relay activation signal transmission failure means that if the system does not receive confirmation information from the next access control point after the preset waiting time has expired, it infers that the signal was not successfully transmitted or the other party failed to respond correctly. This can be triggered based on a timer timeout event. Maintaining the door associated with the initial access control point in an open state is also considered. "Activation position" refers to the system's actions to keep the door associated with the current access control point open after a signal transmission failure, instead of restoring it to a closed state as originally planned. This can be achieved by continuously sending opening commands to the door drive components, locking the door status, or preventing the door from closing automatically. "Preset control center" refers to the central management platform responsible for the management and emergency response of the entire access control system. It can be a physical server cluster or a software system. "Path interruption notification" refers to the alarm information sent by the starting access control point to the control center to report the failure of the relay activation signal transmission and potential interruption of the evacuation path. It can include the identifier of the access control point where the failure occurred and the identifier of the next access control point expected to receive the signal.

[0138] This application's solution sets a preset waiting time after sending the relay activation signal, and determines the transmission failure if no confirmation is received within this time, thus promptly identifying potential fault points in the relay chain. Because of this timely failure determination, the system does not execute the originally planned operation to restore the blocked state. Instead, it responds to the determination result by keeping the door associated with the starting access control point in the open position. This ensures that the current access control point does not obstruct the evacuation route, maintaining its connectivity. Simultaneously, by sending a path interruption notification containing the identifiers of the starting and next access control points to the preset control center, the fault information is accurately reported to the control center. This mechanism prevents evacuation route interruption when an anomaly occurs during the relay activation signal transmission and provides the control center with necessary fault information so that it can take further emergency measures, such as retrying activation, adjusting evacuation routes, or manual intervention. The entire process improves the reliability of evacuation routes and the efficiency of emergency response without affecting the blocked status of other areas.

[0139] In some preferred embodiments, after an emergency occurs, the control center sends a path guidance instruction to the initial access control point A according to the evacuation route definition. Access control point A enters a guidance standby state upon receiving the instruction. When someone passes through access control point A, it performs an opening action and sends a relay activation signal to the next access control point B in the route definition. Access control point A starts a timer, for example, setting a preset waiting time of 5 seconds, to wait for confirmation information from access control point B. If access control point A does not receive confirmation information from access control point B within 5 seconds, its processor determines that the relay activation signal transmission failed. In response to this determination, access control point A continuously sends opening instructions to its connected door drive component to ensure the door remains open. Simultaneously, access control point A sends a path interruption notification message to the preset control center via a network connection. This message includes the identifier of access control point A (e.g., "ID_A") and the identifier of access control point B (e.g., "ID_B"), as well as a status code indicating path interruption. Upon receiving this notification, the control center can display a problem on its management interface regarding the path segment between access control point A and access control point B, and trigger corresponding alarms or automated processing procedures.

[0140] The above technical solution enables timely detection of faults and maintenance of the current access control system's open state in the event of a failed relay activation signal, preventing evacuation route interruptions. Simultaneously, the fault information is accurately reported to the control center, providing support for subsequent emergency response and improving the overall reliability and emergency response capability of the evacuation system.

[0141] This application further proposes steps for maintaining the door associated with the initial access control point in the open position, including:

[0142] While performing the action of keeping the door in the open position, listen for door closing commands from the control center;

[0143] When a door closing command is received from the control center, the action of maintaining the door in the open position is terminated.

[0144] Perform the action of closing the door.

[0145] Listening for door closing commands from the control center refers to the access control point continuously monitoring the communication link with the control center to receive specific door control commands. This can be achieved using polling communication, interrupt-driven communication, or message queue-based communication mechanisms, with the aim of timely obtaining door status change indications from the control center. Terminating the action of maintaining the door in the open position means stopping the transmission of commands to the door drive component to keep the door open or disconnecting the power connection to maintain the door open position. Executing the action of closing the door refers to sending a command to the door drive component to move the door from the open position to the closed position.

[0146] This application's solution adds monitoring for door closing commands from the control center while maintaining the door in the open position. This allows the access control point to receive remote control commands while handling relay activation signal failures and keeping the door open. When the control center determines that the door needs to be closed based on the actual situation, it can send a door closing command. Upon receiving this command, the access control point will immediately stop maintaining the door's open state and instead execute the door closing action. This mechanism does not simply maintain the door open; it adds a layer of remote control logic. This ensures that even if the emergency evacuation route is interrupted, the door, although temporarily opened for evacuation, is not uncontrollable. The control center can intervene and close the door in a timely manner based on on-site feedback or safety assessments, thus preventing the door from remaining unsupervised and open for extended periods and effectively mitigating the security vulnerabilities that might arise from simply maintaining the open state. This solution, combining automatic opening and remotely controllable closing, achieves a balance between ensuring emergency passage needs and maintaining area security.

[0147] In some preferred embodiments, the access control point can be configured with a communication module, such as an Ethernet interface or a wireless communication module, to establish a communication connection with the control center. After determining that the relay activation signal transmission has failed and triggering the action of maintaining the door open, the control program inside the access control point will enter a loop or enable an interrupt service to continuously check the data stream received through the communication module. This program is designed to recognize door closing instructions of a specific format or containing specific identifiers. For example, the instruction sent by the control center might be a data packet containing the access control point identifier and a "close" command. Once the access control point receives and parses a door closing instruction conforming to a preset format, the control program will immediately stop sending signals to the connected door drive component (e.g., an electric lock or motor controller) to maintain the open state, and subsequently send a signal to close the door. Upon receiving the closing signal, the door drive component will drive the door to the closed position.

[0148] Through the above technical solution, in the event that the door remains open due to the failure of the relay activation signal transmission, the system adds the ability to remotely control and close the door, avoiding the door from remaining open for a long time, reducing potential safety risks, and improving the flexibility and safety of emergency handling.

[0149] In practical applications, after the global lockdown is lifted, the system can revert to normal access control (i.e., normal management state). In normal management state, those skilled in the art can manage access control security by combining commonly used anti-tailgating detection methods with specific application scenarios. For example, a door opening timeout (e.g., 2 to 3 seconds) can be set, automatically triggering an alarm or forcibly closing the door if it remains open for an extended period. Alternatively, infrared sensors, pressure sensors, and video analytics modules can be used to detect the number of people passing through the door; when a single door opening action corresponds to more than one person's passage, an audible and visual alarm is triggered, and an alarm message is sent to the control center. The aforementioned anti-tailgating function is primarily used for access management when the access control is in normal access control mode and is not applicable to path relay authorization processes during global lockdown emergency evacuation.

[0150] refer to Figure 2 This application further proposes an RFID-based temporary access control system, applied to an RFID-based temporary access control method. The system includes:

[0151] The path generation module is used to send a path guidance instruction to the starting access control point based on the path definition containing multiple ordered access control points. The path guidance instruction includes the information of the next access control point.

[0152] The initial access control module is used to enter the guidance standby state after receiving the path guidance instruction, respond to the trigger of any identity credential, execute the door opening action, and send a relay activation signal to the next access control point;

[0153] After receiving the relay activation signal, the relay control module performs a state transition, changing from the blocked state to the relay standby state.

[0154] After the recovery module sends a relay activation signal, it restores the starting access control point to the blocked state.

[0155] The path interruption module is used to keep the door open and send a path interruption notification to the control center when a path interruption signal is received.

[0156] The instruction processing module is used to receive path interruption notifications and issue door closing instructions according to predetermined emergency operations, thereby terminating door opening and executing the closing action.

[0157] The path generation module is a unit responsible for generating instructions to guide the access control system in state switching and information transmission based on preset or dynamically generated path information. Specifically, it can be a software program module running on the control center server, its purpose being to determine evacuation or passage routes and activate the access control response mechanisms along those routes. The starting access control module, located at the beginning of the preset path, is responsible for receiving path guidance instructions, entering a specific working state according to the instructions, and responding to triggers to execute door opening and information transmission functions. Specifically, it can be a hardware circuit or software logic integrated into the access control controller, its purpose being to act as the starting point of the path and initiate the entire chain response process. The relay control module, located in other access control devices along the path besides the starting access control module, is responsible for receiving activation signals from the previous access control device and changing its own working state according to the signals. Specifically, it can be a state machine logic integrated into the access control controller, its purpose being to ensure that the access control devices along the path are activated sequentially, forming a continuous passage. The access control system is divided into three modules: The recovery module is responsible for restoring the access control system to its initial or safe state after it completes its specific task within the path (e.g., sending a relay activation signal). Specifically, it can be a timer or event-triggered control logic. Its purpose is to ensure that the access control system can promptly return to a normal security management state after the path is used. The path interruption module is responsible for monitoring possible abnormal situations (e.g., door malfunction, communication failure) that may occur during the path execution process and taking specific countermeasures when an anomaly is detected. Specifically, it can be an abnormal event listener and reporter. Its purpose is to promptly detect and report problems in path execution for intervention. The instruction processing module is located in the control center or access control device and is responsible for receiving abnormal notifications from the path interruption module or other sources, generating and sending control instructions according to preset emergency strategies. Specifically, it can be an emergency plan execution engine. Its purpose is to respond to path interruption events, control the access control state, and handle abnormal situations.

[0158] This application's solution decomposes the RFID-based temporary access control method into multiple functional modules. The path generation module generates and sends path guidance instructions based on preset path definitions, initiating the entire process. Upon receiving the instruction, the initial access control module enters a specific state, awaiting triggering and executing the door opening action, while simultaneously sending a relay activation signal to the next access control, passing on the responsibility of path activation. The relay control module, upon receiving the relay activation signal, changes its own state, preparing to respond to triggering. The recovery module restores the access control to a secure mode after completing its activation task, ensuring unauthorized personnel cannot pass. The path interruption module continuously monitors for anomalies during path execution and issues notifications when problems are detected. The instruction processing module receives anomaly notifications and issues control instructions, such as closing doors, according to preset emergency plans to handle emergencies. Through the close collaboration of these modules, the system can quickly and accurately open a temporary, controlled passage path when a global lockdown is triggered by an emergency, while maintaining the lockdown status of other areas. This effectively solves the technical challenge of achieving access for specific personnel and crowd evacuation while ensuring overall safety in complex emergency scenarios.

[0159] In some preferred embodiments, this application is implemented as follows. A path generation module can be deployed on a central control server as part of the emergency management software, responsible for storing and managing predefined evacuation path information. When an emergency occurs, this module selects a suitable evacuation path based on the event type and location, and generates path guidance instructions containing the access control sequence and the next access control identifier along the path. These instructions are sent via the network to the starting access control device along the path. The starting access control device integrates the functions of a starting access control module, a recovery module, and a path interruption module. After receiving the path guidance instructions, the starting access control module changes the access control state to guidance standby. At this time, the access control responds to any RFID card or other trigger signal, controls the door to open, and sends a relay activation signal to the next access control device along the path via the network. After the starting access control sends the relay activation signal, the recovery module immediately restores the state of the starting access control to the blocked state. Other access control devices along the path, besides the starting access control, integrate the functions of a relay control module and a path interruption module. After receiving the relay activation signal from the previous access control device, the relay control module changes its state from blocked to relay standby, ready to respond to the trigger. The path interruption module continuously monitors the door status and communication status in any access control device. Once an anomaly is detected (e.g., the door cannot be opened or communication is interrupted), it maintains the current door state (e.g., remains open) and sends a path interruption notification to the central control server. Upon receiving the path interruption notification, the instruction processing module on the central control server, according to the preset emergency operation procedure, can send instructions to the interrupted access control device or other relevant access control devices, such as sending a door closing instruction, to terminate the abnormal state and execute the closing action.

[0160] Through the above technical solutions, this application provides a modularly designed system that effectively implements a RFID-based method for hierarchical management of temporary access rights. The path generation module ensures rapid determination of evacuation routes and issuance of instructions, laying the foundation for subsequent processes. The collaborative work of the initial access control module and the relay control module enables chain activation of temporary access routes, ensuring the continuity and directionality of the evacuation process. The recovery module promptly restores used access control systems to a locked state, effectively preventing unauthorized personnel from entering and improving system security. The introduction of the path interruption module and the instruction processing module provides the system with the ability to respond to sudden abnormal situations, such as door malfunctions or communication interruptions. By maintaining door open or handling the situation according to the emergency plan, the system's reliability and fault tolerance are improved. Overall, through the close cooperation of its various functional modules, this system can quickly and reliably open and manage temporary access routes when a sudden event triggers a global lockdown, effectively solving the technical problem of how to achieve the passage of specific personnel and the evacuation of crowds while maintaining overall safety in complex emergency scenarios.

[0161] The content disclosed above is only a preferred and feasible embodiment of the present invention, and is not intended to limit the scope of protection of the present invention. Therefore, all equivalent technical changes made based on the content of the present invention specification and drawings are included within the scope of protection of the present invention. Furthermore, the elements therein can be updated as technology develops.

Claims

1. A method for hierarchical management of temporary access rights based on RFID, characterized in that, The method includes the following steps: S1: When a sudden event that triggers a global lockdown is detected, the control center generates a path guidance instruction based on the evacuation path definition that includes multiple ordered access control points. The path guidance instruction includes the path identifier, the next access control point identifier, and the authorized validity period. S2: Send the path guidance instruction to the starting access control point in the path definition; S3: After receiving the path guidance instruction, the starting access control point enters the guidance standby state. In the guidance standby state, it responds to the triggering of any identity credential, performs a one-time door opening action, and sends a relay activation signal to the next access control point based on the path guidance instruction. S4: After receiving the relay activation signal, the next access control point will enter the relay standby state from the blocked state. S5: In the relay standby state, the next access control point responds to the trigger of any identity credential, performs a one-time door opening action, and continues to pass the relay activation signal to the access control point located after the next access control point in the path definition; S6: After each access control point completes the corresponding relay activation signal transmission, it returns to the blocked state.

2. The RFID-based temporary access control method as described in claim 1, characterized in that, S3 includes the following steps: In response to the triggering of any identity credential, an opening command is sent to the door drive component associated with the starting access control point, and physical status information returned by the status sensor associated with the door is obtained; Based on the physical state information, determine whether the door is already in the open position; When the judgment result is yes, the starting access control point sends a relay activation signal to the next access control point.

3. The RFID-based temporary access control method as described in claim 1, characterized in that, S3 includes the following steps: In response to the triggering of any identity credential, determine whether the trigger is the first trigger in the guided standby state; If the judgment result is yes, then the door opening action is executed, a relay activation signal is sent to the next access control point, and a timer is started to suppress subsequent trigger responses; During the timing period, if a subsequent identity credential is received, the door opening action will not be performed, nor will the relay activation signal be sent.

4. The RFID-based temporary access control method as described in claim 1, characterized in that, In step S5, when a route reassignment request is detected, a permission reassignment instruction is sent to the next access control point. The permission reassignment instruction is used to instruct the next access control point to forward the relay activation signal to another preset access control point when the relay activation signal is transmitted, so that the other access control point enters the relay standby state from the blocked state.

5. The RFID-based temporary access control method as described in claim 4, characterized in that, In step S5, after the next access control point forwards the relay activation signal to another access control point, it starts a timer to receive the forwarding confirmation information. If no forwarding confirmation message is received from another access control point before the timeout, the relay activation signal is deemed to have failed to forward, and a failure notification is sent to the control center. After receiving the failure notification, the control center sends a remedial activation command to another access control point, so that the other access control point goes from the blocked state to the relay standby state.

6. The RFID-based temporary access control method as described in claim 5, characterized in that, When the preset other access control point receives a remedial activation command or relay activation signal, the preset other access control point extracts the path identifier corresponding to the evacuation path from the received remedial activation command or relay activation signal. The other preset access control point determines whether it is already in the relay standby state corresponding to the extracted path identifier based on the extracted path identifier. When the judgment result is negative, another preset access control point is controlled to enter the relay standby state corresponding to the extracted path identifier.

7. The RFID-based temporary access control method as described in claim 1, characterized in that, The S6 includes the following steps: After sending the relay activation signal, wait to receive confirmation information from the next access control point. The confirmation information indicates that the next access control point has entered the relay standby state. Upon receiving confirmation, the initial access control point is restored to the locked state.

8. The RFID-based temporary access control method as described in claim 7, characterized in that, S6 also includes the following steps: If no confirmation is received within the preset waiting time, the relay activation signal is deemed to have failed to be sent. In response to the judgment result, the door associated with the initial access control point is kept in the open position; Send a path interruption notification to the preset control center, containing the identifier of the starting access control point and the identifier of the next access control point.

9. The RFID-based temporary access control method as described in claim 8, characterized in that, The steps for maintaining the door associated with the initial access control point in the open position include: While performing the action of keeping the door in the open position, listen for door closing commands from the control center; When a door closing command is received from the control center, the action of maintaining the door in the open position is terminated. Perform the action of closing the door.

10. An RFID-based temporary access control system, applied to the RFID-based temporary access control method described in claim 1, characterized in that, The system includes: The path generation module is used to send a path guidance instruction to the starting access control point based on the path definition containing multiple ordered access control points. The path guidance instruction includes the information of the next access control point. The initial access control module is used to enter the guidance standby state after receiving the path guidance instruction, respond to the trigger of any identity credential, execute the door opening action, and send a relay activation signal to the next access control point; After receiving the relay activation signal, the relay control module performs a state transition, changing from the blocked state to the relay standby state. After the recovery module sends a relay activation signal, it restores the starting access control point to the blocked state. The path interruption module is used to keep the door open and send a path interruption notification to the control center when a path interruption signal is received. The instruction processing module is used to receive path interruption notifications and issue door closing instructions according to predetermined emergency operations, thereby terminating door opening and executing the closing action.

Citation Information

Patent Citations

  • Security protective remote management method

    CN105139487A

  • Access control method, system and device based on artificial intelligence and storage medium

    CN110415396A