Safety prevention and control method and system for subway maintenance scene and background management system
Through the combination of IoT electric locks and background management systems, refined security control is achieved in subway maintenance scenarios, solving the lack of informationization and intelligence in channel door management, ensuring safety and management efficiency, providing real-time monitoring and early warning mechanisms, and supporting proactive maintenance.
Patent Information
- Application Number
- CN202510807464.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-09-16
AI Technical Summary
The existing methods for controlling access door safety in subway maintenance scenarios have deficiencies in information-based, intelligent, and refined management, making it difficult to meet the increasingly stringent requirements for safe production. In particular, there is a lack of effective means in terms of authority control, status monitoring, and abnormal warning.
The use of IoT electric locks combined with a backend management system ensures that only authorized personnel can open the channel door within the specified time and area through identity authentication, dynamic access permission configuration and real-time monitoring. The door opening status is monitored in real time, and the early warning mechanism is triggered to deal with abnormal situations in a timely manner.
It achieves refined management of access doors, eliminates illegal opening and misoperation, prevents safety hazards, ensures the isolation of maintenance areas, provides electronic records for post-audit, predicts potential faults and automatically generates maintenance work orders, thus improving the safety and management efficiency of subway maintenance.
Smart Images

Figure CN120656257A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of subway maintenance technology, and in particular to a safety control method, system and background management system for subway maintenance scenarios. Background Art
[0002] As an integral part of urban public transportation, the safe and stable operation of the subway is crucial. Daily inspection and maintenance are essential to ensure the normal operation of the subway system. Subway inspections often involve high-voltage electrical equipment, complex mechanical structures, and limited working space, creating inherent dangers. To ensure the safety of maintenance personnel, prevent equipment damage, and minimize disruption to subway operations, strict and effective safety control of access doors in inspection areas is crucial.
[0003] Currently, in subway maintenance scenarios, the safety management of access doors mainly has the following methods and their shortcomings:
[0004] 1. Traditional mechanical lock management method: This is the most common method. After obtaining work permits and approvals, maintenance personnel receive the mechanical key of the corresponding access door to unlock and enter the maintenance area. However, the main drawbacks of this method are:
[0005] Lack of Supervision: Once the keys are handed over, management cannot monitor the door's status and duration in real time. This can easily lead to maintenance personnel forgetting to close the door or leaving it open for extended periods, creating safety hazards such as unauthorized entry and environmental factors.
[0006] Crude access control: Mechanical key management makes it difficult to implement refined access control, such as limiting access rights to specific areas by specific personnel during specific time periods. Key duplication and misuse can also pose security risks.
[0007] Difficulty in tracing: After a safety incident occurs, it is difficult to accurately trace information such as the time the door was opened and the person who opened the door, which is not conducive to accident investigation and responsibility determination.
[0008] 2. Manual supervision: To compensate for the shortcomings of mechanical lock management, some scenarios are supplemented by manual inspections or dedicated personnel. However, this approach relies on the management staff's commitment and energy, increasing labor costs and making it difficult to provide round-the-clock, comprehensive supervision. This is especially true when the maintenance area is large and the number of access doors is high, where the efficiency and reliability of manual supervision decreases.
[0009] 3. Independent electric-controlled mechanical locks: There are also some electric-controlled mechanical lock products on the market, which are a certain improvement compared to pure mechanical locks. However, these electric-controlled locks are mostly single-point control, and may have a simple card swipe or password unlocking function, but often lack effective linkage with the background information management system. Therefore, although they have solved some key management problems, they still have deficiencies in status monitoring after unlocking, abnormal warnings (such as not closing the door after timeout), dynamic authority management, and linkage with maintenance work orders. It is difficult to achieve closed-loop management and refined early warning and control of the entire unlocking, maintenance, and locking process. In particular, there is a lack of effective technical means to monitor and warn whether the door leaf is actually closed after opening and whether it is closed for the prescribed time.
[0010] In summary, the existing methods for the safety control of access doors in subway maintenance scenarios have obvious deficiencies in informationization, intelligence, and refined management, and are unable to meet the increasingly stringent requirements for safe production. Summary of the Invention
[0011] Based on this, the purpose of the present invention is to provide a safety control method, system and background management system for subway maintenance scenarios, so as to fundamentally solve the problems of the existing subway maintenance in terms of informatization, intelligence and refined management.
[0012] A safety control method for a subway maintenance scenario according to an embodiment of the present invention is applied to a background management system, and the method includes:
[0013] Receiving identity authentication information of a maintenance personnel and unlocking request information for a target maintenance channel door sent via a communication network from an identity authentication control terminal deployed at at least one maintenance channel door in a maintenance operation area;
[0014] Based on the dynamic access rights pre-configured in association with the maintenance task and in combination with the precise spatial location information of the target maintenance access door, the identity authentication information of the maintenance personnel is verified, and it is determined whether the maintenance personnel is authorized to open the target maintenance access door at the current time. The dynamic access rights include at least authorized personnel, authorized area range, and authorized time period.
[0015] If the verification is passed, a corresponding unlocking control instruction is generated according to the preset unlocking logic type of the target IoT electric lock associated with the target maintenance passage door, and the unlocking control instruction is sent to the target IoT electric lock via the communication network, and the door opening time monitoring of the target maintenance passage door is started. The unlocking control instruction is used to instruct the target IoT electric lock to unlock its electronic control part;
[0016] Obtaining the lock body status information of the IoT electric lock and the switch status information of the target maintenance passage door from the IoT electric lock through the communication network, and continuously monitoring the obtained status information and door opening time timing according to preset monitoring rules;
[0017] When the status information or the door opening duration timing indicating an abnormal state is detected during the monitoring process, a predefined early warning mechanism is triggered, which at least includes sending an early warning notification to a designated management terminal or personnel.
[0018] In addition, the safety control method for subway maintenance scenarios according to the above embodiment of the present invention may also have the following additional technical features:
[0019] Furthermore, the step of generating the pre-configured dynamic access rights includes:
[0020] Receive and parse maintenance work order data from a connected maintenance work order management system through a preset data interface. The maintenance work order data includes at least a maintenance task identifier, a planned execution authorization time period, designated authorized personnel information, and a defined authorization area or target operation equipment information;
[0021] If the maintenance work order data contains target operating equipment information, the pre-built spatial data model that associates equipment with access door paths is used to automatically identify the target maintenance access doors on one or more critical paths that must be passed to access the target operating equipment, and the identified target maintenance access doors are included in the authorized area.
[0022] The authorized personnel information, authorized time period, and authorized area range including one or more target maintenance channel doors extracted from the maintenance work order data or identified based on the spatial data model are written into the permission database as configuration parameters, and an associated index is established with the precise spatial location information of the corresponding target maintenance channel door in the spatial data model, thereby forming the dynamic access permission bound to the maintenance work task.
[0023] Furthermore, the step of verifying the identity authentication information of the maintenance personnel and determining whether the maintenance personnel has the right to open the target maintenance passage door at the current time includes:
[0024] Retrieving dynamic access permission data associated with the target maintenance access door from an authority database;
[0025] Comparing the received identity authentication information of the maintenance personnel to see if it matches the authorized personnel information in the dynamic access rights;
[0026] Determining whether the current time falls within the authorized time period of the dynamic access right;
[0027] Using a spatial data model to confirm whether the precise spatial location of the target maintenance access door falls within the authorized area defined in the dynamic access authority;
[0028] Based on the matching results between the maintenance personnel and the authorized personnel, the matching results between the current time and the authorized time period, and the matching results between the precise spatial position and the authorized area range, it is determined whether the maintenance personnel has the right to open the target maintenance passage door at the current time.
[0029] Furthermore, the step of generating a corresponding unlocking control instruction according to a preset unlocking logic type of the target IoT electric-controlled lock associated with the target maintenance passage door includes:
[0030] Query the device configuration file of the target IoT electric lock to determine the corresponding unlocking logic type, which includes power-off unlocking type and power-on unlocking type;
[0031] If the unlocking logic type is the power-off unlocking type, an unlocking control instruction is generated to disconnect the power circuit of the electronic control part;
[0032] If the unlocking logic type is the power-on unlocking type, an unlocking control instruction is generated to energize the unlocking actuator of the electronic control part.
[0033] Furthermore, the step of triggering a predefined early warning mechanism includes:
[0034] Sending an activation instruction to an on-site sound and light alarm controller deployed in the same area or an adjacent area as the target maintenance channel door defined in the spatial data model, the activation instruction including a preset alarm mode and duration parameters;
[0035] At the same time, a timeout alarm notification containing the unique identifier of the target maintenance channel door, the current opening time and the location information is sent to the communication terminal of at least one preset first-level management personnel;
[0036] If no processing feedback on the timeout alarm notification is received within the preset response time, the alarm level will be automatically upgraded, and an upgraded alarm notification will be sent to the communication terminal of a higher-level manager.
[0037] Furthermore, the method further comprises:
[0038] Periodically collect and analyze the operating data of the target IoT electric lock, including the battery power decay rate, historical communication failure frequency, and cumulative number of openings and closings;
[0039] The collected operating data is input into a pre-trained device health assessment model. The device health assessment model outputs a quantitative score of the current health status of the target IoT electric lock and a probability prediction of potential future failures based on the correlation between historical fault data and operating parameters.
[0040] When the quantitative score is lower than the preset health threshold, or the probability prediction of the potential fault exceeds the preset risk threshold, or the cumulative number of switching actions reaches the preset maintenance upper limit, a maintenance or replacement work order is automatically generated in the integrated operation and maintenance management system, and the relevant maintenance personnel are notified.
[0041] Another embodiment of the present invention aims to provide a safety control system for subway maintenance scenarios, which is applied to a background management system. The system includes:
[0042] An information receiving module is used to receive the identity authentication information of the maintenance personnel and the unlocking request information for the target maintenance channel door sent from the identity authentication control terminal deployed at at least one maintenance channel door in the maintenance operation area through the communication network;
[0043] a verification module for verifying the identity authentication information of the maintenance personnel based on a dynamic access right pre-configured in association with the maintenance task and in combination with the precise spatial location information of the target maintenance passage door, and determining whether the maintenance personnel is authorized to open the target maintenance passage door at the current time, wherein the dynamic access right includes at least an authorized person, an authorized area range, and an authorized time period;
[0044] an instruction generation module, configured to, when the verification module passes verification, generate a corresponding unlocking control instruction based on a preset unlocking logic type of a target IoT electric-controlled lock associated with the target maintenance passage door, send the unlocking control instruction to the target IoT electric-controlled lock via a communication network, and initiate timing monitoring of the door opening duration of the target maintenance passage door, wherein the unlocking control instruction is used to instruct the target IoT electric-controlled lock to unlock its electronic control portion;
[0045] An information acquisition and monitoring module is used to obtain the lock body status information of the IoT electric-controlled lock and the switch status information of the target maintenance passage door from the IoT electric-controlled lock via the communication network, and continuously monitor the obtained status information and door opening time timing according to preset monitoring rules;
[0046] The early warning module is used to trigger a predefined early warning mechanism when it is detected during the monitoring process that the status information or the door opening time timing indicates an abnormal state. The early warning mechanism at least includes sending an early warning notification to a designated management terminal or personnel.
[0047] Furthermore, the verification module includes:
[0048] A data receiving and parsing unit is used to receive and parse maintenance work order data from a connected maintenance work order management system through a preset data interface. The maintenance work order data at least includes a maintenance task identifier, a planned execution authorization time period, designated authorized personnel information, and a defined authorization area range or target operation equipment information;
[0049] an authorization area determination unit configured to, if the maintenance work order data includes target operating equipment information, automatically identify target maintenance access doors on one or more critical paths that must be passed through to access the target operating equipment using the pre-built spatial data model that associates equipment with access door paths, and include the identified target maintenance access doors in the authorization area;
[0050] A dynamic access permission generation unit is used to write the authorized personnel information, authorized time period, and authorized area range containing one or more target maintenance channel doors extracted from the maintenance work order data or identified based on the spatial data model as configuration parameters into the permission database, and establish an associated index with the precise spatial location information of the corresponding target maintenance channel door in the spatial data model, thereby forming the dynamic access permission bound to the maintenance operation task.
[0051] Furthermore, the verification module includes:
[0052] A data retrieval unit, configured to retrieve dynamic access authority data associated with the target maintenance access door from an authority database;
[0053] A first data comparison unit is used to compare whether the received identity authentication information of the maintenance personnel matches the authorized personnel information in the dynamic access permission;
[0054] a second data comparison unit, configured to determine whether the current time falls within an authorized time period in the dynamic access authority;
[0055] A third data comparison unit is used to confirm whether the precise spatial position of the target maintenance passage door belongs to the authorized area defined in the dynamic access permission by using the spatial data model;
[0056] The determination unit is used to comprehensively determine whether the maintenance personnel has the right to open the target maintenance passage door at the current time based on the matching results between the maintenance personnel and the authorized personnel, the matching results between the current time and the authorized time period, and the matching results between the precise spatial position and the authorized area range.
[0057] Another embodiment of the present invention aims to provide a background management system, which is characterized in that it includes a memory, a processor, and a program stored in the memory and runnable on the processor, and when the processor executes the program, it implements the safety control method for subway maintenance scenarios as described above.
[0058] The security control method for subway maintenance scenarios provided by the embodiment of the present invention, through the dynamic access permission configuration linked with the maintenance work order, ensures that only authorized personnel can open the specific maintenance channel door at the specified time and in the specified area, eliminating the possibility of illegal opening and misoperation from the source; through real-time monitoring of the door opening time and door status and timeout warning, it effectively prevents the safety hazards caused by forgetting to close the door or the door not being closed tightly, and ensures the isolation status of the maintenance area; through continuous monitoring of the lock body status of the target IoT electric lock and the switch status of the target maintenance channel door, it can timely detect the target maintenance channel door that has not been closed for a timeout or has been illegally opened. It detects abnormal situations such as attempts and immediately triggers a multi-level early warning mechanism (on-site sound and light alarms, notifications to management personnel, and alarm upgrades), which wins valuable time for timely disposal; by transforming traditional offline approval and manual records into online and automated processes, all operations (authorization application, approval, unlocking, locking, and alarm) are electronically recorded to facilitate post-audit and responsibility tracing; through intelligent analysis and health assessment of the operating data of IoT electric locks, potential faults can be predicted in advance, and maintenance work orders can be automatically generated, changing passive maintenance to active maintenance; it solves the problem of insufficient information, intelligence, and refined management of existing subway maintenance. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] Figure 1 This is a flowchart of a safety control method for a subway maintenance scenario in the first embodiment of the present invention;
[0060] Figure 2 This is a schematic structural diagram of a safety control system for a subway maintenance scenario in a second embodiment of the present invention;
[0061] Figure 3 Schematic diagram of the structure of the backend management system in the third embodiment of the present invention;
[0062] The following specific embodiments will further illustrate the present invention in conjunction with the above-mentioned drawings. DETAILED DESCRIPTION
[0063] To facilitate understanding of the present invention, the present invention will be described more fully below with reference to the accompanying drawings. The drawings illustrate several embodiments of the present invention. However, the present invention may be implemented in many different forms and is not limited to the embodiments described herein. Rather, these embodiments are provided to provide a more thorough and comprehensive understanding of the present invention.
[0064] It should be noted that when an element is referred to as being "fixed to" another element, it may be directly on the other element or there may be an intermediate element. When an element is referred to as being "connected to" another element, it may be directly connected to the other element or there may be an intermediate element. The terms "vertical," "horizontal," "left," "right," and similar expressions used herein are for illustrative purposes only.
[0065] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this invention pertains. The terms used in this specification of the present invention are for the purpose of describing specific embodiments only and are not intended to limit the present invention. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.
[0066] Example 1
[0067] See also Figure 1 , which shows a safety control method for a subway maintenance scenario in a first embodiment of the present invention. For ease of illustration, only the parts related to the embodiment of the present invention are shown. The safety control method for a subway maintenance scenario provided by the embodiment of the present invention includes:
[0068] Step S10: receiving identity authentication information of a maintenance personnel and unlocking request information for a target maintenance passage door sent via a communication network from an identity authentication control terminal deployed at at least one maintenance passage door in a maintenance operation area;
[0069] Among them, in one embodiment of the present invention, the method is applied to a background management system, which can be a software application deployed on a server cluster, communicating through the network with the identity authentication control terminal (including face, fingerprint or RFID recognition modules), Internet of Things electric locks (integrated electronic control unit and mechanical lock core) and possible other devices (such as sound and light alarms, cameras) deployed on site.
[0070] Specifically, the backend management system is deployed on a server or cloud platform and includes components such as web application services, API interface services, databases (such as MySQL and PostgreSQL), and message queues (such as Kafka and RabbitMQ). Core functional modules include: user and permission management, device management (identity authentication terminals, IoT locks), spatial data management (GIS / BIM integration), work order docking and task management, real-time monitoring and status display, logging and auditing, and early warning and notification services.
[0071] The identity authentication control terminal is installed near each controlled access door. Its hardware integrates a microcontroller, a network interface (Ethernet or Wi-Fi), and one or more identity recognition modules (such as a high-definition camera with facial recognition algorithm firmware, a fingerprint sensor, and an NFC / RFID reader). The software runs an embedded operating system and application, responsible for collecting authentication information, communicating with the backend, and displaying prompts.
[0072] The IoT electric lock is installed on the maintenance channel door and integrates a microcontroller, a wireless communication module (such as Wi-Fi, BLE, NB-IoT), a power management unit (including a backup battery), a lock tongue status sensor, a door magnetic status sensor, and a circuit to drive the electromagnet or motor.
[0073] The communication network utilizes the subway's existing wired network and Wi-Fi coverage, or deploys dedicated LPWAN (such as LoRaWAN) or cellular IoT (NB-IoT, LTE-M) for IoT devices. All sensitive data transmission is encrypted using TLS / SSL.
[0074] Maintenance personnel authenticate themselves on the identity authentication control terminal (e.g., by face recognition, fingerprint, or employee ID card). The identity authentication control terminal encapsulates the collected raw authentication data (or its characteristic value), the terminal's own unique ID, and the target maintenance channel door ID selected by the user on the terminal interface or automatically associated by the system, into a JSON or Protobuf formatted data packet. This data packet is then sent to the backend management system's API via an HTTPS POST request or a secure MQTT message.
[0075] Furthermore, in embodiments of the present invention, the security control method for subway maintenance scenarios involves various types of maintenance access doors. Specifically, maintenance access doors typically include access doors, regular maintenance side doors, and standby maintenance side doors. Access doors generally refer to main entrances and exits connecting different areas, serving as the primary means of access for personnel on a daily or specific basis. For example, these might be passages connecting office areas with maintenance areas (such as maintenance depots or specific work areas), or between different maintenance halls. These doors are characterized by their relatively high frequency of use (depending on the specific scenario) and are essential for routine maintenance operations. They also have high security requirements, preventing unauthorized personnel from entering sensitive areas. Furthermore, in emergency situations, ease of evacuation may be a concern. Regular maintenance side doors typically refer to doors most frequently used by maintenance personnel to enter specific equipment rooms or maintenance work areas for routine maintenance and operations. Designed specifically for maintenance operations, they may not be used as frequently as access doors, but they do require certain ease of operation. They also have high security requirements, ensuring that only authorized maintenance personnel enter during authorized hours. They are typically standard entrances in the maintenance process. The maintenance standby side door typically refers to a door that is not frequently used or serves as a backup, emergency, or access channel for specific large equipment when inspecting specific equipment or areas. It can also be a door in some key equipment rooms that needs to be highly locked at ordinary times and opened only in specific maintenance or emergency situations. Its characteristics are low frequency of use; extremely high security requirements, and it should be kept in a highly secure locked state at ordinary times; and the opening conditions are more stringent, such as in specific emergency situations or under authorized conditions (for example, when a fault occurs on the commonly used side, or entry from another direction is required), to achieve special entry / exit. It can serve as an alternative escape exit, but its main function is safety isolation.
[0076] Therefore, based on the functional positioning and safety risk assessment of different maintenance channel doors, corresponding lock designs are adapted for the above-mentioned various types of maintenance channel doors. Specifically, the channel door adopts electromagnetic and mechanical dual locking, and the electromagnetic lock is locked when power is on and unlocked when power is off; the commonly used side door for maintenance adopts electromagnetic locking, and is locked when power is on and unlocked when power is off; and the spare side door for maintenance adopts electromagnetic locking, and is locked when power is off and unlocked when power is on.
[0077] In other words, the access door is dual-locked with an electromagnetic lock and a mechanical lock, and both locks must be unlocked simultaneously to open the door. This electromagnetic lock implements intelligent control, remote authorization, status monitoring, and linked alarms. Even if the electromagnetic lock is compromised or malfunctions, the mechanical lock still provides a physical barrier, requiring a mechanical key to open the access door. Conversely, if the mechanical key is lost or counterfeited, the electromagnetic lock cannot be opened without electronic authorization, effectively increasing the difficulty of unauthorized entry. The electromagnetic lock is controlled by a 24V DC power supply and provides status feedback. It is configured to lock when powered on and unlock when powered off. This control method is primarily used for daily security, emergency evacuation priority, and prevention of unauthorized locking. For daily security, the electromagnetic lock is locked under normal power conditions. Authorization (platform verification and power loss) is required to unlock the electromagnetic portion, which can then be opened with the mechanical key. For emergency evacuation priority, the electromagnetic lock automatically unlocks in the event of a system power outage, such as a fire or power outage. This allows personnel to quickly open the door and evacuate using only the mechanical key. To prevent illegal locking, if someone maliciously cuts off the power supply, the passage door will not be locked, and there will still be an escape or rescue route. Furthermore, the key cannot be removed when the mechanical lock in the passage door is unlocked. At this time, the key cannot be removed when the passage door is ajar or not properly locked. The mechanical lock can only be removed after the passage door is closed and locked.
[0078] The side door commonly used for maintenance is electromagnetically locked, and is locked when powered on and unlocked when powered off. At the same time, after the electromagnetic lock is unlocked, the latch has an anti-drop design, and a certain amount of external force is required to open it. Specifically, compared with the double locking mentioned above, it may be more convenient to operate and suitable for the side door commonly used for maintenance. However, it still relies on electronic authorization to ensure basic safety management. The above control method is mainly used for daily safety, maintenance safety and emergency evacuation, as well as operational convenience. Among them, daily safety mainly involves the electromagnetic lock being locked when the power is normally supplied, and the electromagnetic part being unlocked when the power is off after authorization. Among them, maintenance safety and emergency evacuation usually involve the automatic unlocking of the side door commonly used for maintenance when an emergency occurs in the maintenance area (such as equipment failure causing power outage in the area), making it convenient for maintenance personnel to evacuate. The operational convenience mainly involves the electromagnetic lock being unlocked when the power is off after authorization by the maintenance personnel, and the operation is direct. The maintenance backup side door utilizes a control method opposite to the conventional maintenance side door, primarily to ensure the continuous closure of the safety zone, controlled opening, and prevent misoperation. Specifically, ensuring the continuous closure of the safety zone typically means ensuring that the maintenance backup side door remains locked under all circumstances (including power outages, line failures, or system attacks resulting in loss of connectivity). For example, a backup entrance to a high-voltage equipment room, a critical storage facility, or a safety-related control room would automatically remain locked even if the entire area loses power, preventing unauthorized access. This protects critical equipment or restricts access to high-risk areas. Controlled opening means that the maintenance backup side door can only be unlocked upon receiving a clear, authorized "power on" command. This is typically used to open specific rescue routes in emergencies or to allow authorized personnel to enter under unusual circumstances. Preventing misoperation, on the other hand, prevents the automatic opening of doors in critical areas due to unexpected power outages, thus avoiding security vulnerabilities.
[0079] Step S20: Based on the dynamic access rights pre-configured in conjunction with the maintenance task and the precise spatial location information of the target maintenance access door, verify the identity authentication information of the maintenance personnel and determine whether the maintenance personnel has the right to open the target maintenance access door at the current time.
[0080] In one embodiment of the present invention, upon receiving a request, the API interface of the backend management system first verifies the source of the request and the integrity and legitimacy of the data packet. It then confirms the identity of the requesting individual based on identity authentication information (e.g., employee ID, or employee ID obtained through biometric database comparison). Based on the target maintenance access door ID, the precise spatial location of the maintenance access door and any associated maintenance tasks are determined in conjunction with the spatial data management module (which stores the spatial coordinates, region, and associated maintenance tasks of each maintenance access door). The authority database is then retrieved for a dynamic access permission record that matches the employee ID, target door / region, current time, and associated maintenance tasks. This record contains a clear authorization start and end time, the scope of the areas allowed for access (which may be a list of regions or specific doors), and a list of authorized personnel. In other words, a dynamic access permission includes at least authorized personnel, authorized region, and authorized time period. Finally, each condition is compared to ensure that the requesting individual is on the authorized list, the current time is within the authorized time period, and the target door is within the authorized region. If all verification conditions are met, the permission verification passes, and step S30 is executed.
[0081] Specifically, the steps for generating the pre-configured dynamic access rights include:
[0082] Receive and parse maintenance work order data from the connected maintenance work order management system through a preset data interface. The maintenance work order data at least includes the maintenance task identification, the authorized time period for planned execution, the designated authorized personnel information, and the defined authorized area range or target operation equipment information;
[0083] If the maintenance work order data contains target equipment information, the system automatically identifies the target maintenance access doors on one or more critical paths required to access the target equipment using a pre-built spatial data model that associates equipment with access door paths. The identified target maintenance access doors are then included in the authorized area.
[0084] The authorized personnel information, authorized time period, and authorized area range containing one or more target maintenance channel doors extracted from the maintenance work order data or identified based on the spatial data model are written into the permission database as configuration parameters, and an associated index is established with the precise spatial location information of the corresponding target maintenance channel door in the spatial data model, thereby forming dynamic access rights bound to the maintenance work task.
[0085] Specifically, the backend management system achieves data docking with the subway's existing maintenance work order management system (such as CMMS or EAM system) through API interfaces or database views. When a new maintenance work order is generated or the status is updated, the backend management system automatically pulls or receives the pushed maintenance work order data. Parse the work order XML, JSON or data in a specific format to extract key fields, such as: maintenance work order number, planned start / end time, list of responsible persons / team members, description of the work location (such as XX equipment room, YY section), list of equipment involved, etc. A three-dimensional or two-dimensional spatial data model of the subway maintenance area is pre-built through BIM software or GIS platform, in which the location and ID of each maintenance channel door are accurately marked in the spatial data model, as well as the topological relationship and access path with each equipment and area. When the authorized area range in the maintenance work order data is a specific device, the backend management system uses the path planning algorithm or preset association rules in the spatial data model to automatically identify one or more maintenance channel doors that must be passed to reach the device. For example, to inspect equipment A, the spatial data model indicates that one must first enter Area B through Door X and then enter Compartment C, where equipment A is located, through Door Y. Both Doors X and Y are identified as target maintenance access doors. The extracted authorized personnel (which can be mapped to a backend user ID), the authorized time period (work order schedule), and the identified target maintenance access door list (which specifically reflects the scope of the authorized area) are then used as the core parameters of a dynamic access permission record. This record is stored in the backend permission database and indexed and associated with the work order number and the spatial coordinates or unique ID of the corresponding maintenance access door in the spatial data model. As previously mentioned, maintenance access doors include access doors, regular maintenance side doors, and backup maintenance side doors. The authorized area typically includes access doors from outside access to the main maintenance area and regular maintenance side doors to specific equipment rooms or work areas. If necessary, backup maintenance side doors may also be opened (for example, when replacing large equipment, a backup door may be required, or when maintenance on specific high-risk equipment requires access to a dedicated isolation room). It's important to note that different approval processes or permission levels can be set for different types of access doors. For example, opening an access door and a side door for regular maintenance might only require approval from a team leader. Opening a backup access door, however, might require approval from a higher level (such as a workshop manager or safety officer) and might have stricter timeframes.
[0086] In one embodiment of the present invention, the steps of verifying the identity authentication information of the maintenance personnel and determining whether the maintenance personnel has the right to open the target maintenance passage door at the current time include:
[0087] Retrieve dynamic access permission data associated with the target maintenance access door from the permission database;
[0088] Compare the received maintenance personnel's identity authentication information to see if it matches the authorized personnel information in the dynamic access rights;
[0089] Determine whether the current time falls within the authorized time period in the dynamic access permission;
[0090] Use the spatial data model to confirm whether the precise spatial location of the target maintenance access door falls within the authorized area defined in the dynamic access rights;
[0091] Based on the matching results between the maintenance personnel and the authorized personnel, the matching results between the current time and the authorized time period, and the matching results between the precise spatial location and the authorized area range, it is determined whether the maintenance personnel has the right to open the target maintenance channel door at the current time.
[0092] Specifically, when the backend management system receives an unlocking request for a target maintenance channel door, it uses the door ID contained in the request as an index to query the permission database for all dynamic access permission records associated with the door ID and with a status of "valid" or "activated". Then, the unique credentials of the maintenance personnel (such as employee number, fingerprint feature code, hash value of face feature vector) are extracted from the received identity authentication information. This credential is compared one by one with the list of "authorized personnel" in each dynamic access permission record retrieved. If a match is found, this check passes. Get the current precise time of the backend management system. Compare this current time with the "authorized time period" (including start time and end time) in each dynamic access permission record retrieved (that has passed identity comparison). Determine whether the current time is greater than or equal to the start time and less than or equal to the end time. If satisfied, this check passes. Then, using the spatial data model, the precise three-dimensional coordinates of the requested target maintenance channel door or its minimum management unit (such as room or compartment) defined in the spatial data model are obtained, and this precise spatial location is compared with the "authorized area range" defined in each retrieved dynamic access permission record (that has passed the first two checks), where the authorized area range can be a specific list of maintenance channel doors, a predefined area name (such as "Substation No. 1", "Traction Power Supply Area"), or a polygonal area defined by spatial coordinates. The backend management system determines whether the location of the target maintenance channel door falls within or belongs to the authorized area range. If so, this check passes. Only when a dynamic access permission record passes the three-dimensional verification of identity matching, time period matching, and spatial area matching at the same time, the backend management system will finally determine that the maintenance personnel has the right to open the target maintenance channel door at the current time.
[0093] Step S30: Generate a corresponding unlocking control instruction based on the preset unlocking logic type of the target IoT electric lock associated with the target maintenance passage door, send the unlocking control instruction to the target IoT electric lock via the communication network, and start timing monitoring of the door opening time of the target maintenance passage door;
[0094] In one embodiment of the present invention, the unlocking control instruction is used to instruct the target IoT electric-controlled lock to unlock its electronic control part; the step of generating the corresponding unlocking control instruction according to the preset unlocking logic type of the target IoT electric-controlled lock associated with the target maintenance passage door includes:
[0095] Query the device configuration file of the target IoT electric lock to determine the corresponding unlocking logic type, which includes power-off unlocking and power-on unlocking.
[0096] If the unlocking logic type is the power-off unlocking type, an unlocking control instruction is generated to disconnect the power circuit of the electronic control part;
[0097] If the unlocking logic type is the power-on unlocking type, an unlocking control instruction is generated to energize the unlocking actuator of the electronic control part.
[0098] Among them, referring to the above, the unlocking logic of the IoT electric locks (i.e., electromagnetic locks) equipped with different types of maintenance channel door locks is different. For example, the commonly used sides of the channel door and the maintenance door are locked when powered on and unlocked when powered off; while the maintenance spare side door is locked when powered off and unlocked when powered on; therefore, the background management system usually maintains a device management database (or module), which stores the detailed information of each registered IoT electric lock, including its unique device ID, model, installation location (associated with the target maintenance channel door), and a key "unlocking logic type" field. The value of this field is preset to "Fail-Safe" (unlocking when powered off) or "Fail-Secure" (unlocking when powered on). When the permission check is passed, the background management system uses the target maintenance channel door ID to query the associated IoT electric lock ID, and then uses the IoT electric lock ID to query its device file to obtain the "unlocking logic type".
[0099] If the unlock logic type found is "unlock on power failure," the backend management system generates a specific control instruction. This instruction effectively tells the electronic control unit within the IoT electric lock to cut off power to the locking actuator, such as the electromagnet or motor. For example, the instruction might be a digital signal containing a specific opcode. Upon receiving this signal, the lock activates an internal relay or solid-state switch, de-energizing the locking mechanism and unlocking the lock.
[0100] If the unlock logic type found is "Power-on unlock," the backend management system generates a specific control instruction. This instruction effectively instructs the electronic control unit within the IoT electric lock to apply operating voltage / current to its locking actuator. For example, this instruction turns on the lock's internal drive circuit, energizing the electromagnet or motor, causing it to unlock.
[0101] At this point, the backend management system doesn't need to worry about the specific internal structure of the IoT electric lock; it only needs to send abstract control commands based on preset logic types, enhancing the system's versatility and scalability. This ensures that the commands issued by the backend correctly unlock the target IoT electric lock, preventing unlocking failures or lock damage due to incorrect commands. For example, a passage door that needs to ensure smooth escape in the event of a power outage can be configured as "unlock on power failure." For maintenance-related backup side doors in critical areas that need to remain locked in the event of a power outage, the "unlock on power" setting can be configured.
[0102] Step S40: Obtaining the lock status information of the IoT electric lock and the switch status information of the target maintenance passage door from the IoT electric lock via the communication network, and continuously monitoring the obtained status information and door opening time according to preset monitoring rules;
[0103] In one embodiment of the present invention, the IoT electric lock monitors the status of itself and the target access door in real time using its built-in sensors (e.g., a Hall sensor to detect the bolt status and a door magnetic sensor to detect the door open / close status). The lock periodically reports status changes to a backend management system via MQTTS or CoAP, or instantly reports status changes via a persistent HTTPS connection. The backend management system receives status report packets from the IoT electric lock, parses the data, and updates the latest status information to the corresponding records for the IoT electric lock and the target access door in its database. The information may also be pushed to a front-end monitoring interface for real-time display. The backend management system runs a rules engine or set of monitoring logic, which monitors the acquired status information and timers for door opening duration. A rule for monitoring acquired status information might define the following: If the bolt status is "retracted" but the door magnetic status is "closed" for a certain period of time (e.g., 5 seconds), this may indicate that the door is stuck or not fully locked, triggering a low-level "door not locked" alarm. If the battery charge falls below a preset threshold (e.g., 20%), a "low battery" alarm is triggered. The specific monitoring of door opening duration is that when the background management system receives the door magnetic status of a target maintenance channel door and changes to "open", it searches for the door opening duration timer previously started for the target maintenance channel door, and starts the accurate accumulation timing with the current time as the actual door opening time. Its rule engine continuously checks the current value of the timer of all maintenance channel doors in the open state. At the same time, the preset monitoring rules will define the maximum allowable opening duration of each maintenance channel door (timeout threshold, such as 30 minutes). If the timer value of a maintenance channel door exceeds its corresponding timeout threshold, the rule engine will determine it as a timeout and non-closure exception.
[0104] Step S50, when the status information or the door opening duration timer indicates an abnormal state during the monitoring process, a predefined early warning mechanism is triggered;
[0105] In one embodiment of the present invention, the early warning mechanism includes at least sending an early warning notification to a designated management terminal or personnel. When monitoring detects that status data or timer values trigger conditions in the monitoring rule base, the backend management system sends an early warning message to the relevant manager's mobile phone or work terminal via a SMS gateway, email server, or app push service, based on the preset warning level and notification strategy. The message contains information such as the type of anomaly, the location of the maintenance access door, and the time of occurrence.
[0106] Furthermore, the steps to trigger the predefined warning mechanism include:
[0107] Sending an activation instruction to an on-site sound and light alarm controller deployed in the same or adjacent area as the target maintenance channel door defined in the spatial data model, the activation instruction including preset alarm mode and duration parameters;
[0108] At the same time, a timeout alarm notification containing the unique identifier of the target maintenance channel door, the current opening time and the location information is sent to the communication terminal of at least one preset first-level management personnel;
[0109] If no processing feedback on the timeout alarm notification is received within the preset response time, the alarm level will be automatically upgraded and an upgraded alarm notification will be sent to the communication terminal of a higher-level manager.
[0110] Specifically, sound and light alarms (such as sirens and flashing lights) are installed near each maintenance channel door or in the key maintenance areas to which it belongs (such as the control room and the intersection of the main channels). These alarms are connected to the alarm controller via wired or wireless means, and the alarm controller then communicates with the background management system through the network. In the spatial data model of the background, the correspondence between each target maintenance channel door and the on-site sound and light alarm controller (hereinafter referred to as the alarm) in its adjacent area is pre-configured (for example, one alarm may cover multiple doors, or one door is responsible for a specific alarm). The alarm itself is connected to the background or a centralized alarm gateway through a network (such as a wired IP network or wireless Zigbee / LoRa). When the early warning mechanism is triggered (such as the door is not closed after timeout), the background management system queries the corresponding alarm ID or network address based on the ID of the target maintenance channel door. The background management system sends an activation command to the alarm or its gateway. This command typically consists of a data packet containing the target alarm ID, an alarm mode (e.g., 01 - continuous high-pitched sound, 02 - intermittent low-pitched sound, 03 - fast flashing red light), and an alarm duration parameter (e.g., 180 seconds, or until manually reset). Upon receiving the command, the alarm activates its connected horn and lights according to the specified mode and duration.
[0111] At the same time, the backend management system searches the preset notification policy library for a list of contact information (mobile phone number, enterprise WeChat user ID, email address, etc.) for at least one first-level manager (such as a team leader or work area director) responsible for the area where the target door is located or for related maintenance tasks, for abnormal events such as "timeout failure to close the door." The backend management system dynamically generates an alarm notification text containing key information, such as: "[Subway Maintenance Access Control Alarm] Passage door [D00123] located at [B2 Floor Traction Substation Entrance] has been open for [35 minutes and 12 seconds], exceeding the preset threshold of [30 minutes]. Please verify and handle it immediately!" This alarm notification is sent to the communication terminals of all first-level managers in the list through integrated communication interfaces (SMS API, enterprise WeChat API, email SMTP service).
[0112] For each timeout alarm notification issued, the backend management system starts an internal "response timer" (for example, preset to 15 minutes). If before the timer expires, the backend management system does not receive "confirmed", "processing" or "closed" status feedback from any first-level manager regarding the alarm event through the management interface, App operation or other methods; the backend management system automatically marks the internal processing status of this alarm event as "first-level response timeout" and raises its alarm level. Then, the backend management system queries the preset contact list of second-level (or higher-level) managers (such as department managers, security directors) and sends them an upgraded alarm notification, the content of which may be: "[Alarm Upgrade] Channel door [D00123] timed out and did not close the door alarm (opened [50 minutes and 12 seconds]), first-level response timeout, please pay attention and coordinate immediately!"
[0113] In one embodiment of the present invention, the method further comprises:
[0114] Periodically collect and analyze the operating data reported by the target IoT electric lock, including battery power decay rate, historical communication failure frequency, and cumulative opening and closing times;
[0115] The collected operating data is fed into a pre-trained device health assessment model. Based on the correlation between historical fault data and operating parameters, the model outputs a quantitative score of the current health status of the target IoT electric lock and a prediction of the probability of potential future faults.
[0116] When the quantitative score is lower than the preset health threshold, or the probability prediction of potential failure exceeds the preset risk threshold, or the cumulative number of switching operations reaches the preset maintenance limit, a maintenance or replacement work order is automatically generated in the integrated operation and maintenance management system, and the relevant maintenance personnel are notified.
[0117] Specifically, the background management system configures a scheduled task (for example, once every hour or every 24 hours), polls all online target IoT electric locks, or subscribes to the heartbeat packets or status packets that they actively report, which contain information about the battery power decay rate, historical communication failure frequency, and cumulative number of switches, and then stores the acquired operating data in a time series database or a device history database. The battery power decay rate can be calculated by comparing the battery power readings at consecutive time points. The historical communication failure frequency can be calculated by recording the number of times and duration of communication interruptions and data packet losses between the IoT electric lock and the system. The cumulative number of switches can be calculated by the total number of times the IoT electric lock records and reports its electromagnetic lock or mechanical part actions internally.
[0118] Furthermore, a large amount of historical operating data of similar IoT electric locks and records of their eventual failures (battery exhaustion, communication module damage, mechanical jamming, etc.) are collected. Using this operating data, one or more prediction models are trained through supervised learning algorithms (such as decision trees, random forests, gradient boosting machines, or neural networks). For example: a model predicts the remaining battery life or the probability of exhaustion in the next N days. Input features may include current voltage, historical voltage decay curve, ambient temperature, and switching frequency. Or a model evaluates the stability of the communication module. Input features include historical signal strength, disconnection frequency, and number of retransmissions. Or a model evaluates the degree of wear of mechanical components based on the cumulative number of switches and the design life.
[0119] Furthermore, the most recently collected operational data for each IoT electric lock is fed into a pre-trained device health assessment model. The device health assessment model outputs a quantitative score of the IoT electric lock's current health (e.g., a scale of 0-100, with lower scores indicating poor health) and / or the probability of a specific type of potential failure occurring in the future (e.g., "Probability of battery depletion in the next 7 days: 85%"). The backend management system sets a series of thresholds related to the model outputs, such as: health score below 50, probability of battery depletion in the next 7 days above 80%, probability of communication module failure in the next 30 days above 50%, cumulative number of power cycles reaching 90% of the design lifespan, etc. When the assessment result for any IoT electric lock triggers any of these thresholds, the backend management system first sends an alert to the maintenance manager, informing them of the lock's ID, location, predicted risk type (e.g., "battery depletion" or "unstable communication"), and the recommended maintenance window. If the backend management system is integrated with an operations and maintenance management system (e.g., CMMS / EAM), the system automatically calls the O&M management system's API to create a new preventive maintenance work order. The work order content will include detailed information about the lock, predicted failures, and recommended maintenance measures (such as "replace the battery", "check the antenna and re-connect the network", "fully clean and lubricate mechanical parts"), and can be automatically assigned to the corresponding maintenance team or engineer based on preset rules.
[0120] In summary, the security control method for subway maintenance scenarios in the above embodiments of the present invention, through the dynamic access permission configuration linked to the maintenance work order, ensures that only authorized personnel can open the specific maintenance channel door at the specified time and in the specified area, eliminating the possibility of illegal opening and misoperation from the source; through real-time monitoring of the door opening time and door status and timeout warning, it effectively prevents safety hazards caused by forgetting to close the door or the door not being closed tightly, and ensures the isolation status of the maintenance area; through continuous monitoring of the lock body status of the target IoT electric lock and the switch status of the target maintenance channel door, it can timely detect the target maintenance channel door that has not been closed for a timeout or is not closed properly. It detects abnormal situations such as illegal opening attempts and immediately triggers a multi-level early warning mechanism (on-site sound and light alarms, notifications to management personnel, and alarm upgrades), which buys valuable time for timely handling; by transforming traditional offline approval and manual record-keeping into online and automated processes, all operations (authorization application, approval, unlocking, locking, and alarm) are electronically recorded to facilitate post-audit and responsibility tracing; through intelligent analysis and health assessment of IoT electric lock operation data, potential faults can be predicted in advance, and maintenance work orders can be automatically generated, changing passive maintenance to active maintenance; it solves the problem of insufficient informationization, intelligence, and refined management of existing subway maintenance.
[0121] Example 2
[0122] See also Figure 2 , is a schematic diagram of the structure of a safety control system for subway maintenance scenarios provided by a second embodiment of the present invention. For ease of explanation, only the parts related to the embodiment of the present invention are shown. The safety control system for subway maintenance scenarios is applied to a background management system, and the system includes:
[0123] The information receiving module 110 is configured to receive the identity authentication information of the maintenance personnel and the unlocking request information for the target maintenance channel door sent via the communication network from the identity authentication control terminal deployed at at least one maintenance channel door in the maintenance operation area;
[0124] Verification module 120 is used to verify the identity authentication information of the maintenance personnel based on the dynamic access rights pre-configured in conjunction with the maintenance task and the precise spatial location information of the target maintenance access door, and to determine whether the maintenance personnel is authorized to open the target maintenance access door at the current time. The dynamic access rights include at least authorized personnel, authorized area range, and authorized time period;
[0125] The instruction generation module 130 is configured to generate a corresponding unlocking control instruction based on the preset unlocking logic type of the target IoT electric-controlled lock associated with the target access door when the verification module 120 passes the verification, and transmit the unlocking control instruction to the target IoT electric-controlled lock via the communication network, and initiate a timer monitoring of the opening duration of the target access door. The unlocking control instruction is used to instruct the target IoT electric-controlled lock to unlock its electronic control part.
[0126] The information acquisition and monitoring module 140 is used to obtain the lock body status information of the IoT electric lock and the switch status information of the target maintenance passage door from the IoT electric lock through the communication network, and continuously monitor the obtained status information and door opening time according to preset monitoring rules;
[0127] The early warning module 150 is used to trigger a predefined early warning mechanism when status information or door opening time timing indicating an abnormal state is detected during the monitoring process. The early warning mechanism at least includes sending an early warning notification to a designated management terminal or personnel.
[0128] Furthermore, in one embodiment of the present invention, the verification 120 module includes:
[0129] A data receiving and parsing unit is used to receive and parse maintenance work order data from a connected maintenance work order management system through a preset data interface. The maintenance work order data at least includes a maintenance task identifier, a planned execution authorization time period, designated authorized personnel information, and a defined authorization area range or target operation equipment information;
[0130] an authorization area determination unit configured to, if the maintenance work order data includes target operating equipment information, automatically identify target maintenance access doors on one or more critical paths that must be passed through to access the target operating equipment using the pre-built spatial data model that associates equipment with access door paths, and include the identified target maintenance access doors in the authorization area;
[0131] A dynamic access permission generation unit is used to write the authorized personnel information, authorized time period, and authorized area range containing one or more target maintenance channel doors extracted from the maintenance work order data or identified based on the spatial data model as configuration parameters into the permission database, and establish an associated index with the precise spatial location information of the corresponding target maintenance channel door in the spatial data model, thereby forming the dynamic access permission bound to the maintenance operation task.
[0132] Furthermore, in one embodiment of the present invention, the verification module 120 includes:
[0133] A data retrieval unit, configured to retrieve dynamic access authority data associated with the target maintenance access door from an authority database;
[0134] A first data comparison unit is used to compare whether the received identity authentication information of the maintenance personnel matches the authorized personnel information in the dynamic access permission;
[0135] a second data comparison unit, configured to determine whether the current time falls within an authorized time period in the dynamic access authority;
[0136] A third data comparison unit is used to confirm whether the precise spatial position of the target maintenance passage door belongs to the authorized area defined in the dynamic access permission by using the spatial data model;
[0137] The determination unit is used to comprehensively determine whether the maintenance personnel has the right to open the target maintenance passage door at the current time based on the matching results between the maintenance personnel and the authorized personnel, the matching results between the current time and the authorized time period, and the matching results between the precise spatial position and the authorized area range.
[0138] Furthermore, in one embodiment of the present invention, the instruction generation module 130 includes:
[0139] A data query unit, configured to query a device configuration file of the target IoT electric-controlled lock and determine a corresponding unlocking logic type, wherein the unlocking logic type includes a power-off unlocking type and a power-on unlocking type;
[0140] A first instruction generating unit is configured to generate an unlocking control instruction for disconnecting a power circuit of an electronic control part if the unlocking logic type is a power-off unlocking type;
[0141] The second instruction generating unit is used to generate an unlocking control instruction for energizing the unlocking actuator of the electronic control part if the unlocking logic type is the power-on unlocking type.
[0142] Furthermore, in one embodiment of the present invention, the early warning module 150 includes:
[0143] A first early warning unit is configured to send an activation instruction to an on-site sound and light alarm controller deployed in the same area or an adjacent area as the target maintenance channel door defined in the spatial data model, wherein the activation instruction includes a preset alarm mode and duration parameter;
[0144] The second early warning unit is used to send a timeout alarm notification containing the unique identifier of the target maintenance channel door, the current opening time and the location information to the communication terminal of at least one preset first-level management personnel;
[0145] The third early warning unit is configured to automatically raise the alarm level and send an upgraded alarm notification to a communication terminal of a higher-level manager if no processing feedback on the timeout alarm notification is received within a preset response time.
[0146] Furthermore, in one embodiment of the present invention, the system further includes:
[0147] An operation data collection module is used to periodically collect and analyze the operation data of the battery power decay rate, historical communication failure frequency, and cumulative opening and closing times reported by the target IoT electric-controlled lock;
[0148] A data evaluation module, configured to input the collected operating data into a pre-trained device health evaluation model. The device health evaluation model, based on the correlation between historical fault data and operating parameters, outputs a quantitative score of the current health status of the target IoT electric lock and a probability prediction of potential future faults;
[0149] The maintenance module is configured to automatically generate a maintenance or replacement work order in the integrated operation and maintenance management system and notify relevant maintenance personnel when the quantitative score is lower than a preset health threshold, or the probability prediction of the potential fault exceeds a preset risk threshold, or the cumulative number of switching operations reaches a preset maintenance upper limit.
[0150] The implementation principle and technical effects of the safety control system for subway maintenance scenarios provided by the embodiment of the present invention are the same as those of the aforementioned method embodiment. For the sake of brief description, for matters not mentioned in the device embodiment, reference can be made to the corresponding content in the aforementioned method embodiment.
[0151] Example 3
[0152] Another aspect of the present invention also provides a backend management system, see Figure 3 , shown is a background management system in the third embodiment of the present invention, including a memory 200, a processor 100, and a program 300 stored in the memory 200 and executable on the processor. When the processor 100 executes the program 300, it implements the safety control method for subway maintenance scenarios as described in the above embodiment.
[0153] In some embodiments, the processor 100 can be a central processing unit (CPU), a controller, a microcontroller, a microprocessor or other data processing chip, used to run the program code stored in the memory 200 or process data, such as executing access restriction programs.
[0154] Among them, the memory 200 includes at least one type of readable storage medium, and the readable storage medium includes a flash memory, a hard disk, a multimedia card, a card-type memory (such as an SD or DX memory, etc.), a magnetic memory, a magnetic disk, an optical disk, etc. In some embodiments, the memory 200 can be an internal storage unit of the background management system, such as the hard disk of the background management system. In other embodiments, the memory 200 can also be an external storage device of the background management system, such as a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (FlashCard), etc. equipped on the background management system. Furthermore, the memory 200 can also include both an internal storage unit of the background management system and an external storage device. The memory 200 can be used not only to store application software and various types of data installed in the background management system, but also to temporarily store data that has been output or is to be output.
[0155] It should be pointed out that Figure 3 The structure shown does not constitute a limitation on the backend management system. In other embodiments, the backend management system may include fewer or more components than shown in the figure, or combine certain components, or arrange the components differently.
[0156] An embodiment of the present invention further provides a storage medium on which a program is stored. When the program is executed by a processor, the safety control method for subway maintenance scenarios as described in the above embodiment is implemented.
[0157] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example for illustration. In actual applications, the above-mentioned functions can be distributed and completed by different functional units or modules as needed, that is, the internal structure of the storage device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the implementation method can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other and are not used to limit the scope of protection of this application.
[0158] Those skilled in the art will appreciate that the logic and / or steps represented in the flowcharts or otherwise described herein, for example, may be considered as a sequenced list of executable instructions for implementing the logical functions, and may be embodied in any storage medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "storage medium" may be any device that can contain, store, communicate, propagate, or transmit a program for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0159] More specific examples (a non-exhaustive list) of readable storage media include the following: an electrical connection with one or more wires (electronic device), a portable computer disk cartridge (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the storage medium may even be paper or other suitable medium on which the program is printed, since the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering, or processing in another suitable manner as necessary, and then stored in a memory.
[0160] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement the hardware: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0161] Throughout this specification, reference to terms such as "one embodiment," "some embodiments," "examples," "specific examples," or "some examples" means that a specific feature, structure, material, or characteristic described in conjunction with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, schematic representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.
[0162] The above-described embodiments merely illustrate several embodiments of the present invention, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art would be able to make various modifications and improvements without departing from the spirit of the present invention, all of which fall within the scope of protection of the present invention. Therefore, the scope of protection of the present invention shall be determined by the appended claims.
Claims
1. A safety control method for subway maintenance scenarios, characterized in that: Applied to a background management system, the method includes: Receiving identity authentication information of a maintenance personnel and unlocking request information for a target maintenance channel door sent via a communication network from an identity authentication control terminal deployed at at least one maintenance channel door in a maintenance operation area; Based on the dynamic access rights pre-configured in association with the maintenance task and in combination with the precise spatial location information of the target maintenance access door, the identity authentication information of the maintenance personnel is verified, and it is determined whether the maintenance personnel is authorized to open the target maintenance access door at the current time. The dynamic access rights include at least authorized personnel, authorized area range, and authorized time period. If the verification is passed, a corresponding unlocking control instruction is generated according to the preset unlocking logic type of the target IoT electric lock associated with the target maintenance passage door, and the unlocking control instruction is sent to the target IoT electric lock via the communication network, and the door opening time monitoring of the target maintenance passage door is started. The unlocking control instruction is used to instruct the target IoT electric lock to unlock its electronic control part; Obtaining the lock body status information of the IoT electric lock and the switch status information of the target maintenance passage door from the IoT electric lock through the communication network, and continuously monitoring the obtained status information and door opening time timing according to preset monitoring rules; When the status information or the door opening duration timing indicating an abnormal state is detected during the monitoring process, a predefined early warning mechanism is triggered, which at least includes sending an early warning notification to a designated management terminal or personnel.
2. The safety control method for subway maintenance scenarios according to claim 1 is characterized in that: The step of generating the pre-configured dynamic access rights includes: Receive and parse maintenance work order data from a connected maintenance work order management system through a preset data interface. The maintenance work order data includes at least a maintenance task identifier, a planned execution authorization time period, designated authorized personnel information, and a defined authorization area or target operation equipment information; If the maintenance work order data contains target operating equipment information, the pre-built spatial data model that associates equipment with access door paths is used to automatically identify the target maintenance access doors on one or more critical paths that must be passed to access the target operating equipment, and the identified target maintenance access doors are included in the authorized area. The authorized personnel information, authorized time period, and authorized area range including one or more target maintenance channel doors extracted from the maintenance work order data or identified based on the spatial data model are written into the permission database as configuration parameters, and an associated index is established with the precise spatial location information of the corresponding target maintenance channel door in the spatial data model, thereby forming the dynamic access permission bound to the maintenance work task.
3. The safety control method for subway maintenance scenarios according to claim 2 is characterized in that: The step of verifying the identity authentication information of the maintenance personnel and determining whether the maintenance personnel has the right to open the target maintenance passage door at the current time includes: Retrieving dynamic access permission data associated with the target maintenance access door from an authority database; Comparing the received identity authentication information of the maintenance personnel to see if it matches the authorized personnel information in the dynamic access rights; Determining whether the current time falls within the authorized time period of the dynamic access right; Using a spatial data model to confirm whether the precise spatial location of the target maintenance access door falls within the authorized area defined in the dynamic access authority; Based on the matching results between the maintenance personnel and the authorized personnel, the matching results between the current time and the authorized time period, and the matching results between the precise spatial position and the authorized area range, it is determined whether the maintenance personnel has the right to open the target maintenance passage door at the current time.
4. The safety control method for subway maintenance scenarios according to claim 1 is characterized in that: The step of generating a corresponding unlocking control instruction according to a preset unlocking logic type of a target IoT electric-controlled lock associated with the target maintenance passage door comprises: Query the device configuration file of the target IoT electric lock to determine the corresponding unlocking logic type, which includes power-off unlocking type and power-on unlocking type; If the unlocking logic type is the power-off unlocking type, an unlocking control instruction is generated to disconnect the power circuit of the electronic control part; If the unlocking logic type is the power-on unlocking type, an unlocking control instruction is generated to energize the unlocking actuator of the electronic control part.
5. The safety control method for subway maintenance scenarios according to claim 1 is characterized in that: The step of triggering the predefined early warning mechanism includes: Sending an activation instruction to an on-site sound and light alarm controller deployed in the same area or an adjacent area as the target maintenance channel door defined in the spatial data model, the activation instruction including a preset alarm mode and duration parameters; At the same time, a timeout alarm notification containing the unique identifier of the target maintenance channel door, the current opening time and the location information is sent to the communication terminal of at least one preset first-level management personnel; If no processing feedback on the timeout alarm notification is received within the preset response time, the alarm level will be automatically upgraded, and an upgraded alarm notification will be sent to the communication terminal of a higher-level manager.
6. The safety control method for subway maintenance scenarios according to claim 1 is characterized in that: The method further comprises: Periodically collect and analyze the operating data of the target IoT electric lock, including the battery power decay rate, historical communication failure frequency, and cumulative number of openings and closings; The collected operating data is input into a pre-trained device health assessment model. The device health assessment model outputs a quantitative score of the current health status of the target IoT electric lock and a probability prediction of potential future failures based on the correlation between historical fault data and operating parameters. When the quantitative score is lower than the preset health threshold, or the probability prediction of the potential fault exceeds the preset risk threshold, or the cumulative number of switching actions reaches the preset maintenance upper limit, a maintenance or replacement work order is automatically generated in the integrated operation and maintenance management system, and the relevant maintenance personnel are notified.
7. A safety control system for subway maintenance scenarios, characterized in that: Applied to the background management system, the system includes: An information receiving module is used to receive the identity authentication information of the maintenance personnel and the unlocking request information for the target maintenance channel door sent from the identity authentication control terminal deployed at at least one maintenance channel door in the maintenance operation area through the communication network; a verification module for verifying the identity authentication information of the maintenance personnel based on a dynamic access right pre-configured in association with the maintenance task and in combination with the precise spatial location information of the target maintenance passage door, and determining whether the maintenance personnel is authorized to open the target maintenance passage door at the current time, wherein the dynamic access right includes at least an authorized person, an authorized area range, and an authorized time period; an instruction generation module, configured to, when the verification module passes verification, generate a corresponding unlocking control instruction based on a preset unlocking logic type of a target IoT electric-controlled lock associated with the target maintenance passage door, send the unlocking control instruction to the target IoT electric-controlled lock via a communication network, and initiate timing monitoring of the door opening duration of the target maintenance passage door, wherein the unlocking control instruction is used to instruct the target IoT electric-controlled lock to unlock its electronic control portion; An information acquisition and monitoring module is used to obtain the lock body status information of the IoT electric-controlled lock and the switch status information of the target maintenance passage door from the IoT electric-controlled lock via the communication network, and continuously monitor the obtained status information and door opening time timing according to preset monitoring rules; The early warning module is used to trigger a predefined early warning mechanism when it is detected during the monitoring process that the status information or the door opening time timing indicates an abnormal state. The early warning mechanism at least includes sending an early warning notification to a designated management terminal or personnel.
8. The safety control method for subway maintenance scenarios according to claim 7 is characterized in that: The verification module includes: A data receiving and parsing unit is used to receive and parse maintenance work order data from a connected maintenance work order management system through a preset data interface. The maintenance work order data at least includes a maintenance task identifier, a planned execution authorization time period, designated authorized personnel information, and a defined authorization area range or target operation equipment information; an authorization area determination unit configured to, if the maintenance work order data includes target operating equipment information, automatically identify target maintenance access doors on one or more critical paths that must be passed through to access the target operating equipment using the pre-built spatial data model that associates equipment with access door paths, and include the identified target maintenance access doors in the authorization area; A dynamic access permission generation unit is used to write the authorized personnel information, authorized time period, and authorized area range containing one or more target maintenance channel doors extracted from the maintenance work order data or identified based on the spatial data model as configuration parameters into the permission database, and establish an associated index with the precise spatial location information of the corresponding target maintenance channel door in the spatial data model, thereby forming the dynamic access permission bound to the maintenance operation task.
9. The safety control method for subway maintenance scenarios according to claim 8 is characterized in that: The verification module includes: A data retrieval unit, configured to retrieve dynamic access permission data associated with the target maintenance access door from an authority database; A first data comparison unit is used to compare whether the received identity authentication information of the maintenance personnel matches the authorized personnel information in the dynamic access permission; a second data comparison unit, configured to determine whether the current time falls within an authorized time period in the dynamic access authority; A third data comparison unit is used to confirm whether the precise spatial position of the target maintenance passage door belongs to the authorized area defined in the dynamic access permission by using the spatial data model; The determination unit is used to comprehensively determine whether the maintenance personnel has the right to open the target maintenance passage door at the current time based on the matching results between the maintenance personnel and the authorized personnel, the matching results between the current time and the authorized time period, and the matching results between the precise spatial position and the authorized area range.
10. A backend management system, characterized in that: It includes a memory, a processor, and a program stored in the memory and executable on the processor. When the processor executes the program, it implements the safety control method for subway maintenance scenarios as described in any one of claims 1 to 6.
Citation Information
Cited By
Personnel passing verification method and system based on space-time rule dynamic matching
CN121545260A