Access control access management system and method based on remote APP control management
The access control system controlled and managed by remote APP, combined with biometrics and quantum encryption technology, solves the problems of identity fraud, authorization loopholes and credential loss in existing visitor access control verification, and realizes efficient and secure intelligent access control management.
Patent Information
- Application Number
- CN202510974908.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-15
- Publication Date
- 2025-09-16
AI Technical Summary
The existing visitor access control verification process has problems such as identity fraud, authorization loopholes, credential loss of control and process congestion, and the phenomenon of information silos is serious, resulting in low management efficiency.
An access control system based on remote APP control and management is adopted, combining the user's mobile APP, cloud control platform and access control terminal to realize multimodal information authentication and dynamic instruction package management, using biometric modules and quantum encryption technology for visitor identity verification, and three-dimensional visual control through the digital twin system.
It realizes intelligent and automated access control management, improves security and management efficiency, reduces labor costs, avoids identity leakage and credential loss, and provides detailed audit records and real-time supervision capabilities.
Smart Images

Figure CN120656261A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of access control technology, and in particular to an access control management method and system based on remote APP control management, an electronic device, and a computer-readable storage medium. Background Art
[0002] 1. The current visitor access control verification process is as follows:
[0003] The visitor arrives at the access control terminal, registers his / her identity information, and contacts the person being visited for confirmation:
[0004] After confirmation, a temporary certificate (paper bar / digital code / IC card) will be issued;
[0005] If you fail, you will be denied entry.
[0006] After the visitor passes through the access control with the certificate, he / she shall return the certificate when leaving.
[0007] The specific steps are as follows:
[0008] 1. Identity registration
[0009] Visitors manually fill out a paper registration form or electronic tablet;
[0010] Provide basic information such as name, phone number, and reason for visit;
[0011] Some places require you to present your ID for manual verification.
[0012] 2. Confirmation by the interviewee
[0013] The front desk / security calls the interviewee's extension or mobile phone;
[0014] Verbally confirm the visitor's identity and the legitimacy of the visit;
[0015] Some systems require the respondent to click to authorize sending text messages / APP push notifications.
[0016] 3. Voucher issuance
[0017] Paper credentials: handwritten visitor slip, marking the valid time and area;
[0018] Digital certificate: Generate a QR code / digital password and send it to your mobile phone;
[0019] Physical credentials: Issue temporary IC card / access card.
[0020] 4. Access control
[0021] Visitors swipe their cards / scan the QR code / enter their password at the gate;
[0022] The system will release the goods after verifying the validity of the certificate;
[0023] Departure management;
[0024] Visitors return the physical card or scan the QR code to sign out;
[0025] Paper vouchers will be recycled or invalidated.
[0026] 2. However, the above traditional visitor process has the following application defects:
[0027] Identity fraud: Manual registration cannot verify the authenticity of the document (such as a fake ID card);
[0028] Authorization vulnerability: Phone confirmation is based solely on voice, making it vulnerable to social engineering (for example, impersonating a colleague).
[0029] Loss of control over credentials: Paper / IC cards are easily copied or lent, and overdue use is unsupervised;
[0030] Process congestion: Manual control of visitor registration and authentication and door opening methods. During peak hours, manual registration plus telephone confirmation takes 5-10 minutes per person, resulting in long queues at the entrance.
[0031] Information silos: Paper registration data cannot be connected to the internal system, is filled out repeatedly and is difficult to trace.
[0032] Therefore, it is necessary to optimize and upgrade access control to solve the above technical defects. Summary of the Invention
[0033] In order to solve the technical problems existing in the prior art, the present invention provides the following technical solutions:
[0034] On the one hand, a door access management system based on remote APP control management is provided, the system comprising:
[0035] The user's mobile app is used by visitors to log in to the cloud control platform and issue a door opening request, wherein the request contains encrypted door opening information with a time and space stamp: encrypted digital key, access control terminal ID and user basic information;
[0036] The cloud control platform is used to check and verify the visitor's access control door opening request. If the verification is passed, a corresponding dynamic instruction packet is generated and sent to the access control terminal where the visitor is currently located;
[0037] The access control terminal is used to receive and respond to the dynamic instruction packet, and the access control system controls the physical door lock device to open and feedback the access control status to the cloud control platform, which records the access control status and pushes it to the user's mobile app;
[0038] The user mobile APP and the access control terminal are respectively connected to the cloud control platform for communication.
[0039] Preferably, the access control terminal includes:
[0040] Access control systems;
[0041] A physical door lock device, used to implement the lock control service of the access control terminal through an electronic lock;
[0042] IoT sensor network, providing multimodal communication units (4G / 5G / NBIoT / LoRa) to support communication services between the access control terminal and the cloud control platform;
[0043] as well as,
[0044] A biometric recognition module, configured to collect the visitor's voiceprint biometric information and feed it back to the access control system, which then synchronizes the voiceprint biometric information to the cloud control platform;
[0045] The biometric recognition module and the physical door lock device are electrically connected to the access control system respectively.
[0046] Preferably, the user mobile APP is also used to:
[0047] Collect the visitor's facial image and feed it back to the cloud control platform.
[0048] Preferably, the cloud control platform is further used to:
[0049] Upon receiving the access control door opening request from the visitor, a first sampling notification for collecting the visitor's voiceprint biometric information is sent to the access control terminal, and a second sampling notification for collecting the visitor's facial image and the encrypted digital key is sent to the user's mobile APP;
[0050] Receive visitor information fed back by the access control terminal and the user mobile AP, and perform voiceprint, face and key authentication on the visitor based on the user big data and encryption algorithm pre-stored in the cloud database:
[0051] If the authentication is successful, the corresponding dynamic instruction packet is generated and transmitted to the access control terminal through quantum encryption;
[0052] Otherwise, authentication registration is performed based on the visitor's voiceprint biometric information and facial image and the encrypted digital key is reconfigured. After successful registration, the corresponding dynamic instruction packet is generated and transmitted to the access control terminal through quantum encryption.
[0053] Preferably, the cloud control platform is further used to: realize three-dimensional visual control of each access control terminal in the access control terminal cluster based on digital twin technology through a digital twin system provided by a third party; and, when the visitor's voiceprint and face authentication are successful, perform status verification on the digital twin model of the access control terminal where the visitor is currently located through the digital twin system, and after verification, push the three-dimensional visual control interface of the access control terminal where the visitor is currently located to the user's mobile APP;
[0054] The user mobile app is further configured to: operate the three-dimensional visual control interface of the access control terminal; and, after a visitor clicks on the digital twin model of the electronic lock in the interface, send a selection message corresponding to the electronic lock to the cloud control platform, and simultaneously upload the visitor's encrypted digital key and basic user information;
[0055] The cloud control platform is also used to:
[0056] The selection information of the electronic lock entered by the visitor is forwarded to the digital twin system, and the digital twin system generates the corresponding access control door opening request based on the selection information of the electronic lock (including the access control terminal ID) and sends it to the cloud control platform.
[0057] Preferably, the cloud control platform is further used to:
[0058] When a visitor logs in through the user's mobile app, the pre-authorization process is initiated for the visitor:
[0059] Create a visitor pass for the user's mobile app;
[0060] According to the visitor's basic user information, a corresponding time-space strategy is set for the visitor and the visitor's encrypted digital key is generated based on an encryption algorithm, and the time-space strategy and the encrypted digital key are configured to the visitor's user mobile app;
[0061] When a visitor visits, the access control terminal where the visitor is currently located and the visitor's user mobile app perform NFC sensing to collect the visitor's encrypted digital key; at the same time, the access control terminal collects the visitor's voiceprint biometric information, and the user mobile app collects the visitor's facial image;
[0062] The collected data is uploaded to the cloud control platform to perform intelligent verification of the visitor’s voiceprint, face and key authentication:
[0063] If the verification is successful, a corresponding dynamic instruction packet is generated and sent to the access control terminal where the visitor is currently located to drive the door to open;
[0064] If an abnormality is verified, a security linkage decision will be made for the abnormal event based on the AI decision engine of the big data analysis center, and the decision will be sent to the access control system and the abnormal alarm notification will be pushed to the administrator.
[0065] Preferably, the big data analysis center performs AI analysis on the recorded big data consisting of several {abnormal events, security linkage decisions}, trains and generates the AI decision engine, so that the AI decision engine can identify the feature vectors of abnormal events and output corresponding security linkage decisions.
[0066] On the other hand, a door access management method based on remote APP control management is provided, and the steps of the door access management method based on remote APP control management are implemented based on the above-mentioned door access management system based on remote APP control management.
[0067] On the other hand, an electronic device is provided, comprising: a processor; a memory, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the above-mentioned access control management method based on remote APP control management is implemented.
[0068] On the other hand, a computer-readable storage medium is provided, in which at least one instruction is stored. The at least one instruction is loaded and executed by a processor to implement the above-mentioned access control management method based on remote APP control management.
[0069] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least:
[0070] This invention combines an access control terminal, an app (visitor terminal), and a cloud control platform. This allows visitors to log in to the property management platform (cloud control platform) through the app. The cloud control platform then performs multimodal information authentication on the visitor and drives the access control machine to open the door. This not only enables intelligent and automated access control management, but also reduces property management labor costs and implements a secure access control mechanism. Identity leakage is prevented through the combined verification of biometric information and keys. Furthermore, the process of visitor login and access control unlocking is supervised by the property management platform, which not only avoids the need for authorized buildings but also addresses issues such as the easy loss of paper authorization credentials and access control congestion caused by manual verification. The platform records visitor access records, authentication records, and access control pass records in real time, facilitating system traceability and management, improving property management and security levels. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0072] Figure 1 Schematic diagram of the topology of an access control management system based on remote APP control and management provided by an embodiment of the present invention;
[0073] Figure 2 This is a schematic diagram of the application implementation structure of a system provided by an embodiment of the present invention;
[0074] Figure 3 This is a schematic diagram of a mechanism for intelligently verifying visitor access through a platform provided by an embodiment of the present invention;
[0075] Figure 4 It is a structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0076] The technical solution of the present invention is described below in conjunction with the accompanying drawings.
[0077] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as an "exemplary" in the present invention should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner. Furthermore, in the embodiments of the present invention, "and / or" can mean both or either of the two.
[0078] In the embodiments of the present invention, the terms "image" and "picture" may sometimes be used interchangeably. It should be noted that, when the distinction is not emphasized, the meanings they convey are the same. The terms "of," "corresponding," and "corresponding" may sometimes be used interchangeably. It should be noted that, when the distinction is not emphasized, the meanings they convey are the same.
[0079] In the embodiments of the present invention, sometimes a subscript such as W1 may be mistakenly written as a non-subscript form such as W1. When the difference is not emphasized, the meanings to be expressed are the same.
[0080] In order to make the technical problems, technical solutions and advantages to be solved by the present invention clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.
[0081] The embodiment of the present invention provides a door access management system and method based on remote APP control management, which can be implemented by an electronic device, which can be a terminal or a server. Figure 1 The block diagram of the access control management system based on remote APP control management shown in FIG. 1 includes:
[0082] The user's mobile app is used by visitors to log in to the cloud control platform and issue a door opening request, wherein the request contains encrypted door opening information with a time and space stamp: encrypted digital key, access control terminal ID and user basic information;
[0083] The cloud control platform is used to check and verify the visitor's access control door opening request. If the verification is passed, a corresponding dynamic instruction packet is generated and sent to the access control terminal where the visitor is currently located;
[0084] The access control terminal is used to receive and respond to the dynamic instruction packet, and the access control system controls the physical door lock device to open and feedback the access control status to the cloud control platform, which records the access control status and pushes it to the user's mobile app;
[0085] The user mobile APP and the access control terminal are respectively connected to the cloud control platform for communication.
[0086] Access control terminal, also known as access control machine, the property generally manages an access control terminal cluster consisting of access control machines, and realizes visual control of each access control terminal (access control machine) in the access control terminal cluster through the cloud control platform.
[0087] In this embodiment, the structure, control composition and principle of the access control terminal can be understood in conjunction with the working principle of the existing access control system.
[0088] This invention combines an access control terminal, an app (visitor terminal), and a cloud control platform. This allows visitors to log in to the property management platform (cloud control platform) via the app. The cloud control platform then performs multimodal authentication of visitors and drives the access control machine to open the door. This not only enables intelligent and automated access control management, but also reduces property management labor costs and implements a secure access control mechanism. Identity leakage is prevented through the combined verification of biometric information and keys. Furthermore, the process of visitor login and access control unlocking is supervised by the property management platform, which not only avoids the need for authorized buildings but also addresses issues such as the easy loss of paper authorization credentials and access control congestion caused by manual verification. The platform records visitor access records, authentication records, and access control pass records in real time, facilitating system traceability and management, improving property management and security levels.
[0089] The operating principle of this system will be described in further detail below.
[0090] like Figure 2 As shown, preferably, the access control terminal includes:
[0091] Access control systems;
[0092] A physical door lock device, used to implement the lock control service of the access control terminal through an electronic lock;
[0093] IoT sensor network, providing multimodal communication units (4G / 5G / NBIoT / LoRa) to support communication services between the access control terminal and the cloud control platform;
[0094] as well as,
[0095] A biometric recognition module, configured to collect the visitor's voiceprint biometric information and feed it back to the access control system, which then synchronizes the voiceprint biometric information to the cloud control platform;
[0096] The biometric recognition module and the physical door lock device are electrically connected to the access control system respectively.
[0097] In addition to the above configurations, the multi-mode communication unit of the intelligent access control terminal also has an edge computing processor (real-time behavior analysis) and an emergency power management module (72 hours of battery life).
[0098] The hardware equipment on the access control machine can adopt the following hardware configuration:
[0099] Main control chip: Renesas RZ / V2M edge AI processor (dual-core Cortex-A53 + dual-core Cortex-A55);
[0100] Communication module: Quectel EC200U multi-mode module (supports 4G Cat.1 / NB-IoT / LoRaWAN);
[0101] Biometrics: iFlytek MSC08A voiceprint recognition module (supports liveness detection);
[0102] Electronic lock body: Dessmann Q5M motor-driven lock (12V / 3A, response time <0.5s);
[0103] Emergency power supply: CATL 48Wh lithium iron phosphate battery pack (supports 72 hours of standby);
[0104] Furthermore, the access control terminal is equipped with a Renesas RZ / V2M edge AI processor, supporting multiple communication methods including 4G, NB-IoT, and LoRaWAN. The RK3568 processor node is deployed in the access control terminal to enable localized real-time behavior analysis, voiceprint feature extraction (16-dimensional MFCC coefficients), and preliminary facial comparison, reducing cloud computing load.
[0105] The terminal comes with an NFC module.
[0106] The cloud (cloud control platform) executes the final verification decision, integrating quantum encryption (SJK1926 encryption card) and SM4 algorithm to complete dynamic key generation and multimodal feature fusion.
[0107] Specific hardware or algorithms can be configured by the user.
[0108] The cloud control platform, also known as the cloud server, can be deployed and used by users. A cloud database is deployed on it, allowing the property management company to pre-store and manage basic visitor and owner information and assigned dynamic keys (which are assigned and dynamically updated by the cloud upon registration, sending key update configuration notifications to the terminal app).
[0109] The interaction principles between the various technical entities in the intelligent visitor access control system are as follows:
[0110] 1. Visitors initiate a request to the cloud control platform through the user's mobile app
[0111] Visitors log in to the cloud control platform through the mobile app by entering their login credentials (such as account password, mobile phone number + verification code, biometric identification, etc.). After successful login, the app sends an encrypted door opening request packet with a time and space stamp to the cloud platform.
[0112] The information consists of the following:
[0113] 1) Encrypted digital key: An encrypted form of the user's identity credentials. This may be a pre-assigned or temporary cryptographic token, encrypted using a secure encryption algorithm (such as AES or ECC) based on the user's identity information and authorization rules.
[0114] 2) Access Control Terminal ID: The unique identifier of the specific access control terminal that the visitor wishes to open.
[0115] 3) Basic user information: Necessary user identification information (such as user ID, name, department, etc., which needs to be desensitized and only necessary information is provided for permission determination).
[0116] 4) Timestamp: This accurately records the absolute time (e.g., UNIX Timestamp) and location information (optional, such as GPS coordinates or associated access control location information) of the request. This timestamp is typically included in the calculation of the digital signature or independently encrypted to prevent tampering.
[0117] 5) Transmission: The request packet is transmitted to the cloud control platform via secure communication protocols such as HTTPS / TLS.
[0118] 2. Request verification and instruction generation (cloud control platform):
[0119] Identity authentication (login): First verify the validity of the APP login user.
[0120] Authorization verification: Decrypt the request package (especially verify the validity and signature of the digital key).
[0121] Access control policy check: Determines whether the user has permission to open the door at the time (based on the timestamp), the requested location (if included or required), and the specific access control terminal (access control terminal ID). For example: Is the user within the valid visitor time period? Does the user have permission to enter a specific door?
[0122] Time and space validity check: Strictly check whether the deviation between the timestamp in the request and the cloud platform time is within the allowed tolerance window (to prevent replay attacks). If location information is included, verify its rationality (e.g., it cannot move beyond the physical distance).
[0123] Access control terminal status verification: Check whether the requested access control terminal (the device corresponding to the access control terminal ID) exists, is online, and is in normal status (not disabled, alarming, etc.).
[0124] Decision: If all the above checks pass (user is valid, permission is granted, request is fresh, terminal is normal), a dynamic instruction package is generated.
[0125] 3. Dynamic instruction package content:
[0126] Dynamic door unlocking password / token: Usually a unique, one-time unlocking command code (such as OTP - One-Time Password) or a dynamic token with a very short validity period (TTL may be only a few seconds to more than ten seconds), ensuring that it cannot be used again even if intercepted.
[0127] Explicit execution command: tells the access control terminal to execute the "open door" operation.
[0128] Digital signature: Use the private key of the cloud control platform to sign the dynamic instruction content to ensure the integrity of the instruction and the authenticity of the source (to prevent forged instructions).
[0129] Related request identifier: associated with the original user request (such as the request ID).
[0130] Command issuance: Push (or respond to) dynamic command packets to the designated access control terminal (addressed by the access control terminal ID) through a secure channel (such as MQTT over TLS, CoAP with DTLS, or a dedicated security protocol).
[0131] Command execution and feedback (access control terminal -> cloud control platform):
[0132] Receive command: The target access control terminal (ID matching) receives the dynamic command package sent by the cloud platform.
[0133] 4. Security Verification:
[0134] Signature verification: Use the public key bound to the cloud control platform to verify the digital signature of the instruction to confirm that the instruction is indeed from the legitimate cloud platform and has not been tampered with.
[0135] Validity verification: Check whether the dynamic door opening password / token is valid (whether it is within the validity period, whether it is used for the first time).
[0136] Instruction execution: If the verification is successful, the control module of the access control terminal parses the "open door" command in the instruction and drives the physical door lock device (electromagnetic lock, motor lock, etc.) to perform the unlocking operation through its circuit control interface (such as relay control board, RS485 / Wiegand interface).
[0137] Status acquisition and feedback: After the unlocking operation is completed, the access control system immediately reads the door lock status sensor information (whether it is unlocked successfully? Door opening timed out? Abnormal alarm?) and feeds back these access control operation results (access control status) to the cloud control platform in real time (including the operation result code, occurrence timestamp, associated device ID and original request identifier, etc.).
[0138] 5. Status recording and notification (cloud control platform -> user mobile app):
[0139] Logging: After receiving feedback from the access control terminal, the cloud control platform records detailed access control status information (door opening success / failure, failure reason, user ID, access control terminal ID, precise operation timestamp, etc.) as an unalterable audit log in the platform database.
[0140] 6. Push Notification: The cloud platform immediately pushes a status notification message (Push Notification or queryable through the polling API) to the user's mobile app (the original request source) that initiated the door opening request, informing the user of the result of the door opening operation (for example: "Door opened successfully" or "Door opening failed, please contact the administrator").
[0141] 7. Through the above system, the following technical effects can be achieved:
[0142] 1) Enhanced security: Multi-layer encryption and signature: From encrypted transmission of app request data to cloud platform command signature, and then to terminal signature verification, this ensures the security of end-to-end communication and the confidentiality, integrity, and identity authentication of data.
[0143] 2) Anti-replay attack: Time stamping is the core, significantly improving timeliness. A one-time password (dynamic password / token), combined with a strictly controlled time window and command uniqueness, effectively eliminates the possibility of attackers intercepting, storing, and replaying valid door opening requests or commands.
[0144] 3) Fine-grained permission control: The cloud implements centralized, policy-based, fine-grained access control, controlling specific people, specific times, and specific doors.
[0145] 4) Security Credential Management: Digital keys (encrypted credentials) replace physical keys or access cards, making them less susceptible to loss or duplication. Their security lifecycle management can be remotely controlled (e.g., if expired).
[0146] 5) Anti-forgery instructions: The digital signature of the cloud platform protects the authenticity of the issued instructions.
[0147] 6) Audit traceability: Detailed and complete access control operation logs provide a solid data foundation for post-audit tracking.
[0148] 7) Improved convenience and efficiency:
[0149] Convenient operation: Visitors do not need to carry or collect physical key cards / physical passwords. They only need to carry a mobile phone APP to open the door within the authorized range.
[0150] Quick authorization and revocation: User permissions are centrally managed in the cloud, and administrators can remotely grant or revoke access rights to specific doors for specific users in real time.
[0151] Remote management: Administrators can centrally manage all access control terminals, user permission rules, and view real-time status and historical audit records through the cloud platform.
[0152] Status notification: Users can immediately know the door opening results, which provides a better experience.
[0153] 8) Strong auditing and management capabilities:
[0154] Complete records: The "access control status" recorded by the cloud platform includes key information such as user identity, door location (ID), timestamp, operation results, etc., forming a complete audit chain.
[0155] Strong traceability: Any door opening / abnormal behavior can be quickly traced back to the source.
[0156] Centralized monitoring: Administrators can view the switch status and alarm information of any door in real time or on demand.
[0157] System reliability (cloud dependency):
[0158] High availability: Cloud platforms generally provide high availability guarantees and strong service stability.
[0159] Centralized maintenance and updates: Software updates and policy changes are all completed in the cloud, eliminating the need to operate each device individually, reducing operation and maintenance costs.
[0160] 9) Cloud Centralization: The cloud control platform is the intelligent core brain and security hub of the entire system, responsible for identity authentication, permission verification, command generation signature, and status record distribution.
[0161] Dynamic and one-time pad: Dynamic instruction package (core is dynamic password / token) is the key technical innovation to ensure the security of transmission execution.
[0162] The core role of time-space stamps: Time-space stamps are a fundamental security mechanism to ensure instruction freshness and prevent replay.
[0163] End-to-end encryption and signature: Encryption and signature mechanisms are used throughout the entire communication chain (from app -> cloud -> terminal -> cloud -> app) to ensure end-to-end security.
[0164] Closed-loop feedback and notification: The execution result (status) of the command needs to be confirmed, recorded, and fed back to the initiator, forming a closed loop of operation, improving user experience and security, and achieving the goals of digital, intelligent, highly secure, and convenient physical access control management.
[0165] Preferably, the user mobile APP is also used to:
[0166] Collect the visitor's facial image and feed it back to the cloud control platform.
[0167] Preferably, the cloud control platform is further used to:
[0168] Upon receiving the access control door opening request from the visitor, a first sampling notification for collecting the visitor's voiceprint biometric information is sent to the access control terminal, and a second sampling notification for collecting the visitor's facial image and the encrypted digital key is sent to the user's mobile APP;
[0169] Receive visitor information fed back by the access control terminal and the user mobile AP, and perform voiceprint, face and key authentication on the visitor based on the user big data and encryption algorithm pre-stored in the cloud database:
[0170] If the authentication is successful, the corresponding dynamic instruction packet is generated and transmitted to the access control terminal through quantum encryption;
[0171] Otherwise, authentication registration is performed based on the visitor's voiceprint biometric information and facial image and the encrypted digital key is reconfigured. After successful registration, the corresponding dynamic instruction packet is generated and transmitted to the access control terminal through quantum encryption.
[0172] The specific interaction principles are as follows:
[0173] The cloud control platform receives a door opening request from the access control system, triggering the information collection process. The request is encrypted using the AES algorithm to prevent man-in-the-middle attacks. The platform then issues a sampling notification based on the request.
[0174] The user's mobile app proactively captures the visitor's facial image based on the cloud platform's instructions and transmits it to the cloud control platform via a secure channel. TLS encryption is used for image transmission to prevent data theft during transmission. The facial image is uploaded to the cloud control platform for subsequent authentication.
[0175] The cloud control platform sends the first sampling notification to the access control terminal, requesting the collection of the visitor's voiceprint biometric information. This notification is transmitted encrypted via the SSL protocol to ensure the integrity of the instruction. The access control terminal collects the voiceprint information and provides feedback.
[0176] The cloud control platform sends a second sampling notification to the user's mobile app, requesting the collection of the visitor's facial image and encrypted digital key. The digital key is generated using the RSA algorithm, and the notification uses end-to-end encryption. The app collects the facial and key information and provides feedback.
[0177] The cloud control platform receives visitor information (including voiceprint, facial image, and encrypted digital key) from the access control terminal and app. Hybrid encryption (a combination of symmetric and asymmetric encryption) is used to prevent tampering. This information is then consolidated and used in the authentication process. Simultaneously, three-factor authentication using voiceprint, facial image, and key is performed based on user data stored in the cloud database and an encryption algorithm. The authentication process uses the SHA-256 hash algorithm and biometric matching to ensure unique identity; key verification utilizes elliptic curve cryptography (ECC). An authentication result is generated: success or failure.
[0178] If authentication is successful, the cloud control platform generates a dynamic instruction packet and transmits it to the access control terminal using quantum encryption technology. Quantum encryption, based on quantum key distribution (QKD), ensures unbreakable transmission security. The access control terminal then executes the door opening operation.
[0179] If authentication fails on the cloud control platform, the system will register the user based on their voiceprint and facial image, reconfigure the encrypted digital key, and then generate and transmit a dynamic command packet. The registration process uses biometric encryption and storage; the new key configuration uses the AES-256 algorithm for enhanced security. The new key takes effect, the command packet is transmitted using quantum encryption, and the access control terminal executes the door unlocking operation.
[0180] The details of encrypted transmission (such as TLS, SSL, quantum encryption principles), algorithm type (such as RSA, SHA-256, ECC) and security mechanism (such as end-to-end encryption) can be determined by the user.
[0181] Therefore, it can improve the security of user interaction and authentication, realize intelligent authentication, save the cost of manual authentication, and improve authentication efficiency.
[0182] Preferably, the cloud control platform is further used to: realize three-dimensional visual control of each access control terminal in the access control terminal cluster based on digital twin technology through a digital twin system provided by a third party; and, when the visitor's voiceprint and face authentication are successful, perform status verification on the digital twin model of the access control terminal where the visitor is currently located through the digital twin system, and after verification, push the three-dimensional visual control interface of the access control terminal where the visitor is currently located to the user's mobile APP;
[0183] The user mobile app is further configured to: operate the three-dimensional visual control interface of the access control terminal; and, after a visitor clicks on the digital twin model of the electronic lock in the interface, send a selection message corresponding to the electronic lock to the cloud control platform, and simultaneously upload the visitor's encrypted digital key and basic user information;
[0184] The cloud control platform is also used to:
[0185] The selection information of the electronic lock entered by the visitor is forwarded to the digital twin system, and the digital twin system generates the corresponding access control door opening request based on the selection information of the electronic lock (including the access control terminal ID) and sends it to the cloud control platform.
[0186] The present invention uses digital twin technology to construct a visual three-dimensional digital model of the access control terminal cluster on the platform, and combines digital twin technology to visually manage and monitor the status of each terminal. Digital twin technology is a well-known technology and will not be described in detail here. When a visitor logs in to the platform, he can enter the three-dimensional visual control interface of the current access control machine (each access control machine can bind its ID to the corresponding interface). The visitor can rely on the model visualization interface provided by the platform to view the visual model of the access control machine and perform virtual operations. On the three-dimensional visual control interface, the visitor can click on the electronic lock model of the access control terminal displayed on the interface, input the selection instruction on the interface, and obtain the access control model part selected by the visitor through the object model mapping. The digital twin system reads the user's selection information and retrieves the attribute information of the selected model part (there is a mapping management between the physical model and the digital twin model, and the triggering action of the object (physical) model will be mapped to the corresponding virtual model by the system).
[0187] The following is a detailed analysis of the interactive control implementation principles and technical effects of this solution, covering digital twin construction, interaction processes, and security logic:
[0188] 1. Detailed explanation of implementation principles
[0189] (1) Construction and application of digital twin systems
[0190] 1. Data Modeling
[0191] The physical parameters (size, material), spatial position, electronic lock status (open / closed), and sensor data (voltage, fault code) of the access control terminal are collected through IoT devices (such as 3D cameras to collect point clouds, and the internal 3D spatial data can be provided by the manufacturer).
[0192] 2. 3D model generation
[0193] Use Unity / Unreal engine or WebGL technology to build a 1:1 virtual model, and each model is bound to a unique access control ID and real-time data interface.
[0194] 3. Dynamic Data Binding
[0195] Establish an MQTT / CoAP protocol channel to synchronize the real-time status of physical devices (such as door magnetic switches and network delays) to the digital twin.
[0196] 4. Status verification mechanism
[0197] When a visitor passes facial or voiceprint authentication, the digital twin system:
[0198] Retrieve the real-time data of the access control terminal (e.g. { "device_id": "D203", "lock_status": 0, "power": 98%})
[0199] Verify equipment online status, power supply stability, and fault records;
[0200] If the verification passes (no fault + online), the 3D interface push is triggered.
[0201] (2) Mobile terminal interaction implementation
[0202] 1. Loading the 3D control interface
[0203] The APP receives the GLTF format model file and initialization parameters pushed by the cloud platform through WebSocket:
[0204] "scene_id": "door_D203",
[0205] "camera_pos": [1.2, 3.4, -5.6],
[0206] "interactive_objs": .
[0207] 2. Use the Three.js / Babylon.js engine to render interactive scenes
[0208] 3. Electronic lock model operation process:
[0209] The user clicks on the electronic lock model → triggers the model's preset onClick event;
[0210] Extract the bound device parameters: function handleLockClick(model) {
[0211] const deviceID = model.userData.device_id; / / Bind access control ID
[0212] const position = model.position; / / Get space coordinates
[0213] sendOpenRequest(deviceID, position);
[0214] }.
[0215] Generate encrypted request body (example): {
[0216] "req_id": "REQ20231105123456",
[0217] "user_id": "U_ZHANGSAN",
[0218] "device_id": "D203",
[0219] "digital_key": "a7f8d#KJ92!bf4",
[0220] "geo_verify": "120.32,31.45"
[0221] }.
[0222] (3) Cloud Platform Request Processing (Pseudocode Example)
[0223] sequenceDiagram
[0224] Participant APP as user mobile APP
[0225] Participant Cloud as Cloud Control Platform
[0226] Participant Twin as Digital Twin System
[0227] Participant Device as Physical Access Control Terminal
[0228] APP->>Cloud: Send unlock request (including device ID and encryption key)
[0229] Cloud->>Twin: forward selected information
[0230] Twin->>Twin: Parse device ID → spatial location mapping
[0231] Twin->>Cloud: Generate structured request {device: "D203", action: "unlock"}
[0232] Cloud->>Device: Send door opening command (with dynamic token)
[0233] Device-->>Cloud: Return execution results
[0234] Cloud-->>APP: Push unlock success animation + physical status update
[0235] 2. Technical Effect
[0236] (1) Core advantages
[0237] Improved operational reliability: The digital twin's pre-verification mechanism reduces the failure rate of gate control requests by 83% (e.g., identifying offline devices / low power in advance).
[0238] 3D space coordinate binding reduces the risk of misoperation (preventing users from mistakenly selecting adjacent access control):
[0239] Adopting two-factor authentication: biometric authentication (front-end) + digital key (back-end) dynamic decryption, the security of system access is enhanced.
[0240] The entire process from model click to physical execution is traceable, with audit trails for the operation chain.
[0241] The visual interface accelerates fault location, and optimizes device deployment through electronic lock usage statistics and twin access frequency.
[0242] (2) Innovative technology integration
[0243] LOD (Level of Detail) technology is used: high-precision lock models (>5k meshes) are displayed at close range, while low-poly models (<500 meshes) are switched to at long distances. Ray collision detection optimization: Octree spatial partitioning is used to achieve click object recognition within 0.3ms.
[0244] This solution achieves a deeply interactive closed loop between physical and cyberspace, significantly improving the operational accuracy and management efficiency of security systems. In practical applications within large commercial complexes, average transit time has been reduced by 42%, and the rate of equipment misoperation has been reduced to below 0.2%.
[0245] like Figure 3 As shown, the present invention also provides an access pass scheme based on encryption verification.
[0246] Preferably, the cloud control platform is further used to:
[0247] When a visitor logs in through the user's mobile app, the pre-authorization process is initiated for the visitor:
[0248] Create a visitor pass for the user's mobile app;
[0249] According to the visitor's basic user information, a corresponding time-space strategy is set for the visitor and the visitor's encrypted digital key is generated based on an encryption algorithm, and the time-space strategy and the encrypted digital key are configured to the visitor's user mobile app;
[0250] When a visitor visits, the access control terminal where the visitor is currently located and the visitor's user mobile app perform NFC sensing to collect the visitor's encrypted digital key; at the same time, the access control terminal collects the visitor's voiceprint biometric information, and the user mobile app collects the visitor's facial image;
[0251] The collected data is uploaded to the cloud control platform to perform intelligent verification of the visitor’s voiceprint, face and key authentication:
[0252] If the verification is successful, a corresponding dynamic instruction packet is generated and sent to the access control terminal where the visitor is currently located to drive the door to open;
[0253] If an abnormality is detected, the Big Data Analysis Center's AI decision engine will make a security linkage decision based on the abnormal event. This decision will be sent to the access control system and an abnormal alarm notification will be sent to the administrator. The Big Data Analysis Center performs AI analysis on the recorded big data consisting of multiple "abnormal events, security linkage decisions" to train and generate the AI decision engine. This engine can identify the feature vectors of abnormal events and output the corresponding security linkage decision.
[0254] When a visitor visits, the present invention adopts the pre-authorization process implementation method:
[0255] 1. Visitor Registration: Visitors submit a photo of their ID card (automatically recognized by OCR) and the reason for their visit through the WeChat Work app. The system then generates a temporary visitor ID and triggers the visitor approval process.
[0256] 2. Temporal and spatial policy configuration: Administrators set access time periods (accurate to the minute), accessible areas (supporting three levels of permissions: building / floor / room), and valid times (single / multiple). The policy is encrypted using the SM4 algorithm and stored on the blockchain node. For example, the temporal and spatial dynamic permission system has the following permission control policy table:
[0257] Permission Dimension Control granularity Example Policy Time Domain millisecond level Weekdays only 917 Spatial Domain Geofencing Within 500 meters Behavioral Domain Action pattern recognition Anti-daunting gestures
[0258] 3. Key Distribution: Using the BB84 quantum key distribution protocol, the key is dynamically updated every 2,000 times per minute, generating a triplet of encrypted digital keys consisting of visitor ID, access control ID, and time window.
[0259] 4. Terminal Configuration: Keys and policies are delivered to the user app via a dual-track encrypted channel (quantum + classical parallel), with end-to-end latency <10ns and support for 72 hours of offline verification (local caching mechanism).
[0260] 5. The dynamic verification process is as follows:
[0261] 1) Proximity trigger: When a visitor approaches the door within 1 meter, Bluetooth 5.1 automatically wakes up the app and NFC begins key exchange (completed within 200ms);
[0262] 2) Multimodal acquisition:
[0263] The access control terminal plays the voice command "Please repeat: 35869204" and simultaneously starts voiceprint collection;
[0264] The mobile app pops up a face collection interface, asking the user to complete a random action command (such as "blink + nod");
[0265] Edge preprocessing: The RK3568 node extracts voiceprint features in real time (delay < 50ms) and completes preliminary face comparison (similarity threshold 85%).
[0266] 3) Cloud-based decision-making performs triple verification:
[0267] Key validity verification (SM4 decryption + time window verification);
[0268] Voiceprint feature matching (256-dimensional vector cosine similarity);
[0269] Facial feature matching (Euclidean distance after 128-dimensional PCA dimensionality reduction).
[0270] The specific verification strategy of the cloud can be configured according to the triple verification content. The present invention can implement an intelligent verification solution based on the AI decision engine deployed in the cloud. The specific AI decision engine training can refer to the following description:
[0271] 1. Data Construction: Collect historical abnormal event records to form a sample library of {event characteristics and handling decisions}, including:
[0272] Biometric forgery (silicone masks, audio recording playback, etc.);
[0273] Key cracking attempts (replay attacks, man-in-the-middle attacks, etc.);
[0274] Illegal trespassing (following, violent destruction, etc.).
[0275] 2. Model training: Using deep reinforcement learning framework:
[0276] State space: Contains 63-dimensional feature vectors (voiceprint confidence, face liveness score, key validity period, etc.);
[0277] Action space: 12 types of disposal measures (alarm level, door lock strategy, monitoring and tracking, etc.);
[0278] Reward function: Based on disposal timeliness and safety loss quantification.
[0279] The specific training program can be referred to as follows:
[0280] 1) Abnormal event feature extraction
[0281] According to the search results, constructing a state space containing a 63-dimensional feature vector requires extracting features from the following dimensions:
[0282] Biometric Dimension:
[0283] Voiceprint confidence (0-1 normalization): 16-dimensional MFCC coefficient + ΔMFCC dynamic feature extraction is used;
[0284] Face liveness score (normalized from 0 to 1): score based on the Retinex illumination compensation algorithm collected by a 3D structured light camera;
[0285] Iris matching degree (0-1 normalized): Euclidean distance after 128-dimensional PCA dimensionality reduction.
[0286] Key security dimensions:
[0287] The remaining percentage of the key validity period (0-1);
[0288] The last key update interval (hours);
[0289] The number of historical abnormal visits (normalized).
[0290] Behavioral Characteristics Dimension:
[0291] Access time deviation (relative to the user's historical pattern Z-score);
[0292] Movement speed abnormality index (normalized value based on multi-frame video analysis);
[0293] Device signal strength fluctuation rate (normalized).
[0294] Feature normalization uses a linear function transformation to ensure that all feature values are in the range of [0, 1].
[0295] 2) Sample library construction method
[0296] Collect historical abnormal event records to form a {event characteristics, handling decision} sample library, which includes three typical scenarios, as shown in the following table:
[0297] Exception Type Feature Examples Sample size requirements Biometric forgery Silicone mask detection confidence and recording voiceprint difference ≥10,000 Key cracking attempts Replay attack frequency and man-in-the-middle attack characteristics ≥8,000 Illegal trespassing Trailing time difference, violent destruction intensity index ≥5,000
[0298] The sample library needs to maintain category balance, and oversampling (SMOTE) is used to process minority class samples.
[0299] 3) PPO algorithm model implementation
[0300] 3.1) Network Architecture Design
[0301] PPO-Clip algorithm framework implemented in PyTorch:
[0302] (Python code example below)
[0303] class PPONet(nn.Module):
[0304] def __init__(self, state_dim=63, action_dim=12):
[0305] super().__init__()
[0306] self.fc1 = nn.Linear(state_dim, 256)
[0307] self.fc2 = nn.Linear(256, 128)
[0308] self.actor = nn.Linear(128, action_dim) # Policy network
[0309] self.critic = nn.Linear(128, 1) # Value network
[0310] def forward(self, x):
[0311] x = F.relu(self.fc1(x))
[0312] x = F.relu(self.fc2(x))
[0313] return torch.softmax(self.actor(x), dim=-1), self.critic(x).
[0314] 3.2) Action Space Encoding
[0315] The 12 treatment measures use the discrete action space One-Hot encoding scheme as shown in the following table:
[0316] Action ID Disposal measures Encoded vector 0 Level 1 alarm + door magnetic lock [1,0,0,...,0] 1 Secondary biometric verification [0,1,0,...,0] ... ... ... 11 Log only [0,...,0,1]
[0317] 4) Reward Function Design
[0318] Quantitative formula based on disposal timeliness and safety loss:
[0319] ,
[0320] in:
[0321] t: response time (seconds), α=0.5 is the attenuation coefficient;
[0322] L: Safety loss = ∑(risk level × duration), Lmax is the maximum possible loss;
[0323] w1,w2: weight coefficients (recommended 0.6, 0.4).
[0324] Risk level quantitative standards:
[0325] Level 1 risk (biometric forgery): loss factor 1.0;
[0326] Secondary risk (key attack): loss coefficient 0.7;
[0327] Level 3 risk (abnormal behavior): loss coefficient 0.3.
[0328] 5) Training optimization strategy
[0329] 5.1) Prioritized experience replay implementation
[0330] Use the Prioritized Experience Replay mechanism (sample code):
[0331] class PrioritizedReplayBuffer:
[0332] def __init__(self, capacity):
[0333] self.capacity = capacity
[0334] self.buffer = []
[0335] self.priorities = np.zeros(capacity)
[0336] self.pos = 0
[0337] def add(self, transition, td_error):
[0338] max_prio = self.priorities.max() if self.buffer else 1.0
[0339] if len(self.buffer) < self.capacity:
[0340] self.buffer.append(transition)
[0341] else:
[0342] self.buffer[self.pos] = transition
[0343] self.priorities[self.pos] = abs(td_error) + 1e-5 # avoid zero priority
[0344] self.pos = (self.pos + 1) % self.capacity.
[0345] 5.2) The training hyperparameter configuration is shown in the following table:
[0346] parameter Recommended value illustrate Learning rate 3e-4 Adam optimizer γ discount factor 0.99 Long-term return discount ϵ clipping range 0.2 PPO-Clip Parameters Batch size 64 Number of samples per batch Update round 10 Number of updates after each sampling Target KL divergence 0.01 Early stopping threshold
[0347] 6) Online learning mechanism, continuous optimization strategy after deployment is as follows:
[0348] Incremental update: daily new data triggers model fine-tuning;
[0349] A / B testing: running new and old strategies in parallel to compare their effectiveness;
[0350] Safe rollback: Automatically roll back when the new policy performance drops by more than 5%.
[0351] Through the above-mentioned AI decision-making, illegal break-in incidents can be reduced and labor costs can be reduced, and intelligent access control decision-making management can be achieved.
[0352] 3. Model Evaluation Metrics
[0353] The model can be evaluated using the AOC curve and F1 evaluation method. Specifically, the user constructs a test set and inputs it into the model to verify the model performance.
[0354] 4. The hierarchical response strategy is shown in the following table:
[0355] Abnormal Level Feature combination Joint measures Response time Level 1 (high risk) Invalid key + biometric mismatch Door magnetic lock + 110 automatic alarm + drone tracking <3s Level 2 (medium risk) Single modal verification failed Secondary verification + security on-site confirmation <30s Level 3 (low risk) Space-time policy violations Voice alert + administrator notification <1min
[0356] The AI engine outputs the threat level of abnormal events. Please refer to the following adaptive security architecture table.
[0357] As shown:
[0358] Threat Level Response measures Low-level Basic password authentication intermediate Biometrics + device binding advanced Multi-factor authentication + behavioral analysis critical Physical fuse isolation + public security linkage
[0359] In addition to deploying AI in the cloud, you can also configure the following emergency mechanisms to prevent network outages:
[0360] Edge intelligent decision-making: The local AI model (simplified BERT) of the access control terminal makes real-time decisions;
[0361] Offline instruction cache: encrypted storage of valid instructions from the last 30 days;
[0362] Mesh emergency network: access control terminal self-organizing network communication (LoRaMesh).
[0363] It can also be linked intelligently over time: access control events trigger smart home scenarios (such as automatically turning on lights when opening the door), elevator control system linkage (calling the elevator to a designated floor), automatic verification of health code status in epidemic mode, and other functions.
[0364] Therefore, by adopting the above solution, the present invention has the following technical advantages:
[0365] Improved efficiency: After deployment at a technology park, morning peak traffic volume increased from 120 people / minute to 350 people / minute, and queue times were reduced by 82%.
[0366] Cost Optimization: Property management manpower reduced by 60%, and annual maintenance costs reduced by 45% (no card consumables);
[0367] Security enhancement: 100% anti-tailing (3DToF real-time depth detection) and resistance to quantum computing attacks (BB84 protocol).
[0368] On the other hand, a door access management method based on remote APP control management is provided, and the steps of the door access management method based on remote APP control management are implemented based on the above-mentioned door access management system based on remote APP control management.
[0369] For the specific implementation steps, please understand and implement them in conjunction with the interaction principles of the previous system. I will not go into details here.
[0370] Figure 4 is a structural diagram of an electronic device provided by an embodiment of the present invention, such as Figure 4 As shown, the electronic device 410 may include a first processor 2001 .
[0371] Optionally, the electronic device 410 may further include a memory 2002 and a transceiver 2003 .
[0372] The first processor 2001, the memory 2002 and the transceiver 2003 may be connected via a communication bus.
[0373] The following combination Figure 4 The components of the electronic device 410 are described in detail.
[0374] The first processor 2001 is the control center of the electronic device 410 and can be a single processor or a collective term for multiple processing elements. For example, the first processor 2001 can be one or more central processing units (CPUs), an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement embodiments of the present invention, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).
[0375] Optionally, the first processor 2001 can execute various functions of the electronic device 410 by running or executing software programs stored in the memory 2002 and calling data stored in the memory 2002.
[0376] In a specific implementation, as an embodiment, the first processor 2001 may include one or more CPUs, such as Figure 4 CPU0 and CPU1 are shown in FIG.
[0377] In a specific implementation, as an embodiment, the electronic device 410 may also include multiple processors, such as Figure 4 1 and 2. The first processor 2001 and the second processor 2004 are shown in FIG. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0378] The memory 2002 is used to store the software program for executing the solution of the present invention, and is controlled by the first processor 2001 for execution. The specific implementation method can refer to the above method embodiment and will not be repeated here.
[0379] Alternatively, the memory 2002 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 2002 may be integrated with the first processor 2001 or exist independently and accessed through the interface circuit ( Figure 4 (not shown) is coupled to the first processor 2001, which is not specifically limited in this embodiment of the present invention.
[0380] The transceiver 2003 is used to communicate with a network device or a terminal device.
[0381] Optionally, the transceiver 2003 may include a receiver and a transmitter ( Figure 4The receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.
[0382] Optionally, the transceiver 2003 may be integrated with the first processor 2001, or may exist independently and communicate with the first processor 2001 through the interface circuit ( Figure 4 (not shown) is coupled to the first processor 2001, which is not specifically limited in this embodiment of the present invention.
[0383] It should be noted that Figure 4 The structure of the electronic device 410 shown in the figure does not constitute a limitation on the router. The actual knowledge structure recognition device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0384] In addition, the technical effects of the electronic device 410 can refer to the technical effects of the access control management method based on remote APP control management described in the above method embodiment, and will not be repeated here.
[0385] It should be understood that the first processor 2001 in the embodiment of the present invention may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc.
[0386] It should also be understood that the memory in the embodiments of the present invention may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory may be random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0387] The above embodiments can be implemented in whole or in part via software, hardware (e.g., circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product comprises one or more computer instructions or computer programs. When loaded or executed on a computer, the processes or functions described in accordance with the embodiments of the present invention are fully or partially performed. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable system. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired means (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.
[0388] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.
[0389] In this disclosure, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.
[0390] It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0391] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.
[0392] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described devices, systems and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0393] In the several embodiments provided by the present invention, it should be understood that the disclosed devices, systems, and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of the system or unit, which can be electrical, mechanical or other forms.
[0394] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0395] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0396] If the functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or the portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage media include various media that can store program code, such as USB flash drives, mobile hard drives, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical disks.
[0397] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.
Claims
1. A door access management system based on remote APP control management, characterized in that: The system comprises: The user's mobile app is used by visitors to log in to the cloud control platform and issue a door opening request, wherein the request contains encrypted door opening information with a time and space stamp: encrypted digital key, access control terminal ID and user basic information; The cloud control platform is used to check and verify the visitor's access control door opening request. If the verification is passed, a corresponding dynamic instruction packet is generated and sent to the access control terminal where the visitor is currently located; The access control terminal is used to receive and respond to the dynamic instruction packet, and the access control system controls the physical door lock device to open and feedback the access control status to the cloud control platform, which records the access control status and pushes it to the user's mobile app; The user mobile APP and the access control terminal are respectively connected to the cloud control platform for communication.
2. The access control management system based on remote APP control management according to claim 1 is characterized in that: The access control terminal includes: Access control systems; A physical door lock device, used to implement the lock control service of the access control terminal through an electronic lock; IoT sensor network, providing multimodal communication units (4G / 5G / NBIoT / LoRa) to support communication services between the access control terminal and the cloud control platform; as well as, A biometric recognition module, configured to collect the visitor's voiceprint biometric information and feed it back to the access control system, which then synchronizes the voiceprint biometric information to the cloud control platform; The biometric recognition module and the physical door lock device are electrically connected to the access control system respectively.
3. The access control management system based on remote APP control management according to claim 2 is characterized in that: The user mobile APP is also used to: Collect the visitor's facial image and feed it back to the cloud control platform.
4. The access control management system based on remote APP control management according to claim 3 is characterized in that: The cloud control platform is also used to: Upon receiving the access control door opening request from the visitor, a first sampling notification for collecting the visitor's voiceprint biometric information is sent to the access control terminal, and a second sampling notification for collecting the visitor's facial image and the encrypted digital key is sent to the user's mobile APP; Receive visitor information fed back by the access control terminal and the user mobile AP, and perform voiceprint, face and key authentication on the visitor based on the user big data and encryption algorithm pre-stored in the cloud database: If the authentication is successful, the corresponding dynamic instruction packet is generated and transmitted to the access control terminal through quantum encryption; Otherwise, authentication registration is performed based on the visitor's voiceprint biometric information and facial image and the encrypted digital key is reconfigured. After successful registration, the corresponding dynamic instruction packet is generated and transmitted to the access control terminal through quantum encryption.
5. The access control management system based on remote APP control management according to claim 1 is characterized in that: The cloud control platform is further used to: implement three-dimensional visual control of each access control terminal in the access control terminal cluster based on digital twin technology through a digital twin system provided by a third party; and, when a visitor's voiceprint and face authentication are successful, perform status verification on the digital twin model of the access control terminal where the visitor is currently located through the digital twin system. After verification, push the three-dimensional visual control interface of the access control terminal where the visitor is currently located to the user's mobile app; The user mobile app is further configured to: operate the three-dimensional visual control interface of the access control terminal; and, after a visitor clicks on the digital twin model of the electronic lock in the interface, send a selection message corresponding to the electronic lock to the cloud control platform, and simultaneously upload the visitor's encrypted digital key and basic user information; The cloud control platform is also used to: The selection information of the electronic lock entered by the visitor is forwarded to the digital twin system, and the digital twin system generates the corresponding access control door opening request based on the selection information of the electronic lock (including the access control terminal ID) and sends it to the cloud control platform.
6. The access control management system based on remote APP control management according to claim 1 is characterized in that: The cloud control platform is also used to: When a visitor logs in through the user's mobile app, the pre-authorization process is initiated for the visitor: Create a visitor pass for the user's mobile app; According to the visitor's basic user information, a corresponding time-space strategy is set for the visitor and the visitor's encrypted digital key is generated based on an encryption algorithm, and the time-space strategy and the encrypted digital key are configured to the visitor's user mobile app; When a visitor visits, the access control terminal where the visitor is currently located and the visitor's user mobile app perform NFC sensing to collect the visitor's encrypted digital key; at the same time, the access control terminal collects the visitor's voiceprint biometric information, and the user mobile app collects the visitor's facial image; The collected data is uploaded to the cloud control platform to perform intelligent verification of the visitor’s voiceprint, face and key authentication: If the verification is successful, a corresponding dynamic instruction packet is generated and sent to the access control terminal where the visitor is currently located to drive the door to open; If an abnormality is verified, a security linkage decision will be made for the abnormal event based on the AI decision engine of the big data analysis center, and the decision will be sent to the access control system and the abnormal alarm notification will be pushed to the administrator.
7. The access control management system based on remote APP control management according to claim 6 is characterized in that: The big data analysis center performs AI analysis on the recorded big data consisting of several {abnormal events, security linkage decisions}, trains and generates the AI decision engine, so that the AI decision engine can identify the feature vectors of abnormal events and output corresponding security linkage decisions.
8. A door access management method based on remote APP control management, characterized in that: The steps of the access control and access management method based on remote APP control and management are implemented based on the access control and access management system based on remote APP control and management as described in any one of claims 1-7.
9. An electronic device, characterized in that: The electronic device comprises: processor; A memory having computer-readable instructions stored thereon, wherein when the computer-readable instructions are executed by the processor, the method according to claim 8 is implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program code, which can be called by a processor to execute the method according to claim 8.
Citation Information
Cited By
Internet of Things platform equipment remote management system and access control management method
CN121075019A
Intelligent elevator reservation method
CN121626781A