Pass authority management system and method
By adopting an access authority management system in nuclear power facilities, using encrypted cards for contactless transmission between physically isolated areas, and automating the management of access authorities, the problems of low efficiency and high error rate in access authority management in nuclear power facilities have been solved, and safe and efficient access authority management has been achieved.
Patent Information
- Application Number
- CN202510774135.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-06-10
AI Technical Summary
In the existing technology, the access authority management of different security level areas in nuclear power facilities is inefficient and has a high error rate. In addition, manual management is unsafe and inefficient.
The access authority management system is adopted, through information collection, management approval, contactless transmission and access authority decision-making subsystems, using encrypted cards to transmit data between physically isolated areas, automatically managing access authorities and ensuring information security.
It improves the efficiency of access authority management, reduces the error rate, ensures the security and accuracy of data transmission, simplifies the processing procedures, and saves human resources.
Smart Images

Figure CN120672286A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the fields of security technology and nuclear power technology, and more particularly to an access authority management system and method. Background Art
[0002] In the fields of nuclear power facilities, nuclear power production, and nuclear power material processing, according to safety principles, multiple areas with different security levels need to be demarcated, and physically connected data channels are not allowed between multiple areas, that is, multiple areas with different security levels are physically isolated.
[0003] In actual business operations, to ensure the safe operation of each area, access to and from these areas must be strictly controlled. Existing technologies manually manage access to and from these areas, resulting in low efficiency and high error rates. Summary of the Invention
[0004] In view of the above problems, the present disclosure provides a system and method for managing access rights.
[0005] According to a first aspect of the present disclosure, a pass authorization management system is provided, comprising: an information collection subsystem for collecting basic pass information of an object corresponding to a first area for which pass authorization is to be processed; a management and approval subsystem for approving the pass authorization of the object based on the basic pass information and generating an approval result; a contactless transmission subsystem comprising: a first data transmission module for encoding the approval result to obtain target transmission data, and storing the target transmission data in an encryption card included in the first data transmission module; a second data transmission module for reading the target transmission data from the encryption card and parsing the target transmission data to obtain target pass authorization information; and a pass authorization decision subsystem, disposed in a second area, for issuing pass authorization information to an access control system corresponding to the object based on the target pass authorization information, simultaneously updating pass verification information corresponding to the object, and sending the updated pass verification information to a card production peripheral. The first area and the second area are physically isolated, the security level of the second area is higher than that of the first area, and the card production peripheral represents a device for producing and updating pass cards corresponding to the object.
[0006] According to an embodiment of the present disclosure, the above-mentioned first data transmission module includes: an information generation module, which is used to encode the above-mentioned approval results according to predetermined coding rules to generate specific coding format data; an encryption module, which is used to encrypt the above-mentioned specific coding format data according to a predetermined encryption algorithm to obtain target transmission data; and a card writer, which is used to write the above-mentioned target transmission data into the above-mentioned encryption card.
[0007] According to an embodiment of the present disclosure, the above-mentioned second data transmission module includes: a card reader for reading the above-mentioned target transmission data from the above-mentioned encryption card; an information parsing module for parsing the above-mentioned target transmission data to obtain the above-mentioned approval result; a mapping module for mapping the access area information included in the above-mentioned approval result into access control device information corresponding to the access area, and obtaining the above-mentioned target access authority information based on the above-mentioned access control device information and the above-mentioned approval result.
[0008] According to an embodiment of the present disclosure, the contactless transmission subsystem further includes: a driving module, configured to move the encryption card between the first data transmission module and the second data transmission module.
[0009] According to an embodiment of the present disclosure, the above-mentioned management and approval subsystem includes: an authority allocation module, which is used to send the above-mentioned basic access information to the first review end based on the above-mentioned basic access information, and set the access rights of the above-mentioned object and the access rights of the accompanying objects of the above-mentioned object in response to the above-mentioned first review end, and generate an authority allocation result corresponding to the above-mentioned object; an approval module, which is used to send the above-mentioned authority allocation result to the second review end in response to the above-mentioned first review end clicking on the review operation, and generate an approval result in response to the above-mentioned second review end clicking on the confirmation operation based on the above-mentioned authority allocation result.
[0010] According to an embodiment of the present disclosure, the format of the above-mentioned basic access information includes at least one of the following: text, image and table; the above-mentioned basic access information includes: object attribute information, attribute information of the initial review object corresponding to the above-mentioned object and access requirement information of the above-mentioned object.
[0011] According to an embodiment of the present disclosure, the above-mentioned access authority decision subsystem includes: an access authority decision interface module, which is used to receive the above-mentioned target access authority information, and according to the access control device information included in the above-mentioned target access authority information, issue access authorization information to the access control system corresponding to the access control device.
[0012] According to an embodiment of the present disclosure, the information collection subsystem includes: an identification and analysis module, which is used to analyze and verify the initial basic access information corresponding to the object to obtain the basic access information.
[0013] According to an embodiment of the present disclosure, the management and approval subsystem further includes: an information management module for displaying basic access information; and a storage module for storing the approval results and approval process information.
[0014] The second aspect of the present disclosure provides a method for managing access rights, including: collecting basic access information of an object to be processed for access rights corresponding to a first area; approving the access rights of the object based on the basic access information and generating an approval result; encoding the approval result to obtain target transmission data, and storing the target transmission data in an included encryption card; reading the target transmission data from the encryption card, and parsing the target transmission data to obtain target access rights information; in the second area, based on the target access rights information, issuing access authorization information to the access control system corresponding to the object, and updating the access verification information corresponding to the object, and sending the updated access verification information to a card production peripheral, wherein the first area and the second area are physically isolated, the security level of the second area is greater than that of the first area, and the card production peripheral represents a device for producing and updating pass cards corresponding to the object.
[0015] According to an embodiment of the present disclosure, access permission approval is automatically performed in the first area of two physically isolated areas, and the target transmission data including the approval result corresponding to the object is contactlessly transmitted from the first area to the second area using an encryption card. During the contactless transmission, compared with the QR code ferry method, the information is transmitted using an encryption card, which further ensures the security of the transmitted information. In the second area, access authorization information is automatically issued to the access control system corresponding to the object based on the target transmission data, and the access verification information corresponding to the object is updated at the same time, and the updated access verification information is sent to the card production peripheral, so that the object can subsequently obtain the updated pass card according to the card production peripheral, and pass through the relevant access control equipment according to the updated pass card. Compared with manual access permission management between two physically isolated areas, the access permission management efficiency can be greatly improved and the error rate can be reduced while ensuring the security of data transmission between the two physically isolated areas. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] The above contents and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:
[0017] Figure 1 A schematic diagram of a traffic authorization management system according to an embodiment of the present disclosure is schematically shown;
[0018] Figure 2 Schematic diagrams of access authorization management systems according to other embodiments of the present disclosure are schematically shown;
[0019] Figure 3 A schematic diagram schematically illustrates an access authorization management system according to other embodiments of the present disclosure; and
[0020] Figure 4 The flowchart of the access authority management method according to the embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION
[0021] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.
[0022] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise," "include," etc. used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0023] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0024] When expressions such as "at least one of A, B, and C, etc." are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).
[0025] In the technical solutions of the embodiments of the present disclosure, the user information (including but not limited to user personal information, user image information, user device information, such as location information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved are all information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with relevant laws, regulations and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0026] Within nuclear power facilities, nuclear power production, and nuclear power material processing, the varying security levels of multiple areas necessitate the decentralized management of access rights for personnel and vehicles entering and exiting these areas. To ensure the safe and normal operation of each area, frequent and rapid access management is required to create, adjust, and cancel access rights for personnel or vehicles in different areas. This technology, which relies on manual operations on separate systems within isolated control areas, relies on paper documents and manual comparisons between screens across different systems to complete information transmission and translation. This is neither secure nor efficient, and is prone to errors.
[0027] When a large number of people need to create, adjust, or cancel access permissions, it requires significant effort and inefficiency. Furthermore, agents must travel to various locations multiple times to complete operations like facial image binding. Consequently, existing manual access permission management is inefficient, leading to long wait times for people and vehicles entering and exiting, and a large number of personnel are required to complete the process. Furthermore, when there are many people involved and access permissions are applied to multiple areas, the error rate is high, hindering business operations.
[0028] In order to at least partially solve the technical problems existing in the related art, the present disclosure provides an access authority management system and method, which can be applied to the fields of security technology and nuclear power technology.
[0029] Figure 1 A schematic diagram of a traffic authorization management system according to an embodiment of the present disclosure is schematically shown.
[0030] like Figure 1 As shown, the access authorization management system 100 may include an information collection subsystem 110 , a management and approval subsystem 120 , a contactless transmission subsystem 130 , and an access authorization decision subsystem 140 .
[0031] The information collection subsystem 110 may be used to collect basic access information of objects corresponding to the first area for which access permission is to be processed.
[0032] According to an embodiment of the present disclosure, the first area may be a management area in a nuclear power plant.
[0033] According to an embodiment of the present disclosure, the object may be a person or a vehicle, etc.
[0034] According to an embodiment of the present disclosure, when the object is a person, the basic access information corresponding to the person may include: basic information, picture information, docking contact information, etc.
[0035] For example, if the object is a person, the basic access information corresponding to the person may include: name, ID number, phone number, name and phone number of the corresponding reviewer, contact department, access area name, and information of accompanying persons, etc. If the object is a car, the basic access information corresponding to the car may include: license plate number.
[0036] The management and approval subsystem 120 can be used to approve the access rights of objects based on basic access information and generate an approval result.
[0037] For example, after receiving basic access information, the management approval subsystem 120 can allocate access rights to the object based on the docking department and contact personnel included in the basic access information, and complete the approval of access rights according to the preset approval flow, and then generate an approval result.
[0038] The contactless transmission subsystem 130 may include a first data transmission module 131 and a second data transmission module 132 .
[0039] The first data transmission module 131 can be used to encode the approval result to obtain target transmission data, and store the target transmission data in the encryption card 1311 included in the first data transmission module 131 .
[0040] According to the embodiments of the present disclosure, the method for encoding the approval result can be selected according to actual conditions and is not limited here.
[0041] For example, the approval result can be encoded in a QR code and then encrypted to obtain the target transmission data. Alternatively, the approval result can be character-encoded and then encrypted to obtain the target transmission data. Encryption can be performed using a national secret algorithm or an asymmetric encryption algorithm.
[0042] According to embodiments of the present disclosure, encryption card 1311 may be any physical medium capable of storing data. The encryption card 1311 may be selected based on practical circumstances and is not limited herein. For example, encryption card 1311 may include any of the following: an IC card, an RFID card, a Bluetooth card, and the like.
[0043] The second data transmission module 132 can be used to read target transmission data from the encryption card 1311 and parse the target transmission data to obtain target access authority information.
[0044] According to the embodiments of the present disclosure, target transmission data may be decoded and mapped to obtain target access authority information.
[0045] According to an embodiment of the present disclosure, the contactless transmission subsystem 130 may include a first data transmission module 131 and a second data transmission module 132, which can realize the one-way transmission of information collected by the management and approval subsystem 120 to the access authority decision subsystem 140 in a contactless manner, without relying on any physical network or hardware signal, supporting data encryption transmission and dynamic key management, and ensuring the secure and accurate transmission of data.
[0046] The access authority decision subsystem 140 is set in the second area and can be used to issue access authorization information to the access control system corresponding to the object based on the target access authority information, and at the same time update the access verification information corresponding to the object, and send the updated access verification information to the card production peripheral. Among them, the first area and the second area are physically isolated, the security level of the second area is greater than that of the first area, and the card production peripheral represents a device for producing and updating the pass card corresponding to the object.
[0047] According to an embodiment of the present disclosure, after the access authority decision subsystem 140 sends the updated access verification information to the card production peripheral, the subject can obtain an updated pass card or a newly produced pass card from the card production peripheral, thereby automatically producing and updating the pass card. Because the access authority decision subsystem 140 can issue access authorization information to the access control system corresponding to the subject based on the target access authority information, the creation and adjustment of access authority information can be automatically achieved, allowing the subject to access the access control device corresponding to the access control system based on the automatically updated pass card.
[0048] According to an embodiment of the present disclosure, the second area may be a protected area of a nuclear power plant.
[0049] According to an embodiment of the present disclosure, the access authority decision subsystem 140 is physically connected to the second data transmission module 132. To ensure data security in the access authority decision subsystem 140, the second data transmission module 132 can only transmit data to the access authority decision subsystem 140 in one direction.
[0050] According to an embodiment of the present disclosure, when the access authority decision subsystem 140 issues access authorization information to the access control system corresponding to the object based on the target access authority information, the issuing method may include transmission through a network interface or importing a format file.
[0051] According to an embodiment of the present disclosure, access permission approval is automatically performed in the first area of two physically isolated areas, and the target transmission data including the approval result corresponding to the object is contactlessly transmitted from the first area to the second area using an encryption card. During the contactless transmission, compared with the QR code ferry method, the information is transmitted using an encryption card, which further ensures the security of the transmitted information. In the second area, access authorization information is automatically issued to the access control system corresponding to the object based on the target transmission data, and the access verification information corresponding to the object is updated at the same time, and the updated access verification information is sent to the card production peripheral, so that the object can subsequently obtain the updated pass card according to the card production peripheral, and pass through the relevant access control equipment according to the updated pass card. Compared with manual access permission management between two physically isolated areas, the access permission management efficiency can be greatly improved and the error rate can be reduced while ensuring the security of data transmission between the two physically isolated areas.
[0052] According to the embodiments of the present disclosure, the access authorization management system provided by the embodiments of the present disclosure includes an information collection subsystem, a management and approval subsystem, a contactless transmission subsystem, and an access authorization decision-making subsystem. Through the coordinated cooperation between subsystems located in multiple separate or isolated areas, it can realize the collection of basic access information, the allocation, approval, contactless transmission, and automatic generation, update, and issuance of access authorization information. This solves the efficiency, accuracy, and security issues of generating access authorization information for batches of personnel, frequent adjustments to access authorization information, and the distribution of access authorization information across multiple areas, thereby saving human resources, shortening processing time, and simplifying the processing process. At the same time, it meets the requirements of cross-regional physical isolation and data confidentiality.
[0053] Figure 2 A schematic diagram of a pass authorization management system according to some other embodiments of the present disclosure is schematically shown.
[0054] like Figure 2 As shown, the access authority management system 200 may include an information collection subsystem 210, a management and approval subsystem 220, a contactless transmission subsystem 230, and an access authority decision subsystem 240. Figure 2 The information collection subsystem 210, the management and approval subsystem 220, the contactless transmission subsystem 230 and the access authority decision subsystem 240 are respectively Figure 1 The information collection subsystem 110, management and approval subsystem 120, contactless transmission subsystem 130 and access authority decision subsystem 140 are similar and will not be described here for brevity.
[0055] exist Figure 2 In the example, the information collection subsystem 210 may include an identification and analysis module 211 .
[0056] The identification and analysis module 211 may be used to analyze and verify the initial basic access information corresponding to the object to obtain the basic access information.
[0057] According to an embodiment of the present disclosure, the format of the basic access information includes at least one of the following: text, image, and table. The basic access information includes: object attribute information, attribute information of the initial review object corresponding to the object, and access requirement information of the object.
[0058] According to embodiments of the present disclosure, object attribute information may include: name, ID number, phone number, license plate number of the accompanying vehicle, data of the accompanying person, and the name, phone number, and ID number of the accompanying person. Attribute information for the initial review subject corresponding to the object may include: name, phone number, and corresponding department of the initial review subject. Access requirement information for the object may include: name of the access area.
[0059] For example, the information collection subsystem 210 can collect identity information, facial information, and license plate information in image format. It can also collect text-based information such as name, phone number, license plate number, access zone name, reviewer name, phone number, and contact department. It can also collect initial basic access information related to multiple people in table format.
[0060] For example, the recognition and parsing module 211 can parse information in text format, image format, and table format to obtain the parsed basic access information corresponding to each object, and then verify the parsed basic access information corresponding to each object to obtain the basic access information.
[0061] For example, the parsed basic access information corresponding to each object can be checked for special characters and information length. For example, the name corresponding to the object can be checked to be greater than or equal to 2 and less than or equal to 4 characters, and the ID number corresponding to the object can contain no special characters.
[0062] According to an embodiment of the present disclosure, the identification and parsing module 211 parses and verifies the initial basic access information corresponding to the object, and can perform integrity verification on the initial basic access information to obtain basic access information.
[0063] exist Figure 2 In the example, the management and approval subsystem 220 may include an information management module 221 , a permission allocation module 222 , an approval module 223 and a storage module 224 .
[0064] The information management module 221 can be used to display basic traffic information.
[0065] According to an embodiment of the present disclosure, the information management module 221 can display the basic access information of the object in the foreground, so that the basic access information corresponding to each object can be centrally managed and viewed using the information management module 221.
[0066] The authority allocation module 222 can be used to send basic access information to the first audit end based on the basic access information, and in response to the first audit end, set the access authority of the object and the access authority of the accompanying object to generate an authority allocation result corresponding to the object.
[0067] According to the embodiment of the present disclosure, the accompanying object can be set for the accompanying person and accompanying vehicle information.
[0068] According to an embodiment of the present disclosure, the permission allocation module 222 can determine the initial review subject and the corresponding docking department based on basic access information, and send the basic access information to the first review terminal where the initial review subject resides. Based on the basic access information, the initial review subject can set access permissions for the subject, accompanying person information, and accompanying vehicle information at the first review terminal. Then, in response to the first review terminal setting access permissions for the subject and the accompanying persons, the permission allocation module 222 generates a permission allocation result corresponding to the subject.
[0069] The approval module 223 can be used to send the authority allocation result to the second review end in response to the first review end clicking the review operation, and generate the approval result in response to the second review end clicking the confirmation operation based on the authority allocation result.
[0070] According to an embodiment of the present disclosure, after the initial review object clicks to issue the review operation at the first review end, the approval module 223 can push the authority allocation result to each approval node (the approval end where the review object with a higher level than the initial review object is located) according to the preset approval flow to complete the approval work and generate the approval result.
[0071] According to an embodiment of the present disclosure, the approval module 223 can approve the access permission information according to different access permissions (i.e., different permission allocation results) according to different preset approval flows, and associate and bind the final approval result and approval node information with the access permission information.
[0072] According to an embodiment of the present disclosure, the first review end and the second review end may be a mobile APP end or a web page end.
[0073] According to an embodiment of the present disclosure, the approval result may include basic access information and assigned authority information.
[0074] The storage module 224 can be used to store approval results and approval process information.
[0075] According to an embodiment of the present disclosure, the storage module 224 can implement local storage of basic access information, assigned authority information, and approval process information.
[0076] exist Figure 2 In the embodiment, the first data transmission module 231 may include an encryption card 2311 , an information generation module 2312 , an encryption module 2313 and a card writer 2314 .
[0077] According to an embodiment of the present disclosure, Figure 2 The encryption card 2311 in Figure 1 The encryption card 1311 is similar to that in FIG. 1 , and for the sake of simplicity, it will not be described here.
[0078] The information generation module 2312 can be used to encode the approval results according to predetermined encoding rules to generate data in a specific encoding format.
[0079] According to the embodiments of the present disclosure, the predetermined encoding rule can be selected according to actual conditions and is not limited here. For example, the predetermined encoding rule can be a QR code encoding rule or a rule for generating a text symbol combination image.
[0080] The encryption module 2313 can be used to encrypt data in a specific encoding format according to a predetermined encryption algorithm to obtain target transmission data.
[0081] According to the embodiments of the present disclosure, the predetermined encryption algorithm can be selected according to actual conditions and is not limited here. For example, the predetermined encryption algorithm can be a national secret algorithm or an asymmetric encryption algorithm.
[0082] According to an embodiment of the present disclosure, the information generation module 2312 encodes the approval result according to predetermined coding rules to generate specific coding format data, and the encryption module 2313 encrypts the specific coding format data according to a predetermined encryption algorithm to obtain the target transmission data, thereby realizing secondary encryption of the approval result to ensure the security of the transmission of the data included in the approval result.
[0083] The card writer 2314 can be used to write target transmission data into the encryption card 2311.
[0084] According to an embodiment of the present disclosure, the card writer 2314 can write the encrypted target transmission data into the encryption card 2311 in a contactless manner.
[0085] According to an embodiment of the present disclosure, the encryption card 2311 can be used to carry the encoded target transmission data and transmit the target transmission data between two areas in a contactless manner.
[0086] exist Figure 2 In the embodiment, the second data transmission module 232 may include a card reader 2321 , an information parsing module 2322 and a mapping module 2323 .
[0087] The card reader 232 can be used to read target transmission data from the encryption card.
[0088] According to an embodiment of the present disclosure, the target transmission data is written into the encryption card 2311 using the card writer 2314, and then the target transmission data is read from the encryption card 2311 using the card reader 2321, so that the target transmission data is transmitted from the first data transmission module 231 to the second data transmission module 232 in a contactless manner using the encryption card 2311. Compared with the transmission of the target transmission data by the QR code ferry method, the target transmission data will not be leaked due to image capture by other external devices, and the data transmission is safer.
[0089] The information parsing module 2322 can be used to parse the target transmission data to obtain the approval result.
[0090] For example, when encryption module 2313 uses a dynamic key to encrypt data in a specific encoding format to obtain the target transmission data, card writer 2314 can be used to write the dynamic key into encryption card 2311. Card reader 232 reads the target transmission data and dynamic key from encryption card 2311, and information parsing module 2322 decrypts and decodes the target transmission data using the dynamic key to obtain the approval result.
[0091] According to an embodiment of the present disclosure, the information parsing module 2322 parses the target transmission data, thereby restoring the target transmission data in a specific encoding format and obtaining an approval result.
[0092] The mapping module 2323 can be used to map the access area information included in the approval result into the access control device information corresponding to the access area, and obtain the target access permission information according to the access control device information and the approval result.
[0093] exist Figure 2 In the embodiment, the contactless transmission subsystem 230 may further include a driving module 233 .
[0094] The driving module 233 may be used to move the encryption card 2311 between the first data transmission module 231 and the second data transmission module 232 .
[0095] According to an embodiment of the present disclosure, the driving module 233 can drive the encryption card 2311 to move, circulate between the card writer 2314 and the card reader 2321, and complete the data transmission process.
[0096] According to an embodiment of the present disclosure, the driving module 233 can drive the encryption card 2311 to move between the first data transmission module 231 and the second data transmission module 232 to achieve contactless data transmission between the first data transmission module 231 and the second data transmission module 232.
[0097] According to an embodiment of the present disclosure, the driving module 233 may include an umbrella-shaped structure and a transmission mechanism, which may fix multiple encryption cards 2311 at different positions on the umbrella edge of the umbrella-shaped structure. The umbrella-shaped structure may be connected to the transmission structure, and the transmission structure may drive the umbrella-shaped structure to rotate, so as to rotate each encryption card 2311 fixed to the umbrella-shaped structure from one side of the first data transmission module 231 (or card writer 2314) and the second data transmission module 232 (or card reader 2321) to the other side.
[0098] exist Figure 2 In the example, the access authority decision subsystem 240 may include an access authority decision interface module 241 .
[0099] The access authority decision interface module 241 may be configured to receive target access authority information and, based on access control device information included in the target access authority information, issue access authorization information to the access control system 201 corresponding to the access control device.
[0100] According to an embodiment of the present disclosure, the access authority decision interface module 241 can receive target access authority information according to the interface protocol, and issue access authorization information to the access control system 201 corresponding to the access control device based on the access control device information included in the target access authority information, thereby automatically realizing the creation and adjustment of access authority information.
[0101] Figure 3 A schematic diagram of a pass authorization management system according to some other embodiments of the present disclosure is schematically shown.
[0102] like Figure 3 As shown, the access authorization management system 300 may include an information collection subsystem 310 , a management and approval subsystem 320 , a contactless transmission subsystem 330 , and an access authorization decision subsystem 340 .
[0103] The information collection subsystem 310 may include an identification and analysis module 311, an input module 312, and a first interface module 313. Figure 3 The recognition and analysis module 311 in Figure 2 The identification and analysis module 211 in is similar and will not be described here for simplicity.
[0104] The entry module 312 can be used to enter the initial basic access information required for access authority management, and supports the entry and submission of information in the form of text, images, and table attachments.
[0105] The entry module 312 can provide an information entry interface to record the initial basic access information of the object in writing, or communicate with mini-programs, mobile apps, automatic terminals, web pages, etc. to obtain the initial basic access information of the object.
[0106] The first interface module 313 can be used to transmit the collected basic traffic information to the outside through the interface protocol, and supports data encryption transmission.
[0107] The management and approval subsystem 320 may include an information management module 321, a rights allocation module 322, an approval module 323, a storage module 324 and a second interface module 325. Figure 3 The information management module 321, the authority allocation module 322, the approval module 323 and the storage module 324 are respectively Figure 2 The information management module 221, authority allocation module 222, approval module 223 and storage module 224 are similar and will not be described again for simplicity.
[0108] The second interface module 325 can be used to perform data connection with the information collection subsystem 310, the contactless transmission subsystem 330 and other external management systems, such as the Peixin / OA system 303, through an interface protocol.
[0109] For example, the second interface module 325 can obtain basic access information from the first interface module 313 through the interface protocol, send the permission allocation result corresponding to the object to the second review end for review, and send the approval result to the first data transmission module 331 for encoding and encryption processing.
[0110] The contactless transmission subsystem 330 may include a first data transmission module 331, a second data transmission module 332, and a driver module 333. The first data transmission module 331 may include an encryption card 3311, an information generation module 3312, an encryption module 3313, a card writer 3314, and a third interface module 3315. The second data transmission module 332 may include a card reader 3321, an information parsing module 3322, a mapping module 3323, and a fourth interface module 3324.
[0111] in, Figure 3 The middle drive module 333 and Figure 2 Similar to the driver module 233 in, Figure 3 The encryption card 3311, information generation module 3312, encryption module 3313 and card writer 3314 are respectively Figure 2 The encryption card 2311, information generation module 2312, encryption module 2313 and card writer 2314 are similar. Figure 3The card reader 3321, the information parsing module 3322, the mapping module 3323 and the fourth interface module 3324 are respectively connected to Figure 2 The card reader 2321, information parsing module 2322, mapping module 2323 and fourth interface module 2324 are similar and will not be described again for the sake of brevity.
[0112] The third interface module 3315 can be used to realize data transmission and key transmission with the management approval subsystem 320, and the fourth interface module 3324 can be used to realize data transmission and key transmission with the access authority decision subsystem 340. The fourth interface module 3324 and the access authority decision interface module 341 included in the access authority decision subsystem 340 are physically connected.
[0113] For example, the third interface module 3315 can receive the approval result sent by the second interface module 325. In the case of data encryption transmission between the second data transmission module 332 and the access authority decision subsystem 340, the fourth interface module 3324 can transmit the data and encryption key to the access authority decision subsystem 340.
[0114] The access authority decision subsystem 340 may include an access authority decision interface module 341, a card management module 342, a card authority information storage module 343, and a certificate production module 344. Figure 3 The access authority decision interface module 341 and Figure 2 The access authority decision interface module 241 is similar to that in FIG. 2 and will not be described here for simplicity.
[0115] The card management module 342 may be used to associate and bind target access permission information with the object's access card and manage the bound information.
[0116] The card authority information storage module 343 can be used to store pass card information and target pass authority information.
[0117] The card making module 344 can be used to send the updated pass verification information to the card making peripheral device 302, so that the card making peripheral device 302 can realize the pass card making, update and writing functions.
[0118] Based on the above-mentioned access authority management system, an embodiment of the present disclosure further provides an access authority management method.
[0119] Figure 4 The flowchart of the access authority management method according to the embodiment of the present disclosure is schematically shown.
[0120] like Figure 4 As shown, the access authority management method includes operations S410 to S450.
[0121] In operation S410, basic access information of an object for which access permission is to be processed corresponding to a first area is collected.
[0122] In operation S420, the access authority of the object is approved according to the basic access information, and an approval result is generated.
[0123] In operation S430, the approval result is encoded to obtain target transmission data, and the target transmission data is stored in the included encryption card.
[0124] In operation S440, the target transmission data is read from the encryption card, and the target transmission data is parsed to obtain target access authority information.
[0125] In operation S450, in the second area, based on the target access permission information, access authorization information is issued to the access control system corresponding to the object, and the access verification information corresponding to the object is updated at the same time, and the updated access verification information is sent to the card production peripheral, wherein the first area and the second area are physically isolated, the security level of the second area is greater than that of the first area, and the card production peripheral represents a device for producing and updating the pass card corresponding to the object.
[0126] According to the embodiments of the present disclosure, Figure 4 Operation S430 shown, encoding the approval result to obtain target transmission data, and storing the target transmission data in the included encryption card, may include the following operations:
[0127] Encode the approval results according to the predetermined coding rules to generate data in a specific coding format;
[0128] Encrypting the data in a specific encoding format according to a predetermined encryption algorithm to obtain target transmission data;
[0129] Write the target transmission data to the encryption card.
[0130] According to the embodiments of the present disclosure, Figure 4 Operation S440 shown, reading the target transmission data from the encryption card and parsing the target transmission data to obtain the target access permission information, may include the following operations:
[0131] Read the target transmission data from the encryption card;
[0132] Analyze the target transmission data and obtain the approval result;
[0133] The access area information included in the approval result is mapped into the access control device information corresponding to the access area, and the target access authority information is obtained according to the access control device information and the approval result.
[0134] According to an embodiment of the present disclosure, the access authority management method further includes:
[0135] Move the encryption card between the first data transmission module and the second data transmission module.
[0136] According to the embodiments of the present disclosure, Figure 4 Operation S420 shown, which is to review and approve the access rights of the object based on the basic access information and generate an approval result, may include the following operations:
[0137] According to the basic access information, the basic access information is sent to the first audit terminal, and in response to the first audit terminal, the access rights of the object and the access rights of the accompanying objects of the object are set, and a permission allocation result corresponding to the object is generated;
[0138] In response to the first review end clicking on the review operation, the authority allocation result is sent to the second review end, and in response to the second review end clicking on the confirmation operation based on the authority allocation result, the approval result is generated.
[0139] According to an embodiment of the present disclosure, the format of the basic traffic information includes at least one of the following: text, image, and table;
[0140] Basic access information includes: object attribute information, attribute information of the initial review object corresponding to the object, and object access requirement information.
[0141] According to the embodiments of the present disclosure, Figure 4 Operation S420 shown, in the second area, sends access authorization information to the access control system corresponding to the object based on the target access permission information, updates the access verification information corresponding to the object, and sends the updated access verification information to the card production peripheral device, which may include the following operations:
[0142] Receive target access authority information, and issue access authorization information to the access control system corresponding to the access control device based on the access control device information included in the target access authority information.
[0143] According to the embodiments of the present disclosure, Figure 4 Operation S410 shown, collecting basic access information of the object for which access permission is to be processed corresponding to the first area, may include the following operations:
[0144] The initial basic access information corresponding to the object is parsed and verified to obtain the basic access information.
[0145] According to the embodiments of the present disclosure, Figure 4The operation S410 shown is to review and approve the access rights of the object according to the basic access information and generate an approval result, and also includes the following operations: displaying the basic access information; storing the approval result and approval process information.
[0146] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems and methods according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0147] Those skilled in the art will appreciate that the features described in the various embodiments and / or claims of this disclosure may be combined and / or coupled in various ways, even if such combinations and / or couplings are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure may be combined and / or coupled in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or couplings are intended to fall within the scope of this disclosure.
[0148] The embodiments of the present disclosure are described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be used in combination to advantage. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present disclosure.
Claims
1. A traffic authorization management system, comprising: An information collection subsystem, configured to collect basic access information of objects to be processed for access permission corresponding to the first area; A management and approval subsystem is used to approve the access rights of the object according to the basic access information and generate an approval result; The contactless transmission subsystem includes: a first data transmission module, configured to encode the approval result to obtain target transmission data, and store the target transmission data in an encryption card included in the first data transmission module; A second data transmission module is used to read the target transmission data from the encryption card and parse the target transmission data to obtain target access authority information; The access authority decision subsystem is set in the second area, and is used to issue access authorization information to the access control system corresponding to the object based on the target access authority information, and at the same time update the access verification information corresponding to the object, and send the updated access verification information to the card production peripheral, wherein the first area and the second area are physically isolated, the security level of the second area is greater than that of the first area, and the card production peripheral represents a device for producing and updating the pass card corresponding to the object.
2. The access authorization management system according to claim 1, wherein: The first data transmission module includes: An information generation module, configured to encode the approval result according to a predetermined encoding rule to generate data in a specific encoding format; An encryption module, configured to encrypt the data in the specific encoding format according to a predetermined encryption algorithm to obtain target transmission data; A card writer is used to write the target transmission data into the encryption card.
3. The access authorization management system according to claim 1, wherein: The second data transmission module includes: A card reader, configured to read the target transmission data from the encryption card; An information analysis module, configured to analyze the target transmission data to obtain the approval result; A mapping module is used to map the access area information included in the approval result into access control device information corresponding to the access area, and obtain the target access authority information according to the access control device information and the approval result.
4. The access authorization management system according to any one of claims 1 to 3, wherein: The contactless transmission subsystem further includes: A driving module is used to move the encryption card between the first data transmission module and the second data transmission module.
5. The access authorization management system according to any one of claims 1 to 3, wherein: The management approval subsystem includes: a permission allocation module, configured to send the basic access information to a first audit terminal based on the basic access information, and in response to the first audit terminal, set access permissions for the object and for an accompanying person of the object, thereby generating a permission allocation result corresponding to the object; The approval module is used to send the authority allocation result to the second audit terminal in response to the first audit terminal clicking the issue audit operation, and generate an approval result in response to the second audit terminal clicking the confirmation operation according to the authority allocation result.
6. The access authorization management system according to any one of claims 1 to 3, wherein: The format of the basic access information includes at least one of the following: text, image and table; The basic access information includes: object attribute information, attribute information of the initial audit object corresponding to the object, and access requirement information of the object.
7. The access authorization management system according to any one of claims 1 to 3, wherein: The access authority decision subsystem includes: The access authority decision interface module is used to receive the target access authority information and, based on the access control device information included in the target access authority information, issue access authorization information to the access control system corresponding to the access control device.
8. The access authorization management system according to any one of claims 1 to 3, wherein: The information collection subsystem includes: The identification and analysis module is used to parse and verify the initial basic access information corresponding to the object to obtain the basic access information.
9. The access authorization management system according to claim 5, wherein: The management approval subsystem also includes: Information management module, used to display basic traffic information; The storage module is used to store the approval results and approval process information.
10. A method for managing access rights, comprising: Collecting basic access information of the subject to be processed for access permission corresponding to the first area; According to the basic access information, the access authority of the object is reviewed and approved, and an approval result is generated; Encoding the approval result to obtain target transmission data, and storing the target transmission data in the included encryption card; Reading the target transmission data from the encryption card and parsing the target transmission data to obtain target access authority information; In the second area, based on the target access permission information, access authorization information is issued to the access control system corresponding to the object, and the access verification information corresponding to the object is updated at the same time, and the updated access verification information is sent to the card production peripheral, wherein the first area and the second area are physically isolated, the security level of the second area is greater than that of the first area, and the card production peripheral represents a device for producing and updating the pass card corresponding to the object.
Citation Information
Patent Citations
Data writing method and user terminal
CN104899529A
Door access system based on Wiegand protocol and control method
CN109544769A
Airport pass information safety management method and system
CN111582685A
Offline multi-area authorization method and access control system
CN118155326A
Smart park access control management method and system based on Internet of Things
CN120071490A