Access right management system and method

CN120672286BActive Publication Date: 2026-09-08NUCTECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510774135.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2026-09-08
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

相关技术,通过人工方式对通过各个区域的人员及车辆的通行权限进行管理,管理效率低且出错率高

Benefits of technology

[0015] According to embodiments of this disclosure, access permission approval is automatically performed in the first area of ​​two physically isolated areas. Target data, including the approval result, corresponding to the object, is transmitted contactlessly from the first area to the second area using an encrypted card. During this contactless transmission, compared to QR code transfer, using an encrypted card further ensures the security of the transmitted information. In the second area, access authorization information is automatically issued to the access control system corresponding to the object based on the target data, while simultaneously updating the access verification information corresponding to the object. The updated access verification information is then sent to a card-making peripheral device, allowing the object to subsequently obtain an updated access card and pass through the relevant access control equipment. Compared to manual access permission management between two physically isolated areas, this method significantly improves access permission management efficiency and reduces the error rate while ensuring the security of data transmission between the two areas.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120672286B_ABST
    Figure CN120672286B_ABST
Patent Text Reader

Abstract

The present disclosure provides a kind of access authority management system and method.The system includes: information acquisition subsystem, for collecting the basic access information of the object to be handled access authority corresponding to the first area;Management approval subsystem, for generating approval result according to basic access information, the access authority of object is approved;Non-contact transmission subsystem includes: first data transmission module, for encoding approval result, obtaining target transmission data, and storing target transmission data into encrypted card;Second data transmission module, for reading target transmission data from encrypted card, and obtaining target access authority information by analyzing target transmission data;Access authority decision subsystem is set in the second area, for issuing access authorization information to access control system corresponding to object according to target access authority information, simultaneously updating access verification information corresponding to object, and sending updated access verification information to card certificate manufacturing peripheral.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the fields of security technology and nuclear power technology, and more specifically to an access control system and method. Background Technology

[0002] In the fields of nuclear power facilities, nuclear power production, and nuclear power material processing, according to safety principles, it is necessary to delineate multiple areas with different safety levels. Data channels that are physically connected between these multiple areas are not allowed; that is, the multiple areas with different safety levels are physically isolated from each other.

[0003] In actual business operations, to ensure the safe operation of each area, strict control must be exercised over the access rights of personnel and vehicles entering and exiting these areas. Currently, managing access rights manually is inefficient and prone to errors. Summary of the Invention

[0004] In view of the above problems, this disclosure provides an access control system and method.

[0005] According to the first aspect of this disclosure, an access control management system is provided, comprising: an information collection subsystem for collecting basic access information of an object with access rights pending in a first area; a management approval subsystem for approving access rights for the object based on the basic access information and generating an approval result; and a contactless transmission subsystem comprising: a first data transmission module for encoding the approval result to obtain target transmission data and storing the target transmission data in an encrypted card included in the first data transmission module; a second data transmission module for reading the target transmission data from the encrypted card and parsing the target transmission data to obtain target access control information; and an access control decision subsystem, located in a second area, for issuing access authorization information to the access control system corresponding to the object based on the target access control information, updating access verification information corresponding to the object, and sending the updated access verification information to a card production peripheral device, wherein the first area and the second area are physically isolated, the second area has a higher security level than the first area, and the card production peripheral device represents a device for producing and updating access cards corresponding to the object.

[0006] According to an embodiment of this disclosure, the first data transmission module includes: an information generation module, used to encode the approval result according to a predetermined encoding rule to generate data in a specific encoding format; an encryption module, used to encrypt the data in the specific encoding format according to a predetermined encryption algorithm to obtain target transmission data; and a card writer, used to write the target transmission data into the encrypted card.

[0007] According to an embodiment of this disclosure, the second data transmission module includes: a card reader for reading the target transmission data from the encrypted card; an information parsing module for parsing the target transmission data to obtain the approval result; and a mapping module for mapping the access area information included in the approval result to access control device information corresponding to the access area, and obtaining the target access permission information based on the access control device information and the approval result.

[0008] According to an embodiment of this disclosure, the contactless transmission subsystem further includes a drive module for moving the encrypted card between the first data transmission module and the second data transmission module.

[0009] According to an embodiment of this disclosure, the aforementioned management approval subsystem includes: a permission allocation module, configured to send the basic access information to a first review terminal based on the basic access information, and in response to the first review terminal, set access permissions for the object and access permissions for accompanying persons of the object, thereby generating a permission allocation result corresponding to the object; and an approval module, configured to send the permission allocation result to a second review terminal in response to the first review terminal clicking the "issue review" operation, and in response to the second review terminal clicking the "confirm" operation based on the permission allocation result, thereby generating an approval result.

[0010] According to embodiments of this disclosure, the format of the basic access information includes at least one of the following: text, image, and table; the basic access information includes: object attribute information, attribute information of the initial review object corresponding to the object, and access requirement information of the object.

[0011] According to an embodiment of this disclosure, the access control decision subsystem includes: an access control decision interface module, used to receive the target access control information and, based on the access control device information included in the target access control information, issue access authorization information to the access control system corresponding to the access control device.

[0012] According to an embodiment of this disclosure, the information collection subsystem includes: an identification and parsing module, used to parse and verify the initial basic access information corresponding to the object to obtain the basic access information.

[0013] According to embodiments of this disclosure, the aforementioned management and approval subsystem further includes: an information management module for displaying basic access information; and a storage module for storing the aforementioned approval results and approval process information.

[0014] The second aspect of this disclosure provides a method for access control management, comprising: collecting basic access information of an object with access rights pending in a first area; approving access rights for the object based on the basic access information and generating an approval result; encoding the approval result to obtain target transmission data and storing the target transmission data in an encrypted card; reading the target transmission data from the encrypted card and parsing the target transmission data to obtain target access control information; in a second area, issuing access authorization information to the access control system corresponding to the object based on the target access control information, updating access verification information corresponding to the object, and sending the updated access verification information to a card production peripheral, wherein the first area and the second area are physically isolated, the security level of the second area is higher than that of the first area, and the card production peripheral represents a device for producing and updating access cards corresponding to the object.

[0015] According to embodiments of this disclosure, access permission approval is automatically performed in the first area of ​​two physically isolated areas. Target data, including the approval result, corresponding to the object, is transmitted contactlessly from the first area to the second area using an encrypted card. During this contactless transmission, compared to QR code transfer, using an encrypted card further ensures the security of the transmitted information. In the second area, access authorization information is automatically issued to the access control system corresponding to the object based on the target data, while simultaneously updating the access verification information corresponding to the object. The updated access verification information is then sent to a card-making peripheral device, allowing the object to subsequently obtain an updated access card and pass through the relevant access control equipment. Compared to manual access permission management between two physically isolated areas, this method significantly improves access permission management efficiency and reduces the error rate while ensuring the security of data transmission between the two areas. Attached Figure Description

[0016] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0017] Figure 1 A schematic diagram of an access control system according to an embodiment of the present disclosure is shown.

[0018] Figure 2 A schematic diagram of an access control system according to other embodiments of the present disclosure is shown;

[0019] Figure 3 A schematic diagram of an access control system according to other embodiments of the present disclosure is shown; and

[0020] Figure 4 A flowchart illustrating a access control method according to an embodiment of the present disclosure is shown. Detailed Implementation

[0021] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0022] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0023] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0024] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).

[0025] In the technical solutions of this disclosure, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, take necessary confidentiality measures, do not violate public order and good morals, and provide corresponding operation entry points for users to choose to authorize or refuse.

[0026] In the fields of nuclear power facilities, nuclear power production, and nuclear power material processing, the varying safety levels across different areas necessitate that the entire process of managing access permissions for personnel and vehicles is distributed across these areas. To ensure the normal and safe operation of each area, frequent and rapid management of access permissions for personnel and vehicles in different areas is required. Currently, this can only be achieved manually, operating on different systems within isolated control areas, relying on paper documents and manual comparison of screens across different systems for information transmission and translation. This approach is neither safe nor efficient and is prone to errors.

[0027] When a large number of people need to create, adjust, or cancel access permissions, it requires a significant investment of manpower and is inefficient. Furthermore, it necessitates agents traveling to different areas multiple times to complete tasks such as facial image binding. Therefore, the current manual management of access permissions is very inefficient, resulting in long waiting times for people and vehicles, requiring a large workforce to complete the task. When there are many people processing access permissions and the access permissions cover many areas, the error rate is high, hindering business operations.

[0028] In order to at least partially solve the technical problems existing in the related technologies, this disclosure provides an access control system and method that can be applied to the fields of security technology and nuclear power technology.

[0029] Figure 1 A schematic diagram of an access control system according to an embodiment of the present disclosure is shown.

[0030] like Figure 1 As shown, the access control system 100 may include an information collection subsystem 110, a management approval subsystem 120, a contactless transmission subsystem 130, and an access control decision subsystem 140.

[0031] The information collection subsystem 110 can be used to collect basic access information of objects with pending access permissions corresponding to the first area.

[0032] According to embodiments of this disclosure, the first area may be a management area within a nuclear power plant.

[0033] According to embodiments of this disclosure, the object can be a person or a vehicle, etc.

[0034] According to embodiments of this disclosure, when the object is a person, the basic access information corresponding to the person may include: basic information, image information, contact information, etc.

[0035] For example, when the object is a person, the basic access information corresponding to that person may include: name, ID number, phone number, the name and phone number of the reviewer corresponding to that person, the department to which they are contacted, the name of the access area, and information about accompanying persons. When the object is a vehicle, the basic access information corresponding to that vehicle may include: license plate number.

[0036] The management approval subsystem 120 can be used to approve access permissions for objects based on basic access information and generate approval results.

[0037] For example, after receiving basic access information, the management approval subsystem 120 can assign access permissions to the target based on the contact department and contact person included in the basic access information, and complete the approval of access permissions according to the preset approval flow, and then generate the approval result.

[0038] The contactless transmission subsystem 130 may include a first data transmission module 131 and a second data transmission module 132.

[0039] The first data transmission module 131 can be used to encode the approval result, obtain the target transmission data, and store the target transmission data in the encrypted card 1311 included in the first data transmission module 131.

[0040] According to embodiments of this disclosure, the method of encoding the approval results can be selected according to the actual situation and is not limited thereto.

[0041] For example, the approval result can be encoded into a QR code and then encrypted to obtain the target data for transmission. Alternatively, the approval result can be encoded into characters and then encrypted to obtain the target data for transmission. Encryption can be performed using national cryptographic algorithms or asymmetric encryption algorithms.

[0042] According to embodiments of this disclosure, the encrypted card 1311 can be any form of physical medium capable of storing data. The encrypted card 1311 can be selected according to actual circumstances and is not limited thereto. For example, the encrypted card 1311 may include any of the following: IC card, RFID card, and Bluetooth card, etc.

[0043] The second data transmission module 132 can be used to read target transmission data from the encrypted card 1311 and parse the target transmission data to obtain target access permission information.

[0044] According to embodiments of this disclosure, target transmission data can be decoded and mapped to obtain target access permission information.

[0045] According to embodiments of this disclosure, the contactless transmission subsystem 130 may include a first data transmission module 131 and a second data transmission module 132, which can realize the one-way transmission of information collected by the management approval subsystem 120 to the access control decision subsystem 140 in a contactless manner, without relying on any physical network or hardware signal, supporting encrypted data transmission and dynamic key management, and ensuring the secure and accurate transmission of data.

[0046] The access control decision subsystem 140, located in the second area, can be used to issue access authorization information to the access control system corresponding to the target based on the target access control information, update the access verification information corresponding to the target, and send the updated access verification information to the card production peripheral. The first area and the second area are physically isolated, and the security level of the second area is higher than that of the first area. The card production peripheral represents the device for producing and updating access cards corresponding to the target.

[0047] According to embodiments of this disclosure, after the access control decision subsystem 140 sends the updated access verification information to the card creation peripheral, the object can obtain the updated access card or a newly created access card on the card creation peripheral, thereby automatically realizing the creation and updating of access cards. Since the access control decision subsystem 140 can issue access authorization information to the access control system corresponding to the object based on the target access control information, it can automatically realize the creation and adjustment of access control information, so that the object can open the access control device corresponding to the access control system based on the automatically updated access card.

[0048] According to embodiments of this disclosure, the second area can be the protected area of ​​a nuclear power plant.

[0049] According to embodiments of this disclosure, the access control decision subsystem 140 and the second data transmission module 132 are physically connected. To ensure data security in the access control decision subsystem 140, the second data transmission module 132 can only transmit data unidirectionally to the access control decision subsystem 140.

[0050] According to embodiments of this disclosure, when the access permission decision subsystem 140 issues access authorization information to the access control system corresponding to the object based on the target access permission information, the issuance method may include transmission via a network interface or import of a format file.

[0051] According to embodiments of this disclosure, access permission approval is automatically performed in the first area of ​​two physically isolated areas. Target data, including the approval result, corresponding to the object, is transmitted contactlessly from the first area to the second area using an encrypted card. During this contactless transmission, compared to QR code transfer, using an encrypted card further ensures the security of the transmitted information. In the second area, access authorization information is automatically issued to the access control system corresponding to the object based on the target data, while simultaneously updating the access verification information corresponding to the object. The updated access verification information is then sent to a card-making peripheral device, allowing the object to subsequently obtain an updated access card and pass through the relevant access control equipment. Compared to manual access permission management between two physically isolated areas, this method significantly improves access permission management efficiency and reduces the error rate while ensuring the security of data transmission between the two areas.

[0052] According to embodiments of this disclosure, the access control system provided includes an information collection subsystem, a management and approval subsystem, a contactless transmission subsystem, and an access control decision subsystem. Through the collaborative cooperation of subsystems located in multiple separate or isolated areas, it can achieve the collection of basic access information, allocation and approval of access rights, contactless transmission, automatic generation, updating, and distribution of access control information. This solves the efficiency, accuracy, and security issues related to the generation of access control information for batches of personnel, frequent adjustments to access control information, and the distribution of access control information across multiple regions, saving human resources, shortening processing time, and simplifying procedures. It also meets requirements for cross-regional physical isolation and data confidentiality.

[0053] Figure 2 The diagram illustrates an access control system according to other embodiments of the present disclosure.

[0054] like Figure 2 As shown, the access control system 200 may include an information collection subsystem 210, a management approval subsystem 220, a contactless transmission subsystem 230, and an access control decision subsystem 240. Among them, Figure 2 The information collection subsystem 210, management approval subsystem 220, contactless transmission subsystem 230, and access control decision subsystem 240 are respectively connected to... Figure 1 The information collection subsystem 110, management approval subsystem 120, contactless transmission subsystem 130 and access control decision subsystem 140 are similar, and will not be described in detail here for the sake of brevity.

[0055] exist Figure 2 In this system, the information acquisition subsystem 210 may include an identification and analysis module 211.

[0056] The identification and parsing module 211 can be used to parse and verify the initial basic access information corresponding to the object to obtain the basic access information.

[0057] According to embodiments of this disclosure, the format of basic access information includes at least one of the following: text, image, and table. Basic access information includes: object attribute information, attribute information of the initial review object corresponding to the object, and access requirement information of the object.

[0058] According to embodiments of this disclosure, object attribute information may include: name, ID number, telephone number, license plate number of the accompanying vehicle, data of the accompanying person, and the name, telephone number, and ID number of the accompanying person. The attribute information of the initial review object corresponding to the object may include: the name, telephone number, and corresponding department of the initial review object. The object's access requirement information may include: the name of the access area.

[0059] For example, the information collection subsystem 210 can collect identity information, facial information, and license plate number information in image format. It can also collect information in text format such as name, phone number, license plate number, access area name, reviewer's name, phone number, and contact department. Furthermore, it can collect initial basic access information related to multiple individuals in tabular format.

[0060] For example, the recognition and parsing module 211 can parse information in text format, image format, and table format to obtain the parsed basic access information corresponding to each object, and then verify the parsed basic access information corresponding to each object to obtain the basic access information.

[0061] For example, special character checks and information length checks can be performed on the parsed basic access information corresponding to each object. For instance, the name corresponding to the object can be checked to be greater than or equal to 2 and less than or equal to 4 characters, and the ID number corresponding to the object can be checked to contain no special characters.

[0062] According to embodiments of this disclosure, the identification and parsing module 211 parses and verifies the initial basic access information corresponding to the object, thereby enabling integrity verification of the initial basic access information and obtaining the basic access information.

[0063] exist Figure 2 In the process, the management and approval subsystem 220 may include an information management module 221, a permission allocation module 222, an approval module 223, and a storage module 224.

[0064] The information management module 221 can be used to display basic access information.

[0065] According to embodiments of this disclosure, the information management module 221 can display the basic access information of objects in the front end, so as to centrally manage and view the basic access information corresponding to each object using the information management module 221.

[0066] The permission allocation module 222 can be used to send basic access information to the first review terminal based on the basic access information, and respond to the first review terminal to set the access permissions of the object and the access permissions of the accompanying objects of the object, and generate the permission allocation result corresponding to the object.

[0067] According to embodiments of this disclosure, the accompanying party can set information on the accompanying person and the accompanying vehicle.

[0068] According to embodiments of this disclosure, the permission allocation module 222 can determine the initial review object and the corresponding department based on basic access information, and send the basic access information to the first review terminal where the initial review object is located. The initial review object can set access permissions, accompanying personnel information, and accompanying vehicle information on the first review terminal based on the basic access information. Then, in response to the first review terminal setting access permissions for the object and accompanying persons, the permission allocation module 222 generates a permission allocation result corresponding to the object.

[0069] The approval module 223 can be used to respond to the first review end clicking the "issue review" operation, send the permission allocation result to the second review end, and respond to the second review end clicking the "confirm" operation according to the permission allocation result to generate the approval result.

[0070] According to the embodiments of this disclosure, after the initial review object clicks to issue the review operation at the first review end, the approval module 223 can push the permission allocation result to each approval node (the approval end where the review object with a higher level than the initial review object is located) according to the preset approval flow to complete the approval work and generate the approval result.

[0071] According to embodiments of this disclosure, the approval module 223 can approve access permission information according to different preset approval flows based on different access permissions (i.e., different permission allocation results), and associate and bind the final approval result and approval node information with the access permission information.

[0072] According to embodiments of this disclosure, the first review terminal and the second review terminal can be a mobile APP terminal or a web page terminal.

[0073] According to embodiments of this disclosure, the approval result may include basic access information and assigned permission information.

[0074] Storage module 224 can be used to store approval results and approval process information.

[0075] According to embodiments of this disclosure, storage module 224 can locally store basic access information, assigned permission information, and approval process information.

[0076] exist Figure 2 In the first data transmission module 231, there may be an encrypted card 2311, an information generation module 2312, an encryption module 2313, and a card writer 2314.

[0077] According to embodiments of this disclosure, Figure 2 The encrypted card 2311 and Figure 1 The encrypted card 1311 is similar, and for the sake of simplicity, it will not be described in detail here.

[0078] The information generation module 2312 can be used to encode the approval results according to the predetermined coding rules and generate data in a specific coding format.

[0079] According to embodiments of this disclosure, the predetermined encoding rules can be selected based on actual circumstances, and are not limited thereto. For example, the predetermined encoding rules can be QR code encoding rules or rules for generating text symbol combination images.

[0080] The encryption module 2313 can be used to encrypt data in a specific encoding format according to a predetermined encryption algorithm to obtain the target transmission data.

[0081] According to embodiments of this disclosure, the predetermined encryption algorithm can be selected based on actual circumstances, and is not limited thereto. For example, the predetermined encryption algorithm can be a national cryptographic algorithm or an asymmetric encryption algorithm.

[0082] According to an embodiment of this disclosure, the information generation module 2312 encodes the approval result according to a predetermined encoding rule to generate data in a specific encoding format, and the encryption module 2313 encrypts the data in the specific encoding format according to a predetermined encryption algorithm to obtain the target transmission data, thereby realizing secondary encryption of the approval result to ensure the security of the transmission of the data included in the approval result.

[0083] The card writer 2314 can be used to write target data into the encrypted card 2311.

[0084] According to embodiments of this disclosure, the card writer 2314 can write encrypted target transmission data into the encrypted card 2311 in a contactless manner.

[0085] According to embodiments of this disclosure, the encrypted card 2311 can be used to carry encoded target transmission data and transfer the target transmission data between two areas in a contactless manner.

[0086] exist Figure 2 In this module, the second data transmission module 232 may include a card reader 2321, an information parsing module 2322, and a mapping module 2323.

[0087] The card reader 232 can be used to read target transmission data from an encrypted card.

[0088] According to the embodiments of this disclosure, the target transmission data is written to the encrypted card 2311 using the card writer 2314, and then the target transmission data is read from the encrypted card 2311 using the card reader 2321. This enables the target transmission data to be transmitted non-contactly from the first data transmission module 231 to the second data transmission module 232 using the encrypted card 2311. Compared with the QR code transfer method for transmitting target transmission data, the target transmission data will not be leaked due to images being captured by other external devices, making data transmission more secure.

[0089] The information parsing module 2322 can be used to parse the target transmitted data to obtain the approval result.

[0090] For example, when the encryption module 2313 encrypts data in a specific encoding format using a dynamic key to obtain the target transmission data, the card writer 2314 can write the dynamic key into the encryption card 2311. The card reader 232 reads the target transmission data and the dynamic key from the encryption card 2311, and the information parsing module 2322 decrypts and then decodes the target transmission data using the dynamic key to obtain the approval result.

[0091] According to embodiments of this disclosure, the information parsing module 2322 parses the target transmission data, which can restore the target transmission data in a specific encoding format and obtain the approval result.

[0092] The mapping module 2323 can be used to map the access area information included in the approval result into access control device information corresponding to the access area, and obtain the target access permission information based on the access control device information and the approval result.

[0093] exist Figure 2 In this context, the non-contact transmission subsystem 230 may also include a drive module 233.

[0094] The drive module 233 can be used to move the encryption card 2311 between the first data transmission module 231 and the second data transmission module 232.

[0095] According to embodiments of this disclosure, the drive module 233 can drive the encrypted card 2311 to move, circulating between the card writer 2314 and the card reader 2321 to complete the data transmission process.

[0096] According to an embodiment of this disclosure, the driving module 233 can drive the encryption card 2311 to move between the first data transmission module 231 and the second data transmission module 232, so as to realize contactless data transmission between the first data transmission module 231 and the second data transmission module 232.

[0097] According to embodiments of this disclosure, the driving module 233 may include an umbrella-shaped structure and a transmission mechanism, which can fix multiple encrypted cards 2311 at different positions on the edge of the umbrella-shaped structure. The umbrella-shaped structure may be connected to the transmission mechanism, which can drive the umbrella-shaped structure to rotate, so that the encrypted cards 2311 fixed to the umbrella-shaped structure are rotated cyclically from one side of the first data transmission module 231 (or card writer 2314) and the second data transmission module 232 (or card reader 2321) to the other side.

[0098] exist Figure 2 In the process, the access control decision subsystem 240 may include an access control decision interface module 241.

[0099] The access permission decision interface module 241 can be used to receive target access permission information and, based on the access control device information included in the target access permission information, issue access authorization information to the access control system 201 corresponding to the access control device.

[0100] According to the embodiments of this disclosure, the access permission decision interface module 241 can receive target access permission information according to the interface protocol, and issue access authorization information to the access control system 201 corresponding to the access control device according to the access control device information included in the target access permission information, which can automatically realize the creation and adjustment of access permission information.

[0101] Figure 3 The diagram illustrates an access control system according to other embodiments of the present disclosure.

[0102] like Figure 3 As shown, the access control system 300 may include an information collection subsystem 310, a management approval subsystem 320, a contactless transmission subsystem 330, and an access control decision subsystem 340.

[0103] The information acquisition subsystem 310 may include an identification and parsing module 311, an input module 312, and a first interface module 313. Figure 3 The recognition and parsing module 311 in the middle and Figure 2 The identification and parsing module 211 is similar, and will not be described in detail here for the sake of simplicity.

[0104] The data entry module 312 can be used to enter the initial basic access information required for access permission management, and supports the entry and submission of information in the form of text, images, and table attachments.

[0105] The data entry module 312 can provide an information entry interface to record the initial basic access information of an object in writing, or communicate with mini programs, mobile apps, automatic terminals and web pages to obtain the initial basic access information of an object.

[0106] The first interface module 313 can be used to transmit the collected basic access information to the outside world through the interface protocol, and supports encrypted data transmission.

[0107] The management approval subsystem 320 may include an information management module 321, a permission allocation module 322, an approval module 323, a storage module 324, and a second interface module 325. Among these, Figure 3 The information management module 321, permission allocation module 322, approval module 323, and storage module 324 are respectively connected to... Figure 2 The information management module 221, permission allocation module 222, approval module 223 and storage module 224 are similar, and will not be described in detail here for the sake of simplicity.

[0108] The second interface module 325 can be used to interface with the information acquisition subsystem 310, the contactless transmission subsystem 330, and other external management systems, such as the Peixin / OA system 303, through the interface protocol.

[0109] For example, the second interface module 325 can obtain basic access information from the first interface module 313 through the interface protocol, send the permission allocation result corresponding to the object to the second review end for review, and send the approval result to the first data transmission module 331 for encoding and encryption processing.

[0110] The contactless transmission subsystem 330 may include a first data transmission module 331, a second data transmission module 332, and a driver module 333. The first data transmission module 331 may include an encrypted card 3311, an information generation module 3312, an encryption module 3313, a card writer 3314, and a third interface module 3315. The second data transmission module 332 may include a card reader 3321, an information parsing module 3322, a mapping module 3323, and a fourth interface module 3324.

[0111] in, Figure 3 The middle drive module 333 and Figure 2 The driver module 233 is similar to that in the example. Figure 3 The encrypted card 3311, information generation module 3312, encryption module 3313, and card writer 3314 are respectively connected to... Figure 2 The encrypted card 2311, information generation module 2312, encryption module 2313, and card writer 2314 are similar. Figure 3The card reader 3321, information parsing module 3322, mapping module 3323, and fourth interface module 3324 are respectively connected to... Figure 2 The card reader 2321, information parsing module 2322, mapping module 2323 and fourth interface module 2324 are similar, and will not be described in detail here for the sake of simplicity.

[0112] The third interface module 3315 can be used to transmit data and keys with the management and approval subsystem 320. The fourth interface module 3324 can be used to transmit data and keys with the access control decision subsystem 340. The fourth interface module 3324 and the access control decision interface module 341 included in the access control decision subsystem 340 are physically connected.

[0113] For example, the third interface module 3315 can receive the approval result sent by the second interface module 325. When encrypted data transmission occurs between the second data transmission module 332 and the access control decision subsystem 340, the fourth interface module 3324 can transmit the data and encryption key to the access control decision subsystem 340.

[0114] The access control decision subsystem 340 may include an access control decision interface module 341, a card management module 342, a card access control information storage module 343, and a card issuance module 344. Among these, Figure 3 The access control decision interface module 341 and Figure 2 The access permission decision interface module 241 is similar, and will not be described in detail here for the sake of simplicity.

[0115] The card management module 342 can be used to associate and bind target access permission information with the access card of the object, and manage the bound information.

[0116] The card and pass information storage module 343 can be used to store access card information and target access permission information.

[0117] The card production module 344 can be used to send the updated access verification information to the card production peripheral 302, so that the card production peripheral 302 can realize the functions of access card production and update writing.

[0118] Based on the above access control system, embodiments of this disclosure also provide an access control method.

[0119] Figure 4 A flowchart illustrating a access control method according to an embodiment of the present disclosure is shown.

[0120] like Figure 4 As shown, the access control management method includes operations S410 to S450.

[0121] When operating S410, basic access information of the objects whose access permissions are pending and correspond to the first area is collected.

[0122] When operating S420, based on basic access information, access permissions are approved for objects, and approval results are generated.

[0123] In operation S430, the approval result is encoded to obtain the target transmission data, and the target transmission data is stored in the included encrypted card.

[0124] During operation of S440, target transmission data is read from the encrypted card and parsed to obtain target access permission information.

[0125] When operating S450, in the second area, based on the target access permission information, access authorization information is sent to the access control system corresponding to the object, and the access verification information corresponding to the object is updated. The updated access verification information is then sent to the card creation peripheral. The first area and the second area are physically isolated, and the security level of the second area is higher than that of the first area. The card creation peripheral represents the device that creates and updates the access card corresponding to the object.

[0126] According to embodiments of this disclosure, for example, Figure 4 The operation S430 shown encodes the approval result to obtain the target transmission data and stores the target transmission data in the included encrypted card, which may include the following operations:

[0127] The approval results are encoded according to predetermined coding rules to generate data in a specific coding format;

[0128] Data in a specific encoding format is encrypted using a predetermined encryption algorithm to obtain the target transmission data;

[0129] The target data is transmitted and written to the encrypted card.

[0130] According to embodiments of this disclosure, for example, Figure 4 The operation S440 shown reads the target transmission data from the encrypted card and parses the target transmission data to obtain the target access permission information, which may include the following operations:

[0131] Read the target transmitted data from the encrypted card;

[0132] The target transmitted data is parsed to obtain the approval result;

[0133] The access area information included in the approval result is mapped to the access control device information corresponding to the access area, and the target access permission information is obtained based on the access control device information and the approval result.

[0134] According to embodiments of this disclosure, the access control method further includes:

[0135] The encrypted card is moved between the first data transmission module and the second data transmission module.

[0136] According to embodiments of this disclosure, for example, Figure 4 The operation S420 shown describes the process of approving access permissions for an object based on basic access information and generating an approval result. This may include the following operations:

[0137] Based on the basic access information, the basic access information is sent to the first review terminal, and the first review terminal responds by setting the access permissions for the object and the access permissions for the accompanying objects, generating the permission allocation result corresponding to the object;

[0138] In response to the first reviewer clicking the "Issue Review" button, the permission allocation result is sent to the second reviewer. The second reviewer then clicks the "Confirm" button based on the permission allocation result to generate the approval result.

[0139] According to embodiments of this disclosure, the format of basic communication information includes at least one of the following: text, images, and tables;

[0140] Basic access information includes: object attribute information, attribute information of the initial review object corresponding to the object, and access requirements information of the object.

[0141] According to embodiments of this disclosure, for example, Figure 4 Operation S420, as shown, in the second area, sends access authorization information to the access control system corresponding to the object based on the target access permission information, updates the access verification information corresponding to the object, and sends the updated access verification information to the card creation peripheral. This operation may include the following:

[0142] Receive target access permission information, and based on the access control device information included in the target access permission information, issue access authorization information to the access control system corresponding to the access control device.

[0143] According to embodiments of this disclosure, for example, Figure 4 Operation S410, as shown, collects basic access information for objects with pending access permissions corresponding to the first area, and may include the following operations:

[0144] The initial basic access information corresponding to the object is parsed and verified to obtain the basic access information.

[0145] According to embodiments of this disclosure, for example, Figure 4The operation S410 shown above approves the access permission of the object based on the basic access information and generates the approval result. It also includes the following operations: displaying the basic access information; and storing the approval result and approval process information.

[0146] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems and methods according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0147] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0148] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. An access control system, comprising: The information collection subsystem is used to collect basic access information for objects with pending access permissions corresponding to the first area; The management approval subsystem is used to approve the access permissions of the object based on the basic access information and generate an approval result, wherein the approval result includes basic access information and assigned permission information; The contactless transmission subsystem includes: The first data transmission module is used to encode the approval result to obtain target transmission data, and store the target transmission data in the encrypted card included in the first data transmission module; The first data transmission module includes: an information generation module, used to encode the approval result according to a predetermined encoding rule to generate data in a specific encoding format; an encryption module, used to encrypt the data in the specific encoding format according to a predetermined encryption algorithm to obtain target transmission data; and a card writer, used to write the target transmission data into the encrypted card. A driving module is used to move the encrypted card between the first data transmission module and the second data transmission module; The second data transmission module is used to read the target transmission data from the encrypted card and parse the target transmission data to obtain the target access permission information. The first data transmission module and the second data transmission module transmit the information collected by the management approval subsystem to the access permission decision subsystem in a contactless manner. The access control decision subsystem, located in the second area, is used to issue access authorization information to the access control system corresponding to the target access control information based on the target access control information, and simultaneously update the access verification information corresponding to the target. The updated access verification information is then sent to the card creation peripheral. The first area and the second area are physically isolated, with the second area having a higher security level than the first area. The card creation peripheral represents a device for creating and updating access cards corresponding to the target. The second data transmission module can only transmit data unidirectionally to the access control decision subsystem.

2. The access control system according to claim 1, wherein, The second data transmission module includes: A card reader for reading the target transmission data from the encrypted card; The information parsing module is used to parse the target transmitted data to obtain the approval result; The mapping module is used to map the access area information included in the approval result into access control device information corresponding to the access area, and obtain the target access permission information based on the access control device information and the approval result.

3. The access control system according to any one of claims 1 to 2, wherein, The management approval subsystem includes: The permission allocation module is used to send the basic access information to the first review terminal based on the basic access information, and respond to the first review terminal to set the access permissions of the object and the access permissions of the accompanying objects of the object, and generate a permission allocation result corresponding to the object; The approval module is used to respond to the first review terminal clicking the "issue review" operation, send the permission allocation result to the second review terminal, and respond to the second review terminal clicking the "confirm" operation according to the permission allocation result to generate the approval result.

4. The access control system according to any one of claims 1 to 2, wherein, The format of the basic access information includes at least one of the following: text, image, and table; The basic access information includes: object attribute information, attribute information of the initial review object corresponding to the object, and access requirement information of the object.

5. The access control system according to any one of claims 1 to 2, wherein, The access control decision subsystem includes: The access permission decision interface module is used to receive the target access permission information and, based on the access control device information included in the target access permission information, issue access authorization information to the access control system corresponding to the access control device.

6. The access control system according to any one of claims 1 to 2, wherein, The information collection subsystem includes: The identification and parsing module is used to parse and verify the initial basic access information corresponding to the object to obtain the basic access information.

7. The access control system according to claim 3, wherein, The management approval subsystem also includes: The information management module is used to display basic access information; The storage module is used to store the approval results and approval process information.

8. A method for managing access permissions, applied to the access permission management system according to any one of claims 1 to 7, comprising: Collect basic access information for the objects whose access permissions are pending in the first area; Based on the basic access information, the access permission of the object is approved, and an approval result is generated, wherein the approval result includes the basic access information and the assigned permission information; Encoding the approval result to obtain target transmission data, and storing the target transmission data in an encrypted card includes: encoding the approval result according to a predetermined encoding rule to generate data in a specific encoding format; encrypting the data in the specific encoding format according to a predetermined encryption algorithm to obtain target transmission data; and writing the target transmission data into the encrypted card. Read the target transmission data from the encrypted card and parse the target transmission data to obtain the target access permission information; In the second area, based on the target access permission information, access authorization information is sent to the access control system corresponding to the object, and the access verification information corresponding to the object is updated. The updated access verification information is then sent to the card creation peripheral. The first area and the second area are physically isolated, and the security level of the second area is higher than that of the first area. The card creation peripheral represents a device for creating and updating access cards corresponding to the object.

Citation Information

Patent Citations

  • Airport pass information safety management method and system

    CN111582685A

  • Offline multi-area authorization method and access control system

    CN118155326A