Room card full life cycle dynamic authority management method and system

By collaborating with the cloud and smart door locks, using trigger events to actively wake up communication, and combining dynamic circuit breaking and secondary authentication, the delay and security risks of hotel room card permission cancellation are solved, and automated, instant and highly secure management is achieved.

CN120675805APending Publication Date: 2025-09-19GLOBAL CARD SYSTEMS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511027392.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

In the existing technology, the hotel room card permission cancellation process relies on manual operation, which is inefficient and poses security risks. The networked door lock causes permission cancellation delays due to dormancy, making it impossible to achieve automated and immediate management.

Method used

By working in collaboration with smart door locks through the cloud management platform, preset trigger events are used to actively wake up the door lock for communication, enabling instant cancellation of permissions. In addition, a dynamic fuse and secondary authentication mechanism are combined to build a full life cycle security management system.

Benefits of technology

It realizes the instant and automatic cancellation of room card permissions, eliminates security loopholes caused by human negligence, improves management efficiency and security, balances the needs of low power consumption and immediacy, and provides high-precision identity authentication and traceable operation records.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675805A_ABST
    Figure CN120675805A_ABST
Patent Text Reader

Abstract

The invention discloses a room card full life cycle dynamic authority management method and system, and belongs to the technical field of hotel management. The core of the method is that authority logout is divided into two stages of decision making and execution: firstly, a cloud management platform makes a decision in advance according to a service instruction, and an access control voucher is updated to be in a ready logout state; then, when the low-power-consumption door lock monitors a door closing event or a preset triggering event such as overtime when the door is not closed, the door lock is actively awakened, and a communication window is established and maintained with the cloud; and finally, the cloud platform immediately issues a formed freezing instruction by using the communication opportunity so as to cancel the voucher. Through the mechanism of cloud decision making and lock end triggering, the potential safety hazard of authority logout delay caused by dormancy of the door lock is thoroughly solved, and the safety and management efficiency of the hotel access control system are remarkably improved. Preferably, the invention further discloses a dynamic risk management and control mechanism for the high-authority vouchers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of smart door locks, the Internet of Things, and hotel management technology, and in particular to a method and system for dynamic permission management of room cards throughout their life cycle. Background Art

[0002] In hotels and apartments, timely and reliable cancellation of guest room card permissions after check-out is a core component of security management. However, existing room card cancellation solutions often suffer from cumbersome processes, manual reliance, and slow response times, resulting in significant management costs and security risks.

[0003] Currently, there are two main methods for handling room cards after check-out. The first is the "front desk collection and cancellation" model: guests return their room cards to the front desk upon check-out. Staff then physically swipe each card using a specialized card-making device to modify the card data, rendering it invalid. This model has several drawbacks: First, it relies heavily on manual labor, making it inefficient. This is especially true during peak check-out periods, which can cause guests to wait and staff to be overwhelmed. Second, it requires that room cards be physically collected. If a guest loses or fails to return a card, the card's permissions remain valid, creating a security vulnerability.

[0004] The second method is the "on-site guest room reset" mode, which is common when a guest leaves their key card in the room. In this mode, after completing cleaning or inspection, the cleaning or management staff must swipe a special management card (such as a "reset card" or "initialization card") on the guest room door lock to reset the authorization list within the lock, thereby invalidating the previous guest's key card. This mode has more significant drawbacks: not only does it require staff to visit each checked-out room one by one, which consumes a lot of manpower and time, but it is also prone to human negligence (such as forgetting to swipe the card) resulting in permission cancellation failure, allowing the old key card to open the door for a considerable period of time, posing a serious security risk.

[0005] Even with the introduction of connected smart door locks using low-power wide area networks (such as NB-IoT), these issues haven't been fundamentally resolved. To conserve battery life, these locks are often offline or semi-offline, communicating only with cloud servers via periodic "heartbeat" cycles. This means that even if the hotel management system (PMS) updates the room status in the cloud immediately after a guest checks out, it can't immediately send the deregistration command to the dormant door lock; the command still has to wait for the next heartbeat cycle (which can take several minutes).

[0006] In summary, neither manual physical operation nor the passive communication mechanisms of existing networked door locks can achieve automated and immediate deregistration of door card permissions after check-out, inherently resulting in low management efficiency and security delays. Therefore, providing a new method and system that allows low-power door locks to intelligently and proactively collaborate with the cloud to instantly deregister permissions during check-out, a critical business node, remains a core technical challenge in this field. Summary of the Invention

[0007] The purpose of the present invention is to overcome the shortcomings of the existing technology and provide a method and system for dynamic permission management of room cards throughout their life cycle, aiming to completely get rid of the dependence on manual on-site operations and solve the security risk of delayed execution of permission cancellation instructions due to dormancy of networked door locks, thereby comprehensively improving the safety and automation management level of the hotel.

[0008] The present invention provides a method for dynamic permission management of room cards throughout their life cycle, comprising the following steps: S1: In the cloud management platform, the business status of the target access control credential associated with the target door lock is updated to the pre-cancellation state to generate a pending permission freezing decision; S2: When the target door lock detects at least one preset trigger event, it will actively wake up and establish and maintain a communication connection with the cloud management platform for a preset duration; S3: After establishing a communication connection with the target door lock, the cloud management platform queries its own database based on the identity of the target door lock. When it is confirmed that the target access control credential associated with the target door lock has been marked as ready for cancellation, it immediately sends a permission freezing instruction to the target door lock to cancel its access permission.

[0009] It can be seen that compared with the existing technology, the core of the technical solution provided by the present invention is to build a new collaborative mechanism of "cloud decision-making, lock-end triggering, and real-time execution", which has the following significant beneficial effects: the present invention completely abandons the cumbersome process of relying on staff to use card makers or permission cards to swipe cards on site to cancel permissions in the existing technology. The permission cancellation process is automatically completed by the cloud and the door lock end without any human intervention, realizing true automation and unmanned operation, greatly improving management efficiency, and eliminating security vulnerabilities caused by human negligence. At the same time, compared with traditional networked door locks that rely on passive "heartbeats" and cause delays of several minutes, the present invention uses a mechanism in which the door lock actively creates a communication window when key physical events such as closing the door or not closing the door occur, ensuring that the freezing decision that has already been formed in the cloud can be delivered and executed as soon as possible, shortening the security risk window from "minutes" to "seconds", completely solving the delay problem of permission cancellation, and reducing security risks to a minimum. Furthermore, the present invention does not require the door lock to be online at all times. Instead, it maintains low-power dormancy most of the time, and only intelligently and briefly maintains an online state at specific times when there is a high probability of executing instructions, such as "closing the door on check-out day." This refined strategy perfectly balances the hotel's core demand for long-lasting door locks and the critical demand for instant and secure check-out, taking into account both low power consumption and immediacy, and the technical solution has more advantages.

[0010] Optionally, the preset trigger event is that the target door lock determines that the door body where it is located has a door closing event.

[0011] It can be seen that using the "door closing event" as a trigger condition accurately captures the key business action of the guest leaving the hotel, ensuring that the system can be activated at the moment when permission cancellation is most needed, thereby achieving efficient and timely security response.

[0012] Optionally, the target door lock is configured to establish and maintain a communication connection for a preset duration only after a door closing event occurs on a preset check-out date associated with the target access control credential.

[0013] It can be seen that this date-based intelligent wake-up strategy allows the door lock to maintain online communication for a long time only during the high-risk time node of the check-out day, and quickly resume sleep at other times to save power. This greatly extends the battery life of the door lock while ensuring immediacy, perfectly balancing the needs of security and power consumption.

[0014] Optionally, the preset trigger event also includes a door not closed timeout event; wherein, the door not closed timeout event is an event actively triggered by the door lock after the door body of the target door lock is continuously opened for more than a preset time period.

[0015] It can be seen that this design enhances the system's fault tolerance and security, and can cover abnormal scenarios such as guests forgetting to close the door. It ensures that even if there is no clear "door closing" action, a communication window can be created to execute the permission deregistration instruction, plugging potential security management loopholes.

[0016] Optionally, it also includes: For an access control credential that is authorized to open multiple different target door locks, the cloud management platform monitors the number of door openings within a preset time window. When the number of door openings exceeds the preset fuse threshold, the fuse mechanism is automatically triggered, suspending the access rights of the access control credential; When the access rights of an access control credential are suspended, the credential holder is required to perform a secondary biometric authentication on a designated authentication terminal. After passing the authentication, the cloud management platform will restore their access rights.

[0017] It can be seen that this mechanism elevates security management from retrospective to pre-emptive prevention. By automatically suspending abnormal use of high-authority credentials, it effectively curbs the risk of employee cards and other credentials being abused or stolen. The subsequent secondary biometric authentication ensures that only the legitimate holder of the credential can restore permissions, thus forming a complete risk closed-loop management.

[0018] Optionally, the fuse threshold of the access control credential that is authorized to open multiple different target door locks is bound to the role of the credential holder and can be dynamically configured by the cloud management platform.

[0019] It can be seen that this design provides great flexibility and precision for security policies, allowing managers to customize circuit breaking rules based on the actual work needs and risk levels of different positions such as cleaning and maintenance, avoiding the interference of "one-size-fits-all" policies on normal work, and making security management and control more humane and operational.

[0020] Optionally, the secondary biometric authentication includes at least one of fingerprint recognition, iris recognition or face recognition.

[0021] It can be seen that the use of unique biometrics for secondary authentication provides the highest level of identity authentication security compared to traditional password or card authentication. It can reliably confirm that the operator is the credential holder himself, effectively eliminating the risk of credentials being misused to restore permissions.

[0022] Optionally, it also includes: the cloud management platform stores and backs up all permission changes, authentication processes and access control credential operation records to form a traceable log for subsequent audits.

[0023] It can be seen that this has achieved full traceability of all key operations, providing solid and reliable electronic evidence for safety audits, accident investigations and responsibility determination, and comprehensively improving the standardization and credibility of hotel access control management.

[0024] The present invention also provides a corresponding system, including a cloud management platform and a target door lock, for implementing the above method.

[0025] Optionally, the system may also include an authentication terminal for implementing risk management of high-authority credentials such as employee cards.

[0026] It can be seen that by setting up dedicated authentication terminals in secure areas such as security offices, high-risk permission recovery operations are centralized in a controlled environment, further strengthening the security of the process and effectively preventing the possibility of authentication attempts in non-secure areas.

[0027] Further features and advantages of the present invention will become apparent from the following detailed description of exemplary embodiments of the present invention with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments of the invention and, together with the description, serve to explain the principles of the invention.

[0029] Figure 1 This is a flow chart of a method for dynamic permission management of a room card throughout its life cycle according to an embodiment of the present invention. DETAILED DESCRIPTION

[0030] Various exemplary embodiments of the present invention will now be described in detail with reference to the accompanying drawings. It should be noted that unless otherwise specifically stated, the relative arrangement of components and steps, numerical expressions and numerical values ​​set forth in these embodiments do not limit the scope of the present invention.

[0031] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way intended to limit the invention, its application, or uses.

[0032] Technologies, methods, and equipment known to ordinary technicians in the relevant art may not be discussed in detail, but where appropriate, they should be considered part of the specification.

[0033] In all examples shown and discussed herein, any specific values ​​should be interpreted as merely exemplary and not limiting. Therefore, other examples of the exemplary embodiments may have different values.

[0034] It should be noted that like reference numerals and letters refer to like items in the following figures, and therefore, once an item is defined in one figure, it need not be further discussed in subsequent figures.

[0035] This invention provides a dynamic access management system and method for the entire lifecycle of room cards. The overall concept is to build a closed-loop management system that collaborates with a cloud-based management platform, smart door lock terminals, and designated authentication terminals. The core concept of this system is to separate decision-making from execution, leverage event-driven real-time communication, and dynamically adjust security policies to implement full lifecycle security management and control for two core credentials in the hotel access control system: standard room cards representing guests (target access control credentials) and high-authority access control credentials representing employees. This includes authorization, use, monitoring, and cancellation.

[0036] The system's architecture centers around a cloud-based management platform, acting as a decision-making and command distribution center, closely interacting with various peripheral systems and devices. It obtains authoritative business status from the hotel's front-office management system (such as the Property Management System) and pre-generates permission change decisions based on this information. It also maintains bidirectional communication with smart door locks, waiting for communication opportunities on the lock side to issue pre-prepared control commands. Based on this architecture, the system focuses on two complementary innovative features: an instant deactivation mechanism for standard room cards, and a dynamic circuit breaker and secondary authentication mechanism for high-privilege employee cards. These two core features are described in detail below.

[0037] Example 1: Realization of instant cancellation of room card permissions like Figure 1 As shown, the present invention provides a method for dynamic permission management of room cards throughout their life cycle, comprising the following steps: S1: In the cloud management platform, the business status of the target access control credential associated with the target door lock is updated to the pre-cancellation state to generate a pending permission freezing decision; S2: When the target door lock detects at least one preset trigger event, it will actively wake up and establish and maintain a communication connection with the cloud management platform for a preset duration; S3: After establishing a communication connection with the target door lock, the cloud management platform queries its own database based on the identity of the target door lock. When it is confirmed that the target access control credential associated with the target door lock has been marked as ready for cancellation, it immediately sends a permission freezing instruction to the target door lock to cancel its access permission.

[0038] Specifically, the following embodiments describe in detail how to implement near-real-time automated deregistration of room card permissions after a guest checks out.

[0039] 1. Cloud-based decision-making Regardless of the subsequent scenarios, the first step is always completed in the cloud. When the hotel front desk performs a check-out for a room in the property management system (PMS), the system immediately synchronizes this instruction to the cloud management platform via an API. Upon receiving this instruction, the cloud management platform immediately makes a decision: the room card associated with the door lock is marked as "pre-cancellation state" in the database. This state indicates that a permission freeze instruction has been generated but is awaiting issuance, pending execution once communication with the target door lock is established.

[0040] 2. Lock-end event triggers communication Since the door lock is usually in a low-power sleep state, a physical event is needed to trigger it to wake up and connect to the network. The present invention designs multiple trigger mechanisms to cope with different scenarios.

[0041] Scenario A: Normal closing and departure In this scenario, the door lock detects a "door closing event" through its built-in sensor. The door lock's microcontroller (MCU) is immediately awakened and, based on a pre-set strategy, determines whether to establish and maintain communication.

[0042] Date-based smart wake-up policy: This policy is designed to balance immediate response and power consumption. When a guest checks in, their "expected check-out date" information is synchronized to the door lock.

[0043] On the expected check-out date: When the guest closes the door, the door lock detects that it is the expected check-out date. It will then proactively establish and maintain a communication connection with the cloud for a preset duration (for example, stay online for 30 minutes).

[0044] On non-scheduled check-out days: After the door is locked and closed, no report is made or only regular event reports are made, and then the device immediately resumes sleep mode without waking up to save power.

[0045] Scenario B: The door is not closed after check-out (abnormal scenario handling) This system also takes into account the extreme situation that the guest does not close the door after checking out.

[0046] Door open timeout trigger mechanism: The door lock has a built-in "door open timeout" timer (for example, 15 minutes). If the door remains open for longer than this time, the door lock will automatically wake up, establish and maintain a communication connection with the cloud for a preset duration, and report a "door open timeout event." This allows the system to create a communication window even if the door is not closed.

[0047] 3. Cloud command execution and logging In any of these scenarios, once the door lock establishes a communication connection with the cloud, the cloud platform will use this connection to execute instructions. If the cloud has already marked the door lock as "pre-deregistration state," or if the door lock receives a check-out instruction from the PMS while communication is established, the cloud will immediately issue a "freeze permission instruction." The cloud management platform also logs the time the freeze permission instruction was issued, the target door lock ID, and the execution result returned by the door lock, ensuring traceability of the entire automated deregistration process.

[0048] 4. Heartbeat mechanism protection As a final safeguard, the lock's regular heartbeat (e.g., every 5 minutes) is the final communication opportunity. In any case, as long as the lock communicates with the cloud via heartbeat, the cloud will check whether it has any pending instructions to ensure that the permission can be revoked.

[0049] Through the above-mentioned design of "separation of decision-making and execution" and "the lock end actively creating communication opportunities through various events", the present invention ensures that the room card authority can be cancelled in the fastest and most reliable way regardless of the scenario.

[0050] Example 2: Dynamic Fusing and Secondary Authentication of Employee Cards This embodiment describes a dynamic risk management mechanism for an access control credential (hereinafter referred to as a high-authority credential) that is authorized to open multiple different target door locks. This mechanism is intended to prevent abuse of authority rather than simply track it down afterwards.

[0051] First, the cloud-based management platform provides a highly flexible and refined interface for configuring circuit breaker policies. Hotel administrators can use this platform to set personalized circuit breaker rules for different employee roles (such as cleaners, maintenance workers, and floor managers) that match their job responsibilities. The core of these rules is the definition of a "circuit breaker threshold," which typically consists of two dimensions: a time window (e.g., "within 10 minutes") and the number of door openings allowed within that window (e.g., "visiting five different rooms"). These thresholds are not fixed but can be dynamically adjusted by authorized administrators based on the hotel's actual operational needs.

[0052] The cloud-based management platform uses an efficient stream processing engine to track every high-privilege credential's operation in real time. Whenever a high-privilege credential successfully swipes a door lock, the lock reports a log containing the card ID, lock ID, door opening time, and result. Upon receiving this log, the cloud-based platform immediately updates the counter for the number of door openings for that credential within a sliding time window.

[0053] The system continuously compares the real-time usage of high-privilege credentials against the circuit breaker thresholds associated with their roles. When a credential's door-opening behavior reaches a preset upper threshold, the cloud management platform immediately and automatically triggers the circuit breaker mechanism, atomically updating the credential's permission status in the database to "frozen" or "suspended." Thereafter, any subsequent attempts to open any door with that credential will fail due to the frozen permissions, providing a powerful preventative and behavioral deterrent.

[0054] Once privileges are suspended, the credential holder must personally perform a second authentication at a designated, physically fixed authentication terminal before their privileges can be restored. This authentication terminal, typically installed in a hotel's security office, employee access points, or other monitored, high-security areas, integrates a high-precision biometric authentication module, such as a fingerprint scanner, iris reader, or facial recognition camera. Employees verify their biometrics at the terminal, and upon successful authentication, the terminal sends a successful authentication message to the cloud.

[0055] After receiving this successful authentication information, the cloud management platform will verify that it is correct before restoring the corresponding credential status to "normal" and resetting its door opening counter so that it can continue to work normally.

[0056] To ensure traceability throughout the risk management process, the cloud management platform maintains detailed logs of all operational activities described in this embodiment. This includes, but is not limited to, every door opening with high-privilege credentials, the specific events that triggered circuit-breaker thresholds, the precise times at which permissions were suspended and restored, and every biometric authentication attempt and result (success or failure) made by the user on the authentication terminal. These logs are securely stored and backed up, forming a complete audit trail, providing robust data support for subsequent security incident analysis, accountability delineation, and compliance reviews.

[0057] In summary, the present invention specifically describes the method and system for dynamic permission management of room cards throughout their life cycle through Embodiment 1 and Embodiment 2.

[0058] For standard room cards, this invention establishes a collaborative "cloud-based decision-making, lock-side triggering" model: the cloud makes the initial decision, while the low-power door lock proactively wakes up and connects to the network upon detecting key events such as door closing, creating an instant communication window for the cloud to issue pre-established freeze commands. This mechanism not only solves the issue of delayed permission cancellation caused by traditional networked door locks due to dormancy, but also balances the needs of immediacy and long battery life through intelligent wake-up strategies.

[0059] This invention incorporates a closed-loop risk management mechanism featuring dynamic circuit breaking and secondary authentication for high-privilege credentials like cleaning cards. By combining real-time monitoring and automatic circuit breaking of abnormal door openings with high-security biometric secondary authentication at designated terminals, this approach effectively prevents and deters the risk of abuse, elevating security management to a new level.

[0060] The combination of the two constitutes an automated, highly secure and traceable full life cycle management system.

[0061] Although some specific embodiments of the present invention have been described in detail by way of examples, it should be understood by those skilled in the art that the above examples are for illustration only and are not intended to limit the scope of the present invention. It should be understood by those skilled in the art that modifications may be made to the above embodiments without departing from the scope and spirit of the present invention. The scope of the present invention is defined by the appended claims.

Claims

1. A dynamic permission management method for room card throughout its life cycle, characterized in that: The following steps are involved: S1: In the cloud management platform, the business status of the target access control credential associated with the target door lock is updated to the pre-cancellation state to generate a pending permission freezing decision; S2: When the target door lock detects at least one preset trigger event, it actively wakes up and establishes and maintains a communication connection with the cloud management platform for a preset duration; S3: After establishing a communication connection with the target door lock, the cloud management platform queries its own database based on the identity identification of the target door lock. When it is confirmed that the target access control credential associated with the target door lock has been marked as the pre-cancellation state, it immediately issues a permission freezing instruction to the target door lock to cancel its access permission.

2. The method according to claim 1, characterized in that The preset trigger event is that the target door lock determines that the door body where it is located has a door closing event.

3. The method according to claim 2, characterized in that The target door lock is configured to establish and maintain a communication connection for the preset duration only after the door closing event occurs on the preset check-out date associated with the target access control credential.

4. The method according to claim 1, wherein The preset trigger event also includes a door not closed timeout event; wherein, the door not closed timeout event is an event actively triggered by the door lock after the door body of the target door lock is continuously opened for more than a preset time period.

5. The method according to claim 1, wherein Also includes: For an access control credential that is authorized to open multiple different target door locks, the cloud management platform monitors the number of door openings within a preset time window. When the number of door openings exceeds the preset fuse threshold, the fuse mechanism is automatically triggered, suspending the access rights of the access control credential; When the access rights of the access control certificate are suspended, the certificate holder is required to perform a secondary biometric authentication on a designated authentication terminal. After passing the authentication, the cloud management platform will restore the access rights.

6. The method according to claim 5, characterized in that The fuse threshold of the access control certificate that is authorized to open multiple different target door locks is bound to the role of the certificate holder and can be dynamically configured by the cloud management platform.

7. The method according to claim 5, characterized in that The secondary biometric authentication includes at least one of fingerprint recognition, iris recognition or face recognition.

8. The method according to claim 1, characterized in that Also includes: The cloud management platform stores and backs up all permission changes, authentication processes, and access control credential operation records to form a traceable log for subsequent audits.

9. A dynamic permission management system for the entire life cycle of a room card, characterized in that: include: A cloud management platform communicating with the management system, a target door lock provided on the door, and a designated authentication terminal for implementing the method according to claim 5; The cloud management platform is used to perform the method steps as described in any one of claims 1 and 5 to 8; The target door lock is configured to execute the method steps according to any one of claims 1 to 4, communicate with the cloud management platform, and receive and execute the permission freezing instruction; The authentication terminal is used to provide the secondary biometric authentication function as claimed in claim 5.

10. The system according to claim 9, characterized in that The target door lock is further configured to: Built-in clock and memory for acquiring and storing the preset check-out date associated with the target access credential; The system is configured to establish and maintain a communication connection for the preset duration only after a door closing event occurs on the preset check-out date.