Access control management method, device and system
By integrating reading, access detection, and communication components into the access control device, connecting it to the controller, and storing authentication requests and access information, the problem of duplicate authentication in existing technologies is solved, realizing a refined management and enhanced security access control management system.
Patent Information
- Application Number
- CN202410483213.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-22
- Publication Date
- 2025-10-24
AI Technical Summary
In existing technologies, access control systems cannot achieve refined management, which allows authorized personnel to allow unauthorized personnel to enter through repeated authentication, resulting in low security.
By setting up reading devices, access detection components, and communication components in access control equipment, connecting them to the controller, and storing authentication requests and access information, the system can determine the passage behavior of personnel by combining authentication requests and access information, identify and record the passage direction, and prevent duplicate authentication and abnormal passage.
It enables refined management of personnel access behavior, avoids duplicate authentication for the same person, and improves the security and management efficiency of the target area.
Smart Images

Figure CN120833644A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the access control management field, in particular to an access control management method, device and system. BACKGROUND
[0002] The access control management system can control the access of personnel in a target area, and can also control the access of personnel when entering or leaving the target area, accurately record the access records, ensure that authorized personnel can freely access, and limit unauthorized personnel from entering. In the prior art, the access of personnel is limited according to the authority of the personnel, but this can cause authorized personnel to repeatedly authenticate through the authority, and cannot achieve fine management. SUMMARY
[0003] The purpose of the embodiments of the present application is to provide an access control management method, device and system to achieve fine management of personnel access and improve the safety guarantee of the target area. The specific technical solutions are as follows:
[0004] The present application provides an access control management method, which is applied to a controller, the controller is connected with at least one access control device, the entrance and the exit of each access control device are respectively provided with a recognition device, a passing detection component and a communication component, the recognition device is used to identify personnel requesting to pass through the access control device, the passing detection component is used to detect personnel passing through the access control device, and the communication component is used to send an authentication request and passing information to the controller according to the personnel identified by the recognition device and the personnel detected by the passing detection component, the controller pre-stores the authentication request and passing information sent by each access control device, the authentication request is used to represent personnel requesting to pass through the access control device and the passing direction, and the passing information is used to represent personnel passing through the access control device and the passing direction.
[0005] The method comprises the following steps:
[0006] In response to a first authentication request sent by a first access control device, the first authentication request is stored and the personnel and the passing direction represented by the first authentication request are identified as a first personnel and a first passing direction; whether the first personnel has a preset prohibited passing behavior is determined according to the pre-stored authentication request and passing information; if not, a passing permission instruction is sent to the first access control device to allow the first personnel to pass through the first access control device; and in response to first passing information sent by the first access control device, the first passing information is recorded, wherein the first passing information is sent by the first access control device after detecting that the first personnel passes through the first access control device.
[0007] The embodiments of the present application have the following beneficial effects:
[0008] The access control management method, device and system provided by the embodiment of the application can store a first authentication request and identify a person and a passing direction represented by the first authentication request as a first person and a first passing direction in response to the first authentication request sent by a first access control device, determine whether the first person has a preset prohibited passing behavior according to pre-stored authentication request and passing information, send a passing permission instruction to the first access control device if the first person does not have the preset prohibited passing behavior, so that the access control device allows the first person to pass, and record first passing information in response to the first passing information sent by the access control device. In the embodiment of the application, whether the first person has the preset prohibited passing behavior is determined by the authentication request and the passing information together. Since the passing information is recorded after the person to be passed passes, the passing behavior of the person to be passed can be audited based on the passing record, so that repeated authentication of the same passing person is avoided and fine management is realized.
[0009] Of course, implementing any product or method of the application does not necessarily require all the advantages described above to be achieved at the same time. BRIEF DESCRIPTION OF DRAWINGS
[0010] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced. Obviously, the drawings in the following description only constitute some embodiments of the application, and other embodiments can also be obtained by those skilled in the art based on these drawings.
[0011] Figure 1 A flowchart of an access control management method provided by the embodiment of the application;
[0012] Figure 2a A framework diagram of an access control management system provided by the embodiment of the application;
[0013] Figure 2b A general flowchart of authentication and passing on a client access control device provided by the embodiment of the application;
[0014] Figure 2c A general flowchart of authentication and passing on a server access control device provided by the embodiment of the application;
[0015] Figure 2d An activity diagram of a whole scheme of an access control management system provided by the embodiment of the application;
[0016] Figure 2e A flowchart of a whole scheme provided by the embodiment of the application;
[0017] Figure 3 A schematic diagram of an access control management device provided by the embodiment of the application;
[0018] Figure 4 An electronic device schematic diagram is provided for the embodiments of the present application. DETAILED DESCRIPTION
[0019] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art based on the present application belong to the scope of protection of the present application.
[0020] In the technical solutions of the present application, the operations of obtaining, storing, using, processing, transmitting, providing and disclosing of user personal information are all performed after obtaining the authorization of the user.
[0021] Gate: It is a kind of intelligent access control equipment, including swing gate, three-roller gate, wing gate and other forms, its essence is a kind of passage blocking device, used to form controlled area and uncontrolled area. Its main function is to manage the entrance and exit of personnel, vehicles and other objects, and to control their access to specific areas or buildings. Gate is mainly used in public places, enterprises, schools, airports, railway stations, shopping centers, communities and other places with high population density, which can play a good role in entrance management and security protection.
[0022] Access control management platform: It is a large-scale security management system based on Internet technology, which contains access control equipment parameter management, personnel information management, personnel attendance, equipment operation monitoring, data analysis, early warning and other functions. The access control management platform can authorize, manage and monitor the access of personnel in specific places by connecting the installed and used access control equipment. The access control management platform is widely used in public places, enterprises, communities, government agencies, schools and other places.
[0023] Fine entrance and exit management: It is a more strict and fine entrance and exit management scheme compared with the traditional one which only manages the entrance and exit according to whether it has the access right. Fine entrance and exit management can effectively control behaviors such as multiple verification and authentication in the same direction, entering and exiting on behalf of others, not passing after verification and authentication, conflict of two-way verification and authentication, tailing, and reverse intrusion.
[0024] Reading equipment: It is a device in the access control equipment for reading the identity information of the person to be passed, including all reading equipment that can read access control cards, two-dimensional codes, faces, irises, fingerprints, etc.
[0025] Passage detection component: a component in the access control device for detecting the passage of a person from the access control device. Unlike the reading device capable of identifying the person, the passage detection component can only detect the passage of a person from the access control device, but cannot identify the person passing through the access control device. For example, the passage detection component can be composed of a group of infrared emitters and infrared receivers. The infrared emitters are used to continuously emit infrared signals to the infrared receivers, and the light path of the infrared signals emitted by the infrared emitters is located on the passage of the person from the access control device. When no one passes through the access control device, the infrared receiver can normally receive the infrared signal. When a person passes through the access control device, the infrared receiver will not be able to normally receive the infrared signal due to the blocking of the person. When the person passes through the access control device, the infrared receiver will again be able to normally receive the infrared signal. Therefore, whenever the infrared receiver appears normally receiving signal → unable to receive signal → normally receiving signal, it can be considered that a person has passed through the access control device.
[0026] Communication component: the communication component in the present application refers to any component capable of realizing communication between the access control device and the controller. The communication component is used to send an authentication request and passage information to the controller according to the person identified by the reading device and the person detected by the passage detection component. The authentication request and passage information will be described in detail in the method embodiment section below, and will not be described here. The controller in the present application can be integrated in the access control device, or can be independent of the access control device. For example, the controller in the present application can be integrated in the aforementioned access control management platform. Moreover, the controller in the present application can be a physical controller, or a logical controller composed of multiple distributed control units. According to the type of the controller, the communication component library can be a component for realizing internal communication, external limited communication or external wireless communication, which is not limited in the present application.
[0027] Access control device: applied to the entrance and exit of some area, used for managing the personnel entering and exiting the area. Its essence is a kind of passage blocking device, which realizes the blocking / allowing of the passage of personnel through the aforementioned gate machine, and is used to form a controlled area and an uncontrolled area. Therefore, the passage direction is divided into two cases, one is the direction from the uncontrolled area to the controlled area, and the other is the direction from the controlled area to the uncontrolled area. Therefore, the passage direction can be marked by the passage identifier, so as to be identified by the controller. The access control device in the present application is provided with a reading device, a passage detection component and a communication component at the entrance and the exit.
[0028] In the related art, when the entrance and exit are managed, the personnel access is only limited according to the personnel authority, but this can make the authorized personnel repeatedly authenticate by using the authority, and the security is not high, and the foregoing fine entrance and exit management requirement cannot be met. For example, the authorized personnel A first authenticates to make the access control open, and let the non-authorized personnel B pass through the access control, and then the authorized personnel A second authenticates to make the access control open again, and pass through the access control by himself, thereby causing the authorized personnel A and the non-authorized personnel B to pass through the access control together.
[0029] Therefore, the embodiments of the present application provide a method for managing access control, which is applied to a controller connected with at least one access control device, and the controller pre-stores authentication requests and passing information sent by each access control device, the authentication request is used to indicate the personnel requesting to pass through the access control device and the passing method, and the passing information is used to indicate the personnel passing through the access control device and the passing direction.
[0030] As shown in the method, the method comprises the following steps. Figure 1
[0031] S101, in response to a first authentication request sent by a first access control device, storing the first authentication request and identifying the personnel and the passing direction indicated by the first authentication request as a first personnel and a first passing direction.
[0032] S102, determining whether the first personnel has a preset prohibited passing behavior according to the pre-stored authentication request and passing information.
[0033] S103, if not, sending a passing permission instruction to the first access control device to make the first access control device allow the first personnel to pass.
[0034] S104, in response to first passing information sent by the first access control device, recording the first passing information.
[0035] In the embodiments of the present application, the authentication request is recorded when the personnel to be passed requests to pass, and the passing information is recorded after the personnel to be passed passes, and the passing direction is recorded in both the authentication request and the passing information, and under normal circumstances, the personnel should request to pass before actually passing when passing through the access control, and under normal circumstances, the passing direction of the personnel passing through the access control should be alternately in and out, therefore, the personnel's passing behavior can be determined to be normal or not by combining the authentication request and the passing information, and the personnel with abnormal passing behavior can be effectively prevented from passing.
[0036] The foregoing S101-S104 will be described in detail below.
[0037] In S101, the first access control device can be an access control device integrated with a controller, or an access control device not integrated with a controller. Because the access control devices are communicatively connected, they can interact with each other. When the first access control device is an access control device integrated with a controller, the first access control device sends the first authentication request to the controller integrated in the first access control device; when the first access control device is not an access control device integrated with a controller, the first access control device sends the first authentication request to an access control device integrated with a controller, so that the controller integrated in the access control device responds to the first authentication request.
[0038] The first authentication request is sent by the access control device after determining that the person to be passed has the passing right after the right authentication of the person to be passed. How to send the first authentication request will be described in detail later, and will not be described in detail here. The first authentication request includes the personnel information of the person to be passed and the requested passing direction. The personnel information herein can refer to any information capable of uniquely identifying a person, including but not limited to: the number of the person, the card number of the access control card held by the person, the work number of the person, etc.
[0039] The access control device is configured with a recognition device. For an access control device allowing bidirectional passing, two recognition devices are configured on the access control device, and the two recognition devices are respectively arranged at the entrance and exit of the access control device. Then, the passing direction requested by the person to be passed can be determined by the recognition device triggering the authentication request. For example, if the recognition device triggering the authentication request is the recognition device arranged at the entrance of the access control device, the passing direction requested by the person to be passed is entering, and if the recognition device triggering the authentication request is the recognition device arranged at the entrance of the access control device, the passing direction requested by the person to be passed is leaving.
[0040] The first person is a person to be passed. In order to distinguish from other persons requesting or passing through the access control device in the following, the first person is referred to as the first person herein. The first passing direction is the passing direction requested by the first person. It can be understood that at this time, the first person only requests to pass through the access control device along the first passing direction, and actually has not passed through the access control device.
[0041] In S102, the controller pre-stores the authentication request and the passing information sent by each access control device. The authentication request is generated when the person to be passed needs to pass but has not passed successfully, and the passing information is generated after passing successfully.
[0042] If the first person exists the preset prohibited passing behavior, it means that the first person cannot pass; if the first person does not exist the preset prohibited passing behavior, it means that the first person can pass.
[0043] The preset forbidden passing behavior in the present disclosure includes a repeated passing behavior. The repeated passing behavior refers to that when a passageway is already being passed by a person, other persons pass through the passageway. Specifically, the other persons can pass in the same direction as the person or in the opposite direction of the person. The repeated passing behavior includes single-passageway repeated authentication passing and multi-passageway repeated authentication passing. The judgment method of the repeated passing behavior will be described in detail below, and thus will not be described herein again.
[0044] In S103, the controller sends a passing permission instruction to the first access control device after determining that the first person does not have the preset forbidden passing behavior, so that the first access control device opens the gate to allow the first person to pass after receiving the passing permission instruction.
[0045] In S104, the first access control device sends first passing information to the controller after the first person passes, so as to record the passing of the first person this time, and to determine whether the first person has the preset forbidden passing behavior based on the passing information and the authentication request in subsequent passing.
[0046] The judgment method of the foregoing repeated passing behavior will be described below.
[0047] The repeated passing behavior in the present disclosure refers to continuous entering a certain area or continuous leaving a certain area. For example, a person requests to enter a park at 9:00 on January 1st, and the person requests to enter the park again at 12:00 on January 1st. During this period, the person does not have the behavior of leaving the park. At this time, the person has the repeated passing behavior. Another example is that a person requests to enter a park through an access control device 1 at 9:00 on January 1st, and the person enters the park through an access control device 2 at 9:01 on January 1st. At this time, the person cannot enter the park through two different access control devices, and thus has the repeated passing behavior. It can be understood that, under normal circumstances, a person enters an area and then leaves the area before entering the area again. Therefore, if the person has the repeated passing behavior, it means that the passing behavior of the person is abnormal, and the person may have the behavior of authenticating the identity of another person or abnormally entering the area. Therefore, in this case, the entering and leaving of the person are abnormal, and the person can be forbidden to pass.
[0048] In the embodiments of the present application, there is a corresponding relationship between the authentication request and the access information, which is used to uniquely correspond the authentication request and the access information. In this way, one access information can be uniquely determined according to the authentication request. For example, each time a person wants to enter an area, when the personnel information and the personnel authority are verified, an authentication request is generated, and when the personnel access is successful, an access information is generated. Assuming that personnel A requests to enter a park at 9 o'clock on January 1st, an authentication request 1 is generated after verification, an access information 1 is generated after successful access, and requests to exit the park at 10 o'clock on January 1st, an authentication request 2 is generated after verification, and an access information 2 is generated after successful access. Among them, the authentication request 1 corresponds to the access information 1, and the authentication request 2 corresponds to the access information 2. The authentication request also includes time information, so according to the corresponding relationship and the time information, it can be known that the authentication request corresponds to the access information when the personnel A enters and exits the area.
[0049] In the present application, according to the pre-stored authentication request and access information, it is determined whether the first personnel has a preset prohibited access behavior. The current access time authentication request of the to-be-access personnel can be determined according to the pre-stored authentication request, and then the access information corresponding to the last access time at the current access time is found. The access direction corresponding to the current access time authentication request is found in the access information, and it is found that the last access is normal access and the current access direction is from the controlled area to the uncontrolled area. Then the last access direction should be from the uncontrolled area to the controlled area. If the access directions of the two times are the same, it means that it is repeated access, that is, there is a preset prohibited access behavior.
[0050] However, each time the current authentication request corresponding access information is searched from the authentication request and the access information, the search efficiency is not high because the recorded authentication requests are very many.
[0051] In order to improve the search efficiency, the authentication request will be deleted after each successful access. In this way, the current access authentication request is always the authentication request as long as there is an authentication request, and the efficiency can be improved.
[0052] Specifically, after the controller receives the first access information sent by the first access control device in S104, the method further includes:
[0053] S105, deleting the first authentication request.
[0054] In this step, once the to-be-access personnel successfully access, the authentication request will be recorded as access information, and the authentication request will not exist. Therefore, when the controller receives the first access information, it has already successfully accessed, and at this time the first authentication request will be deleted.
[0055] Based on this, for the case of single-channel repeated authentication access, the determination in S102 whether the first person has the preset prohibited access behavior according to the pre-stored authentication request and access information includes:
[0056] S1021, if the controller does not store the authentication request of the first person, determine the second access direction of the first person in the access information.
[0057] In this step, since the authentication request is deleted after each successful access, there is no authentication request of the first person in the controller after each successful access, that is, there is no authentication request in the controller, which means that the first person is only performing access verification on the first access control device at this time, and the first person does not perform authentication on other access control devices. The second access direction of the first person determined in the access information is the access direction when the first person accessed last time before the current access.
[0058] S1022, if the first access direction is the same as the second access direction, determine that the first person has the preset prohibited access behavior.
[0059] In this step, the first access direction and the second access direction are the same, that is, the current access direction and the last access direction are the same, which is obviously not a compliant access. Normally, when a person enters and exits, it should be one in and one out, that is, the current access direction and the last access direction are different. Therefore, for non-compliant access, the first person should be determined to have the preset prohibited access behavior.
[0060] In another possible embodiment, for the case of multi-channel repeated authentication access, the determination in S102 whether the first person has the preset prohibited access behavior according to the pre-stored authentication request and access information further includes:
[0061] S1023, if the controller pre-stores an authentication request for indicating the first person, determine that the first person has the preset prohibited access behavior.
[0062] In this step, since the authentication request is deleted after each successful access, there is no authentication request of the first person in the controller after each successful access. The controller has an authentication request, which means that the first person performs access verification on other access control devices in addition to the first access control device, that is, there is a repeated access situation.
[0063] Therefore, if the controller pre-stores an authentication request for indicating the first person, it is determined that the first person has the preset prohibited access behavior.
[0064] There is a case that the first person is authenticated successfully, but fails to pass through due to various reasons, and the controller still stores the authentication request of the first person, which will exist all the time because of the failure to pass through, and the authentication request has no corresponding pass information. In order to not affect the normal passing of the first person, the above method further comprises:
[0065] S106, if no first pass information sent by the access control device is received within a preset time period since the sending of the pass instruction, the first authentication request is deleted, and first abnormal event information indicating that the first person fails to pass through the first access control device is recorded.
[0066] In this step, pass information corresponding to the authentication request is generated every time the pass is successful. No pass information is generated if the pass is not successful.
[0067] If no first pass information sent by the access control device is received within a preset time period, it indicates that the first person fails to pass through.
[0068] In this embodiment, if no first pass information sent by the access control device is received within a preset time period since the sending of the pass instruction, the first authentication request is deleted, so that the first authentication request is not mistaken as an authentication request sent by a different access control device in the next pass authentication, and is determined as repeated authentication, i.e. determined as the preset prohibited pass behavior, thereby improving user experience.
[0069] In actual passing process, some people will use the authority of the authorized person to forcibly pass through during the passing process of the authorized person, thereby causing problems in the safety of the controlled area.
[0070] In this embodiment, the access control device provides a pre-warning mode selection for determining the strength of the current access control management. When the pre-warning mode is selected, it indicates that the access control management is relatively strong, and only the authenticated person is allowed to pass through, and any unauthorized person forcibly passing through is prevented. When the pre-warning mode is not selected, it indicates that the access control management is relatively weak, and the authenticated person is allowed to pass through, and any unauthorized person forcibly passing through is allowed.
[0071] Specifically, the above method further comprises:
[0072] S107, if the first access control device is in the pre-warning mode, and detection information sent by the first access control device when detecting the second person is received during the passing process of the first person, a closing instruction is sent to the first access control device to prevent the second person from passing through during the passing process of the first person.
[0073] In this step, the first personnel passing process refers to the period from when the first personnel is allowed to pass to when the passing information is finally received, during which the first access control device detects that only one person is passing. The first access control device can determine that only one person is passing during this period by taking pictures through a camera, or an infrared device can be configured on the passage to determine that only one person is passing during this period.
[0074] The detection information of the second person refers to the information sent by the first access control device to the controller to remind the controller that there are other people passing during the first personnel passing process after the first access control device detects the second person.
[0075] The second person here is not limited in number and can be one or more.
[0076] When the controller receives the detection information, it means that there are other people during the first personnel passing process. For example, the second person can follow the first person to pass, or the second person can break in from the opposite direction of the first person's passing direction (without passing authentication).
[0077] During the first personnel passing process, even if there are second persons who need to pass normally, they also need to go through the passing process after the first personnel passes. That is, during the first personnel passing process, the controller will not receive any authentication request.
[0078] During the first personnel passing process, if there are second persons who need to pass normally, the first access control device will give a voice prompt: "Someone is passing, please wait!", if the second person is in the opposite direction of the first person's passing direction, it will prompt: "The opposite side is passing, please wait!"
[0079] S108, if the first access control device is not in the pre-warning mode, and during the first personnel passing process, the detection information sent by the first access control device when detecting the second person is received, the second abnormal event information indicating that there are other people passing during the first personnel passing process is recorded after the first personnel passes.
[0080] In this embodiment, the access control device can select a pre-warning mode of access control management, and different operations are performed on the second person passing during the first personnel passing process according to different pre-warning modes, so that different management efforts can be selected according to actual application scenarios, and the applicability of access control management is improved.
[0081] The embodiment of the present application further provides a door access management method, which is applied to a first door access device, a controller is connected with at least one door access device, the first door access device is any one of the at least one door access device, and a reading device, a passing detection component and a communication component are arranged at the entrance and the exit of each door access device respectively, the reading device is used for identifying a person requesting to pass through the door access device, the passing detection component is used for detecting the person passing through the door access device, and the communication component is used for sending an authentication request and passing information to the controller according to the person identified by the reading device and the person detected by the passing detection component, the controller pre-stores the authentication request and the passing information sent by each door access device, the authentication request is used for representing the person requesting to pass through the door access device and the passing direction, and the passing information is used for representing the person passing through the door access device and the passing direction. The method comprises the following steps:
[0082] S201, in response to the reading device identifying a first person, determining a passing direction requested by the first person as a first passing direction according to the position where the reading device is arranged;
[0083] S202, sending a first authentication request representing the first person and the first passing direction to the controller through the communication component, so that the controller stores the first authentication request and identifies the first person and the first passing direction represented by the first authentication request in response to the first authentication request sent by the first door access device; determining whether the first person has a preset prohibited passing behavior according to the pre-stored authentication request and passing information; if not, sending a passing permission instruction to the first door access device;
[0084] S203, in response to the passing permission instruction, allowing the first person to pass; and in response to the passing detection component detecting that the person passes through the first door access device along the first passing direction, sending first passing information representing the first person and the first passing direction to the controller through the communication component, so that the controller records the first passing information in response to the first passing information sent by the door access device.
[0085] In this step, the execution process of the controller is the same as that of S101-S104, and thus is not described in detail.
[0086] When the person to be passed enters the detection area of the door access device, the door access device is triggered, and the door access device sends the first authentication request to the controller after receiving the trigger instruction.
[0087] Specifically, S201 can comprise the following steps.
[0088] S2011, in response to the reading device identifying the person to be passed, identifying personnel information of the person to be passed, and verifying the person to be passed and the passing right of the person to be passed.
[0089] In this step, the to-be-passing personnel enters the detection area of the access control device, and the reading device identifies the to-be-passing personnel, and the to-be-passing personnel is the first personnel in the above.
[0090] In S2012, if the to-be-passing personnel is qualified and has passing permission, a first authentication request is sent to the controller.
[0091] In the embodiment of the application, whether the first personnel has a preset prohibited passing behavior is determined by the authentication request and the passing information. Since the passing information is recorded after the to-be-passing personnel passes, the passing behavior of the to-be-passing personnel can be audited based on the passing record, thereby avoiding repeated authentication of the same passing personnel and realizing fine management.
[0092] The application also provides an access control management system, which comprises a controller and a first access control device. The controller is connected with at least one access control device, and the first access control device is any one of the access control devices. A reading device, a passing detection component, and a communication component are respectively arranged at the entrance and the exit of each access control device. The reading device is used to identify personnel requesting to pass the access control device. The passing detection component is used to detect personnel passing the access control device. The communication component is used to send an authentication request and passing information to the controller according to the personnel identified by the reading device and the personnel detected by the passing detection component. The controller pre-stores the authentication request and the passing information sent by each access control device. The authentication request is used to represent personnel requesting to pass the access control device and a requested passing direction. The passing information is used to represent personnel passing the access control device and a passing direction. Wherein,
[0093] The first access control device is used to determine the passing direction requested by the first personnel as a first passing direction according to the position where the reading device is arranged in response to the reading device identifying the first personnel. A first authentication request representing the first personnel and the first passing direction is sent to the controller through the communication component. The first access control device is any one of the access control devices.
[0094] The controller is used to store the first authentication request and identify the first personnel and the first passing direction represented by the first authentication request in response to the first authentication request. Whether the first personnel has a preset prohibited passing behavior is determined according to the pre-stored authentication request and passing information. If not, a passing permission instruction is sent to the first access control device.
[0095] The first access control device is also used to allow the first personnel to pass in response to the passing permission instruction, and send first passing information representing the first personnel and the first passing direction to the controller through the communication component in response to the passing detection component detecting that the personnel passes the first access control device along the first passing direction.
[0096] The controller is also used to record the first passing information in response to the first passing information.
[0097] As Figure 2a shown, a schematic diagram of a gate management system framework provided by an embodiment of the present application. In the embodiment of the present application, the gate device is configured with a reading device, which is used to identify the personnel information of the to-be-passing personnel when the to-be-passing personnel enters the exit detection area or the entrance detection area. For two different passing directions, the gate device can be configured with two reading devices, so that the passing direction can be determined according to the number of the reading device. In the system, a plurality of gate devices are communicatively connected between each other and can interact through a network. The gate device configured with a controller is referred to as a server-side gate device, and the other gate devices are referred to as client-side gate devices. The gate device controls the access of personnel through a gate control board, and the gate control board and the reading device communicate internally.
[0098] The above system further includes a platform end for implementing gate device management, personnel information management, and entrance and exit event management. The entrance and exit event is the behavior of the to-be-passing personnel passing through the gate device.
[0099] In actual application, the actual scene of personnel passing through the foregoing gate management method into a certain area mainly includes the following eight entrance and exit scene processing logics:
[0100] 1. Authorized personnel authentication passing
[0101] A personnel authenticates at the non-controlled area side of a certain gate (a gate on a gate device), and after the authentication is passed, a prompt of “authentication passed, please pass” is given, the gate is opened, the A personnel passes through the gate and enters the controlled area. The A personnel in the controlled area authenticates at the controlled area side of a certain gate, and after the authentication is passed, a prompt of “authentication passed, please pass” is given, the gate is opened, and the A personnel passes through the gate and enters the non-controlled area.
[0102] In the embodiment of the present application, the gate management system further includes an audio device for giving voice prompts during personnel passing. The authentication passed means that the personnel passes the personnel information, the personnel passing right, and the absence of a preset prohibited passing behavior, and can pass.
[0103] 2. Non-authorized personnel authentication passing
[0104] The A personnel authenticates at the non-controlled area side of a certain gate, and after the authentication fails, a prompt of “authentication failed, no right” is given, and the gate is not opened. The A personnel authenticates at the controlled area side of a certain gate, and after the authentication fails, a prompt of “authentication failed, no right” is given, and the gate is not opened.
[0105] The authentication failure includes at least one of the following: the personnel information does not pass, and the personnel passing right does not pass. The authentication failure described above refers to that the personnel passing right of the A personnel does not pass.
[0106] 3. Single-channel repeated authentication access for authorized personnel
[0107] Under the single-gate channel, A personnel is authenticated at the gate, and after the authentication is passed, the personnel attempts to let B personnel pass through. After B personnel enters, when A personnel is authenticated again, the authentication fails, and a prompt "Repeated access, please contact the administrator" is given. This can prevent personnel from using the existing authorization to authenticate multiple times in the same channel to allow unauthorized personnel to enter the controlled area. The above authentication failure refers to the pre-set prohibited access behavior of A personnel.
[0108] 4. Multi-channel repeated authentication access for authorized personnel
[0109] Under the multi-gate channel, A personnel is authenticated at gate channel one, and after the authentication is passed, the A personnel quickly authenticates at the non-controlled area side of gate channel two, and the authentication fails, with a prompt "Already authenticated in other channels". This can prevent personnel from using multiple face scans in different channels to allow unauthorized personnel to enter the controlled area. The above authentication failure refers to the pre-set prohibited access behavior of A personnel.
[0110] 5. Authorized personnel verification passed without access
[0111] A personnel is authenticated at a certain gate channel and the authentication is passed. After the gate is opened, the A personnel does not access, and after the access time is exceeded, the gate is closed. At this time, the system does not report an attendance event and an access event, but reports an abnormal event containing the information of the personnel. After the gate is closed, the A personnel still has the permission to open the door and access. This can manage personnel access according to the actual access situation of the personnel, rather than judging according to the authorization verification result only, which is more humanized.
[0112] 6. Reverse intrusion access
[0113] The system provides an optional warning mode. If the warning mode is turned on, A personnel is authenticated at the gate entry and the authentication is passed. After the gate is opened, B personnel enters the channel from the opposite direction of the gate exit (the opposite direction of A personnel). At this time, the gate is immediately closed. After B personnel exits, the gate is opened again to wait for A personnel to access. This can prevent personnel from entering the controlled area in the opposite direction, and at the same time, avoid the situation of repeated authentication of authorized personnel after the gate is closed due to reverse intrusion.
[0114] 7. Tail access
[0115] The system provides an optional warning mode. If the warning mode is turned on, A personnel is authenticated at the gate entry and the authentication is passed. After the gate is opened, B personnel follows A personnel to enter the gate channel. At this time, the gate is immediately closed. This can prevent unauthorized personnel from following authorized personnel to enter the controlled area.
[0116] The system provides an optional early warning mode. If the early warning mode is closed, the tailing will not immediately close the gate.
[0117] 8. Two-way simultaneous authentication of authorized personnel
[0118] When A and B personnel enter and exit in the same channel, A personnel enter in the direction of the gate, and B personnel exit in the direction of the gate. Two people are authenticated at the same time, but A personnel are identified first. A personnel side prompts: "authentication passed, please pass". B personnel side prompts: "pass on the opposite side, please wait". When A personnel complete the passage, B personnel can normally authenticate and pass. It is interactive and friendly, improves experience, and avoids the situation of "narrow road, brave wins".
[0119] For the above eight scenarios, as shown in Figure 2b , it is a general flowchart for authentication and passage on the client access control device.
[0120] The specific implementation process includes:
[0121] "Authorized personnel authentication passage"
[0122] Personnel authenticate on the reading device of the client access control device. The reading device will transmit personnel information to the client access control device mainboard. After the client access control device mainboard receives the personnel information, it first acquires the reading device number that is currently passing. If there is no reading device number that is currently passing, it compares the personnel information, judges whether the personnel information has passage authority. If the personnel information has passage authority, it further packs the personnel information, client access control device information and reading device information into a first authentication request, and sends the first authentication request to the server access control device through the network.
[0123] After the server access control device receives the first authentication request, the controller of the server access control device first searches in the cache authentication request whether there is an authentication request. If there is no authentication request, it further searches the personnel information in the passage information database. If the personnel information is not searched, it means that it is the first authentication, and temporarily records the first authentication request and returns the authentication success data to the client access control device. If the personnel information is searched, it means that it is not the first authentication, and further judges the access control device information and reading device information recorded in the database. If the authentication passage direction of the last time is different from the current authentication direction, temporarily record the first authentication request and return the authentication success data to the client access control device. After the client access control device receives the authentication success information sent by the server, it sends the authentication success result to the access control device, and the access control device prompts "authentication passed, please pass", and controls the gate to open, waiting for the pedestrian to pass.
[0124] The client access control device detects the pedestrian passing from the authentication direction side, the gate of the client access control device is closed, and the personnel passing information is sent to the server access control device through the network; the server access control device receives the personnel passing information of the client access control device, and then records the authentication request update to the passing information database.
[0125] “Non-authorized personnel authentication passing”
[0126] The personnel authenticates on the reading device of the client access control device, and the reading device transmits the personnel information to the client access control device main control board; the client access control device main control board receives the personnel information, first acquires the reading device number that is passing, and if there is no reading device number that is passing, personnel information comparison is performed to determine whether the personnel information has passing authority.
[0127] If the personnel information has no passing authority, the authentication failure result is sent to the access control device, and the access control device prompts “authentication failure, no authority”.
[0128] “Authorized personnel single channel repeated authentication passing”
[0129] The personnel authenticates on the reading device of the client access control device, and the reading device transmits the personnel information to the client access control device main control board; the client access control device main control board receives the personnel information, first acquires the reading device number that is passing, and if there is no reading device number that is passing, personnel information comparison is performed to determine whether the personnel information has passing authority. If the personnel information has passing authority, the personnel information, client access control device information and reading device information are packaged into a first authentication request, and the first authentication request is sent to the server access control device through the network.
[0130] After the server access control device receives the first authentication request, it first searches the authentication request cache temporarily stored in the server access control device to determine whether there is an authentication request. If there is no authentication request, the personnel information is further searched in the passing information database. After the personnel information is searched, it is further determined whether the access control device information and the reading device information recorded in the database are the same as the last authentication passing direction and the current authentication direction, which indicates repeated authentication passing. The server access control device returns authentication failure data to the client access control device. After the client access control device receives the authentication failure information sent by the server, the authentication failure result is sent to the access control device, and the access control device prompts “repeated passing, please contact the administrator”.
[0131] “Authorized personnel multi-channel repeated authentication passing”
[0132] The personnel authenticates on the reading device of the client access control device, and the reading device transmits the personnel information to the main control board of the client access control device. After the main control board of the client access control device receives the personnel information, the reading device number of the personnel currently passing is acquired. If there is no reading device number of the personnel currently passing, the personnel information is compared, and whether the personnel information has the passing right is judged. If the personnel information has the passing right, the personnel information, the client access control device information and the reading device information are packaged into a first authentication request, and the first authentication request is sent to the server access control device through the network.
[0133] After the server access control device receives the first authentication request, whether there is an authentication request in the authentication request buffer temporarily stored in the server access control device is searched. If there is an authentication request, it is indicated that the personnel has been authenticated in other channels and has not passed. The server access control device returns the data of authentication failure to the client access control device. After the client access control device receives the authentication failure information sent by the server, the result of authentication failure is sent to the access control device, and the access control device prompts that the personnel has been authenticated in other channels.
[0134] “the personnel with the passing right has not passed after the verification”
[0135] The personnel authenticates on the reading device of the client access control device, and the reading device transmits the personnel information to the main control board of the client access control device. After the main control board of the client access control device receives the personnel information, the reading device number of the personnel currently passing is acquired. If there is no reading device number of the personnel currently passing, the personnel information is compared, and whether the personnel information has the passing right is judged. If the personnel information has the passing right, the personnel information, the client access control device information and the reading device information are packaged into a first authentication request, and the first authentication request is sent to the server access control device through the network.
[0136] After the server access control device receives the first authentication request, whether there is an authentication request in the authentication request buffer temporarily stored in the server access control device is searched. If there is an authentication request, it is indicated that the personnel has been authenticated in other channels and has not passed. The server access control device returns the data of authentication failure to the client access control device. After the client access control device receives the authentication failure information sent by the server, the result of authentication failure is sent to the access control device, and the access control device prompts that the personnel has been authenticated in other channels.
[0137] The client access control device has not detected pedestrian access, and the client access control device will control the gate to close after reaching the access timeout time. Similarly, the server access control device has not received the pedestrian access information from the client access control device, and the previously stored authentication request will be cleared after reaching the access timeout time, so that the next authentication of the personnel can still pass. Finally, an abnormal event of access timeout containing personnel information is reported to the platform.
[0138] “Reverse intrusion access”
[0139] The personnel authenticate on the reading device of the client access control device, and the reading device transmits the personnel information to the client access control device mainboard. After receiving the personnel information, the client access control device mainboard first acquires the reading device number that is currently passing, and if there is no reading device number that is currently passing, the personnel information is compared to determine whether the personnel information has access permission. If the personnel information has access permission, the personnel information, client access control device information and reading device information are packaged into a first authentication request, and the first authentication request is sent to the server access control device through the network.
[0140] After the server access control device receives the first authentication request, it first searches the authentication request cache temporarily stored in the server access control device to determine whether there is an authentication request. If there is no authentication request, the personnel information is searched in the database of access information. If the personnel information is not searched, it means that it is the first authentication, and the first authentication request is temporarily recorded and the authentication success data is returned to the client access control device. If the personnel information is searched, it means that it is not the first authentication, and the access control device information and reading device information recorded in the database are further judged. If the last authentication access direction is different from the current authentication direction, the first authentication request is temporarily recorded and the authentication success data is returned to the client access control device. After the client access control device receives the authentication success information sent by the server, the authentication success result is sent to the access control device, the access control device prompts “authentication passed, please access”, and controls the gate to open, waiting for the pedestrian to pass.
[0141] The client access control device detects that the personnel enters the gate from the opposite direction, and further judges whether the warning mode is currently enabled. If the warning mode is currently enabled, the gate is immediately closed, and when all the personnel in the channel exit, the gate is opened again to wait for the personnel with permission to pass from the authentication direction. If the warning mode is not currently enabled, the gate will only sound and light alarm, and the gate will not be closed after the reverse access, waiting for the personnel with permission to pass from the authentication direction. Finally, an abnormal event of reverse intrusion is reported to the platform.
[0142] “Tail access”
[0143] The personnel is authenticated on the reading device of the client access control device, and the reading device transmits the personnel information to the main control board of the client access control device. After receiving the personnel information, the main control board of the client access control device first acquires the reading device number that is currently passing, and if there is no reading device number that is currently passing, the personnel information is compared, and it is judged whether the personnel information has a passing right. If the personnel information has a passing right, the personnel information, the client access control device information and the reading device information are further packaged into a first authentication request, and the first authentication request is sent to the server access control device through the network.
[0144] After receiving the first authentication request, the server access control device first searches the authentication request cache temporarily stored in the server access control device to check whether there is an authentication request. If there is no authentication request, the personnel information is further searched in the database of passing information. If the personnel information is not searched, it is indicated that it is the first authentication, and the first authentication request is temporarily recorded and the data of authentication success is returned to the client access control device. If the personnel information is searched, it is indicated that it is not the first authentication, and the access control device information and the reading device information recorded in the database are further judged. If the passing direction of the last authentication is different from the passing direction of the current authentication, the first authentication request is temporarily recorded and the data of authentication success is returned to the client access control device. After receiving the authentication success information sent by the server, the client access control device sends the result of authentication success to the access control device, and the access control device prompts "authentication passed, please pass" and controls the gate to be opened to wait for the pedestrian to pass.
[0145] During the passing of the personnel by the client access control device, the tailing passing is detected, and it is further judged whether the early warning mode is currently started. If the early warning mode is currently started, the gate is immediately controlled to be closed, the tailing personnel is blocked outside the passage, and the personnel with the right can pass normally. If the early warning mode is not currently started, only the sound and light alarm is performed, and the personnel passing is not controlled. After the personnel passes, the gate is closed, the passing information of the personnel is sent to the server access control device through the network, and after receiving the personnel passing information of the client access control device, the server access control device records the authentication request temporarily stored in the database of passing information. Finally, an abnormal event of tailing alarm is reported to the platform.
[0146] "Two-way simultaneous authentication passing of personnel with right"
[0147] In actual situations, there is no real "simultaneous authentication", even if it is two-way simultaneous authentication, there will always be one before and one after. The system preferentially processes the authentication information of the first authentication side.
[0148] The personnel authenticates on the reading device of the client-side access control device, and the reading device transmits the personnel information to the main control board of the client-side access control device. After receiving the personnel information, the main control board of the client-side access control device first acquires the reading device number of the personnel who is passing through. If there is a reading device number of the personnel who is passing through, it indicates that the personnel who is passing through is authenticating. Further, it is judged whether the reading device number of the personnel who is passing through is consistent with the reading device number of the personnel who is authenticating. If they are inconsistent, it indicates that the personnel who is authenticating is passing through in the opposite direction. The result of authentication failure is transmitted to the access control device, and the access control device prompts “passing through in the opposite direction, please wait”.
[0149] As shown in FIG. 1, it is a schematic diagram of the overall process of authenticating and passing through on the server-side access control device. Figure 2c
[0150] “Personnel with authentication permission authenticates and passes through”
[0151] The personnel authenticates on the reading device of the server-side access control device, and the reading device transmits the personnel information to the main control board of the server-side access control device. After receiving the personnel information, the main control board of the server-side access control device first acquires the reading device number of the personnel who is passing through. If there is no reading device number of the personnel who is passing through, it performs personnel information comparison and judges whether the personnel information has passing-through permission.
[0152] If the personnel information has passing-through permission, it first searches the authentication request cache temporarily stored in the server-side access control device to determine whether there is an authentication request. If there is no authentication request, it further searches the personnel information in the database of passing-through information. If the personnel information is not searched, it indicates that it is the first authentication, and the first authentication request is temporarily recorded. If the personnel information is searched, it indicates that it is not the first authentication, and further, it is judged whether the information of the access control device and the information of the reading device are consistent. If the passing-through direction of the last authentication is different from the passing-through direction of the current authentication, the first authentication request is temporarily recorded. The server-side access control device transmits the result of successful authentication to the access control device, and the access control device prompts “authentication passed, please pass through”. At the same time, the access control device controls the gate to open and waits for the pedestrian to pass through.
[0153] After the server-side access control device detects that the pedestrian passes through from the authentication direction side, the server-side gate is closed, and the temporarily recorded authentication request is updated and recorded in the database of passing-through information.
[0154] “Personnel without authentication permission authenticates and passes through”
[0155] The personnel authenticates on the reading device of the server-side access control device, and the reading device transmits the personnel information to the main control board of the server-side access control device. After receiving the personnel information, the main control board of the server-side access control device first acquires the reading device number of the personnel who is passing through. If there is no reading device number of the personnel who is passing through, it performs personnel information comparison and judges whether the personnel information has passing-through permission.
[0156] The personnel information does not have access permission, and the access control device is prompted with "authentication failure, no permission".
[0157] "Single-channel repeated authentication access for personnel with access permission"
[0158] The personnel authenticates on the reading device of the service-side access control device, and the reading device transmits the personnel information to the main control board of the service-side access control device. After receiving the personnel information, the main control board of the service-side access control device first acquires the reading device number that is currently being accessed. If there is no reading device number that is currently being accessed, the personnel information is compared, and it is determined whether the personnel information has access permission.
[0159] The personnel information has access permission. First, it is searched in the authentication request cache temporarily stored in the service-side access control device whether there is an authentication request. If there is no authentication request, the personnel information is further searched in the database of access information. After the personnel information is searched, it is further determined whether the access control device information and the reading device information recorded in the database are the same as the access direction of the previous authentication and the current authentication direction. If they are the same, it indicates repeated authentication access. The service-side access control device transmits the authentication failure result to the access control device, and the access control device is prompted with "repeated access, please contact the administrator".
[0160] "Multi-channel repeated authentication access for personnel with access permission"
[0161] The personnel authenticates on the reading device of the service-side access control device, and the reading device transmits the personnel information to the main control board of the service-side access control device. After receiving the personnel information, the main control board of the service-side access control device first acquires the reading device number that is currently being accessed. If there is no reading device number that is currently being accessed, the personnel information is compared, and it is determined whether the personnel information has access permission.
[0162] The personnel information has access permission. First, it is searched in the authentication request cache temporarily stored in the service-side access control device whether there is an authentication request. If there is an authentication request, it indicates that the personnel has been authenticated in other channels and has not accessed. The service-side access control device transmits the authentication failure result to the access control device, and the access control device is prompted with "authentication in other channels".
[0163] "Access without access for personnel with access permission after verification"
[0164] The personnel authenticates on the reading device of the service-side access control device, and the reading device transmits the personnel information to the main control board of the service-side access control device. After receiving the personnel information, the main control board of the service-side access control device first acquires the reading device number that is currently being accessed. If there is no reading device number that is currently being accessed, the personnel information is compared, and it is determined whether the personnel information has access permission.
[0165] The personnel information has the access right, first searches whether there is an authentication request in the authentication request cache temporarily stored by the service side access control device, there is no authentication request, then further searches the personnel information in the access information database, no personnel information is searched, which means it is the first authentication, then temporarily records the first authentication request; the personnel information is searched, which means it is not the first authentication, then further judges the access control device information and the reading device information, the last authentication access direction is different from the current authentication direction, and the first authentication request is temporarily recorded. The service side access control device sends the authentication success result to the access control device, the access control device prompts "authentication passed, please access", and controls the gate to open, waiting for the pedestrian to access.
[0166] The service side access control device does not detect the pedestrian access all the time, when the access timeout time is reached, the service side access control device controls the gate to close, and clears the previously temporarily stored authentication request; ensures that the personnel can still access next time. Finally, an abnormal event of access timeout containing personnel information is reported to the platform.
[0167] "Reverse break-in access"
[0168] The personnel authenticates on the reading device of the service side access control device, and the reading device transmits the personnel information to the service side access control device main control board; after the service side access control device main control board receives the personnel information, the reading device number of the personnel currently accessing is acquired, there is no reading device number of the personnel currently accessing, then the personnel information is compared, and whether the personnel information has the access right is judged.
[0169] The personnel information has the access right, first searches whether there is an authentication request in the authentication request cache temporarily stored by the service side access control device, there is no authentication request, then further searches the personnel information in the access information database, no personnel information is searched, which means it is the first authentication, then temporarily records the first authentication request; the personnel information is searched, which means it is not the first authentication, then further judges the access control device information and the reading device information, the last authentication access direction is different from the current authentication direction, and the first authentication request is temporarily recorded. The service side access control device sends the authentication success result to the access control device, the access control device prompts "authentication passed, please access", and controls the gate to open, waiting for the pedestrian to access.
[0170] The service side access control device detects that the personnel enters the gate from the opposite direction, further judges whether the early warning mode is currently started. The gate is immediately controlled to close when the early warning mode is currently started, the gate is opened again when the personnel in the channel completely exit, and waits for the personnel with the access right to access from the authentication direction; the gate only performs the sound and light alarm when the early warning mode is not currently started, does not control the personnel access, and does not close the gate after the reverse access, and waits for the personnel with the access right to access from the authentication direction. Finally, an abnormal event of reverse break-in is reported to the platform.
[0171] "Tailgating"
[0172] The personnel is authenticated on the reader of the server-side access control device, and the reader transmits the personnel information to the server-side access control device main control board. After receiving the personnel information, the server-side access control device main control board first obtains the number of the reading device that is passing. If there is no reading device number that is passing, the personnel information is compared to determine whether the personnel information has access authority.
[0173] The personnel information has access rights. First, the authentication request cache temporarily stored in the server-side access control device is searched to see if there is an authentication request. If there is no authentication request, the personnel information is further searched in the access information database. If the personnel information is not retrieved, it means that this is the first authentication, and the first authentication request is temporarily recorded. If the personnel information is retrieved, it means that it is not the first authentication, and the access control device information and the reading device information are further judged. If the direction of the previous authentication is different from the direction of this authentication, the first authentication request is also temporarily recorded. The server-side access control device sends the result of successful authentication to the access control device, and the access control device prompts "Authentication passed, please pass" and controls the gate to open, waiting for pedestrians to pass.
[0174] "Authorized personnel can pass through two-way authentication at the same time"
[0175] A person authenticates on the access control device's reader on the server side, which transmits the person's information to the client access control device's main control panel. After receiving the person's information, the client access control device's main control panel first obtains the ID of the reader currently passing through. If there is already a reader ID currently passing through, it indicates that someone is currently authenticating and passing through the gate. It then determines whether the existing reader ID and the ID of the currently authenticated reader ID are consistent. If they are inconsistent, it indicates that someone is currently authenticating and passing through in the opposite direction. The authentication failure result is sent to the access control device, which then prompts, "The person is passing through from the opposite side. Please wait."
[0176] The above has respectively described how to identify and handle various abnormal events (i.e., preset prohibited passage behaviors) when authenticating on the client access control device and the server access control device. In order to more clearly explain the access control management method provided by this application, the following will illustrate the access control management method provided by this application in combination with personnel, reading devices in access control devices, gates, controllers, and access control management platforms. Figure 2d The access control authentication process shown.
[0177] In this example, the person first triggers the reading device by face recognition, card swiping or fingerprint recognition, etc. to make the reading device identify the person, and request the gate to verify the identified person's credentials to confirm whether the person's identity can pass through the access control device. If it can pass, the verification is successful, at this time the gate requests the controller to verify the person's authority, and executes the access control management method provided by the application to confirm whether the person has a preset prohibited passing behavior. If not, the verification is successful, at this time the controller controls the gate to open to allow the person to pass. The gate opens and feeds back the verification success result to the reading device, so that the reading device reminds the person that the verification is successful and can pass through the access control device.
[0178] After the gate is opened, as shown in Figure 2d There are many possibilities, which will be described below:
[0179] Normal case: the person passes normally, and after confirming that the person passes through the gate, the person's verification passing event, i.e. the real person passing event, is recorded, and the gate uploads the real person passing event to the access control management platform for event statistics as the basis for subsequent authority verification.
[0180] Abnormal case 1: multiple people pass in succession, i.e. a tailing event occurs, at this time the gate will close after the first person passes to prevent the tailing person from passing through the gate. And report the tailing event to the access control management platform for event statistics.
[0181] Abnormal case 2: no person passes, in this application, no person passing means that no person passes through the gate within a preset time after the authority verification is successful. At this time, since no person passes, the passing record will not be updated. And the gate will report the person timeout event to the access control management platform for event statistics.
[0182] Abnormal case 3: the opposite direction of the person's requested passing direction detects a person passing, for example, assuming that the person's requested passing direction is to enter the access control device, if it is detected that a person exits the access control device, it is considered that an abnormal situation exists at this time. It can be understood that if it is detected that a person passes in the opposite direction, it can be considered that a person tries to break into the access control device in the opposite direction when the gate is opened, so the gate can be closed immediately at this time to prevent reverse intrusion, until it is detected that no person passes in the opposite direction, the gate is opened again to allow the person who has passed the authority verification to pass through the access control device. And at this time the gate will also report the reverse intrusion event to the access control management platform for event statistics.
[0183] In addition to the above abnormal handling cases 1-3, the aforementioned authority verification will also fail in the case where the person has a preset prohibited passing behavior. These cases can also be considered abnormal cases. As previously described, the case where the person has a preset prohibited passing behavior includes the following two cases:
[0184] Abnormal case 4: Same direction continuous verification of a person, that is, the passing direction of the person this time is consistent with the passing direction of the person recorded in the communication record last time passing through the access control device, that is, the aforementioned "single-channel repeated authentication passing of authorized personnel" case, which can be seen from the foregoing related description and will not be repeated here. It can be understood that at this time, it can be considered that the person passes through the access control device again to lead other personnel to pass through the access control device, that is, there is a phenomenon of irregularly leading people, so the gate machine will also report the anti-underground return verification failure event to the access control management platform for event statistics.
[0185] Abnormal case 5: Same direction continuous verification of multiple gate machines, that is, the person passes through the access control device at one access control device and does not pass through, and then performs permission verification at another access control device, that is, the aforementioned "multi-channel repeated authentication passing of authorized personnel" case, which can be seen from the foregoing related description and will not be repeated here. It can be understood that at this time, it can be considered that the person attempts to open multiple gate machines at the same time to pass through the access control device with other personnel, that is, there is a phenomenon of irregularly leading people, so the gate machine will also report the anti-underground return verification failure event to the access control management platform for event statistics.
[0186] It can be understood that, as described above, the continuous verification in abnormal cases 4-5 can only be successful for the first time, and subsequent verification cannot be successful.
[0187] Figure 2d The following will be the functions that can be achieved by the access control management method provided by the present application as the dimension to better explain the access control management method provided by the present application.
[0188] Referring to Figure 2e The access control management method provided by the present application can at least achieve the following four functions:
[0189] Function 1: Limit single-channel repeated authentication.
[0190] That is, to prevent personnel from irregularly leading people by means of single-channel repeated authentication, and the single-channel repeated authentication can be seen from the foregoing related description and will not be repeated here.
[0191] Function 2: Limit multi-channel repeated authentication.
[0192] That is, to prevent personnel from irregularly leading people by means of multi-channel repeated authentication, and the multi-channel repeated authentication can be seen from the foregoing related description and will not be repeated here.
[0193] Function 3: Real person real passing determination.
[0194] That is, in the access control management method provided by the present application, the access record is only updated when it is detected that the person has actually passed through the access control device. If the person has not passed through the access control device within a certain period of time after passing through the verification, or if it is detected that there is a reverse rush, the access record will not be updated. This is the basis for realizing the aforementioned function 1 and function 2. For how to realize function 1 and function 2 based on the access record, please refer to the relevant description in the foregoing, which will not be repeated here.
[0195] Function 4: Alert mode.
[0196] That is, the person is prevented from passing through the access control device in the above-mentioned tailing and reverse rush manner. Please refer to the relevant description of the above-mentioned abnormal situation 1 and abnormal situation 3, which will not be repeated here.
[0197] The embodiment of the present application provides an access control management device. The device is applied to a controller, the controller is connected with at least one access control device, the entrance and the exit of each access control device are respectively provided with a recognition device, a passing detection component and a communication component, the recognition device is used for identifying a person requesting to pass through the access control device, the passing detection component is used for detecting the person passing through the access control device, and the communication component is used for sending an authentication request and access information of the person identified by the recognition device and the person detected by the passing detection component to the controller, the controller pre-stores the authentication request and the access information sent by each access control device, the authentication request is used for representing the person requesting to pass through the access control device and the passing direction, and the access information is used for representing the person passing through the access control device and the passing direction.
[0198] As shown in Figure 3 The device comprises an identification module 301, a determination module 302, a passing module 303 and a record module 304. The identification module 301 is used for storing a first authentication request and identifying a person and a passing direction represented by the first authentication request as a first person and a first passing direction in response to the first authentication request sent by a first access control device. The determination module 302 is used for determining whether the first person has a preset prohibited passing behavior according to the pre-stored authentication request and access information. The passing module 303 is used for sending a passing permission instruction to the first access control device to make the first access control device allow the first person to pass if the determination result is negative. The record module 304 is used for recording first access information in response to the first access information sent by the first access control device, wherein the first access information is sent by the first access control device after detecting that the first person passes through the first access control device.
[0199] The embodiment of the application further provides a door access management device, the device is applied to a first door access equipment, a controller is connected with at least one door access equipment, the first door access equipment is any door access equipment in the at least one door access equipment, and a reading equipment, a passing detection component and a communication component are arranged at the entrance and the exit of each door access equipment respectively, the reading equipment is used for identifying personnel requesting to pass through the door access equipment, the passing detection component is used for detecting the personnel passing through the door access equipment, and the communication component is used for sending an authentication request and passing information to the controller according to the personnel identified by the reading equipment and the personnel detected by the passing detection component, the controller pre-stores the authentication request and the passing information sent by each door access equipment, the authentication request is used for indicating the personnel requesting to pass through the door access equipment and the passing direction, and the passing information is used for indicating the personnel passing through the door access equipment and the passing direction.
[0200] The device comprises a sending module, which is used for, in response to the reading equipment identifying the first personnel, determining the passing direction requested by the first personnel as a first passing direction according to the position where the reading equipment is arranged, sending a first authentication request indicating the first personnel and the first passing direction to the controller through the communication component, so that the controller stores the first authentication request and identifies the personnel and the passing direction indicated by the first authentication request in response to the first authentication request, determines whether the first personnel has a preset prohibited passing behavior according to the pre-stored authentication request and passing information, sends a passing permission instruction to the first door access equipment if the first personnel does not have the preset prohibited passing behavior, allows the first personnel to pass through in response to the passing permission instruction, and sends first passing information indicating the first personnel and the first passing direction to the controller through the communication component in response to the passing detection component detecting that the personnel passes through the first door access equipment along the first passing direction, so that the controller records the first passing information in response to the first passing information.
[0201] The embodiment of the application further provides an electronic device, as shown in the figure, comprising: Figure 4
[0202] A memory 401 is used for storing a computer program.
[0203] A processor 402 is used for executing the program stored in the memory 401, and the following steps are implemented:
[0204] In response to the first authentication request sent by the first access control device, the first authentication request is stored, and the personnel and the passing direction represented by the first authentication request are identified as the first personnel and the first passing direction; according to the pre-stored authentication request and passing information, it is determined whether the first personnel has a preset prohibited passing behavior; if not, a passing permission instruction is sent to the first access control device to allow the first personnel to pass through the first access control device; in response to the first passing information sent by the first access control device, the first passing information is recorded, wherein the first passing information is sent by the first access control device after detecting that the first personnel passes through the first access control device.
[0205] Or,
[0206] In response to the first personnel being identified by the identification device, the passing direction requested by the first personnel is determined as the first passing direction according to the position where the identification device is arranged; a first authentication request representing the first personnel and the first passing direction is sent to the controller through the communication component, so that the controller stores the first authentication request and identifies the first personnel and the first passing direction represented by the first authentication request in response to the first authentication request; according to the pre-stored authentication request and passing information, it is determined whether the first personnel has a preset prohibited passing behavior; if not, a passing permission instruction is sent to the first access control device; in response to the passing permission instruction, the first personnel is allowed to pass through the first access control device; and in response to the passing detection component detecting that the personnel passes through the first access control device along the first passing direction, a first passing information representing the first personnel and the first passing direction is sent to the controller through the communication component, so that the controller records the first passing information in response to the first passing information.
[0207] And the above-mentioned electronic device can further include a communication bus and / or a communication interface, and the processor 402, the communication interface and the memory 401 can complete mutual communication through the communication bus.
[0208] The communication bus mentioned in the above-mentioned electronic device can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0209] The communication interface is used for communication between the above-mentioned electronic device and other devices.
[0210] The memory can include a random access memory (RAM) and can also include a non-volatile memory (NVM), such as at least one disk memory. Optionally, the memory can also be at least one storage device located away from the aforementioned processor.
[0211] The processor described above can be a general processor, including a central processing unit (CPU), a network processor (NP), etc.; can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component.
[0212] In yet another embodiment provided in the present application, a computer readable storage medium is also provided, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement the steps of any of the access control management methods described above.
[0213] In yet another embodiment provided in the present application, a computer program product containing instructions, which, when run on a computer, causes the computer to execute any of the access control management methods in the above embodiments.
[0214] In the embodiments described above, all or some of the steps can be implemented by using software, hardware, firmware or any combination thereof. When implemented by using software, all or some of the steps can be implemented in the form of one or more computer programs. The computer program is stored in a computer readable medium, and can be executed by a computer to perform all or some of the steps described above. The computer readable medium can be a computer program product in the form of a memory, such as a read-only memory (ROM), a flash memory, a random access memory (RAM), a programmable read-only memory (PROM) or an electrically programmable read-only memory (EPROM). The computer readable medium can also be a removable storage medium, such as a floppy disk, a flexible disk, an optical disk, a magnetic disk, a memory card or a memory stick. The computer readable medium can also be a computer database, a computer network or a computer server. The computer program can be executed by a computer to perform all or some of the steps described above.
[0215] It should be noted that, in the present document, the terms such as first and second are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply there is any such actual relationship or order between these entities or operations. Also, the terms "comprising", "containing", or any other variant thereof are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements does not include those elements only, but can also include other elements not expressly listed, or also include elements inherent in such process, method, article, or apparatus. Without more limitations, an element defined by the phrase "comprising a" does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0216] Each of the embodiments in the present document is described in a related manner, and the same or similar parts between the embodiments can be referred to each other. Each of the embodiments focuses on the difference from other embodiments. In particular, for the system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the description of the method embodiments.
[0217] The above only describes the preferred embodiments of the present application, and is not used to limit the protection scope of the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A method of managing access to a door, characterized by, The method is applied to a controller connected with at least one access control device, each access control device being provided with a recognition device, a passing detection component and a communication component at its entrance and exit respectively, the recognition device being used to identify a person requesting to pass through the access control device, the passing detection component being used to detect the person passing through the access control device, and the communication component being used to send an authentication request and passing information to the controller according to the person identified by the recognition device and the person detected by the passing detection component, the controller pre-storing authentication requests and passing information sent by each access control device, the authentication request being used to represent a person requesting to pass through the access control device and a passing direction, and the passing information being used to represent a person passing through the access control device and a passing direction; The method comprises: in response to a first authentication request sent by a first access control device, storing the first authentication request and identifying the person and the passing direction represented by the first authentication request as a first person and a first passing direction; determining whether the first person has a preset prohibited passing behavior according to the pre-stored authentication requests and passing information; if not, sending a passing permission instruction to the first access control device to allow the first person to pass through the first access control device; in response to first passing information sent by the first access control device, recording the first passing information, wherein the first passing information is sent by the first access control device after detecting that the first person passes through the first access control device.
2. The method of claim 1, wherein, After the step of recording the first passing information in response to the first passing information sent by the first access control device, the method further comprises: deleting the first authentication request; The step of determining whether the first person has a preset prohibited passing behavior according to the pre-stored authentication requests and passing information comprises: if the controller does not store an authentication request of the first person, determining a second passing direction of the first person in the passing information, wherein the second passing direction is the passing direction of the first person when the first person last passed through the access control device; if the first passing direction is the same as the second passing direction, determining that the first person has a preset prohibited passing behavior.
3. The method of claim 1, wherein, After the step of recording the first passing information in response to the first passing information sent by the first access control device, the method further comprises: deleting the first authentication request; The step of determining whether the first person has a preset prohibited passing behavior according to the pre-stored authentication requests and passing information comprises: if the controller pre-stores an authentication request representing the first person, determining that the first person has a preset prohibited passing behavior.
4. The method of claim 1, wherein, The method further comprises: if no first passing information sent by the first access control device is received after a preset time period from sending the passing permission instruction, deleting the first authentication request and recording first abnormal event information representing that the first person does not pass through the first access control device.
5. The method of claim 1, wherein, The method further comprises: If the first access control device is in the pre-warning mode, and the detection information sent by the first access control device when detecting the second person is received during the first person's passing, a closing instruction is sent to the first access control device to make the access control device prohibit the second person from passing during the first person's passing.
6. The method of claim 5, wherein, The method further comprises: If the first access control device is not in the pre-warning mode, and the detection information sent by the first access control device when detecting the second person is received during the first person's passing, second abnormal event information indicating that other people pass during the first person's passing is recorded after the first person's passing.
7. An access management method characterized by comprising: The method is applied to a first access control device, the first access control device is connected with a controller, the controller is connected with at least one access control device, the first access control device is any one of the at least one access control device, and a recognition device, a passing detection assembly, and a communication assembly are respectively arranged at the entrance and the exit of each access control device. The recognition device is used to identify a person requesting to pass the access control device, the passing detection assembly is used to detect the person passing the access control device, and the communication assembly is used to send an authentication request and passing information of the person identified by the recognition device and the person detected by the passing detection assembly to the controller. The controller pre-stores the authentication request and passing information sent by each access control device. The authentication request is used to indicate the person requesting to pass the access control device and the requested passing direction, and the passing information is used to indicate the person passing the access control device and the passing direction. The method comprises: In response to the recognition device identifying a first person, a passing direction requested by the first person is determined as a first passing direction according to the position where the recognition device is arranged; A first authentication request indicating the first person and the first passing direction is sent to the controller through the communication assembly, so that the controller stores the first authentication request and identifies the first person and the first passing direction indicated by the first authentication request in response to the first authentication request. According to the pre-stored authentication request and passing information, it is determined whether the first person has a preset prohibited passing behavior. If not, a passing permission instruction is sent to the first access control device; In response to the passing permission instruction, the first person is allowed to pass; and in response to the passing detection assembly detecting that a person passes the first access control device along the first passing direction, first passing information indicating the first person and the first passing direction is sent to the controller through the communication assembly, so that the controller records the first passing information in response to the first passing information.
8. An access management system, characterized by comprising: The system comprises a controller and at least one access control device, the controller is connected with the at least one access control device, each access control device is provided with a recognition device, a passing detection component and a communication component at the entrance and the exit respectively, the recognition device is used for identifying a person requesting to pass through the access control device, the passing detection component is used for detecting the person passing through the access control device, and the communication component is used for sending an authentication request and passing information to the controller according to the person identified by the recognition device and the person detected by the passing detection component, the controller pre-stores the authentication request and the passing information sent by each access control device, the authentication request is used for indicating the person requesting to pass through the access control device and the passing direction, and the passing information is used for indicating the person passing through the access control device and the passing direction; wherein, The first access control device is used for determining the passing direction requested by the first person as a first passing direction according to the position where the recognition device is arranged in response to the recognition device identifying the first person, and sending a first authentication request indicating the first person and the first passing direction to the controller through the communication component; wherein the first access control device is any access control device; The controller is used for storing the first authentication request and identifying the first person and the first passing direction indicated by the first authentication request in response to the first authentication request, determining whether the first person has a preset prohibited passing behavior according to the pre-stored authentication request and passing information, and sending a passing permission instruction to the first access control device if not; The first access control device is also used for allowing the first person to pass in response to the passing permission instruction, and sending first passing information indicating the first person and the first passing direction to the controller through the communication component in response to the passing detection component detecting that the person passes through the first access control device along the first passing direction; The controller is also used for recording the first passing information in response to the first passing information.
9. An access management device, characterized by comprising: The device is applied to a controller, the controller is connected with at least one access control device, each access control device is provided with a recognition device, a passing detection component and a communication component at the entrance and the exit respectively, the recognition device is used for identifying a person requesting to pass through the access control device, the passing detection component is used for detecting the person passing through the access control device, and the communication component is used for sending an authentication request and passing information to the controller according to the person identified by the recognition device and the person detected by the passing detection component, the controller pre-stores the authentication request and the passing information sent by each access control device, the authentication request is used for indicating the person requesting to pass through the access control device and the passing direction, and the passing information is used for indicating the person passing through the access control device and the passing direction; The device comprises: An identification module is used for storing a first authentication request and identifying a person and a passing direction indicated by the first authentication request in response to the first authentication request sent by a first access control device, as a first person and a first passing direction; The determining module is configured to determine whether the first person has a preset prohibited access behavior according to the pre-stored authentication request and access information. The access module is configured to send an access permission instruction to the first access control device to allow the first person to access if the first person does not have the preset prohibited access behavior. The recording module is configured to record first access information sent by the first access control device in response to the first access information, wherein the first access information is sent by the first access control device after detecting that the first person accesses the first access control device.
10. An access management device, characterized by comprising: The device is applied to a first access control device, and a controller is connected with at least one access control device. The first access control device is any one of the at least one access control device. An identification device, an access detection component, and a communication component are arranged at an entrance and an exit of each access control device respectively. The identification device is configured to identify a person who requests to pass through the access control device. The access detection component is configured to detect the person who passes through the access control device. The communication component is configured to send an authentication request and access information to the controller according to the person identified by the identification device and the person detected by the access detection component. The controller pre-stores the authentication request and access information sent by each access control device. The authentication request is used to represent the person who requests to pass through the access control device and the requested access direction. The access information is used to represent the person who passes through the access control device and the access direction. The device comprises: The sending module is configured to determine a first access direction requested by a first person according to a position where the identification device is arranged as the first access direction in response to the identification device identifying the first person. The communication component is configured to send a first authentication request representing the first person and the first access direction to the controller to allow the controller to store the first authentication request and identify the first person and the first access direction represented by the first authentication request in response to the first authentication request. The controller is configured to determine whether the first person has a preset prohibited access behavior according to the pre-stored authentication request and access information. The communication component is configured to send an access permission instruction to the first access control device if the first person does not have the preset prohibited access behavior. The first person is allowed to access in response to the access permission instruction. The communication component is configured to send first access information representing the first person and the first access direction to the controller in response to the access detection component detecting that the person passes through the first access control device along the first access direction. The controller is configured to record the first access information in response to the first access information.
11. An electronic device, comprising: The device comprises: A memory is configured to store a computer program. A processor is configured to execute the program stored in the memory to implement the method in any one of claims 1-7.