Intelligent key cabinet authority management method and device, electronic equipment and storage medium
By dynamically generating key permissions by acquiring information from the electronic ticketing system, and combining identity authentication and time verification, the static nature of smart key cabinet permission management is solved, enabling dynamic management of key retrieval and improving security and compliance.
Patent Information
- Application Number
- CN202511400319.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-28
- Publication Date
- 2025-11-21
AI Technical Summary
The current access control system of smart key cabinets is static and cannot be deeply integrated with the operation safety management system, which leads to the private use, abuse or misuse of keys, and makes it impossible to trace the compliance of key access behavior, thus posing a security risk.
By acquiring work tickets or operation tickets from the electronic ticketing system, key access permission configurations are dynamically generated. Combined with identity authentication and time verification, an opening command is generated, and operation logs are recorded and associated with the electronic ticketing system to achieve dynamic management of key access.
It achieves precise matching between key access permissions and work information, ensuring security and compliance, reducing safety risks, and conforming to power operation management standards.
Smart Images

Figure CN120997932A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of data processing, and in particular to an intelligent key cabinet permission management method and device, an electronic device and a storage medium. BACKGROUND
[0002] In industries with extremely high requirements for safety production, such as electric power, petrochemical industry and rail transit, the management of keys (such as keys of power distribution rooms, equipment cabinets and switch boxes) is a crucial link in safety regulations. The traditional mechanical key cabinet management mode has problems such as cumbersome registration procedures, easy recording errors and difficult traceability, and has been gradually replaced by intelligent key cabinets. The intelligent key cabinet of the prior art usually uses biometric identification (such as fingerprint, face), password or IC card technology to manage permissions. The system permissions are generally divided into two levels: one is the cabinet door opening permission, that is, the information of authorized personnel is pre-recorded in the system, and the authorized personnel can open the cabinet door; the other is the taking and placing permission of specific keys, that is, the permission of each key or each key position is set separately, and the authorized personnel can only take and place the specific keys that he has the permission to take and place.
[0003] However, the above prior art solution still has significant defects: the permission management is static and pre-configured. Once a person is granted the taking and using permission of a key, he can take and place the key at any time within the permission validity period (usually long-term validity) without specific reasons. This mode is divorced from specific work tasks and safety approval processes, which can easily lead to private use, abuse or misuse of keys, and cannot forcibly associate the taking and using behavior of the key with specific work tasks, work time and safety measures. When a safety accident or a responsibility dispute occurs, although the system records "who" took away the key "when", it cannot effectively trace "why" the key was taken away, whether the behavior is authorized and related to the current work task, which causes the safety management process to be out of joint and the responsibility division to be still not clear enough, leaving a safety hazard.
[0004] Therefore, there is an urgent need for an intelligent key cabinet solution that can be deeply linked with work safety management system and realize dynamic and task-based permission management to make up for the shortcomings of the prior art. SUMMARY
[0005] The present disclosure provides an intelligent key cabinet permission management method and device, an electronic device and a storage medium, which aims to solve at least one of the above related technical problems.
[0006] According to a first aspect of the present disclosure, an intelligent key cabinet permission management method is provided, comprising:
[0007] obtaining work ticket or operation ticket information from an electronic two-ticket system, the work ticket or the operation ticket information at least including work responsible person, work team members and corresponding key numbers;
[0008] According to the received work ticket or operation ticket information, a key access permission configuration is dynamically generated;
[0009] Identity authentication information of a target user is received;
[0010] The identity of the target user and the current time are verified to be within the permission configuration range of the work ticket or operation ticket information;
[0011] If the verification is passed, an opening instruction is generated to open the storage device where the key corresponding to the key number is located, so that the target user accesses the key corresponding to the key number.
[0012] Optionally, after the key access permission configuration is dynamically generated according to the received work ticket or operation ticket information, the method further comprises:
[0013] When the validity period of the work ticket or operation ticket ends or the ticket state becomes final, the access permission of the target user to the key corresponding to the key number is revoked.
[0014] Optionally, the identity authentication information includes a security key or biometric information, and the biometric information includes at least one of facial information or fingerprint information.
[0015] Optionally, after the storage device where the key corresponding to the key number is located is opened, the method further comprises:
[0016] Identity information of the target user, the key number taken or placed, and operation time stamp are recorded, and an operation log is generated;
[0017] The operation log is stored in association with the corresponding ticket in the electronic two-ticket system.
[0018] Optionally, the method further comprises:
[0019] If the identity authentication of the target user is successful but there is no permission configuration for key access at the current time, an unauthorized access warning information is sent to the system administrator, and opening the cabinet door is refused.
[0020] According to a second aspect of the present disclosure, an intelligent key cabinet permission management device is provided, comprising:
[0021] An acquisition unit is configured to acquire work ticket or operation ticket information from an electronic two-ticket system, the work ticket or operation ticket information including at least work responsible person, work team member, and corresponding key number;
[0022] A generation unit is configured to dynamically generate a key access permission configuration according to the received work ticket or operation ticket information;
[0023] The receiving unit is used to receive the identity authentication information of the target user.
[0024] The verification unit is used to verify the identity of the target user and whether the current time is within the permission configuration range of the work ticket or the operation ticket information;
[0025] An opening unit is used to generate an opening command if the verification is successful, to open the storage device containing the key corresponding to the key number, so that the target user can retrieve the key corresponding to the key number.
[0026] Optional, also includes:
[0027] The revocation unit is used to revoke the target user's access permission to the key corresponding to the key number when the validity period of the work ticket or operation ticket expires or the ticket status becomes terminated, after dynamically generating the key access permission configuration based on the received work ticket or operation ticket information.
[0028] Optionally, the identity authentication information includes a security key or biometric information, wherein the biometric information includes at least one of facial information or fingerprint information.
[0029] Optional, also includes:
[0030] The recording unit is used to record the target user's identity information, the key number that was retrieved and placed, and the operation timestamp after opening the storage device where the key corresponding to the key number is located, and to generate an operation log.
[0031] The storage unit is used to associate and store the operation log with the corresponding ticket in the electronic two-ticket system.
[0032] Optional, also includes:
[0033] The alarm unit is used to send an unauthorized access alarm message to the system administrator and refuse to open the cabinet door if the target user's identity authentication is successful but there is no key access permission configuration at the current time.
[0034] According to a third aspect of this disclosure, an electronic device is provided, comprising:
[0035] At least one processor; and
[0036] A memory communicatively connected to the at least one processor; wherein,
[0037] The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method described in the first aspect above.
[0038] According to a fourth aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are configured to cause the computer to perform the method described in the first aspect above.
[0039] According to a fifth aspect of this disclosure, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the method described in the first aspect above.
[0040] This disclosure provides a method and device for intelligent key cabinet access management, an electronic device, and a storage medium. By acquiring work ticket or operation ticket information from the electronic ticketing system, including the work supervisor, work team members, and corresponding key numbers, it dynamically generates key retrieval permission configurations. It can also receive and verify the identity of the target user and whether the current time is within the scope of the above-mentioned permission configuration. Only after successful verification is an opening command generated to open the corresponding key storage device. Therefore, it can solve the problems in the prior art where key retrieval permissions are not associated with the work ticket or operation ticket information of the electronic ticketing system, the permission configuration cannot be dynamically adjusted, and there is a lack of compliance verification of user identity and retrieval time, resulting in chaotic key retrieval, high security risks, and non-compliance with power operation specifications. It achieves the technical effect of accurately matching key retrieval permissions with electronic ticketing operation information, dynamically adapting permissions to operation requirements, ensuring the security and compliance of key retrieval, and conforming to the power operation management process.
[0041] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description
[0042] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein:
[0043] Figure 1 A flowchart illustrating a smart key cabinet access control method provided in this embodiment of the disclosure;
[0044] Figure 2 This is a schematic diagram of the structure of an intelligent key cabinet access control device provided in an embodiment of the present disclosure;
[0045] Figure 3 A schematic diagram of another intelligent key cabinet access control device provided in this embodiment of the present disclosure;
[0046] Figure 4 A schematic block diagram of an example electronic device provided for embodiments of this disclosure. Detailed Implementation
[0047] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0048] The following description, with reference to the accompanying drawings, outlines an intelligent key cabinet access control method and apparatus, electronic device, and storage medium according to embodiments of this disclosure.
[0049] Figure 1 This is a flowchart illustrating a smart key cabinet access control method provided in an embodiment of this disclosure.
[0050] like Figure 1 As shown, the method includes the following steps:
[0051] Step 101: Obtain work ticket or operation ticket information from the electronic two-ticket system. The work ticket or operation ticket information includes at least the person in charge of the work, the work team members, and the corresponding key number.
[0052] In the embodiments of this disclosure, in the power operation scenario, the electronic two-ticket system is a digital management system in the power industry used to standardize operation processes and record key operation information. The work tickets and operation tickets stored in the system have undergone compliance review and have authenticity, integrity and traceability. Compared with traditional paper tickets, it can effectively avoid problems such as information loss, tampering or transmission delay, and provide a reliable data source for subsequent key management related operations. The "acquisition" here is not random extraction, but rather based on the actual needs of the current power operation. Through pre-defined interfaces or compliant data exchange protocols between systems, valid work tickets or operation tickets (i.e., not expired or invalidated) are precisely selected from the electronic work ticket system. This information must include at least the work supervisor, work team members, and corresponding key numbers. The work supervisor is the person who coordinates the entire operation process and bears primary responsibility for the safety and quality of the operation; their information defines the responsible party. Work team members are the personnel involved in the specific execution of the operation; recording this information clarifies the scope of their participation. The corresponding key number is a unique identifier corresponding to the key of the equipment required for the operation (such as distribution boxes, switchgear, etc.). Each number is precisely associated with a specific equipment key, ensuring accurate location of the required key later. This provides accurate and reliable basic data for subsequent key management, ensuring that key-related information is directly linked to the responsible party and participating personnel, avoiding issues such as mismatched keys or unauthorized access to keys due to inaccurate information.
[0053] Step 102: Dynamically generate key access permission configuration based on the received work order or operation ticket information.
[0054] In the embodiments of this disclosure, key access permission configuration is dynamically generated based on the work order or operation ticket information received in step 101. Here, "dynamic generation" does not mean a preset fixed permission template, but rather the construction of permission rules based on the core content of the ticket information and adapted in real time to the actual needs of the current power operation. Specifically, the permission boundaries are defined by combining the work supervisor, work team members, and corresponding key numbers in the ticket information. For example, the work supervisor, as the operation coordinator, may have the right to access all key numbers required for the operation, and even the right to review the key access of work team members. The permission configuration of work team members corresponds only to the specific key number required for their participation in the operation, avoiding access to irrelevant keys. At the same time, the permission configuration is also implicitly associated with the operation time range implied in the ticket information (such as the start to end period of the operation on the ticket), ensuring that the permission is only effective within the effective operation period and is not a permanent permission. The "key access permission configuration" here is a complete set of rules that includes "permission subject (who can access), permission object (which key to access, corresponding key number), and permission validity period (when can access be made)," rather than a single "allow access" instruction. Moreover, the "dynamic" aspect is reflected in the fact that when ticket information changes (such as the addition or reduction of work team members, or the adjustment of the key number required for the operation), the permission configuration will be updated synchronously without the need for manual re-entry or modification, and will always remain consistent with the actual needs of the current operation.
[0055] To avoid a disconnect between permission configuration and operational needs, and to prevent situations where "operators do not have the corresponding key permissions" or "non-operators have key permissions", while reducing the workload and error rate of manual permission configuration, and ensuring the accuracy and timeliness of key access permissions.
[0056] Step 103: Receive the target user's identity authentication information.
[0057] In the embodiments of this disclosure, "target user" refers to personnel who may need to access the key corresponding to the operation. As mentioned above, this mainly includes the work supervisor and work team members recorded in the work order or operation ticket information, rather than irrelevant personnel. "Identity authentication information" is the valid basis for proving the identity of the target user. Common forms include, but are not limited to, the user's power operation work badge number, personal biometric features (such as fingerprints, faces), and identity identification codes registered with the system. This information must correspond to the user information previously registered in the electronic two-ticket system or key management related system to ensure verifiability. The "receiving" process is not simply receiving information provided arbitrarily by the user, but rather acquiring it through preset identity information collection devices (such as work badge readers, biometric feature collectors) or compliant information input interfaces. The collection process must ensure the integrity and accuracy of the information to avoid subsequent identity verification failures due to missing or incorrect information. For example, if the user provides a work badge number, the system must receive every character of the number completely; if fingerprints are collected, the fingerprint image must be clear and identifiable to provide a reliable information foundation for subsequent verification steps.
[0058] By obtaining the target user's identity authentication information, a direct basis is provided for subsequent verification of the user's identity and legitimacy. Irrelevant personnel are filtered out from the source, and non-operational personnel are prevented from arbitrarily initiating key access requests, thus initially strengthening the security defense line of key management.
[0059] Step 104: Verify the identity of the target user and whether the current time falls within the permission configuration range of the work ticket or operation ticket information.
[0060] In the embodiments of this disclosure, verifying the identity of the target user and whether the current time falls within the scope of the permission configuration is a crucial step connecting the initial information with the subsequent key retrieval. Specifically, "verifying the identity of the target user" requires a precise comparison between the identity authentication information received in step 103 (such as employee ID number, biometrics, etc.) and the work supervisor and work team member registration information obtained in step 101. For example, if the user provides an employee ID number, the system will retrieve the corresponding personnel ID database recorded in the ticket information to verify whether the input number is in the database and not marked as invalid; if it is a biometric feature, it will be matched with the previously registered feature template to ensure that the user currently requesting key retrieval is indeed an authorized worker and not an unauthorized person impersonating the user. The verification process, "verifying whether the current time is within the permission configuration range," implicitly refers to the valid job time period extracted from the ticket information (such as the start and end times of the job as indicated on the work ticket). The system will obtain the current standard time in real time (not the user-reported time, to prevent human tampering) and determine whether the time falls within the valid job time period. Simultaneously, it combines this with the rule in the permission configuration generated in step 102, "binding permission validity to job time period," to ensure that the user can only initiate a key retrieval request during job execution. The entire verification process is not a single-condition judgment but requires both "identity within the authorized list" and "time within the valid time period" to be met simultaneously. If either condition is not met, the verification fails, and the verification result is recorded in the system in real time for subsequent traceability.
[0061] By employing dual verification, the compliance of key retrieval is ensured from both the "person" and "time" dimensions, preventing violations such as identity theft and unauthorized access, thereby further enhancing the security and standardization of key management.
[0062] Step 105: If the verification is successful, an opening command is generated to open the storage device containing the key corresponding to the key number, so that the target user can retrieve the key corresponding to the key number.
[0063] In the embodiments disclosed herein, "if verification passes" specifically means that after step 104, both the target user's identity (confirming they are the work supervisor or work team member registered in the work order or operation ticket) and the current time (within the valid work period) meet the authorization requirements. Only then will the system trigger subsequent operations; it is not enough for a single condition to be met to start. "Generate opening command" is not a simple unlock signal, but rather the system combines the previously acquired key number to generate a precise command containing the unique identifier of the storage device corresponding to that key (such as the exclusive compartment code of the smart key cabinet, or the address of the independent electronic lock). The storage device here is mostly a smart key management device specifically for power operations. Each key is stored in an independent storage unit (such as a compartment with an electronic lock or a sealed drawer) that corresponds one-to-one with the key number. The command is transmitted to the storage device through a preset control protocol to ensure that only the unlocking mechanism of the unit where the target key is located is triggered, rather than the entire device being opened, thus preventing other unauthorized keys from being exposed. After "opening the storage device containing the key corresponding to the key number", the target user can directly access the corresponding key in that unit. The entire process does not require manual intervention to unlock unrelated storage units, and the key accessed is completely matched with the previous permission configuration. That is, the user can only access the key corresponding to the key number within their permission range and will not access the keys for other operations.
[0064] By controlling the opening of the storage device with precise commands, we can prevent unrelated keys from being accidentally taken or touched, thus ensuring the security of key management. We can also eliminate the need for manual key searching and unlocking, thereby improving retrieval efficiency. At the same time, we can form a closed loop with the previous verification to ensure that the entire key retrieval process is compliant and controllable.
[0065] This disclosure provides a method for managing access permissions for an intelligent key cabinet. By acquiring work ticket or operation ticket information from the electronic ticketing system, including the work supervisor, work team members, and corresponding key numbers, the method dynamically generates key retrieval permission configurations. It can also receive and verify the identity of the target user and whether the current time falls within the scope of the aforementioned permission configuration. Only after successful verification is an opening command generated to open the corresponding key storage device. Therefore, it can solve the problems in the prior art where key retrieval permissions are not associated with the work ticket or operation ticket information of the electronic ticketing system, the permission configuration cannot be dynamically adjusted, and there is a lack of compliance verification of user identity and retrieval time, resulting in chaotic key retrieval, high security risks, and non-compliance with power operation specifications. This method achieves the technical effect of accurately matching key retrieval permissions with electronic ticketing operation information, dynamically adapting permissions to operation requirements, ensuring the security and compliance of key retrieval, and conforming to the power operation management process.
[0066] Within the scope of the embodiments described in this disclosure, after dynamically generating the key access permission configuration based on the received work order or operation ticket information, there are several other feasible specific implementation steps. To present these diverse implementation methods in a clear, accurate, and organized manner, some exemplary implementation methods are specifically explained below: When the validity period of the work order or operation ticket expires or the ticket status becomes terminated, the target user's access permission to the key corresponding to the key number is revoked.
[0067] Specifically, after dynamically generating key access permission configurations based on work order or operation ticket information, for the implementation method of "revoke the target user's corresponding key access permission when the work order or operation ticket expires or the ticket status changes to terminated," the core logic and operational details need to be clarified: "The expiration of the work order or operation ticket" refers to the deadline reached when the work validity period (e.g., from 9:00 to 17:00 on the same day) pre-marked on the ticket has arrived. The system will automatically capture this time node through real-time data synchronization with the electronic ticket system, without the need for manual triggering. "Ticket status changes to terminated" covers a variety of compliance scenarios, including the "work terminated" status marked by the person in charge of the work in the electronic ticket system after the work is completed as planned, the "ticket invalidated" status marked due to changes in the work plan or external factors causing the work to be canceled, and the "ticket terminated" status when a safety hazard occurs during the work process and it needs to be suspended and will not be resumed. These status change information will also be transmitted to the key access management module in real time. The "revocation of permission" here is not simply deleting the original permission configuration record. Instead, the system automatically marks the access permission of the target user (the originally authorized work supervisor or work team member) for the corresponding key number as "invalid". At the same time, the control logic of the key storage device is updated simultaneously. That is, the instruction permission that originally allowed the user to open the corresponding key slot is cleared. Even if the user submits identity authentication later, the system will refuse to generate the opening instruction because the permission has expired. Moreover, the entire revocation process is recorded. The permission invalidation record can be linked to the ticket status change record of the electronic ticketing system for easy traceability.
[0068] This system ensures that key access permissions are terminated simultaneously with ticket validity, preventing users from illegally accessing keys even after tickets have expired. It completely eliminates the security risks associated with "expired permissions" and eliminates the need for manual intervention to revoke permissions, thus improving the automation and compliance of access management.
[0069] Furthermore, the identity authentication information includes a security key or biometric information, wherein the biometric information includes at least one of facial information or fingerprint information.
[0070] Specifically, the form of identity authentication information is further clarified, including security keys or biometric information, where biometric information includes at least one of facial or fingerprint information. The "security key" here is not an ordinary digital password, but rather exclusive verification information pre-registered in the electronic ticketing system and key access management modules. It can take the form of a software key (such as a randomly generated dynamic number string, which must be obtained through a bound authorized device) or a hardware key (such as a dedicated encrypted Ukey with a built-in unique identification chip). Its core characteristics are uniqueness and immutability. Only security keys that have been associated and registered in the system can serve as valid identity authentication evidence, effectively preventing the risk of ordinary passwords being leaked or stolen. Biometric information relies on a user's inherent physiological characteristics for identity verification, possessing innate and unreplicable attributes: "Facial information" captures detailed information such as the contour features, relative positions of facial features, and iris texture through specialized acquisition equipment, forming a unique facial feature template stored in the system. During verification, the real-time facial information is compared with the template to confirm identity. "Fingerprint information" collects unique information such as the skin texture and feature points (e.g., endpoints, bifurcation points) at the user's fingertips, constructing a fingerprint feature database. During verification, a fingerprint sensor acquires real-time fingerprint data and matches it with information in the database. In practical applications, the appropriate authentication method can be selected based on the power operation environment. For example, in dusty work scenarios, fingerprint recognition is easily affected, and facial information authentication can be prioritized; in scenarios requiring rapid single-person verification, fingerprint recognition is more convenient.
[0071] By employing diverse and highly secure identity authentication methods, the risk of identity theft is further reduced. At the same time, it adapts to the actual needs of different power operation scenarios, balancing security and ease of operation, and providing a more reliable foundation for subsequent permission verification.
[0072] Within the scope of the embodiments described in this disclosure, after opening the storage device containing the key corresponding to the key number, there are several other feasible specific implementation steps. To present these diverse implementation methods in a clear, accurate, and organized manner, some exemplary implementation methods are specifically explained below: Record the target user's identity information, the key number retrieved / placed, and the operation timestamp, and generate an operation log; associate the operation log with the corresponding ticket in the electronic ticketing system and store it.
[0073] Specifically, after opening the storage device containing the key corresponding to the key number, the steps of recording operation information and associating it with storage must be performed. The specific process must revolve around the completeness of information recording and the accuracy of association logic: "Recording the target user's identity information" does not only record a simple name, but also needs to simultaneously record the core identifiers used by the user in the early stage of identity authentication (such as the registered work badge number, the system's unique ID corresponding to biometric information), to ensure that the specific person can be directly located during subsequent tracing and to avoid identity confusion due to issues such as "duplicate names"; "Key numbers taken and put away" must clearly distinguish the operation type - if it is "taken," then the key number currently taken out is recorded, if it is "returned," then the key number returned is recorded, and the number must be completely consistent with the key number in the previous work ticket / operation ticket to ensure that the key flow trajectory can be accurately matched; "Operation timestamp" is a standard time (accurate to the second) automatically generated by the system, which does not rely on manual input and avoids the distortion of records caused by human modification of time. This timestamp will serve as the core time node of the operation log and correspond to the time dimension of the ticket information in subsequent associated storage.
[0074] The generated "operation log" is a structured data record containing the above three elements and operation type (retrieval / return), not a collection of scattered information. After the log is generated, it will automatically undergo anti-tampering processing (such as adding a system signature) to ensure the authenticity of the log content during subsequent audits. The "storage associated with the corresponding ticket in the electronic ticketing system" uses the unique identifier of the work ticket / operation ticket obtained in the early stage (such as the ticket number) to bind the operation log with the full information of the ticket in the electronic ticketing system (work content, responsible personnel, effective time period, etc.). After binding, when querying the ticket in the electronic ticketing system, the corresponding key retrieval and release log can be retrieved synchronously. Conversely, when querying the key operation log, the corresponding work ticket can be quickly associated, realizing full-link information communication of "ticket-key-person-time".
[0075] By fully recording key operation information and linking it to work tickets, the entire key usage trajectory can be traced. If problems such as lost keys or unauthorized use occur later, the responsible personnel and related work processes can be quickly located. At the same time, it provides complete data support for compliance audits of power operations and further strengthens the standardization of work processes.
[0076] Within the scope of the embodiments described in this disclosure, in addition to the foregoing, there are several other feasible specific implementation steps. To present these diverse implementation methods in a clear, accurate, and organized manner, some exemplary implementation methods are specifically explained below: If the target user's identity authentication is successful but there is no key access permission configuration at the current time, an unauthorized access alarm message is sent to the system administrator, and the cabinet door is refused to be opened.
[0077] Specifically, for the scenario of "target user identity authentication successful but no key access permission configuration at the current time," it is necessary to send an unauthorized access alert to the system administrator and refuse to open the cabinet door. The specific process needs to focus on the correlation between scenario definition, alert transmission, and operation restrictions. "Successful identity authentication" means that the security key or biometric information (such as face or fingerprint) provided by the target user has been verified by the system, confirming that they are indeed the work leader or work team member registered in the work order / operation ticket, eliminating the possibility of identity fraud. The core of "no key access permission configuration at the current time" is that the standard time obtained by the system (not the time filled in by the user) does not fall within the permission validity period bound to the work order / operation ticket. For example, if the valid time period marked on the work order is 9:00-17:00 on the same day, and the user initiates an access request at 18:00, although the identity is compliant, the time exceeds the permission range, which is the case of "no permission configuration." The permission validity period here is directly related to the work execution time period in the previous ticket information to ensure that the permission is synchronized with the work progress. When "sending an unauthorized access alert to the system administrator," the alert content is not simply a "not authorized" message, but includes key traceability information: the target user's system registration identifier (such as employee ID number, unique ID corresponding to biometric features), the key number attempted to access, the precise timestamp of the request, and the specific reason for the unauthorized access (the current time exceeds the configured permission period). The alert can be sent via a pop-up window on the system management terminal, SMS to the bound administrator's mobile phone, or a dedicated maintenance APP, ensuring that the administrator is aware of the abnormal situation in real time. "Refusing to open the cabinet door" is a precise control of the key storage device—the system will not generate an opening command for the storage unit corresponding to the key number. Even if the storage device receives a user's operation trigger signal, it will only provide a "current access permission not granted" prompt (such as a display on the device screen or a voice broadcast), and it only restricts the storage unit where the target key is located, without affecting cabinet door operations under other compliant permissions.
[0078] It should be noted that the embodiments of this disclosure may include multiple steps. For ease of description, these steps are numbered, but these numbers are not a limitation on the execution time slots or execution order between the steps; these steps can be implemented in any order, and the embodiments of this disclosure do not limit this.
[0079] Corresponding to the above-described method for managing access based on smart key cabinets, this disclosure also proposes a smart key cabinet access management device. Since the device embodiments of this disclosure correspond to the method embodiments described above, details not disclosed in the device embodiments can be referred to the method embodiments described above, and will not be repeated here.
[0080] Figure 2 This is a schematic diagram of the structure of an intelligent key cabinet access control device provided in an embodiment of this disclosure, as shown below. Figure 2 As shown, it includes:
[0081] The acquisition unit 21 is used to acquire work ticket or operation ticket information from the electronic two-ticket system. The work ticket or operation ticket information includes at least the work supervisor, work team members and the corresponding key number.
[0082] The generation unit 22 is used to dynamically generate key access permission configuration based on the received work order or operation ticket information;
[0083] Receiving unit 23 is used to receive the identity authentication information of the target user;
[0084] Verification unit 24 is used to verify the identity of the target user and whether the current time is within the permission configuration range of the work ticket or the operation ticket information;
[0085] The opening unit 25 is used to generate an opening command if the verification is successful, to open the storage device where the key corresponding to the key number is located, so that the target user can retrieve the key corresponding to the key number.
[0086] Furthermore, in one possible implementation of this embodiment, such as Figure 3 As shown, it also includes:
[0087] The revocation unit 26 is used to revoke the target user's access permission to the key corresponding to the key number when the validity period of the work ticket or operation ticket expires or the ticket status becomes terminated, after dynamically generating the key access permission configuration based on the received work ticket or operation ticket information.
[0088] Furthermore, in one possible implementation of this embodiment, the identity authentication information includes a security key or biometric information, wherein the biometric information includes at least one of facial information or fingerprint information.
[0089] Furthermore, in one possible implementation of this embodiment, such as Figure 3 As shown, it also includes:
[0090] The recording unit 27 is used to record the target user's identity information, the key number that was retrieved and placed, and the operation timestamp after opening the storage device where the key corresponding to the key number is located, and to generate an operation log.
[0091] Storage unit 28 is used to associate and store the operation log with the corresponding ticket in the electronic two-ticket system.
[0092] Furthermore, in one possible implementation of this embodiment, such as Figure 3 As shown, it also includes:
[0093] Alarm unit 29 is used to send an unauthorized access alarm message to the system administrator and refuse to open the cabinet door if the target user's identity authentication is successful but there is no key access permission configuration at the current time.
[0094] It should be noted that the foregoing explanation of the method embodiments also applies to the apparatus of this embodiment, and the principle is the same, so it is not limited in this embodiment.
[0095] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0096] Figure 4 A schematic block diagram of an example electronic device 300 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0097] like Figure 4 As shown, the electronic device 300 includes a computing unit 301, which can perform various appropriate actions and processes based on a computer program stored in ROM (Read-Only Memory) 302 or a computer program loaded from storage unit 308 into RAM (Random Access Memory) 303. The RAM 303 can also store various programs and data required for the operation of the electronic device 300. The computing unit 301, ROM 302, and RAM 303 are interconnected via a bus 304. An I / O (Input / Output) interface 305 is also connected to the bus 304.
[0098] Multiple components in electronic device 300 are connected to I / O interface 305, including: input unit 306, such as keyboard, mouse, etc.; output unit 307, such as various types of displays, speakers, etc.; storage unit 308, such as disk, optical disk, etc.; and communication unit 309, such as network card, modem, wireless transceiver, etc. Communication unit 309 allows electronic device 300 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0099] The computing unit 301 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 301 include, but are not limited to, CPUs (Central Processing Units), GPUs (Graphics Processing Units), various special-purpose AI (Artificial Intelligence) computing chips, various computing units running machine learning model algorithms, DSPs (Digital Signal Processors), and any suitable processor, controller, microcontroller, etc. The computing unit 301 performs the various methods and processes described above, such as the smart key cabinet access control method. For example, in some embodiments, the smart key cabinet access control method can be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 308. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 300 via ROM 302 and / or communication unit 309. When the computer program is loaded into RAM 303 and executed by the computing unit 301, one or more steps of the methods described above can be performed. Alternatively, in other embodiments, the computing unit 301 may be configured to perform the aforementioned smart key cabinet access control method by any other suitable means (e.g., by means of firmware).
[0100] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application-Specific Standard Products), SOCs (System-on-Chips), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0101] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0102] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, RAM, ROM, EPROM (Electrically Programmable Read-Only Memory) or flash memory, optical fiber, CD-ROM (Compact Disc Read-Only Memory), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0103] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0104] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include LANs (Local Area Networks), WANs (Wide Area Networks), the Internet, and blockchain networks.
[0105] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service ecosystem, addressing the shortcomings of traditional physical hosts and VPS (Virtual Private Server, or simply "VPS") services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.
[0106] It's important to note that artificial intelligence (AI) is the study of enabling computers to simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It encompasses both hardware and software technologies. AI hardware technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, and big data processing. AI software technologies primarily include computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graph technologies.
[0107] The various numerical designations such as "first," "second," etc., used in this disclosure are merely for ease of description and are not intended to limit the scope of the embodiments of this disclosure, nor do they indicate a sequential order.
[0108] At least one of the features described in this disclosure can also be described as one or more, and multiple features can be two, three, four or more, and this disclosure does not impose any limitations. In the embodiments of this disclosure, for a technical feature, the technical features in that technical feature are distinguished by "first", "second", "third", "A", "B", "C" and "D", etc., and there is no sequential order or size order among the technical features described by "first", "second", "third", "A", "B", "C" and "D".
[0109] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0110] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A method for managing access permissions in a smart key cabinet, characterized in that, include: Obtain work ticket or operation ticket information from the electronic two-ticket system. The work ticket or operation ticket information includes at least the work supervisor, work team members, and the corresponding key number. Based on the received work order or operation ticket information, dynamically generate key access permission configuration; Receive the target user's authentication information; Verify the identity of the target user and whether the current time falls within the permission configuration range of the work order or operation ticket information; If the verification is successful, an opening command is generated to open the storage device containing the key corresponding to the key number, so that the target user can retrieve the key corresponding to the key number.
2. The method according to claim 1, characterized in that, After dynamically generating the key access permission configuration based on the received work order or operation ticket information, the method further includes: When the validity period of the work ticket or operation ticket expires or the ticket status becomes terminated, the target user's access permission to the key corresponding to the key number is revoked.
3. The method according to claim 1, characterized in that, The identity authentication information includes a security key or biometric information, and the biometric information includes at least one of facial information or fingerprint information.
4. The method according to claim 1, characterized in that, After opening the storage device containing the key corresponding to the key number, the process also includes: Record the target user's identity information, the key number used, and the operation timestamp, and generate an operation log; The operation log is associated with and stored in the corresponding ticket in the electronic two-ticket system.
5. The method according to claim 1, characterized in that, Also includes: If the target user's identity is successfully authenticated but there is no key access permission configuration at the current time, an unauthorized access alarm message is sent to the system administrator, and the cabinet door is refused to be opened.
6. A smart key cabinet access control device, characterized in that, include: The acquisition unit is used to acquire work ticket or operation ticket information from the electronic two-ticket system. The work ticket or operation ticket information includes at least the work supervisor, work team members, and the corresponding key number. The generation unit is used to dynamically generate key access permission configuration based on the received work order or operation ticket information. The receiving unit is used to receive the identity authentication information of the target user. The verification unit is used to verify the identity of the target user and whether the current time is within the permission configuration range of the work ticket or the operation ticket information; An opening unit is used to generate an opening command if the verification is successful, to open the storage device containing the key corresponding to the key number, so that the target user can retrieve the key corresponding to the key number.
7. The apparatus according to claim 6, characterized in that, Also includes: The revocation unit is used to revoke the target user's access permission to the key corresponding to the key number when the validity period of the work ticket or operation ticket expires or the ticket status becomes terminated, after dynamically generating the key access permission configuration based on the received work ticket or operation ticket information.
8. An electronic device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-5.
9. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to perform the method according to any one of claims 1-5.
10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method according to any one of claims 1-5.
Citation Information
Cited By
Intelligent key multi-module collaborative management method and system
CN122141984A