Access control system integrating multiple identification modes
By integrating multiple identification modules and intelligent decision-making algorithms, the access control system solves the problems of low security and poor adaptability in existing technologies, achieving high security, high adaptability and convenient management, and improving passage efficiency and system stability.
Patent Information
- Application Number
- CN202511289177.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-10
- Publication Date
- 2026-01-23
AI Technical Summary
Existing access control systems suffer from low security, poor adaptability, inconvenient management, slow response, and weak fault tolerance, making it difficult to meet multi-level security needs. In particular, they are easily cracked in high-security scenarios and can cause congestion during peak hours due to excessively long verification times.
It integrates three types of identification modules: biometrics, RFID cards, and mobile terminals. It calculates the liveness confidence through multi-dimensional features, and combines intelligent decision-making algorithms and fault self-healing functions to achieve high security, high adaptability, and convenient management, with rapid response and remote management capabilities.
It improves the security level of the access control system, shortens the identification time, increases the passage efficiency, enhances the system stability and fault tolerance, and meets the security needs of different scenarios.
Smart Images

Figure CN121393010A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of access control security technology, in particular to an access control system integrating multiple identification modes. BACKGROUND
[0002] With the continuous improvement of security needs, the access control system has developed from traditional mechanical key access control to electronic and intelligent access control. The access control systems on the market currently mostly use a single identification mode, such as radio frequency card access control, password access control or single biometric feature access control. However, these systems have obvious defects: radio frequency card access control is prone to card loss and stolen card problems; password access control has the risk of password leakage and forgetting; single biometric feature access control (such as only face recognition) has a significant decrease in recognition accuracy in strong light, backlight or temporary changes in user facial features (such as injury, makeup), and cannot meet the use needs of special groups (such as patients with facial burns).
[0003] Some existing technologies attempt to combine two identification modes, such as password + radio frequency card or face recognition + password, but still have the problems of insufficient security and poor scene adaptability. For example, when the user loses the radio frequency card and the password is leaked at the same time, the access control system is easy to be illegally cracked; in high security demand scenes (such as laboratories, safes), the combination of only two identification modes cannot meet the multi-level security requirements. In addition, most existing access control systems lack remote management, intelligent response and fault self-healing capabilities, cannot monitor the equipment state in real time, are difficult to adjust the identification strategy according to the needs of different time periods and different areas, and are prone to congestion due to long verification time during peak periods, and the access control may be out of control or unable to open when a single module fails, affecting normal use.
[0004] Therefore, there is an urgent need for an access control system that can integrate multiple identification modes, have intelligent scene adaptation, fast response, remote management and high fault tolerance capabilities, to solve the problems of low security, poor adaptability, inconvenient management, slow response and weak fault tolerance in the prior art. SUMMARY
[0005] The purpose of the present application is to provide an access control system integrating multiple identification modes, which integrates multiple identification modules, optimizes control logic and expands functions, realizes high security, high adaptability and convenient management of the access control system, and at the same time improves the passing efficiency through an intelligent prediction mechanism and enhances the system stability through a fault self-healing function, to meet the security needs in different scenes.
[0006] In order to achieve the above object, the present application provides the following technical scheme: a door access control system integrating multiple identification modes, comprising an identification module group, a central control unit, a linkage execution mechanism, a data storage unit, a remote management platform and a power supply unit; the identification module group is used for collecting user identification information, the central control unit is used for processing the identification information and generating control instructions, the linkage execution mechanism is used for realizing door access control and state prompting in response to the control instructions, the data storage unit is used for storing user data and system operation records, the remote management platform is used for remote monitoring and management, and the power supply unit is used for supplying power to each module of the system.
[0007] As a preferred embodiment of the present application, the identification module group at least comprises a biological feature identification sub-module, a radio frequency identification sub-module and a mobile terminal identification sub-module; the biological feature identification sub-module integrates a face recognition unit, a fingerprint recognition unit and an iris recognition unit, and each unit has a living body detection function; the radio frequency identification sub-module supports 125KHz low-frequency card and 13.56MHz high-frequency card reading, and has a copy-proof encryption function; the mobile terminal identification sub-module is connected with a user mobile terminal through Bluetooth 5.0, NFC or WiFi6 protocol, and supports dynamic verification code, encrypted two-dimensional code and APP authorization identification.
[0008] As a preferred embodiment of the present application, the living body detection function of the biological feature identification sub-module is realized through multi-dimensional feature judgment: the face recognition unit calculates the living body confidence through depth information, skin texture and dynamic features, the fingerprint recognition unit judges the living body through the pressure change rate and the skin capacitance value, and the iris recognition unit confirms the living body through dynamic response and blood vessel texture matching degree; when the living body confidence is greater than or equal to a preset threshold (face recognition is greater than or equal to 0.8, fingerprint recognition is greater than or equal to 0.75, and iris recognition is greater than or equal to 0.85), it is determined as a real user.
[0009] As a preferred embodiment of the present application, the central control unit is built-in with an intelligent decision algorithm, which can automatically determine the scene type according to time and location information; the scene type includes commuting period (7:00-9:00 on weekdays, 17:00-19:00), night period (22:00-6:00 of the next day) and holiday period; different scenes correspond to different identification mode combinations, a single identification mode is used in the commuting period, and a double identification mode is used in the night period and the holiday period.
[0010] As a preferred embodiment of the present application, the central control unit is also built-in with an identification result intelligent prediction and pre-verification module; the module collects user historical access data in the past 30 days through the data storage unit, including the frequency of commonly used identification modes, the distribution of access time period and the access location preference, constructs a user-specific behavior model using a decision tree machine learning algorithm, and the model is automatically updated every week.
[0011] As a preferred embodiment of the present application, the triggering condition of the intelligent prediction and pre-verification module of the recognition result is that the user enters the recognition module sensing range (within 1.5 meters of the face recognition camera, within 0.5 meters of the radio frequency card sensing area), and the system detects the presence of the user through infrared human body sensing or mobile terminal Bluetooth signal; if the current time and location of the user meet the "customary time period + customary location" feature in the behavior model, the system automatically preloads the high-frequency use recognition sub-module and the corresponding authorization information of the user to the cache area, shortening the verification time to ≤0.3 seconds during formal recognition.
[0012] As a preferred embodiment of the present application, the recognition result intelligent prediction and pre-verification module also has an abnormal behavior dynamic adjustment function; when abnormal user behavior (non-customary time period access, use of non-high-frequency recognition methods) is detected, the system calculates the abnormal behavior degree, and when the abnormal degree ≥0.6, the verification level is automatically upgraded, one additional verification item is added based on the original recognition method, and an abnormal behavior warning is sent to the remote management platform.
[0013] As a preferred embodiment of the present application, the system has a multi-module cooperative fault self-healing function; the central control unit sends a heartbeat detection signal to each recognition sub-module every 30 seconds, and if there is no feedback for 3 consecutive times, it is determined that the module has failed; at the same time, the fault type (hardware fault / software fault) is located through image analysis and circuit voltage detection, the state of the linkage execution mechanism is judged through lock body current detection and audio feedback detection, and the communication link fault is located through communication protocol state detection.
[0014] As a preferred embodiment of the present application, the multi-module cooperative fault self-healing function adopts a hierarchical self-healing strategy: when the recognition sub-module fails, it automatically switches to other authorized recognition sub-modules of the user and guides the user to operate through the sound and light prompt unit; when the linkage execution mechanism fails, the standby lock body (response time ≤0.5 seconds) and the LED text prompt screen are activated; when the communication link fails, it automatically switches to a backup network (switches to 4G / 5G when wired network is interrupted) and temporarily stores local data for synchronization to the cloud after communication is restored.
[0015] As a preferred embodiment of the present application, the power supply unit adopts a dual power supply mode of mains and backup battery; the mains is powered through an AC220V to DC12V / 2A power adapter, and the backup battery is a 18650 lithium battery pack (capacity 5000mAh); when the mains is interrupted, the backup battery can maintain the normal operation of the system core functions (recognition, control, alarm) for not less than 4 hours, and at the same time sends a mains interruption reminder to the remote management platform.
[0016] Compared with the prior art, the present application has the following advantages:
[0017] 1. The integrated access control system with multiple identification methods has high security level, integrates three types of identification modules of biological characteristics, radio frequency card and mobile terminal, avoids single identification defects, calculates living body confidence through multi-dimensional feature recognition of biological characteristics, resists counterfeit attacks, improves verification level and gives early warning in abnormal behavior, and reduces illegal intrusion risk.
[0018] 2. The integrated access control system with multiple identification methods has high efficiency, preloads authorized information when meeting user's usual behavior, takes ≤0.3 seconds for identification, relieves peak congestion, automatically switches modes according to scenes, realizes single identification for rapid access during commuting period, realizes double identification for security at night and during holidays, and balances efficiency and security.
[0019] 3. The integrated access control system with multiple identification methods runs more stably, detects faults through 30-second heartbeat detection, automatically switches identification modules, activates standby lock in lock body failure, switches standby network in communication failure, has high self-healing rate, and has dual power supply of commercial power and 18650 lithium battery, maintains core functions for ≥4 hours in power failure, and reduces operation interruption. BRIEF DESCRIPTION OF DRAWINGS
[0020] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0021] Figure 1 The system architecture of the present application. DETAILED DESCRIPTION
[0022] The technical solutions in the embodiments of the present application will be described clearly and completely in the following with reference to the drawings of the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.
[0023] Please refer to Figure 1 The present application provides a technical solution: an integrated access control system with multiple identification methods, comprising an identification module group, a central control unit, a linkage execution mechanism, a data storage unit, a remote management platform and a power supply unit; the identification module group is used for collecting user identification information, the central control unit is used for processing identification information and generating control instructions, the linkage execution mechanism is used for realizing access control opening and closing and state prompting in response to the control instructions, the data storage unit is used for storing user data and system operation records, the remote management platform is used for remote monitoring and management, and the power supply unit is used for power supply for each module of the system.
[0024] The identification module group at least includes a biometric identification submodule, a radio frequency identification submodule, and a mobile terminal identification submodule. The biometric identification submodule includes a face recognition unit, a fingerprint recognition unit, and an iris recognition unit, and each unit has a living body detection function. The radio frequency identification submodule supports 125KHz low-frequency card and 13.56MHz high-frequency card reading, and has a copy-proof encryption function. The mobile terminal identification submodule is connected with a user mobile terminal through Bluetooth 5.0, NFC, or WiFi6 protocol, and supports dynamic verification code, encrypted two-dimensional code, and APP authorization identification.
[0025] The living body detection function of the biometric identification submodule is realized through multi-dimensional feature judgment. The face recognition unit calculates the living body confidence through depth information, skin texture, and dynamic characteristics. The fingerprint recognition unit judges the living body through pressure change rate and skin capacitance value. The iris recognition unit confirms the living body through dynamic response and blood vessel texture matching degree. When the living body confidence is greater than or equal to a preset threshold, it is determined as a real user.
[0026] A high-definition camera with a resolution not less than 1080P is used to collect the user's face image. The collection range is within 1.5 meters in front of the camera. The image sampling frequency is set to 30 frames per second to ensure that the captured face image is clear and continuous.
[0027] Image preprocessing: The collected original image is subjected to noise reduction, grayscale, and alignment processing. A Gaussian filter algorithm is used to remove image noise, and the formula is: where G(x, y) is the pixel value of the filtered image at the (x, y) coordinate, σ is the Gaussian standard deviation (value range 0.5-1.2), and (u, v) is the center coordinate of the filter kernel.
[0028] The color image is converted to a grayscale image through a grayscale transformation formula: Gray(x, y) = 0.299(x, y) + 0.587G(x, y) + 0.114B(x, y), where R(x, y), G(x, y), and B(x, y) are the red, green, and blue channel pixel values of the original color image at the (x, y) coordinate, and Gray(x, y) is the pixel value after grayscale.
[0029] Based on facial feature points, such as 68 key feature points including eye corners, nose tip, and mouth corners, image alignment is performed through affine transformation to correct facial posture deviation and ensure the accuracy of subsequent feature extraction.
[0030] The ToF sensor is used to obtain facial three-dimensional depth data, calculate the depth values D i (i = 1, 2,..., n) of key areas such as forehead, nose bridge, and chin, and calculate the depth average value
[0031] The LBP algorithm is used to extract the skin texture features. For each pixel point in the gray image, the gray value of the pixel is compared with the gray values of the eight neighboring pixels. If the value is greater than the neighboring pixel value, it is recorded as 1, otherwise it is recorded as 0, and an 8-bit binary number is generated as the LBP value of the pixel. The formula is: wherein g c is the gray value of the center pixel (x, y), g p is the gray value of the pth neighboring pixel, and s(z) is a sign function, s(z) = 1 when z ≥ 0, and s(z) = 0 when z < 0.
[0032] Through the continuous three frames of face images, the displacement amount Δp x (horizontal direction) and Δp y (vertical direction) of the facial feature points are calculated to obtain the dynamic features such as blinking and mouth movement. The calculation method of the dynamic feature value M is: wherein k is the number of feature points participating in the calculation, which is set to 20 by default, Δp xi and Δp yi are the displacement amounts of the ith feature point in the horizontal and vertical directions, respectively.
[0033] According to the weight proportions of the depth information, skin texture and dynamic features (0.3, 0.4 and 0.3 respectively), the living body confidence C face of the face recognition unit is calculated. The formula is:
[0034] wherein C match is the normalized value of the depth information, reflecting the authenticity of the three-dimensional contour of the face, LBP total is the matching number of the current skin texture and the preset real skin texture template, LBP max is the total texture feature quantity, is the normalized value of the dynamic feature, M face is the preset maximum dynamic feature value, and when C G ≥ 0.8, it is determined that the facial features are living.
[0035] The user's fingerprint image is collected by a capacitive fingerprint sensor. The sensing area is within 0.5 meters, and the collection resolution is 500 dpi. The pressure data during the collection process is recorded, and the pressure sampling frequency is 10 times per second. The fingerprint image is binarized and thinned. The adaptive threshold binarization algorithm is used to convert the gray-scale fingerprint image into a black and white binary image. The calculation method of the threshold T is:
[0036] wherein m x n is the image pixel size, S tis the standard deviation of the image gray scale, k is the adjustment coefficient, the value range is 0.2-0.5, the binary image is refined by the skeleton extraction algorithm (such as Zhang-Suen algorithm), the center pixels of the fingerprint ridge line are reserved, the redundant pixels are removed, and the fingerprint skeleton image is obtained.
[0037] According to the collected pressure data P1, P2, …, P t , t is the sampling number, the pressure change rate R P is calculated, and the formula is: When the real fingerprint is pressed, the pressure will change naturally with the pressing force, and the pressure change rate needs to be in a reasonable preset interval (0.2-0.8 N / s).
[0038] Through the capacitance detection module of the fingerprint sensor, the skin capacitance value C i (i = 1, 2, …, m) when the fingerprint ridge line contacts the sensor is collected, and the average capacitance C is calculated, and the formula is The capacitance value of the real skin has a fixed range (10-30 pF), and the capacitance value of the fake fingerprint usually exceeds the range.
[0039] From the refined fingerprint skeleton image, feature points such as end points and branch points are extracted, the coordinates (x j , y j ) and direction angle θ j (j = 1, 2, …, k) of the feature points are recorded, and a fingerprint feature template is constructed.
[0040] Combined with the pressure change rate, the skin capacitance value and the matching degree of the fingerprint features (the weight proportions are 0.3, 0.3 and 0.4 respectively), the live confidence C finger of the fingerprint recognition unit is calculated, and the formula is: Wherein, is the normalized value of the pressure change rate, R pmax is the preset maximum pressure change rate, C min and C max are the minimum and maximum values of the real skin capacitance value respectively, is the normalized value of the capacitance value, F match is the matching feature point number of the current fingerprint feature and the user's preset fingerprint template, F total is the total number of feature points. When C finger ≥0.75, it is determined that the fingerprint feature is live.
[0041] The user's iris image is collected by a near-infrared camera (wavelength 700-900 nm), the collection range is within 1.5 meters in front of the camera, and low-power infrared light is emitted to excite the iris blood vessel response. The collection resolution is 1280*720 pixels, which ensures clear capture of iris texture and blood vessel distribution.
[0042] The iris image is subjected to iris positioning and normalization processing, and the Hough transform algorithm is used to position the inner circle (pupil) and outer circle (iris boundary) of the iris. The inner circle equation is (x-a1) 2 +(y-b1) 2 =r1 2 , and the outer circle equation is where (a1, b1) and (a2, b2) are the coordinates of the inner and outer circle centers, respectively, and r1 and r2 are the radii of the inner and outer circles, respectively.
[0043] The iris region is segmented from the image, and the polar coordinate transformation is used to convert the annular iris image to a rectangular image, realizing normalization. The polar coordinate transformation formula is: (r, θ)→(x, y), x=r*cosθ, y=r*sinθ, where (r, θ) is the polar coordinate of the iris annular region, (x, y) is the normalized rectangular coordinate, r∈[r1, r2], θ∈[0, 2π).
[0044] During the collection process, the contraction / dilation response of the iris pupil is observed through the slight change (change amplitude ±10%) of the infrared light intensity, and the pupil radius change Δr is recorded. The calculation method of the dynamic response value R d is as follows: where s is the number of response detections, which is set to 5 by default, Δr i is the pupil radius change of the i-th detection. The real iris will produce obvious radius change with the light intensity, while the fake iris has no dynamic response.
[0045] The Gabor filter algorithm is used to extract the iris blood vessel texture features. The Gabor filter formula is: where λ is the filter wavelength, θ is the filter direction, ψ is the phase shift, σ is the standard deviation of the Gaussian envelope, γ is the spatial aspect ratio, x′=xcosθ+ysinθ, y′=-xsinθ+ycosθ. Through multi-scale and multi-direction Gabor filtering, the detailed features of the iris blood vessel texture are obtained.
[0046] Based on the dynamic response value and the blood vessel texture matching degree (weight ratio is 0.4 and 0.6 respectively), the living confidence C iris of the iris recognition unit is calculated, and the formula is: where R is the dynamic response value normalized value, R dmax is the preset maximum dynamic response value, and Vmatch V is the number of matching textures of the current iris blood vessel texture and the user preset iris template total is the total number of blood vessel texture features. When C iris ≥ 0.85, the iris feature is determined to be a living body.
[0047] When the biometric sub-module completes at least one of face recognition, fingerprint recognition, and iris recognition, if the living body confidence of the corresponding recognition unit reaches a preset threshold (face recognition ≥ 0.8, fingerprint recognition ≥ 0.75, and iris recognition ≥ 0.85), it is determined to be a real user, and the recognition result is transmitted to the central control unit; if multiple recognition methods are used simultaneously, the average value of the living body confidence of each unit is taken as the final confidence, and when the average value ≥ 0.8, it is determined to be a real user, ensuring the accuracy and security of identity verification.
[0048] The central control unit is built-in with an intelligent decision algorithm, which can automatically determine the scene type according to the time and location information. The scene types include commuting period, night period, and holiday period. Different scenes correspond to different combinations of recognition modes. Single recognition mode is used in commuting period, and double recognition mode is used in night and holiday periods.
[0049] The central control unit also has a built-in intelligent prediction and pre-verification module for recognition results. This module collects the user's historical access data in the past 30 days through the data storage unit, including the frequency of commonly used recognition methods, the distribution of access time periods, and the preference for access locations. A decision tree machine learning algorithm is used to build a user-specific behavior model, which is automatically updated every week.
[0050] The triggering condition of the intelligent prediction and pre-verification module for recognition results is that the user enters the recognition module sensing range, and the system detects the user's presence through infrared human sensing or mobile terminal Bluetooth signal. If the user's current time and location match the usual time period and usual location characteristics in the behavior model, the system automatically preloads the user's frequently used recognition sub-module and corresponding authorization information into the cache area, shortening the verification time to ≤ 0.3 seconds during formal identification.
[0051] The intelligent prediction and pre-verification module for recognition results also has an abnormal behavior dynamic adjustment function. When abnormal behavior is detected, the system calculates the abnormality degree, and when the abnormality degree ≥ 0.6, the verification level is automatically upgraded, one additional verification item is added based on the original recognition method, and an abnormal behavior warning is sent to the remote management platform.
[0052] The current time T curr includes year, month, day, hour, and minute, and a preset date attribute table is called from the data storage unit to determine whether the current date is a holiday. Holidays are marked as H = 1, and weekdays are marked as H = 0.
[0053] The current access position attribute L is obtained by encoding the area identification bound to the physical address of the access control device, such as a unique MAC address, for example, the access control of the office area is marked as L=1, and the access control of the machine room is marked as L=2, and different positions correspond to unified preset coding.
[0054] Based on the time and position information, the scene type S is determined by an intelligent decision algorithm, and the specific steps are as follows: if it is a weekday H=0, and the current time T curr satisfies 7:00≤T curr ≤9:00 or 17:00≤T curr ≤19:00, it is preliminarily determined as a commuting period candidate, and further combined with the position attribute L, if it is a high-frequency passing area of personnel, the office entrance L=1, then it is finally determined as a commuting period, recorded as S=1.
[0055] Regardless of the date attribute H=0 or H=1, if the current time T curr satisfies 22:00≤T curr ≤6:00 the next day, it is determined as a night period, recorded as S=2.
[0056] If it is a holiday H=1, and does not satisfy the night period time range, it is determined as a holiday period, recorded as S=3.
[0057] According to the determined scene type S, a preset mode mapping table is called to determine the corresponding identification mode combination: when S=1, a single identification mode is adopted, that is, the user can select any one of the biological characteristics, the radio frequency card or the mobile terminal identification mode, and the mode code is recorded as M=1.
[0058] When S=2 or S=3, a double identification mode is adopted, and two different types of identification modes need to be selected, such as biological characteristics+radio frequency card, mobile terminal+biological characteristics, and the mode code is recorded as M=2.
[0059] The mapping relationship formula can be expressed as:
[0060] The target user's historical passing data in the past 30 days is extracted from the data storage unit, including:
[0061] The frequency F of the commonly used identification mode i (i=1,2,3) corresponds to biological characteristic identification, radio frequency identification, and mobile terminal identification, respectively, unit: times.
[0062] The passing time period distribution T dist : 24 hours a day is divided into 12 2-hour intervals, and the passing frequency T j (j=1,2,…,12) of the user in each interval is recorded.
[0063] The passing position preference Lpref : record the number of times L that the user passes through the access control at different locations k (k = 1, 2, …, n), n is the total number of access controls in the system.
[0064] Normalize the collected frequency data to eliminate the dimension effect:
[0065] Recognition method frequency normalized value Where, is the total number of passes in the last 30 days, F norm,i The value range is [0, 1], and the larger the value, the higher the frequency of using this identification method.
[0066] Passage time period normalized value Passage location normalized value
[0067] Using the decision tree machine learning algorithm, the normalized F norm,i , T norm,j , L norm,k are used as feature vectors to build a user behavior model. The split node selection of the model is based on the principle of maximum information gain. The information gain IG(A) calculation formula is: Where, Entropy(S) is the entropy of data set S, Values(A) is all possible values of feature A, S v is the subset of data set S with feature A taking value v, |S|, |S v | are the sample sizes of data set S and subset S v , respectively. The calculation formula of entropy Entropy(S) is: Where, c is the number of categories (such as different identification method combination categories), p i is the proportion of samples of the i-th category in data set S. The model automatically calls the latest 30 days of data every week to update, ensuring the timeliness of the model.
[0068] Detect whether the user enters the identification module sensing range: if the face recognition camera detects a target within 1.5 meters (judged by image contour recognition), or the radio frequency card sensing area detects a signal within 0.5 meters, it is recorded as a sensing trigger signal T rig1 = 1, otherwise T rig1 = 0, when T rig1 = 1 and T rig2 = 2, trigger the pre-verification process; otherwise, do not trigger.
[0069] Extract the current time T curr corresponding to the time interval j curr , calculate the current time period matching degree
[0070] Extract the current access control location Lcurr Calculate the matching degree of the current position.
[0071] Calculate the overall behavioral matching degree M total The weighted summation method is used (time period matching score weight 0.6, location matching score weight 0.4): M total =0.6×M T +0.4×M L If M total If the current time and location match the user's usual behavior characteristics, the system will determine if the current time and location match the user's behavior characteristics; otherwise, the system will not perform the preloading operation.
[0072] When the system determines that the behavior matches the user's usual behavioral characteristics, it automatically identifies the frequently used identification submodule, namely F. norm,i The maximum corresponding recognition method i max The system then extracts the authorization information corresponding to the user's identification method (such as biometric templates, RFID card authorization codes, mobile terminal binding information, etc.) from the data storage unit and loads it into the system cache. After preloading, the verification time t during actual identification can be shortened to ≤0.3 seconds, with a time reduction rate R. t The calculation formula is: Among them, t original This is the average verification time without preloading, typically 1-2 seconds, t preload This refers to the verification time after preloading.
[0073] Non-standard time period access determination: If the current time period matching degree M T <0.3 (preset low matching threshold), is recorded as time period anomaly A. T =1, otherwise A T =0.
[0074] Determination of Non-High-Frequency Recognition Methods: If the user's currently selected recognition method i curr corresponding (Preset low-frequency threshold) is denoted as abnormal identification method A. F =1, otherwise A F =0.
[0075] When A T =1 or A F When the value is 1, abnormal behavior is determined; otherwise, it is determined as normal behavior.
[0076] Calculate the degree of behavioral anomaly D based on anomaly type. abn The formula is: Where α is the time period anomaly weight (value 0.5), β is the identification method anomaly weight (value 0.5), (1-M T () represents the contribution value of anomalies during the time period. To identify the mode of abnormal contribution value, D abn The value range is [0, 1].
[0077] If D abn ≥ 0.6, the preset abnormal threshold, automatically promote the verification level: on the basis of the user's current selection of identification mode, increase 1 additional verification item, such as the original selection of fingerprint identification, additional face recognition verification, the new verification mode combination is M new = M curr +1, M curr is the original verification mode.
[0078] At the same time, send the abnormal behavior warning information to the remote management platform, the warning information contains user ID, abnormal time T curr , abnormal position L curr , abnormal degree D abn and the current identification mode, the warning trigger flag W is set to 1, the formula is expressed as: If D abn < 0.6, maintain the original verification level, do not send the warning.
[0079] The system has a multi-module cooperative fault self-healing function, the central control unit sends a heartbeat detection signal to each identification sub-module every 30 seconds, and if there is no feedback for 3 times in a row, it is determined that the module is faulty. At the same time, through image analysis, circuit voltage detection, positioning fault type, through lock body current detection, audio feedback detection to judge the state of the linkage execution mechanism, through the communication protocol state detection to locate the communication link fault.
[0080] The central control unit sends a heartbeat detection signal S ighb to each identification sub-module, biological feature recognition, radio frequency identification, mobile terminal identification, every 30 seconds, records the feedback signal S igfb of the sub-module.
[0081] Set the continuous no feedback times threshold K = 3, if a sub-module does not return S igfb for K times in a row, that is, S igfb = 0, then preliminarily determine that the sub-module is faulty, the fault mark F mod = 1; otherwise F mod = 0.
[0082] Further positioning of fault type (hardware fault / software fault):
[0083] Hardware fault detection: through the circuit voltage detection module to collect the sub-module power supply voltage V mod , if V mod is out of the normal range, the preset normal voltage range V min < V mod < V maxIf the normal voltage of the biometric sub-module is 5V±0.2V, it is determined that there is a hardware failure, and the failure type T fault =1.
[0084] Software failure detection: if V mod is within the normal range, the image analysis (e.g., whether the biometric sub-module can output valid image data) or data interaction detection (e.g., whether the RFID sub-module can parse card data) is performed. If valid data cannot be output, it is determined that there is a software failure, and the failure type T fault =2
[0085] Lock body state detection: the working current I lock of the lock body is collected by the lock body current detection module, and the normal working current range I min of the lock body is preset. lock <I max If I lock is outside the range, it is recorded as lock body current anomaly A I =1; otherwise, A I =0.
[0086] Audio feedback detection: the audio feedback signal S i g audio of the actuator is collected by the audio detection module. If the preset normal audio (e.g., the click sound of the lock body switch) is not detected, it is recorded as audio anomaly A audio =1; otherwise, A audio =0. If A I =1 or A audio =1, it is determined that there is a failure in the linkage actuator, and the failure flag F exe =1; otherwise, F exe =0
[0087] The data packet transmission success rate R trans of the communication link is collected by the communication protocol state detection module (e.g., TCP / IP protocol detection), and the calculation formula is as follows: where N suc is the number of successfully transmitted data packets, and N total is the total number of transmitted data packets. If R trans <90% of the preset success rate threshold), it is determined that there is a communication link failure, and the failure flag F com =1; otherwise, F com =0.
[0088] The multi-module cooperative fault self-healing function adopts a hierarchical self-healing strategy: when a sub-module fault is identified, it is automatically switched to other authorized sub-modules of the user, the user is guided to operate through the sound and light prompting unit, when the linkage actuator fails, the standby lock body and the LED text prompt screen are activated, when the communication link fails, it is automatically switched to the standby network, and the local data is temporarily stored and synchronized to the cloud after the communication is restored.
[0089] When F mod = 1, the list of other authorized sub-modules of the user is called from the data storage unit List auth , such as the user has authorized biometric identification and mobile terminal identification, if the biometric identification sub-module fails, List auth extracts mobile terminal identification, automatically switches to the identification sub-module in the list, switches the execution flag S switch = 1, and simultaneously starts the sound and light prompting unit to guide the user to operate. The success rate of switching , where N succ_switch is the number of successful switches, N total_switch is the total number of switches, and R switch ≥ 95%.
[0090] When F exe = 1, the standby lock body is activated, the standby lock body response time t resp ≤ 0.5 seconds, and the response time calculation formula is: t resp = T activate -T fault_detect , where T activate is the standby lock body activation time, and T fault_detect is the fault detection completion time.
[0091] Simultaneously start the LED text prompt screen to display fault information and prompt the user to use normally.
[0092] When F com = 1, it is automatically switched to the standby network (such as switching to a 4G / 5G wireless network from a wired network), and the switching trigger signal Trig com = 1. The local data (such as access records, fault logs) is temporarily stored in the local cache area of the data storage unit, and after the communication is restored (determined by R trans ≥ 90%), the local temporarily stored data is synchronized to the cloud, and the data synchronization integrity I sync is calculated as follows: , where N sync_suc is the number of successfully synchronized data to the cloud, N sync_total is the total number of local temporarily stored data, and I sync = 100%.
[0093] The power supply unit adopts a dual power supply mode of commercial power and backup battery. The commercial power is supplied through an AC 220V to DC 12V / 2A power adapter, and the backup battery is a 18650 lithium battery pack. When the commercial power is interrupted, the backup battery can maintain the normal operation of the system core function for not less than 4 hours, and send a commercial power interruption reminder to the remote management platform.
[0094] Embodiment one: This embodiment is for a certain commercial office building, including a first floor lobby, 2-15 floor office area, underground 1 floor garage, system configuration and operation process as follows:
[0095] The first floor lobby access control integrates a biological feature recognition sub-module, a binocular camera with a resolution of 1920x1080 and a frame rate of 30fps, and a near-infrared light supplement wavelength of 850nm; a capacitive fingerprint sensor with a resolution of 500dpi and a working temperature of -20℃-60℃, a radio frequency identification sub-module, a 125KHz / 13.56MHz dual-frequency card reader with a reading distance of 0-10cm, an encryption algorithm of AES-128, a mobile terminal identification sub-module equipped with a Bluetooth 5.0 module + NFC reader, and a WiFi6 communication speed of 1.2Gbps, and a 10.1-inch touch screen for displaying identification status and operation guidance.
[0096] The 2-15 floor office area access control integrates a biological feature recognition sub-module, only face recognition + fingerprint recognition unit, and a password recognition sub-module equipped with an anti-peeping touch keyboard supporting 4-12 dynamic passwords, and a digital layout randomly disturbed every 30 seconds, and no radio frequency identification sub-module to avoid card management confusion in the office area.
[0097] The underground garage access control integrates a radio frequency identification sub-module, a 13.56MHz high-frequency card, an adaptive vehicle passive tag, a mobile terminal identification sub-module, only Bluetooth 5.0, supporting automatic induction when the vehicle is close, and no biological feature recognition sub-module to avoid the influence of the dim environment of the garage on the recognition accuracy.
[0098] The central control unit configuration: adopts an industrial-grade ARM Cortex-A9 processor, built-in Linux system, carries intelligent decision algorithm and fault detection program; communication interface supports RS485, TCP / IP, 4G module.
[0099] The linkage execution mechanism configuration: the first floor lobby and the office area access control use electromagnetic locks, and the garage access control uses motor locks; each access control is equipped with an audible and visual prompt unit and a 1.5-inch LED backup display screen; the first floor lobby and the underground garage access control are additionally equipped with a backup electromagnetic lock.
[0100] Data storage and remote management platform configuration: local data storage uses encrypted Flash chip, cloud server is deployed in building property machine room; remote management platform supports Web and mobile APP, sets 3-level administrator permissions, super administrator: manages all devices and users; floor administrator: only manages corresponding floor access control and users; security administrator: only views access records and handles alarms.
[0101] Power supply unit configuration: all access control devices use mains power + backup battery dual power supply, mains power is supplied through AC 220V to DC 12V / 2A power adapter, backup battery is 2 pieces of 18650 lithium battery; the first floor hall access control is additionally connected to the building UPS to ensure that the system can run for not less than 8 hours when the mains power is interrupted.
[0102] During the rush hour period, 7:30-9:00 and 17:00-19:00 on weekdays:
[0103] First floor hall access control: the central control unit determines the scene as rush hour period through intelligent decision algorithm, automatically enables single recognition mode; at the same time, the recognition result intelligent prediction and pre-validation module starts: through the data storage unit to retrieve the user's historical data in the past 30 days, employee A uses face recognition for 85% of the access in the past 30 days, and accesses frequently from 7:45 to 8:00 every day, and builds a behavior model. When employee A enters the hall at a distance of 1.2 meters from the face recognition camera, the infrared human body sensor detects the presence of the user, the system matches the behavior model, the current time is 7:48, which meets the usual time period; the location is the first floor hall, which meets the usual location, and automatically preloads the face feature template of employee A to the cache area of the central control unit, with a cache validity period of 10 seconds. When employee A faces the camera, the system directly calls the cached template for feature matching, the cosine similarity calculation result is 0.95 (≥ 0.92 threshold), the liveness confidence calculation result is 0.88, the depth information matching degree is 0.9, the skin texture similarity is 0.85, the dynamic feature detection value is 0.88, α = 0.4, β = 0.3, γ = 0.3, and the recognition is determined to be passed, the opening door command is sent within 0.2 seconds, the electromagnetic lock is opened, and the sound and light prompt unit emits green light and ding sound, and the access record is stored synchronously to the local and cloud.
[0104] 2-15 floor office area access control: single recognition mode is also enabled, employees can choose face recognition or fingerprint recognition; for example, employee B chooses fingerprint recognition, after the sensor collects the fingerprint image, 18 feature points (≥ 15 effective feature points) are extracted after preprocessing, the matching rate with the template is 0.78 (≥ 0.7 threshold), the liveness confidence is 0.82 (pressure change rate 0.85, skin capacitance value 0.78, δ = 0.6, ε = 0.4), and the access control is opened after the recognition is passed.
[0105] Non-working hours, weekdays 9:00-17:00, weekends and holidays all day:
[0106] Entrance guard of the first floor lobby: dual recognition mode is enabled when the scene is determined to be night time / holiday period; for example, security personnel C needs to enter the building at 20:30, selects face recognition + radio frequency card combination recognition: after face recognition passes (similarity 0.93, living body confidence 0.85), the encrypted ID of the radio frequency card is read, the central control unit compares the ID with the authorized permissions, and sends an opening instruction after confirming the match, and pushes a non-working period access notice to the security administrator APP.
[0107] Entrance guard of the underground garage personnel passage: radio frequency card + mobile terminal dual recognition is enabled, employee D swipes the card, needs to generate an encrypted two-dimensional code through the mobile terminal APP, and the door is opened after the two-dimensional code verification passes, avoiding illegal entry caused by loss of the radio frequency card.
[0108] Abnormal behavior processing: employee E's usual access period is 8:00-8:30, and the usual recognition method is face recognition. At 1:20 in the morning, he attempts to pass through the first floor lobby and uses password recognition; the system calculates the abnormality degree of the behavior: time period matching degree 0.1 (non-usual time period), location matching degree 1.0 (the first floor lobby is the usual location), recognition method matching degree 0.2 (non-usual method), automatically upgrades the verification level to triple recognition, password + fingerprint + face recognition, and sends an abnormal warning to the super administrator and the security administrator, including the live camera snapshot; after employee E completes the triple recognition and all pass, the door is opened, and the system records the complete abnormal processing log.
[0109] Fault processing of recognition sub-module: the face recognition unit of a door guard in the first floor lobby is damaged due to a camera, the central control unit sends a heartbeat detection signal every 30 seconds, and there is no feedback for 3 consecutive times. Combined with image analysis, the fault type is determined to be a hardware fault, and the self-healing strategy is triggered immediately: automatically switch to the next highest weight recognition method, and at the same time, display the face recognition fault on the LED backup display screen, please swipe the radio frequency card or use the mobile terminal APP to recognize, and the sound and light prompt unit synchronously broadcasts the voice; the fault information is sent to the remote management platform in real time, and after the maintenance personnel receive the notification, replace the camera during the next maintenance period, and the door guard is normal during this period, without service interruption.
[0110] Lock body fault processing: the main electromagnetic lock of the door guard of the 10th floor conference room is damaged due to a short circuit in the circuit, the central control unit detects the abnormal current of the lock body, and activates the standby electromagnetic lock within 0.3 seconds. After the employee completes the fingerprint recognition, the standby lock body is normally opened; the system sends a main lock body fault notification to the maintenance administrator, which has switched to the standby lock, and the administrator can replace the main lock body after the meeting ends without affecting the meeting.
[0111] Embodiment two: this embodiment is directed to a certain high-end residential community, a total of 20 buildings, each 18 floors, 1200 households, a community gate, each building unit door 2, 2 underground garage entrances, system configuration and operation process as follows:
[0112] The community gate access control integrates a biometric feature recognition sub-module, a mobile terminal recognition sub-module, and a password-free recognition sub-module; the unit door access control integrates a biometric feature recognition sub-module and a password recognition sub-module, and does not have a radio frequency recognition sub-module; the underground garage entrance access control integrates a radio frequency recognition sub-module and a mobile terminal recognition sub-module; the central control unit is configured with an industrial-grade processor of the same type as that used in office buildings, an additional LoRa module, a built-in owner behavior model, an increased household sharing permission parameter, and support for owner authorization of recognition permissions for family members.
[0113] Linkage actuator configuration: the community gate and the unit door use electromagnetic locks, and the garage vehicle passage uses a barrier gate; each access control device is equipped with a high-definition monitoring camera and is linked with an abnormal alarm unit.
[0114] Data storage and remote management platform configuration: local storage retains 90 days of access data, and cloud storage retains 3 years of data; the remote management platform increases a visitor management module, which supports the generation of a temporary password or an encrypted two-dimensional code by the owner through the APP and sending it to the visitor.
[0115] Power supply unit configuration: the standby battery capacity of the unit door access control is increased to 10000mAh, and the garage access control is connected to the community UPS system to ensure that the barrier gate can be normally lifted during power failure.
[0116] Community gate access: owner F carries a mobile phone, opens the system APP Bluetooth, and when the distance from the gate is 50 meters, the APP positioning triggers the pre-verification preparation; when the owner F enters the face recognition range of 1.5 meters, the system preloads his face feature template, and completes the recognition within 0.25 seconds, and the access control is opened; if the owner F does not carry a mobile phone and the face has temporary changes, iris recognition can be switched to, the system collects the iris image, extracts a 256-dimensional feature vector, and the similarity with the template is 0.96 (≥0.95 threshold value), the living body confidence is 0.88 (dynamic response value 0.85, blood vessel texture matching degree 0.9, ζ=0.55, η=0.45), and the recognition is passed.
[0117] Unit door access: the family members of owner G have been authorized to share permissions, and choose fingerprint recognition, the sensor collects the fingerprint, the matching rate is 0.76 (≥0.7 threshold value), the living body confidence is 0.81, and the access control is opened; if the owner G needs to let the visitor in, a temporary password can be generated through the APP, the visitor inputs the password, the system verifies the validity of the password, and at the same time, the visitor's photo is captured and stored in the cloud for subsequent tracing.
[0118] Garage access process: When owner H drives into the garage, the vehicle's RFID tag enters the recognition range. The system reads the tag's encrypted ID, compares the authorization permissions, and raises the barrier gate within 0.3 seconds. If the vehicle tag is invalid, owner H can turn on Bluetooth via a mobile app. After the system senses the signal, it automatically verifies the owner's identity, and the barrier gate raises normally.
[0119] Troubleshooting Procedure: The fingerprint recognition unit on a building's unit door malfunctioned due to moisture. After the central control unit detected the fault, it automatically switched to a dual recognition mode of facial recognition + temporary password. The LED display showed a fingerprint recognition malfunction, and residents were advised to use facial recognition or a temporary password. At the same time, a fault notification was sent to the property manager. The manager checked the monitoring footage of the malfunctioning access control system through the remote management platform. After confirming that there were no abnormalities, on-site repair was arranged for the next day. During this period, the unit door was open to traffic normally, and there were no complaints from residents.
[0120] As can be seen from the above embodiments, the access control system of the present invention, which integrates multiple identification methods, can flexibly configure hardware and software parameters according to the needs of different scenarios. Through intelligent prediction, dynamic adjustment and fault self-healing mechanisms, it can achieve the goals of efficient passage, high security and high reliability. It is suitable for various places with high requirements for access control and security and has broad application value.
[0121] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0122] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. An access control system integrating multiple identification methods, characterized in that: The system includes an identification module group, a central control unit, a linkage actuator, a data storage unit, a remote management platform, and a power supply unit. The identification module group is used to collect user identification information. The central control unit is used to process the identification information and generate control commands. The linkage actuator is used to respond to control commands to realize access control opening and closing and status prompts. The data storage unit is used to store user data and system operation records. The remote management platform is used for remote monitoring and management. The power supply unit is used to supply power to the various modules of the system.
2. The access control system integrating multiple identification methods according to claim 1, characterized in that: The identification module group includes at least a biometric identification submodule, a radio frequency identification submodule, and a mobile terminal identification submodule. The biometric identification submodule integrates a face recognition unit, a fingerprint recognition unit, and an iris recognition unit, and each unit has a liveness detection function. The radio frequency identification submodule supports reading 125KHz low-frequency cards and 13.56MHz high-frequency cards and has anti-copying encryption function. The mobile terminal identification submodule connects to the user's mobile terminal via Bluetooth 5.0, NFC, or WiFi 6 protocols and supports dynamic verification codes, encrypted QR codes, and APP authorization recognition.
3. The access control system integrating multiple identification methods according to claim 1, characterized in that: The liveness detection function of the biometric recognition submodule is achieved through multi-dimensional feature determination: the face recognition unit calculates the liveness confidence score through depth information, skin texture and dynamic features; the fingerprint recognition unit determines liveness through pressure change rate and skin capacitance value; and the iris recognition unit confirms liveness through dynamic reaction and blood vessel texture matching degree. When the liveness confidence score is greater than or equal to the preset threshold, it is determined to be a real user.
4. The access control system integrating multiple identification methods according to claim 1, characterized in that: The central control unit has a built-in intelligent decision-making algorithm that can automatically determine the scene type based on time and location information. The scene types include commuting time, nighttime time and holiday time. Different scenes correspond to different recognition mode combinations. A single recognition mode is used during commuting time, while a dual recognition mode is used during nighttime and holiday time.
5. The access control system integrating multiple identification methods according to claim 1, characterized in that: The central control unit also has a built-in intelligent prediction and pre-verification module for recognition results. This module collects the user's historical passage data for the past 30 days through the data storage unit, including the frequency of commonly used recognition methods, the distribution of passage time periods and passage location preferences. It uses a decision tree machine learning algorithm to build a user-specific behavior model, which is automatically updated weekly.
6. The access control system integrating multiple identification methods according to claim 1, characterized in that: The triggering conditions for the intelligent prediction and pre-verification module of the recognition result are as follows: the user enters the sensing range of the recognition module, and the system detects the presence of the user through infrared human body sensing or mobile terminal Bluetooth signal. If the user's current time and location match the habitual time period combined with habitual location features in the behavior model, the system automatically preloads the recognition sub-modules frequently used by the user and the corresponding authorization information into the cache area, shortening the verification time during formal recognition to ≤0.3 seconds.
7. The access control system integrating multiple identification methods according to claim 1, characterized in that: The intelligent prediction and pre-verification module for the identification results also has a dynamic adjustment function for abnormal behavior. When abnormal user behavior is detected, the system calculates the abnormality degree. When the abnormality degree is ≥0.6, the verification level is automatically upgraded, an additional verification item is added on the basis of the original identification method, and an abnormal behavior warning is sent to the remote management platform.
8. The access control system integrating multiple identification methods according to claim 1, characterized in that: The system has a multi-module collaborative fault self-healing function. The central control unit sends a heartbeat detection signal to each identification sub-module every 30 seconds. If there is no feedback for 3 consecutive times, the module is determined to be faulty. At the same time, the fault type is located by image analysis and circuit voltage detection, the status of the linkage actuator is determined by lock body current detection and audio feedback detection, and the communication link fault is located by communication protocol status detection.
9. The access control system integrating multiple identification methods according to claim 1, characterized in that: The multi-module collaborative fault self-healing function adopts a hierarchical self-healing strategy: when a sub-module is identified as faulty, it automatically switches to another identification sub-module that has been authorized by the user, and guides the user to operate through the sound and light prompt unit; when the linkage actuator fails, it activates the backup lock body and LED text prompt screen; when the communication link fails, it automatically switches to the backup network and temporarily stores local data until communication is restored and synchronized to the cloud.
10. The access control system integrating multiple identification methods according to claim 1, characterized in that: The power supply unit adopts a dual power supply mode of AC mains power and backup battery. The AC mains power is supplied through an AC220V to DC12V / 2A power adapter, and the backup battery is an 18650 lithium battery pack. When the AC mains power is interrupted, the backup battery can maintain the normal operation of the core functions of the system for no less than 4 hours, and at the same time send a power interruption reminder to the remote management platform.