A permission management device and method suitable for a heterogeneous access controller
By designing an access control management device adapted to heterogeneous access control controllers, and adopting an ARM+FPGA heterogeneous architecture and multiple communication protocol modules, unified management of heterogeneous access control controllers is achieved, solving the problem of low access control efficiency and improving the security and reliability of the system.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ZHEJIANG NINGHANG ENERGY TECHNOLOGY CO LTD
- Filing Date
- 2025-11-17
- Publication Date
- 2026-07-21
AI Technical Summary
Existing technologies are unable to effectively solve the access control management problem of heterogeneous access control controllers, resulting in high system integration difficulty, cumbersome operation, low efficiency, and the existence of permission configuration errors or security vulnerabilities.
Design a permission management device and method adapted to heterogeneous access control controllers. By setting up heterogeneous access control controllers, access control management system and user terminal, adopting ARM+FPGA heterogeneous architecture, multiple communication protocol modules, multi-channel authentication, flexible permission control, hierarchical storage and intelligent learning mechanism, unified management and permission configuration of multiple access control controllers can be realized.
It enables unified and centralized management of heterogeneous access control controllers, reduces system integration and maintenance costs, improves the efficiency and security of access control, ensures the consistency and accuracy of access control data, and enhances the security and reliability of the system.
Smart Images

Figure CN121482905B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of intelligent security and access control technology, specifically to a permission management device and method adapted to heterogeneous access control controllers. Background Technology
[0002] With the development of intelligent security technology, access control systems are widely used in various places such as office buildings, residential communities, and factory parks. As the core component of the access control system, the access controller is responsible for verifying personnel identity information and controlling the opening and closing of access control devices. However, in actual application scenarios, there are often multiple heterogeneous access controllers coexisting. These heterogeneous access controllers differ in hardware architecture, communication protocols, and data formats, which brings many challenges to access control management.
[0003] On the one hand, access controllers produced by different manufacturers use different communication protocols, such as RS485, TCP / IP, ZigBee, Bluetooth, etc., and the data exchange formats are also different, which makes system integration difficult and makes it hard to achieve unified access management and monitoring. For example, old access controllers may use the RS485 protocol, while newly deployed controllers use the TCP / IP protocol, and the two controllers cannot directly exchange data and work together.
[0004] On the other hand, traditional access control methods are usually designed for a single type or a few types of access controllers, lacking adaptability to heterogeneous environments. When it is necessary to configure, update, and query permissions for a large number of heterogeneous access controllers, the operation is cumbersome, inefficient, and prone to permission configuration errors or conflicts. In addition, with the onboarding, offboarding, and job changes of personnel, traditional access control methods are difficult to quickly and accurately update the permission information of each access controller, resulting in security vulnerabilities.
[0005] While existing technologies offer solutions for access control system access management, most fail to effectively address the challenges of managing access in heterogeneous access control controller environments. Some solutions develop specific adapter modules to interface with different access control controllers, but this approach requires separate development for each controller type, resulting in poor scalability and versatility. Other solutions modify access control controllers using a unified communication protocol, but this method is costly and difficult to implement across a large number of existing access control controllers in practical applications. Therefore, the applicant proposes an access management device and method adapted to heterogeneous access control controllers, effectively adapting to access management in these environments to improve efficiency, accuracy, and security. Summary of the Invention
[0006] To address the aforementioned technical problems, this invention proposes a permission management device and method adapted to heterogeneous access control controllers. This involves setting up a heterogeneous access control controller, an access control management system, and a user terminal. The heterogeneous access control controller includes a computing main control module, a communication module, an authentication module, a permission execution module, a status acquisition module, a storage module, and a power supply module. The access control management system includes a protocol adaptation management module, a permission engine detection module, a data storage management module, and a user authentication management module. The user terminal includes a human-computer interaction module, a permission configuration management module, a status monitoring and display module, and an alarm receiving module. The device is used by installing the heterogeneous access control controller, connecting it to other access control controllers, and using the user terminal for permission configuration, communication debugging, control and management of the heterogeneous access control controllers, and displaying their working status. This achieves the need for unified and centralized management of multiple different access control controllers, reducing system integration and maintenance costs.
[0007] To achieve the above objectives, the technical solution adopted by the present invention is as follows: A permission management device and method adapted to heterogeneous access control controllers are disclosed, characterized in that: the permission management device for heterogeneous access control controllers comprises a heterogeneous access control controller, an access control management system, and a user terminal; the heterogeneous access control controller is equipped with a computing main control module, a communication module, an authentication module, a permission execution module, a status acquisition module, a storage module, and a power supply module; the access control management system is equipped with a protocol adaptation management module, a permission engine detection module, a data storage management module, and a user authentication management module; the user terminal is equipped with a human-computer interaction module, a permission configuration management module, a status monitoring and display module, and an alarm receiving module; the method of using the permission management device for heterogeneous access control controllers involves installing the heterogeneous access control controller, connecting it to other access control controllers, and using the user terminal to configure permissions, debug communication, control and manage the heterogeneous access control controllers, and display and view their working status, thus meeting the need for unified and centralized management of multiple different access control controllers.
[0008] Furthermore, the communication module, authentication module, permission execution module, status acquisition module, storage module, and power module of the heterogeneous access control controller configured in the permission management device for the heterogeneous access control controller are specifically as follows: The main control module adopts a heterogeneous architecture of ARM+FPGA as the main control unit. The ARM processor is responsible for running the operating system and high-level software of the access control system, handling complex business logic and data management. The FPGA is used to realize high-speed data processing and protocol parsing acceleration, quickly handle a large number of concurrent data requests from access controllers, and perform hardware-accelerated decryption of encrypted data, significantly improving the processing performance and response speed of the device. Communication module; The communication module integrates an RS485 interface, a ZigBee wireless communication module, a Bluetooth communication module, and an Ethernet interface to connect to a local area network switch, enabling heterogeneous access control controllers and access management devices with different communication protocols to communicate with each other. The identity verification module employs multiple verification methods, including password verification, digital certificate verification, fingerprint verification, and device fingerprint generation based on the controller's hardware characteristics. The verification is compared with pre-stored verification information upon input. For newly connected controllers, a dual verification method of "initial access whitelist + behavior analysis" is used. If the controller's behavior conforms to the normal access mode, access is allowed; otherwise, it is rejected and an anomaly log is recorded. The permission execution module employs spatial, temporal, and scenario dimensions, associating permission units with scenario tags to achieve more flexible permission control. Simultaneously, it sets permission validity periods for the basic permission execution module, including absolute validity, relative validity, and cyclical validity. Status acquisition module; The status acquisition module acquires basic information of heterogeneous access controllers and collects information of their internal functional modules. For controllers with multiple communication protocols, it records in detail the priority, bandwidth usage and data transmission stability parameters of each protocol. For example, if a certain model of controller supports both TCP / IP and Bluetooth protocols, the emergency switching mechanism and switching threshold mode of the Bluetooth protocol when the network is unstable can be known through data acquisition. Storage module; The storage module adopts RAID disk array technology to achieve redundant data storage and improve data reliability. At the same time, it introduces a tiered storage strategy, storing frequently accessed permission data and operation logs on high-speed solid-state drives to improve read and write speeds; storing historical permission data and infrequently used configuration information on large-capacity mechanical hard drives; The storage media uses advanced encryption storage technology to encrypt the stored permission data and program code to prevent data leakage and unauthorized tampering. Power module; The power module is equipped with overvoltage and overcurrent protection devices and a UPS power supply to prevent power failures from damaging the equipment; it provides a stable power supply to ensure the normal operation of the equipment.
[0009] Furthermore, the access control management system's protocol adaptation management module, access engine detection module, data storage management module, and user authentication management module, as set up by the access control management device adapted to heterogeneous access control controllers, specifically comprises: Protocol adaptation management module; The protocol adaptation management module adopts a dynamic protocol optimization and intelligent learning mechanism management mode. Based on the historical communication data of the access control controller, it dynamically adjusts the protocol parsing and conversion strategy. When a certain type of protocol frequently experiences packet loss during data transmission, the system automatically optimizes the caching strategy and retransmission mechanism of that protocol module. At the same time, it supports online upgrades of the protocol adaptation layer, and remotely pushes new protocol parsing algorithms through the permission management system to ensure compatibility with newly emerging access control controller protocols. The software includes a permission engine detection module and a protocol adaptation layer. The built-in intelligent learning engine analyzes the communication data patterns of different access controllers to automatically learn and optimize protocol parsing and conversion rules. When encountering new communication protocols or variants, the learning engine can quickly generate adaptation rules by analogy and reasoning based on the characteristics of existing protocols. The core management software adds a permission simulation testing function, allowing administrators to preview the effects of permission adjustments before making changes and to detect potential permission conflicts or unreasonable permission allocations. A permission auditing module is also introduced to periodically audit permission allocation and usage, generate audit reports, identify potential security risks, and propose improvement suggestions. Furthermore, the software supports multi-user collaborative management, allowing multiple administrators to log in simultaneously for permission management operations. The system uses a locking mechanism to ensure data consistency and integrity. The data storage management module uses flash memory in its storage unit for long-term storage of various data from the access control system. The system stores user access data, access controller configuration information, operation logs, and other data according to a specific database structure, managed using a relational database. Access data is organized and stored according to user, role-based access groups, and basic access units for easy and quick querying and management. To ensure data security, the system periodically backs up the stored data. Backup data is stored on external storage devices and encrypted using encryption algorithms to prevent data leakage. The system also records backup operation logs, including backup time, backup data size, and storage location. When the access control device experiences hardware failure or data corruption, administrators can recover system data from the backup data using the data recovery function. During recovery, the system first verifies the integrity and legality of the backup data, then imports the backup data into the storage unit, overwriting the damaged data and restoring the system to normal operation. The user authentication management module establishes a mapping relationship between role and permission groups and organizational structure. When the enterprise's organizational structure changes, the system automatically adjusts the role and permission groups according to the new organizational structure. For example, after two departments merge, the role and permission groups corresponding to the original departments are automatically merged, and duplicate permission units are removed. At the same time, corresponding permissions are added according to the functional requirements of the new department. In addition, version management of role and permission groups is introduced to record the historical versions of each permission adjustment, which facilitates traceability and rollback. When assigning permissions to users, the system generates a permission recommendation scheme through machine learning algorithms based on information such as the user's position, historical access records, and permission configurations of other users in the same position. At the same time, it detects potential conflicts in the user permission allocation process in real time, such as multiple mutually exclusive access permissions within the same time period. When a conflict is detected, the system automatically prompts the administrator and provides conflict resolution suggestions, such as adjusting the permission time range or canceling some conflicting permissions.
[0010] Furthermore, the user terminal's human-computer interaction module, permission configuration management module, status monitoring and display module, and alarm receiving module in the permission management device adapted to heterogeneous access control controllers specifically include: Human-computer interaction module; The human-computer interaction module is equipped with a high-resolution touch screen and supports gesture operation and voice interaction; Administrators can configure permissions and perform query operations through voice commands; The access control configuration module sets up device addition and access control, as well as personnel addition and access control modes. Device addition and access control acquire basic information about heterogeneous access controllers through network scanning or manual addition. For each access controller, based on its communication protocol type, the appropriate protocol parsing and conversion module is selected in the protocol adaptation layer software, and parameters are configured to ensure normal data communication with the access controller. For example, for access controllers using the TCP / IP protocol, parameters such as IP address and port number are configured; for controllers using the RS485 protocol, parameters such as communication baud rate, data bits, and stop bits are set. This is all done within the core access control software. The system initializes and builds the permission model; defines basic permission units and creates role permission groups based on different user roles; associates actual users with role permission groups to complete the initial allocation of user permissions; the personnel addition and permission setting mode is as follows: when a new employee joins the company, the administrator logs into the permission management system through the user terminal; in the permission management interface, finds the user account corresponding to the new employee and associates it with the "ordinary employee group" role permission group, and the system automatically assigns the employee the permission set corresponding to ordinary employees; if the employee needs additional access to certain specific areas due to work requirements, the administrator can manually add the corresponding basic permission units for them in the permission configuration interface to achieve personalized permission allocation; Status monitoring and display module; The status monitoring and display module adopts a visual graphical interface to display the connection status and permission distribution of the access control controller in the form of a topology diagram, which makes it convenient for managers to intuitively manage and monitor the system; Alarm receiving module: When the alarm receiving module receives an abnormal situation from the access control controller, it will send an alarm signal in the form of a pop-up window. At the same time, when equipped with an audible and visual alarm, it will trigger an alarm and send an alarm signal to the administrator.
[0011] Furthermore, the specific steps of the method for the access control management device adapted to heterogeneous access control controllers are as follows: Step 1: Install the access control device of the heterogeneous access controller on site, connect it to the power supply, and connect it to the local area network switch through the communication module to ensure that the device can communicate with other devices in the network; and connect the heterogeneous access controllers with different communication protocols to the access control device through RS485 interface, ZigBee wireless communication module or Bluetooth communication module according to actual needs. Step 2: Install the user terminal on the administrator's computer or mobile phone. After installation, initialize the system, configure network parameters such as IP address, subnet mask, and gateway, and create user accounts and assign permissions. Step 3: Add devices and set access control and personnel and set permissions through the permission configuration management module; device addition obtains basic information of heterogeneous access controllers through network scanning or manual addition; for each access controller, select the corresponding protocol parsing and conversion module in the protocol adaptation layer software according to its communication protocol type, and configure the parameters to ensure normal data communication with the access controller; define basic permission units and create role permission groups according to different user roles; associate actual users with role permission groups to complete the initial allocation of user permissions; when a new employee joins, the administrator adds the employee list through the user terminal, creates a user account, and associates the corresponding user account with the "ordinary employee group" role permission group. The system automatically assigns the employee the permission set corresponding to ordinary employees; if the employee needs additional access to certain specific areas due to work requirements, the administrator can manually add the corresponding basic permission units for them in the permission configuration interface; when an employee's position changes, such as being promoted from an ordinary employee to a department manager, the administrator... The administrator changes the employee's role and permission group to "Department Manager Group" in the access control system. The system immediately generates a permission update instruction and converts it into a format recognizable by the relevant access controllers through protocol adaptation layer software, then sends it to the corresponding access controllers. Upon receiving the update instruction, the access controller executes the permission update operation, updates the employee's permission information on its own controller, and feeds back the update result to the access control system. The access control system records log information about this permission update operation, including update time, operator, users involved, and access controllers. Simultaneously, visitor permission management is set up. Administrators create temporary user accounts for visitors in the access control system and assign corresponding basic permission units based on the visitor's access needs, such as permission to enter a designated meeting room within a specific time period. Visitors use temporary permission credentials to authenticate and request permissions at the access controller. After successful verification by the access control system, the access controller allows the visitor to pass. After the visitor's visit ends, administrators can delete or disable the visitor's temporary user account and revoke their permissions in the access control system. Step 4: After setup, the device operates automatically. When a person authenticates their identity at the access control controller using an access card or biometric identification, the controller encapsulates the person's identity information and permission request into a data frame and sends it to the access management device via its own communication protocol. Upon receiving the permission request, the access management device's protocol adaptation layer software converts the data frame into a unified format. The access verification module in the core access management software queries the corresponding permission set based on the person's identity information and matches it with the permission request. For example, if the user account corresponding to the access card held by the person belongs to the "ordinary employee group," and the permission request is to enter a certain floor of the office area, the access... The access control module checks whether the user's permission set includes access to that floor. If it does, it returns an instruction to allow access; otherwise, it returns an instruction to deny access and records the access failure information in the system log, including the verification time, personnel identity information, and access controller location. The access controller executes the corresponding operation based on the instructions returned by the access control device. If it receives an instruction to allow access, it controls the access control device to open, allowing personnel to enter; if it receives an instruction to deny access, it keeps the access control closed and can issue an audible or visual alarm according to the settings, while displaying the reason for the denial on the access controller's screen. Step 5: Access Control Status Display. The status monitoring display module uses a visual graphical interface to show the connection status and permission distribution of the access control controllers in the form of a topology diagram. This facilitates intuitive system management and monitoring for administrators. During the display process, the system initiates a permission data synchronization and verification process according to a set cycle. The system first retrieves a list of all connected access control controllers from the device management database, and then communicates with each access control controller sequentially to obtain its currently stored permission data. The permission management system compares the obtained access control controller permission data with its own stored permission data. The comparison methods include checking the number of permission units, the identifier of the permission unit, and the permission description information, etc. If a certain access control controller is found to be in violation of the system's rules, the system will immediately take action. If the access control controller's permission data is inconsistent with the system, the system automatically generates a permission synchronization command and converts it into a format recognizable by the access control controller through protocol adaptation layer software before sending it to the access control controller. Upon receiving the synchronization command, the access control controller updates its local permission data according to the command requirements and feeds back the update result to the access control management system. If a communication failure or access control controller malfunction occurs during the data synchronization process, preventing the synchronization operation from being completed, the access control management system records the log information of the synchronization failure, including the failure time, access control controller identifier, and failure reason, and continues to attempt synchronization in subsequent synchronization cycles until successful, ensuring that the access control status display is always up-to-date. Step Six: Device Alarm. When the alarm receiving module receives an abnormality from the access control controller, it will send an alarm signal via a pop-up window. At the same time, if an audible and visual alarm is provided, it will trigger an alarm and send an alarm signal to the administrator, so that the administrator can handle the situation in a timely manner and ensure the safe and stable operation of the system.
[0012] The benefits of this application are: 1. A permission management device and method adaptable to heterogeneous access control controllers: Through the design of a protocol adaptation layer, it can be compatible with various heterogeneous access control controllers with different communication protocols and data formats. This eliminates the need for large-scale modifications to existing access control controllers, reducing system integration costs and improving the system's versatility and scalability. 2. The permission management device and method adapted to heterogeneous access control controllers constructs a unified permission model, realizing centralized management and rapid allocation of user permissions, while supporting personalized permission fine-tuning; the real-time permission update and periodic synchronization verification mechanism ensures the consistency and accuracy of permission data, improving the efficiency and reliability of permission management. 3. Access control devices and methods adapted to heterogeneous access control controllers: Strict identity authentication and access verification mechanisms effectively prevent unauthorized personnel from entering the controlled area, avoid security vulnerabilities caused by incorrect or conflicting access configurations, and enhance the security of the access control system. 4. Access control device and method adapted to heterogeneous access control controllers: The access control device is equipped with a human-computer interaction unit, providing an intuitive operation interface, which facilitates management personnel to perform access control configuration, query and system management, reducing the difficulty of operation and management costs. 5. The access control device and method system adapts to heterogeneous access control controllers and records detailed access verification logs and operation logs, which facilitates management personnel to trace and audit personnel access and access control operations, thereby improving the standardization and transparency of management. Attached Figure Description
[0013] Figure 1 This is a schematic diagram of the system structure of the present invention. Detailed Implementation
[0014] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments: like Figure 1The diagram illustrates a permission management device and method adapted to heterogeneous access control controllers. The permission management device comprises a heterogeneous access control controller, an access control management system, and a user terminal. The heterogeneous access control controller includes a computing main control module, a communication module, an authentication module, a permission execution module, a status acquisition module, a storage module, and a power supply module. The access control management system includes a protocol adaptation management module, a permission engine detection module, a data storage management module, and a user authentication management module. The user terminal includes a human-computer interaction module, a permission configuration management module, a status monitoring and display module, and an alarm receiving module. The method of using the permission management device is to install the heterogeneous access control controller, connect it to other access control controllers, and use the user terminal for permission configuration, communication debugging, control and management of the heterogeneous access control controllers, and displaying their working status, thus achieving the need for unified and centralized management of multiple different access control controllers.
[0015] The communication module, authentication module, permission execution module, status acquisition module, storage module, and power supply module of the heterogeneous access control controller adapted to the permission management device shown are as follows: The main control module adopts a heterogeneous architecture of ARM+FPGA as the main control unit. The ARM processor is responsible for running the operating system and high-level software of the access control system, and handling complex business logic and data management. The FPGA is used to realize high-speed data processing and protocol parsing acceleration, quickly handle a large number of concurrent data requests from access controllers, and perform hardware-accelerated decryption of encrypted data. Through this heterogeneous architecture, the processing performance and response speed of the device are significantly improved. The communication module integrates an RS485 interface, a ZigBee wireless communication module, a Bluetooth communication module, and an Ethernet interface, connecting to a local area network switch. This enables communication between heterogeneous access control controllers and access management devices using different communication protocols. The communication interface unit integrates an adaptive bandwidth adjustment module, which automatically adjusts the bandwidth allocation of each communication interface based on network load and data transmission requirements. For example, when a large number of access control controllers are simultaneously synchronizing access data, more bandwidth is prioritized for interfaces with high data transmission volumes. Furthermore, the interface unit supports hot-swapping of communication protocols, allowing the addition or replacement of new communication protocol modules without interrupting system operation, thus improving the device's scalability and compatibility. The identity verification module employs a multi-channel verification method, including password verification, digital certificate verification, fingerprint verification, and device fingerprint generation based on the controller's hardware characteristics (such as a combination of MAC address and hardware serial number). The verification is compared with pre-stored verification information upon input. For newly connected controllers, a dual verification method of "initial access whitelist + behavior analysis" is used. If the controller's behavior conforms to the normal access mode, such as data request frequency and request content meeting specifications, access is allowed; otherwise, it is rejected and an anomaly log is recorded. The access control module employs spatial, temporal, and scenario dimensions. For example, it defines access permissions for a laboratory during weekdays (9:00-17:00) and the ongoing safety training scenario. Scenario tags (such as "safety training" and "equipment maintenance") are used to associate access control units, enabling more flexible access control. The basic access control module allows for setting access validity periods, including absolute validity (fixed time period), relative validity (e.g., valid for 7 days after authorization), and cyclical validity (valid Monday through Friday). The module can also adopt a tiered conversion strategy based on the importance and real-time requirements of access data. For urgent access updates (e.g., immediate revocation of permissions after employee departure), data conversion and transmission are prioritized using high-priority communication channels. For routine access data synchronization, data compression techniques (such as GZIP compression) are used to reduce the amount of data transmitted when network load is high. Furthermore, flexible data mapping rules are designed to address the differences in data storage structures among different access controllers, ensuring accurate writing of access data to the controllers. Status acquisition module; The status acquisition module acquires basic information of heterogeneous access controllers and collects information of their internal functional modules. For controllers with multiple communication protocols, it records in detail the priority, bandwidth usage and data transmission stability parameters of each protocol. For example, if a certain model of controller supports both TCP / IP and Bluetooth protocols, the emergency switching mechanism and switching threshold mode of the Bluetooth protocol when the network is unstable can be known through data acquisition. Storage module; The storage module adopts RAID disk array technology to achieve redundant data storage and improve data reliability. At the same time, it introduces a tiered storage strategy, storing frequently accessed permission data and operation logs on high-speed solid-state drives to improve read and write speeds; storing historical permission data and infrequently used configuration information on large-capacity mechanical hard drives; The storage media uses advanced encryption storage technology to encrypt the stored permission data and program code to prevent data leakage and unauthorized tampering. Power module; The power module is equipped with overvoltage and overcurrent protection devices and a UPS power supply to prevent power failures from damaging the equipment; it provides a stable power supply to ensure the normal operation of the equipment.
[0016] The access control management system shown, adapted to heterogeneous access control controllers, includes a protocol adaptation management module, a permission engine detection module, a data storage management module, and a user authentication management module. It is deeply customized based on the RT-Linux real-time operating system, optimizing the system's task scheduling algorithm and interrupt handling mechanism to ensure the real-time requirements of the access control management system. For example, high priority is assigned to permission verification and urgent permission update tasks to ensure these critical tasks are processed promptly. Simultaneously, the operating system's memory management is optimized, employing memory pool technology to reduce memory fragmentation and improve memory utilization efficiency. Specifically: Protocol adaptation management module; The protocol adaptation management module adopts a dynamic protocol optimization and intelligent learning mechanism management mode. Based on the historical communication data of the access control controller, it dynamically adjusts the protocol parsing and conversion strategy. When a certain type of protocol frequently experiences packet loss during data transmission, the system automatically optimizes the caching strategy and retransmission mechanism of that protocol module. At the same time, it supports online upgrades of the protocol adaptation layer, and remotely pushes new protocol parsing algorithms through the permission management system to ensure compatibility with newly emerging access control controller protocols. The software includes a permission engine detection module and a protocol adaptation layer. The built-in intelligent learning engine analyzes the communication data patterns of different access controllers to automatically learn and optimize protocol parsing and conversion rules. When encountering new communication protocols or variants, the learning engine can quickly generate adaptation rules by analogy and reasoning based on the characteristics of existing protocols. The core management software adds a permission simulation testing function, allowing administrators to preview the effects of permission adjustments before making changes and to detect potential permission conflicts or unreasonable permission allocations. A permission auditing module is also introduced to periodically audit permission allocation and usage, generate audit reports, identify potential security risks, and propose improvement suggestions. Furthermore, the software supports multi-user collaborative management, allowing multiple administrators to log in simultaneously for permission management operations. The system uses a locking mechanism to ensure data consistency and integrity. The data storage management module uses flash memory in its storage unit for long-term storage of various data from the access control system. The system stores user access data, access controller configuration information, operation logs, and other data according to a specific database structure, managed using a relational database. Access data is organized and stored according to user, role-based access groups, and basic access units for easy and quick querying and management. To ensure data security, the system periodically backs up the stored data. Backup data is stored on external storage devices and encrypted using encryption algorithms to prevent data leakage. The system also records backup operation logs, including backup time, backup data size, and storage location. When the access control device experiences hardware failure or data corruption, administrators can recover system data from the backup data using the data recovery function. During recovery, the system first verifies the integrity and legality of the backup data, then imports the backup data into the storage unit, overwriting the damaged data and restoring the system to normal operation. The user authentication management module establishes a mapping relationship between role and permission groups and organizational structure. When the enterprise's organizational structure changes, the system automatically adjusts the role and permission groups according to the new organizational structure. For example, after two departments merge, the role and permission groups corresponding to the original departments are automatically merged, and duplicate permission units are removed. At the same time, corresponding permissions are added according to the functional requirements of the new department. In addition, version management of role and permission groups is introduced to record the historical versions of each permission adjustment, which facilitates traceability and rollback. When assigning permissions to users, the system generates a permission recommendation scheme through machine learning algorithms based on information such as the user's position, historical access records, and permission configurations of other users in the same position. At the same time, it detects potential conflicts in the user permission allocation process in real time, such as multiple mutually exclusive access permissions within the same time period. When a conflict is detected, the system automatically prompts the administrator and provides conflict resolution suggestions, such as adjusting the permission time range or canceling some conflicting permissions.
[0017] The user terminal of the access control device adapted to heterogeneous access controllers, as shown, includes a human-computer interaction module, an access configuration management module, a status monitoring and display module, and an alarm receiving module, specifically as follows: Human-computer interaction module; The human-computer interaction module is equipped with a high-resolution touch screen and supports gesture operation and voice interaction; Managers can perform permission configuration and query operations through voice commands, such as "query Zhang San's permission information" or "add Li Si's access permission to the meeting room".
[0018] The access control configuration module sets up device addition and access control, as well as personnel addition and access control modes. Device addition and access control acquire basic information about heterogeneous access controllers through network scanning or manual addition. For each access controller, based on its communication protocol type, the appropriate protocol parsing and conversion module is selected in the protocol adaptation layer software, and parameters are configured to ensure normal data communication with the access controller. For example, for access controllers using the TCP / IP protocol, parameters such as IP address and port number are configured; for controllers using the RS485 protocol, parameters such as communication baud rate, data bits, and stop bits are set. This is all done within the core access control software. The system initializes and builds the permission model; defines basic permission units and creates role permission groups based on different user roles; associates actual users with role permission groups to complete the initial allocation of user permissions; the personnel addition and permission setting mode is as follows: when a new employee joins the company, the administrator logs into the permission management system through the user terminal; in the permission management interface, finds the user account corresponding to the new employee and associates it with the "ordinary employee group" role permission group, and the system automatically assigns the employee the permission set corresponding to ordinary employees; if the employee needs additional access to certain specific areas due to work requirements, the administrator can manually add the corresponding basic permission units for them in the permission configuration interface to achieve personalized permission allocation; Status monitoring and display module; The status monitoring and display module adopts a visual graphical interface to display the connection status and permission distribution of the access control controller in the form of a topology diagram, which makes it convenient for managers to intuitively manage and monitor the system; Alarm receiving module: When the alarm receiving module receives an abnormal situation from the access control controller, it will send an alarm signal in the form of a pop-up window. At the same time, when equipped with an audible and visual alarm, it will trigger an alarm and send an alarm signal to the administrator.
[0019] The specific steps of the method for adapting the access control device to heterogeneous access controllers are as follows: Step 1: Install the access control device of the heterogeneous access controller on site, connect it to the power supply, and connect it to the local area network switch through the communication module to ensure that the device can communicate with other devices in the network; and connect the heterogeneous access controllers with different communication protocols to the access control device through RS485 interface, ZigBee wireless communication module or Bluetooth communication module according to actual needs. Step 2: Install the user terminal on the administrator's computer or mobile phone. After installation, initialize the system, configure network parameters such as IP address, subnet mask, and gateway, and create user accounts and assign permissions. Step 3: Add devices and set access control and personnel access through the permission configuration management module; add devices by network scanning or manual addition to obtain basic information of the heterogeneous access controllers; for each access controller, select the corresponding protocol parsing and conversion module in the protocol adaptation layer software according to its communication protocol type, and configure the parameters to ensure normal data communication with the access controller; define basic permission units, such as "entry permission to Room 101, 1st Floor, Building A, Office Building, from 8:00 to 18:00 on weekdays" and "24-hour access permission to the parking lot entrance," etc.; according to different users... User roles are defined, and role permission groups are created, such as "Regular Employee Group," "Department Manager Group," and "Visitor Group," etc., and basic permission units are assigned to the corresponding role permission groups. Simultaneously, actual users are associated with role permission groups to complete the initial allocation of user permissions. When a new employee joins, administrators add the employee to the employee list through the user terminal, create a user account, and associate the corresponding user account with the "Regular Employee Group" role permission group. The system automatically assigns the employee the set of permissions corresponding to regular employees. If the employee needs additional access to certain specific areas for work purposes... Access permissions are configured by administrators who can manually add corresponding basic permission units in the permission configuration interface. When an employee's position changes, such as being promoted from a regular employee to a department manager, the administrator can modify the employee's role permission group to "Department Manager Group" in the permission management system. The system immediately generates a permission update instruction and converts it into a format recognizable by the relevant access controllers through protocol adaptation layer software, then sends it to the corresponding access controllers. Upon receiving the update instruction, the access controller executes the permission update operation, updates the employee's permission information on its controller, and feeds back the update result to the permission management system. The permission management system records log information about this permission update operation, including update time, operator, users involved, and access controllers. Visitor permission management is also configured. Administrators create temporary user accounts for visitors in the permission management system and assign corresponding basic permission units based on the visitor's access needs, such as permission to enter a designated meeting room within a specific time period. Visitors use temporary permission credentials to authenticate and request permissions at the access controller. After successful verification by the permission management system, the access controller allows the visitor to pass. After the visitor's visit ends, administrators can delete or disable the visitor's temporary user account and revoke their permissions in the permission management system. Step 4: After setup, the device operates automatically. When a person authenticates their identity at the access control controller using an access card or biometric identification, the controller encapsulates the person's identity information and permission request into a data frame and sends it to the access management device via its own communication protocol. Upon receiving the permission request, the access management device's protocol adaptation layer software converts the data frame into a unified format. The access verification module in the core access management software queries the corresponding permission set based on the person's identity information and matches it with the permission request. For example, if the user account corresponding to the access card held by the person belongs to the "ordinary employee group," and the permission request is to enter a certain floor of the office area, the access... The access control module checks whether the user's permission set includes access to that floor. If it does, it returns an instruction to allow access; otherwise, it returns an instruction to deny access and records the access failure information in the system log, including the verification time, personnel identity information, and access controller location. The access controller executes the corresponding operation based on the instructions returned by the access control device. If it receives an instruction to allow access, it controls the access control device to open, allowing personnel to enter; if it receives an instruction to deny access, it keeps the access control closed and can issue an audible or visual alarm according to the settings, while displaying the reason for the denial on the access controller's screen. During system operation, a dynamic adjustment mechanism for role-based permission groups is employed. This mechanism establishes a mapping between role-based permission groups and the organizational structure. When the organizational structure changes (e.g., departmental mergers or splits), the system automatically adjusts the role-based permission groups according to the new structure. For example, after two departments merge, the original role-based permission groups are automatically merged, and duplicate permission units are removed. Simultaneously, corresponding permissions are added based on the functional requirements of the new department. Furthermore, version management of role-based permission groups is introduced, recording historical versions of each permission adjustment for easy tracking and rollback. The system also utilizes intelligent recommendation and conflict detection for user permissions. When assigning permissions to users, the system generates a recommended permission scheme based on the user's job title, historical access records, and permission configurations of other users in the same job title, using machine learning algorithms. Simultaneously, the system detects potential conflicts during user permission allocation in real time, such as multiple mutually exclusive access permissions within the same time period. When a conflict is detected, the system automatically alerts the administrator and provides conflict resolution suggestions, such as adjusting the permission time range or canceling some conflicting permissions. The system employs a hierarchical permission data conversion strategy, two-way real-time permission update guarantee, and intelligent synchronization verification and prediction for permission data processing and synchronization during operation. The hierarchical permission data conversion strategy adopts a hierarchical conversion strategy based on the importance and real-time requirements of the permission data. For urgent permission updates (such as immediate revocation of permissions after personnel leave the company), data conversion and transmission are prioritized, and a high-priority communication channel is used. For routine permission data synchronization, when the network load is high, data compression technology (such as GZIP compression) is used to reduce the amount of data transmitted. Meanwhile, flexible data mapping rules are designed to address the differences in data storage structures among different access control controllers, ensuring that permission data is accurately written to the controllers. Two-way real-time permission updates ensure that, in addition to the access control system actively pushing update commands, the access control controller proactively sends a permission synchronization request to the access control system after detecting local permission data tampering (through data verification codes or digital signatures) or recovering from a hardware failure. Upon receiving the request, the system quickly responds and synchronizes the permission data, ensuring the accuracy of the controller's permission data. During the update process, a transaction mechanism is used to guarantee the atomicity of the permission update operation; if any step fails, all operations are automatically rolled back. Intelligent synchronization verification and prediction perform periodic synchronization verification. The system not only compares the consistency of permission data but also analyzes the changing trends of permission data. Machine learning algorithms are used to predict potential future permission changes, allowing for advance data pre-synchronization and reducing synchronization time during actual changes. For example, based on historical data, the system predicts the pattern of employee attendance permission adjustments at the beginning of each month and automatically pre-synchronizes relevant permission data before the beginning of the month. Furthermore, for controllers that have not undergone permission changes for a long time, the synchronization cycle is appropriately extended to reduce system resource consumption. The system also integrates multi-factor authentication, intelligent permission verification decisions, and access control with auditing to achieve permission verification and access control. The access controller supports combinations of various authentication methods, such as "card swipe + fingerprint" and "facial recognition + dynamic password." During permission verification, the combination of authentication factors is dynamically adjusted according to different security level requirements. For high-security areas, multi-factor authentication is mandatory; for ordinary areas, authentication methods can be flexibly selected based on user settings or system policies. Simultaneously, behavioral biometric recognition, such as the user's gait and card-swiping habits, is introduced as an auxiliary verification method to improve the accuracy of identity authentication and achieve multi-factor authentication integration. When performing permission verification, the permission management system considers not only the user's permission set but also current environmental factors (such as weather conditions and the flow of people within a given time period). The system uses information such as quantity and device status (e.g., whether the access controller is malfunctioning) to make more intelligent permission verification decisions. For example, in heavy rain, it can automatically open temporary access to emergency escape routes. When an access controller malfunctions, it can temporarily adjust the permission range of surrounding controllers to ensure normal personnel access, thus achieving intelligent permission verification decisions. The access controller can also be linked with other security devices (such as surveillance cameras and alarm systems). When permission verification fails, the access controller automatically triggers surrounding surveillance cameras to record video and sends an abnormal alarm to the alarm system. At the same time, it records detailed logs of each permission verification and access control operation, including operation time, personnel information, access controller location, verification result, and linked operations. The log information supports multi-dimensional query and analysis, facilitating security audits and event tracing for management personnel, and enabling the linkage and auditing of access control. Step 5: Access Control Status Display. The status monitoring display module uses a visual graphical interface to show the connection status and permission distribution of the access control controllers in the form of a topology diagram. This facilitates intuitive system management and monitoring for administrators. During the display process, the system initiates a permission data synchronization and verification process according to a set cycle. The system first retrieves a list of all connected access control controllers from the device management database, and then communicates with each access control controller sequentially to obtain its currently stored permission data. The permission management system compares the obtained access control controller permission data with its own stored permission data. The comparison methods include checking the number of permission units, the identifier of the permission unit, and the permission description information, etc. If a certain access control controller is found to be in violation of the system's rules, the system will immediately take action. If the access control controller's permission data is inconsistent with the system, the system automatically generates a permission synchronization command and converts it into a format recognizable by the access control controller through protocol adaptation layer software before sending it to the access control controller. Upon receiving the synchronization command, the access control controller updates its local permission data according to the command requirements and feeds back the update result to the access control management system. If a communication failure or access control controller malfunction occurs during the data synchronization process, preventing the synchronization operation from being completed, the access control management system records the log information of the synchronization failure, including the failure time, access control controller identifier, and failure reason, and continues to attempt synchronization in subsequent synchronization cycles until successful, ensuring that the access control status display is always up-to-date. Step Six: Device Alarm. When the alarm receiving module receives an abnormality from the access control controller, it will send an alarm signal via a pop-up window. At the same time, if an audible and visual alarm is provided, it will trigger an alarm and send an alarm signal to the administrator, so that the administrator can handle the situation in a timely manner and ensure the safe and stable operation of the system.
[0020] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any other way. Any modifications or equivalent changes made based on the technical essence of the present invention shall still fall within the scope of protection claimed by the present invention.
Claims
1. A permission management device adapted to heterogeneous access control controllers, characterized in that: The access control management device adapted to heterogeneous access control controllers consists of a heterogeneous access control controller, an access control management system, and a user terminal. The heterogeneous access control controller includes a computing main control module, a communication module, an authentication module, an access control execution module, a status acquisition module, a storage module, and a power supply module. The access control management system includes a protocol adaptation management module, an access control engine detection module, a data storage management module, and a user authentication management module. The user terminal includes a human-computer interaction module, an access control configuration management module, a status monitoring and display module, and an alarm receiving module. The device is used by installing the heterogeneous access control controller, connecting it to other access control controllers, and configuring access permissions, debugging communication, controlling and managing the heterogeneous access control controllers, and displaying their working status through the user terminal, thus meeting the need for unified and centralized management of multiple different access control controllers. Protocol adaptation management module; The protocol adaptation management module adopts a dynamic protocol optimization and intelligent learning mechanism management mode. Based on the historical communication data of the access control controller, it dynamically adjusts the protocol parsing and conversion strategy. When a certain type of protocol frequently experiences packet loss during data transmission, the system automatically optimizes the caching strategy and retransmission mechanism of that protocol module. At the same time, it supports online upgrades of the protocol adaptation layer, and remotely pushes new protocol parsing algorithms through the permission management system to ensure compatibility with newly emerging access control controller protocols. The software includes a permission engine detection module and a protocol adaptation layer. The built-in intelligent learning engine analyzes the communication data patterns of different access controllers to automatically learn and optimize protocol parsing and conversion rules. When encountering new communication protocols or variants, the learning engine can quickly generate adaptation rules by analogy and reasoning based on the characteristics of existing protocols. The core management software adds a permission simulation testing function, allowing administrators to preview the effects of permission adjustments before making any changes, and to detect any permission conflicts or unreasonable permission allocations. Simultaneously, a permission auditing module is introduced to periodically audit permission allocation and usage, generate audit reports, identify potential security risks, and propose improvement suggestions. Furthermore, the software supports multi-user collaborative management, allowing multiple administrators to log in simultaneously for permission management operations. The system uses a locking mechanism to ensure data consistency and integrity.
2. The access control device adapted to heterogeneous access controllers according to claim 1, characterized in that: The communication module, authentication module, permission execution module, status acquisition module, storage module, and power module of the heterogeneous access control controller configured in the permission management device for the heterogeneous access control controller are specifically as follows: The main control module adopts a heterogeneous architecture of ARM+FPGA as the main control unit. The ARM processor is responsible for running the operating system and high-level software of the access control system, handling complex business logic and data management. The FPGA is used to realize high-speed data processing and protocol parsing acceleration, quickly handle a large number of concurrent data requests from access controllers, and perform hardware-accelerated decryption of encrypted data, significantly improving the processing performance and response speed of the device. Communication module; The communication module integrates an RS485 interface, a ZigBee wireless communication module, a Bluetooth communication module, and an Ethernet interface to connect to a local area network switch, enabling heterogeneous access control controllers and access management devices with different communication protocols to communicate with each other. The identity verification module employs multiple verification methods, including password verification, digital certificate verification, fingerprint verification, and device fingerprint generation based on the controller's hardware characteristics. The verification is compared with pre-stored verification information upon input. For newly connected controllers, a dual verification method of "initial access whitelist + behavior analysis" is used. If the controller's behavior conforms to the normal access mode, access is allowed; otherwise, it is rejected and an anomaly log is recorded. The permission execution module employs spatial, temporal, and scenario dimensions, associating permission units with scenario tags to achieve more flexible permission control. Simultaneously, it sets permission validity periods for the basic permission execution module, including absolute validity, relative validity, and cyclical validity. Status acquisition module; The status acquisition module acquires basic information of heterogeneous access controllers and collects information of their internal functional modules. For controllers with multiple communication protocols, it records in detail the priority, bandwidth usage and data transmission stability parameters of each protocol. If a certain model of controller supports both TCP / IP and Bluetooth protocols, the emergency switching mechanism and switching threshold mode of the Bluetooth protocol when the network is unstable can be determined by data collection. Storage module; The storage module employs RAID disk array technology to achieve redundant data storage and improve data reliability. At the same time, it introduces a tiered storage strategy, storing frequently accessed permission data and operation logs on high-speed solid-state drives to improve read and write speeds, while storing historical permission data and infrequently used configuration information on large-capacity mechanical hard drives. The storage media uses advanced encryption storage technology to encrypt the stored permission data and program code to prevent data leakage and unauthorized tampering. Power module; The power module is equipped with overvoltage and overcurrent protection devices and a UPS power supply to prevent power failures from damaging the equipment; it provides a stable power supply to ensure the normal operation of the equipment.
3. The access control device adapted to heterogeneous access controllers according to claim 1, characterized in that: The access control management system's data storage management module and user authentication management module, set up by the access control management device adapted to heterogeneous access control controllers, are specifically as follows: The data storage management module uses flash memory in its storage unit for long-term storage of various data from the access control system. The system stores user access data, access controller configuration information, operation logs, and other data according to a specific database structure, using a relational database for management. Access data is organized and stored according to dimensions such as user, role-based access groups, and basic access units for easy and quick querying and management. To ensure data security, the system regularly backs up the stored data. Backup data is stored on external storage devices and encrypted using encryption algorithms to prevent data leakage. At the same time, the system records backup operation log information, including backup time, backup data size, storage location, etc. When the access control device experiences hardware failure or data corruption, administrators can use the data recovery function to restore system data from backup data. During the recovery process, the system first verifies the integrity and legality of the backup data, then imports the backup data into the storage unit to overwrite the damaged data, thus restoring the system to normal operation. User authentication management module; The user authentication management module establishes a mapping relationship between role permission groups and organizational structure. When the enterprise's organizational structure changes, the system automatically adjusts the role permission groups according to the new organizational structure. For example, after two departments merge, the role permission groups corresponding to the original departments are automatically merged, and duplicate permission units are removed. At the same time, corresponding permissions are added according to the functional requirements of the new department. In addition, version management of role permission groups is introduced to record the historical versions of each permission adjustment, which facilitates traceability and rollback. When assigning permissions to users, the system generates a permission recommendation scheme through machine learning algorithms based on information such as the user's position, historical access records, and permission configurations of other users in the same position. At the same time, it detects potential conflicts in the user permission allocation process in real time, such as multiple mutually exclusive access permissions in the same time period. When a conflict is detected, the system automatically alerts the administrator and provides conflict resolution suggestions, such as adjusting the time range of permissions or canceling some conflicting permissions.
4. The access control device adapted to heterogeneous access controllers according to claim 1, characterized in that: The user terminal of the access control device adapted to heterogeneous access controllers includes a human-computer interaction module, an access configuration management module, a status monitoring and display module, and an alarm receiving module, which are specifically configured as follows: Human-computer interaction module; The human-computer interaction module is equipped with a high-resolution touch screen and supports gesture operation and voice interaction; Administrators can configure permissions and perform query operations through voice commands; The access control configuration module sets up device addition and access control, as well as personnel addition and access control modes. Device addition and access control obtain basic information about the heterogeneous access controllers through network scanning or manual addition. For each access controller, based on its communication protocol type, the corresponding protocol parsing and conversion module is selected in the protocol adaptation layer software, and parameters are configured to ensure normal data communication with the access controller. For example, for access controllers using the TCP / IP protocol, parameters such as IP address and port number are configured; for controllers using the RS485 protocol, parameters such as communication baud rate, data bits, and stop bits are set. The permission model is initialized and constructed in the core software of the permission management system; basic permission units are defined, and role permission groups are created according to different user roles; actual users are associated with role permission groups to complete the initial allocation of user permissions; the personnel addition and permission setting mode is as follows: when a new employee joins the company, the administrator logs into the permission management system through the user terminal; in the permission management interface, the user account corresponding to the new employee is found and associated with the "ordinary employee group" role permission group, and the system automatically assigns the employee the permission set corresponding to ordinary employees; if the employee needs to have additional access to certain specific areas due to work requirements, the administrator can manually add the corresponding basic permission units for him in the permission configuration interface to realize personalized permission allocation; Status monitoring and display module; The status monitoring and display module adopts a visual graphical interface to display the connection status and permission distribution of the access control controller in the form of a topology diagram, which makes it convenient for managers to intuitively manage and monitor the system; Alarm receiving module: When the alarm receiving module receives an abnormal situation from the access control controller, it will send an alarm signal in the form of a pop-up window. At the same time, when equipped with an audible and visual alarm, it will trigger an alarm and send an alarm signal to the administrator.
5. The method for an access control device adapted to heterogeneous access controllers according to claim 1, characterized in that: The specific steps of the access control device adapted to heterogeneous access controllers are as follows: Step 1: Install the access control device of the heterogeneous access controller on site, connect it to the power supply, and connect it to the local area network switch through the communication module to ensure that the device can communicate with other devices in the network; and connect the heterogeneous access controllers with different communication protocols to the access control device through RS485 interface, ZigBee wireless communication module or Bluetooth communication module according to actual needs. Step 2: Install the user terminal on the administrator's computer or mobile phone. After installation, initialize the system, configure network parameters such as IP address, subnet mask, and gateway, and create user accounts and assign permissions. Step 3: Add devices and set access control and personnel access control through the permission configuration management module; add devices by obtaining basic information of the heterogeneous access controllers through network scanning or manual addition; for each access controller, select the corresponding protocol parsing and conversion module in the protocol adaptation layer software according to its communication protocol type, and configure the parameters to ensure normal data communication with the access controller. Define basic permission units, create role permission groups based on different user roles; associate actual users with role permission groups to complete the initial allocation of user permissions; When a new employee joins the company, administrators add the employee to the employee list and create a user account through the user terminal. The corresponding user account is then associated with the "Regular Employee Group" role and permission group. The system automatically assigns the employee the corresponding set of permissions for regular employees. If the employee needs additional access to certain specific areas for work purposes, administrators can manually add the corresponding basic permission units in the permission configuration interface. When an employee's position changes, such as being promoted from a regular employee to a department manager, administrators modify the employee's role and permission group to the "Department Manager Group" in the permission management system. The system immediately generates a permission update command and converts it into a format recognizable by the relevant access control controllers through protocol adaptation layer software, sending it to the corresponding access control controllers. Upon receiving the update command, the access control controller executes the permission update operation, updating the employee's permission information on that controller and feeding back the update result to the permission management system. The access control system records log information for each access update operation, including update time, operator, users involved, and access controllers. It also sets up visitor access control, where administrators create temporary user accounts for visitors and assign corresponding basic access units based on the visitor's access needs, such as access to a designated meeting room during a specific time period. Visitors use temporary access credentials to authenticate and request permissions at the access control controller. Once the access control system verifies the credentials, the access control controller allows the visitor to pass. After the visitor's visit ends, administrators can delete or disable the visitor's temporary user account and revoke their permissions in the access control system. Step 4: After the setup is complete, the device will run automatically. When a person uses an access card or biometric identification to authenticate their identity at the access controller, the access controller will encapsulate the person's identity information and permission request into a data frame and send it to the access control device through its own communication protocol. After receiving a permission request, the access control device converts the data frame into a unified format using the protocol adaptation layer software. The access verification module in the core access control software queries the corresponding access set based on the personnel's identity information and matches it with the access request. For example, if the user account corresponding to the access card held by the personnel belongs to the "ordinary employee group," and the access request is to enter a certain floor of the office area, the access verification module checks whether the user's access set contains access to that floor. If it does, it returns an instruction to allow access; if it does not, it returns an instruction to deny access and records the access failure information in the system log, including the verification time, personnel identity information, and access controller location. The access controller executes the corresponding operation according to the instructions returned by the access control device. If it receives an instruction to allow access, it controls the access control device to open, allowing the personnel to enter; if it receives an instruction to deny access, it keeps the access control closed and can issue an audible or visual alarm according to the settings, while displaying the reason for the denial on the access controller's display screen. Step 5: Access Control Status Display. The status monitoring display module uses a visual graphical interface to display the connection status and permission distribution of the access control controller in the form of a topology diagram. This makes it convenient for managers to intuitively manage and monitor the system. During the display process, the system starts the permission data synchronization and verification process according to the set cycle. The system first retrieves a list of all connected access controllers from the device management database, and then communicates with each access controller in turn to obtain its currently stored permission data. The permission management system compares the obtained access controller permission data with its own stored permission data. The comparison methods include checking the number of permission units, the identifier of the permission unit, and the permission description information. If the access control controller's permission data is found to be inconsistent with the system, the system automatically generates a permission synchronization command and converts the command into a format that the access control controller can recognize through the protocol adaptation layer software, and sends it to the access control controller; after receiving the synchronization command, the access control controller updates its local permission data according to the command requirements and feeds back the update result to the permission management system. If a communication failure or access controller malfunction occurs during data synchronization, preventing the synchronization operation from being completed, the access control system will record the log information of the synchronization failure, including the failure time, access controller identifier, and reason for failure, and will continue to attempt synchronization in subsequent synchronization cycles until the synchronization is successful, so that the access control status display is always up-to-date. Step Six: Device Alarm. When the alarm receiving module receives an abnormality from the access control controller, it will send an alarm signal via a pop-up window. At the same time, if an audible and visual alarm is provided, it will trigger an alarm and send an alarm signal to the administrator, so that the administrator can handle the situation in a timely manner and ensure the safe and stable operation of the system.